The Nation Is Losing Its Toolbox

Seakip18 Re:Cheap import junk

I found TSP the other month when cleaning up after stubbornly glued wall paper. I went with the TSP alternative due to no-rinse factor and, as another comment said, the environmental factor. Most of the stuff you might need is also in the building material area, not the cleaning aisle oddly.

more than 2 years ago

Solyndra's High-tech Plant To Be Sold

Seakip18 Re:this makes me itchy

6) Company B, having successfully fleeced the public initially, now set out a way to fleece the public....again/
7) Company B, reusing same political connections under Company A, convince gov't to buy Company B's wares.
8) Profit!
9) Use new monies to get policy makers to write restrictions that put your product/industry in a legalized monopoly.
10) Profit!
11) Become overleveraged and essential that you can then afford to make bad decisions without fear of recourse.
12) Hold industry/public hostage using "If we aren't saved, the public suffers greatly".
13) Get public monies again b/c you are too big to fail.
14) Profit!

Ok, that example is mostly a joke....mostly.

more than 2 years ago

University of Florida Eliminates Computer Science Department

Seakip18 Re:"What were you thinking?"

B/c if a professor doesn't publish, they're a bum?

more than 2 years ago

Adafruit's Open-source Wearable Platform, Flora

Seakip18 Re:Why Atmel?

With the Arduino, I can get a LCD + DS18S20 up and running in 20 minutes from unwrapping to code compiled and measuring temps. Part of it may just be where I'm at on the learning curve or maybe it is that easy.

Can you do this on the ARM platform? Not intending to troll, I'm flat out curious about the libraries and ease of use.

more than 2 years ago

OSHA App Costs Gov't $200k

Seakip18 Re:It was actually $467 for the Android version

When you have monthly deliverables, you get a pretty fast feedback loop. The code I write gets put in use pretty darn quick.

I'm not saying a manager keeping updated is a bad thing. I'm just saying that the frequent pings and requests for information can cause more harm than good, especially if a manager thinks they can get highly accurate and highly precise data every time.

about 3 years ago

OSHA App Costs Gov't $200k

Seakip18 Re:It was actually $467 for the Android version

I'm going to etch your comment onto something at my desk so that I will always remember it.

We were at the end a release and the two dev directors start hounding you "When will it be done? How much longer?", etc.

It gets to a point when you just want to say "It'll be done when it's checked in and code reviewed."

about 3 years ago

White House Wants New Copyright Law Crackdown

Seakip18 The damning text

Page 10 of the actual whitepaper.

Ensure Felony Penalties for Infringement By Streaming and by Means of Other New Technology: It is
imperative that our laws account for changes in technology used by infringers. One recent technological
change is the illegal streaming of content. Existing law provides felony penalties for willful copyright
infringement, but felony penalties are predicated on the defendant either illegally reproducing or
distributing the copyrighted work.2 Questions have arisen about whether streaming constitutes the
distribution of copyrighted works (and thereby is a felony) and/or performance of those works (and
thereby is a not a felony). These questions have impaired the criminal enforcement of copyright laws.
To ensure that Federal copyright law keeps pace with infringers, and to ensure that DOJ and U.S. law
enforcement agencies are able to effectively combat infringement involving new technology, the
Administration recommends that Congress clarify that infringement by streaming, or by means of other
similar new technology, is a felony in appropriate circumstances.
Recommendation: The Administration recommends that Congress clarify that infringement by streaming,
or by means of other similar new technology, is a felony in appropriate circumstances.

I like how "appropriate" is not spelled out.

more than 3 years ago

Microsoft Bans Open Source From the Windows Market

Seakip18 Re:Incorrect.

To me, this sounds like MS has no f'ing clue what they are doing as a whole. They're pushing open source via MPL in other areas with codeplex such as MVC.

Then crap like this happens. I gotta imagine that there are software folks at MS wondering why they still work there.

more than 3 years ago

Are You Sure SHA-1+Salt Is Enough For Passwords?

Seakip18 Re:Isn't salting to avoid similarities in hashes?

Gawker actually encrypted,from what I've read, their passwords, rather than store a hash of them. This is what allowed even folks with good passwords to become vulnerable to Gawker's idiocy. The encryption can eventually be broken, exposing everyone's passwords.

