Monday, May 12, 2008

Back-to-myMac brings the Mac Back

An interesting story coming out of White Plans, NY talks of a woman who's apartment was burglarized with close to $5,000 of electronics stolen including a couple of Apple laptops and how she was able to help catch the culprits as well as get her stuff back.

The thief apparently was using the computer and one of the victim's friends (who knew her laptop was stolen) noticed a few days later that she was logged in (presumably on some instant messenger) and called her.

The woman was able to use Apple's "Back To My Mac" application on another computer to get control of her stolen laptop and activated the camera in the laptop, taking pictures of the thief. A quick review with her friends and they figured out that the guy was a friend of a friend of one of her roommates who had been at the apartment a few weeks before.

A quick call to the police and they arrested the thiefs as well as getting back most of the stolen electronics.

I'm guessing that she's happy she wasn't one of those self conscious users who tape over the camera to keep something like this from happening and I'm not at all worried about the thief's privacy violation. Of course, the chances of other thiefs really being this stupid to make use of a stolen computer without wiping it clean are probably pretty low, so I'm not sure how often this kind of think can happen (but you know they still do give out the annual Darwin awards).

Tags : / / / /

Thursday, May 01, 2008

I've been cleared

I've joined the US's Registered Traveler Program. Clear (a subsidiary of Verified Identity Pass Inc.) operates the local facility here at Dulles, so I joined their network.

In exchange for submitting to (and paying for) a background investigation and biometric authentication (fingerprint in my case, though they also had iris scanners there it wouldn't work on me) you get to have a very short security line -- though you still go through the same "take-off-your-shoes" security process. They seem to be working on getting some form of scanner approved for scanning shoes while they are still on your feet, but recently they did not pass the TSA testing that was done.

The cost of the program from Clear is $128 (at least for the first year -- they weren't clear on what subsequent years will cost). $28 of that goes to the TSA for the background investigation and the rest to Clear (of which, I'm sure, a portion goes to the airport). You can extend that by a year when you use a discount code (and the party who gave you the discount code also gets a year -- so there's something in it for everyone. My discount code, if you're interested in getting a free month added to your subscription is: DSCAM1142273 - use it to your hearts content.

One might ask why I would join the program given that I was already a United 1K member and able to use the premium passenger lines at Dulles. There were several reasons including:

  • The premium lines are only available when the flight you a premium member on the flight you are leaving Dulles on. I have seen the staff turn away United premium members when they were booked on some other airline where they did not have status.
  • Even with the premium lines, you can still get stuck in a slow line (I have waited as long as a half hour in the line) and if I'm tight for a flight, that can be too long.
  • The program is available at other airports (though I'm not sure if I'm only able to use it at Clear supported airports or any registered traveler airport) and in particular, San