But yeah, assuming a global salt or non-salted usage, once you figure out the hash for user A, you can easily tell if any other users have that password. The salt isn't really a secret. It just tells the person with your password list "Good luck compromising a user anytime soon with your precomputed hash tables."

more than 3 years ago

The Elder Scrolls V: Skyrim Announced for November 2011

Seakip18 And the working is expected

Sometime in February 2012 after fans and Bethesda patch and finish the content!

I am actually pretty happy about this. I enjoyed morrowind and oblivion a lot and hope they can expand on the great stories just waiting to be told.

about 4 years ago

Are Games Getting Easier?

Seakip18 Re:Think before you speak

I think the issue with that is that it's not really making it any more difficult...just making it longer.

I agree with PA on this-Halo on Legendary is a chore.

There was one exception in Halo 3 where this wasn't true, during the New Mombasa highway.

more than 4 years ago

Code Repository Atlassian Buys Competitor BitBucket

Seakip18 Last Straw

That's it. I'm doing what others have done and blocking kdawson. This summary is crap and should never have been posted.

more than 4 years ago

Father of Java, James Gosling Unloads

Seakip18 I look foward to listening to it in full!

I browsed through the interview and hope I can listen to the podcast soon.

He says some neat things:

James Gosling: Various Oracle employees have been instructed not to wear them. I've noticed this is a great tshirt(the "Free Duke" shirt) to wear in big crowds around here because the seas just parts, 'cuz people are like, 'I don't want to be near that.' Which I find really funny. And the whole free java thing is kind of a weird history with me because Sun from day zero is an open source company and this whole weirdness that we have about open source was not a weirdness open source but a weirdness about the actors and the games in the drama.

James Gosling: Absolutely. I have this love hate thing with Google these days. They can get kind of creepy.

Moderator: Do you use the browser plug ins that prevent the ads and block and analytic stuff?

James Gosling: No. I mean, I sometimes do.

Some...well...things that I don't think I can get behind:

In the enterprise space, things like Cassandra and Voldemort and some of the NoSQL database. I've never got it when it comes to SQL databases. It's like, why? Just give me a hash table and a shitload of RAM and I'm happy. And then you do something to deal with failures. And you look at the way things like the NoSQL movement is. It's various flavors of large scale distributed hash tables and trying to deal with massive scale and massive replication, and you can't back up the database because no tape farm is big enough. And you find scale and reliability can fit together at the same time

and some interesting:

James Gosling: Well that's right, [they](Oracle) didn't own Java, but it just points out, and I don't know how to say it other than to say they were lying, duplicitous shits three years ago and by their turnaround, they're basically admitting that. Oracle is kind of a funny company because they take glory in that. They have no issues with being categorized that way. Some of their PR people might get a little uncomfortable with it, but up at the top, they deeply, deeply don't give a shit.

I'm still not sure how to regard Oracle right now, but I'm comfortable with the idea that Java needs a permanent and legal separate existence from Oracle.

more than 4 years ago

Mozilla Unleashes JaegerMonkey Enabled Firefox 4

Seakip18 Re:The Slashdot Firefox Paradox

Agreed. Even on mobile, it's much easier to go through comment threads than rely on javascript to handle it properly.

more than 4 years ago

Cooking For Geeks

Seakip18 Re:The staples

Where is the "+1 Delicious" mod option?

more than 4 years ago

AT&T Says Net Rules Must Allow 'Paid Prioritization'

Seakip18 Re:I kinda agree...

Think of it like a highway. If certain people pay to get to their exit first, you have to slow down to let them in and through.

Unless they specifically BUILD an exit for those higher paying folks. A Transit Authority never takes an existing road and turns it into a toll road. They build an entirely new infrastructure for that revenue.(Not sure if this is true...just makes sense).

We should see service improvement for extra pay, not maintaining the status quo and degradation.

more than 4 years ago

Dell Selling Faulty PCs

Seakip18 Re:Yep

I remember this exact issue!

Whenever we had an issue with these damn 270's, first thing we did was check the mobo.

It was incredibly easy to identify. The capacitors almost always had a domed top or actually leaked some dielectric fluid onto the mobo.

Dell was good in that the overnighted the mobo with a guy to install it the next day. It's not an excuse for Dell, but they did what they were supposed to.

It was actually a great learning experience for college-age me. I learned alot about software deployment scripts and all that fun stuff to build a stock of machines so that I could easily swap out a machine when the mobos inevitably failed.

more than 4 years ago



Boeing Dismisses Claims of Senior Engineer

Seakip18 Seakip18 writes  |  more than 7 years ago

Seakip18 (1106315) writes "An Senior Engineer for Boeing, Vince Weldon, has argued that their new 787 airplane is deadlier than normal, metal framed airplanes. To his credit, he has worked with composites since 1973. Boeing has denied his claims, insisting that their airplane testing has no dangers to merit his claims.

...Weldon alleges:
The brittleness of the plastic material from which the 787 fuselage is built would create a more severe impact shock to passengers than an aluminum plane, which absorbs impact in a crash by crumpling. A crash also could shatter the plastic fuselage, creating a hole that would allow smoke and toxic fumes to fill the passenger cabin.
-After such a crash landing, the composite plastic material burning in a jet-fuel fire would create "highly toxic smoke and tiny inhalable carbon slivers" that "would likely seriously incapacitate or kill passengers."
-The recently conducted crashworthiness tests — in which Boeing dropped partial fuselage sections from a height of about 15 feet at a test site in Mesa, Ariz. — are inadequate and do not match the stringency of comparable tests done on a 737 fuselage section in 2000.
-The conductive metal mesh embedded in the 787's fuselage surface to conduct away lightning is too light and vulnerable to hail damage, and is little better than a "Band-Aid."
An OSHA claim by Weldon for illegal firing was also denied. The company stated in the OHSA report that he was fired for threating his supervisor."

Seakip18 Seakip18 writes  |  more than 7 years ago

Seakip18 (1106315) writes "The Venezuela State Governement did not renew a license for it's oldest television station, RCTV, this past Sunday. The station was the nations longest broadcasting station for 54 years. After the license expired at midnight, a state-owned Television station, VTV, immediately took over and began broadcasting. The Gov't also begin filing complaints against Univision and CNN for the broadcasting of "a lie which linked President Chavez to violence and murder" and general defamation of President Chavez. The incident refered to is CNN's mistaken broadcasting of images and stories that appeared next to the name of Venezuela President, Hugo Chavez. The EU and US have both issued codemnations of the Venezuleas actions."



Working for Diebo-Errr...Premier Election Solutions

Seakip18 Seakip18 writes  |  more than 6 years ago

Hopefully, I don't get sued over this. But Anon be damned! The knowledge here is by no means guaranteed to be accurate or representative of any employee of PES or Diebold Inc.

I recently finished a stint working temporarily for the election this past week and, rather than get washed away in the story comments by posting too late, I'll just refer here. I'm also too damned tired to comment on the big threads. This should be public knowledge and I'm not revealing which state or it's agreements with PES it has.

So, without going in the nitty gritty details of where or who I am, I worked with Premier as a County Technician for their OS, OSX, TSX and automark machines.

This position acts as the PES lead in many of the counties that are very small. The rest, they complement the ACTUAL counties technicians and IT staff. PES techs are never meant to touch the actual equipment but act as a adviser/support person. Larger counties, the IT staff will be the one asking you the question. But that's not why you are reading. You want to hear about the machines and the software on them.

Common attributes of every unit are the printer. The OS(x) variants use a actual ribbon-impact printer while the TSx uses a thermal printer. The purpose of these units is to provide before and after reports that can be used to verify the election had no-preexisting votes. Before the first vote is put in the unit, the state may require the Zero report to be examined and signed to verify this as well as a totals report to verify the recorded results are thought to be accurate, again, depending on state.

The OS, or Optical Scanner is Die-I mean, PES's oldest model of electronic voting. It's a glorified scantron essentially. You fill in the dots on your ballot, run it in, it tabulates it and you get a paper trail. It uses a 90lb card stock and timing marks on the ballot to determine it's side and feed. You can actually insert the ballot any vertical oriented direction, which is neat. The memory card that it uses is also a relic of the past. It is a 128k battery powered memory card. It holds up to 10 ballot styles (IE-precinct 1, precinct 2...) depending on ballot length. The interesting part: Before "security" became an issue, data and transmission of the ballots to the central server in the county (more on that soon!) was all done unencrypted. Not that reporting totals aren't public record, but the way data was transmitted was via modem using a dial-up interface! No fancy RAS or the such. It wasn't till a firmware patch back in 2006 they implemented client authentication and secure SSL transmission to the unit. Some older counties, that can't afford or want to change, still use the older firmware.

The TSx is the touchscreen ballot system, the most criticized one on Slashdot actually. It runs on Windows CE with/without the Timezone patches and has two PCIMA card slots with a built-in modem. It features a "robust" access control systems and has 1024MB internal memory. It uses a 128MB flash card to load and store the ballots and results on. Newer versions also use openSSL from Nov 2007/Oct 2006, depending on which firmware you use. The most criticized feature of this unit is that there is no paper trail. You vote is abstracted, which already happens with every other system here, but some states do not require a ballot to be printed out of the printer on the unit. Hence, you vote is entirely abstracted. This can be a problem. The election backed up to the memory card and the main unit after every vote. The memory on both of them should never fail at the same time according to our training. IF it does...well......there's your .001% failure rate during an election unless the Logic and Accuracy test were not done. The only problems that paper ballots don't face of a similar type, such as a fire, is that smashing the unit will probably get rid of all the votes. Other than that, the only time the unit SHOULD interact with something besides a voter is when the election memory card is loaded, any of the access cards are loaded or the unit dials up results.

Access control on the TSx needs an explanation on it's own. You see, when the TSx is setup, it can use no voter card or require a votercard. If not used, anybody can walk up to the machine and cast a ballot. If it does use a votercard, it is used one time then erased, requiring the card to be setup again. Each TSx, say, in a county, is keyed to one x-bit key that all resulting encoders and TSx/OSx units are keyed to. In addition, supervisor and Central Admin(if using a new firmware) are also created with that key. This keeps you from walking up with a Central admin card on election day and erasing all of the results. Your card hasn't been created with that key, so no machine or encoder will recognize it.

You load keys onto encoders and machines with something called a Security Key card. It's sole purpose is to hold the security key for each election and be loaded onto the necces. machines and encoders. You lose this card and you are going to be royally fucked. You see, with this card, you can upload the key back to a key card creator tool and then create any number of supervisor or central admin cards with that key. Then, you can access any voting machines various modes such as the central admin mode. With older firmwares, you could access the dreaded "unload election" with just the supervisor card, which is also needed to close the polls. The central admin card fixes that glaring defect. Imagine how many old ladies with that card messing with the TSx doohickey.....*shudder*.

Anyways, that leads me to my next point, lose the central admin card and you are royally fucked. This card allows you to reset or unload the election or load up a previous archive of the election. Now, the intelligent person will point out "Hey, it doesn't matter if you unload/reset the election. We can use that archive to restore to the last vote." True, but any intelligent person also knows taking down one machine isn't enough but a distributed attack during the middle of polls and yikes.... It also allows you to change the security key on the unit for access control. You see, if you try using a voter/supervisor/CA card that isn't keyed right, it will reject the card. Keep trying to insert it, and the card is permanently disabled. Change the key to something that the county can't access...they won't be able to vote with that machine or change the key to right settings. That machine will be knocked out for the election since only reformatting it will work.

If voter cards are used, when a voter needs to use that machine to vote, the encoder that every precinct will have holds whatever ballot style the voter needs. The voter card is inserted to the encoder, the proper ballot style selected and then loaded. The voter is given the card, then they go over to the machine and vote. If the vote is canceled, timed out, or cast, the card is erased and will require to be loaded again prior to voting. Your blank ballot is the card and the digital bits on the memory are the ballot box.

The OSX is the digital cousin of the OS from the TSx side of the family. It uses It still reads your paper ballot but instead of scantron, it makes a digital image of the selection for a race, say president and counts the bubble. The biggest problem this faces is that it relies very very heavily on correct ballot lengths and what not. 55% of the problems on election day dealt with improperly printed ballots that were not perforated correctly or printed properly. The OSx can be set to be very choosy about tolerances and changing them on election day to allow slightly "out of bounds" ballots is unacceptable. It sports the same Mobo as the TSX so it will also have two PCIMA slots and uses the same memory card. It also uses the security keys but only for being able to recognize the supervisor/CA cards.

All of these machines have two ways of uploading their data. The X-variants, since they are Windows CE, use RAS to connect the central server and upload the results. They can do this via ethernet or modem. The OS must use a dialup service or serial port.

The transmission of the results and the authentication that said transmission was authentic is the bread and butter of criticisms. Besides attacking the server directly, being able to intercept and rebroadcast the "correct" results is the easiest way to steer an election. The training obviously did not deal with this, but I surmised it from various areas, such as each printout including a SHA key(except for older OS firmwares.) and the server's receiving settings.

Before the firmware update, the only thing I can surmise is that there was either no encryption or that there was a standard key used to decrypt it. If you want to intercept the transmissions and rebroadcast, it would be trivial for a phreaker who knew how the units transmitted data. Simply have the phone lines connected to the server re-routed to you and then rebroadcast your results in the correct format. A man-in-the-middle attack easily done.

Since then, it looks like Public/Private security keys have been implemented. The data is transmitted using x-bit keys with the RSA-SHA1 or SHA2. If you want to authenticate each client, simply generate the keys on the server and load them onto the memory cards that are in the unit. Your trust network is already known before hand and you can safely discard any other transmissions. Of course, this all comes down to one point of failure....the GEMS server.

GEMS stands for Global Election Management System. It allows a county to setup, organize, layout and print ballots. It allows precincts, vote centers and machines to be created and managed. After loading up the machines, it will receive results from said machines on election night. You set up how many ever OS, TSx, OSx machines are at a precinct. This requires MS Server '03 at least. The way the server receives results is via a "digibox" multiplexer connected to how many ever modems the county wants to support. The only connection to the outside world the server has is those modems.

You want to to bring the election results to a crawl? DOS phone line attack all of those numbers. The county will be forced to bring every machine in and manually upload the results. Not too bad for a small county, but when you have one GEMS server and, say, an entire metropolitan area....yeah. It can get really bad just with all the units trying to phone it at once. Imagine what a concentrated denial attack could do. Counties can mitigate this by having only one machine type for every machine in the precinct upload the results via accumulating, but the issue still stands.

The last and most ancient way of messing with the election is manually entering ballots into the GEMS server. Keep in mind that it would be fucked up if you could actually get away without anyone noticing, but you simply click on the machine that "couldn't" get the right results and add the ballots and their results in. GEMS keeps an audit log of every action, such as that, but I guess if you can access the GEMS server to do this, logs aren't an issue.

What would also be interesting is if a bug were exposed in the dial-up or RAS setup of the GEMS server. I shudder if a buffer overflow that brings a machine down is executed on every machine across the states......yikes. Again, the solution is to disconnect the server from the outside and manually upload results. If you can compromise the server though, and handle working over speeds of less than 56k, all the better.

You'll notice I didn't talk about the automark. Simply put, no one is going to be carrying out fraud on a machine that marks ballots for the severely disabled. The machine is kept around more for ADA compliance than actual use. Most ADA folks either get assistance from poll workers/watchers or use the touch screen. The ballot is counted in any way. It just marks it for the OS(x) to read.

Lastly, the techs supporting these machines are often those out of work, too stupid to get an actual job, or can't afford retire(they're were a few guys who fondly remember "Ma Bell" years). There are full-time employees that serve as election day techs, but most onsite or telephone support is done by guys who are contract via placing service. That is, if the county pays for those services. At the very least, they'll probably keep the nation-wide tech support.

Who you get is whoever is available a week before the election for training. I was able to do it since, hey, I had some free time and this sounded interesting. Read an earlier post if you wonder why.

Pretty much, as long as you can do the most basic of basic call center support, you can do this job. Not well or even acceptably, but you can do the job. The testing to "weed out" the worst involves an open book test that is the exact same as an earlier practice test. We had someone manage to make less than 80% on the test.

Well, I hope you enjoyed reading this and understand more about the voting machines you use.

If you want to start making a difference and help keep these machines from breaking or other stupid stuff, PLEASE PLEASE volunteer to be a poll worker. The people that do it now are often retirees that are 60+ years old and have very limited technical experience.

I know the pay isn't great and you'll have to take vacation to do it but, at some point, us younger folk HAVE to help out. When you raise concerns to the Supervisor of Elections, you will be someone who has actually worked with the machine, not some whiny voter. Plus, you'll get some great food.


I give up

Seakip18 Seakip18 writes  |  more than 6 years ago

Ok. I'm changing locations to Tallahassee, FL for personal reasons. This usually means changing jobs.

Problem- At my current state job, I've got a lot leeway and chance for telecommuting most of the month. I don't mind coming back a week a month. Plus, it's $54K(after insurance) for a fresh college grad living in a place with low cost of living. The past month and a half of job searches with Gov't, hospitals, and some private companies has yielded two interviews with them declining.

Thoughts- There is no guarantee I'll be able to keep this current job but why should I leave if something can't be worked out? The problem has been rationalizing how big of a paycut and what position to settle for. Even if my current job kept me on, should I keep it?

What should a College Grad with about 2 years of generic IT experience(Some programming, some System Admin'ing, lots of team communication and a little team collaborative work) and year of Financial Systems Programming look for and expect in terms of pay?

Met with my boss, who talked to the big boss. They approved some telecommuting and wanted to discuss a small pay bump to offset commuting. Only one problem. They want me to stay where I am most of the month. I, at most, think I could handle 2 weeks for a few months. Face it: It'd be living two lives and the stress a relationship would take, would almost certainly negate the entire purpose for moving.

I'm touched though. The fact an employer is so willing to go this far with me at such a young age/experience. I doubt I'll probably ever find an employer this accommodating, even if it was myself!
I mean, if the company wants to pay someone to fill a desk at the office, they have the full right to that.

Me? I've got nothing to lose. I'm moving regardless.

I told my boss that, at most, two weeks a month would be how much time I spent at the office. If they can work with that requirement, great. Heck, even it's only temporary while they find a new candidate. She was kind of confused and told me to work out what I'd need in terms of commute charges and she would think about the two weeks part. Hope it works out.

Update: See http://tech.slashdot.org/comments.pl?sid=652277&cid=24683589

Update: 8/25/08

Telecommuting has been taken off the table due to office politics and instead, 10hour for 7 days twice a month is being offered. No compensation will be offered till the arrangement has been tested. The remaining 20 hours a month will be worked at home or in the car.

Not sure about this. Maybe I will, maybe I won't.


Letter to my congressman on FISA

Seakip18 Seakip18 writes  |  more than 6 years ago

Congressman Michael T. McCaul
131 Cannon House Office Building
Washington DC 20515
Dear Congressman McCaul,
I am XXXXXXX, a contract Programmer under the hire of XXXX D.O.T. that still votes in your district, that likes to keep up on the latest tech news. However, when glancing through one of my many technical news sites, I came across H.R. 6304, the FISA Bill. As I have been following the bill's progress for many weeks now, noticing that the center issue with the bill deals with telecom immunity for domestic surveillance and spying. I personally find this repulsive in many ways. The idea that any organization may be granted immunity for illegally listening to their very customers is scary enough. The fact that our government will move to protect the safeguard the liability of a company before those of it citizens scares me even more. I cannot even begin to understand WHY or HOW the government can begin to justify illegal activities as safeguarding the American interests and citizens. I do understand that America must keep its surveillance and information gather capabilities, but at the cost of allowing the President to dismiss any and all lawsuits that have legitimate reasons by American citizens.
This is all old news though. What I am more interested in is hearing YOUR reasoning for voting on this bill. How do you know that the President of the United States will not abuse the power granted him with this bill? How do you know that U.S. citizens that are innocent will not be monitored illegally? How do you know that you are doing the right thing by circumventing the rights of The People and protecting the interests of companies?


Meanwhile, back at the ranch

Seakip18 Seakip18 writes  |  more than 6 years ago

Going through my education, I was never once sat down in front of a circuit or such and explained exactly how the resistor and diode did theirs jobs. Heck, getting my bachelor CS degree, we focused on what the CPU did without ever seeing one out of it's case.

Lately, I've had this obsession with making up lost time. I've been desperately trying to find an online resource to start from scratch on. So far, I've pieced together enough skills solder and work with a controller. But as far as really digging into Ohm's law and designing a circuit that will allow a controller to process input from analog reading such as basic resistances, are a mystery.

It's pretty frustrating for now, but I'll overcome my ignorance and find understanding.

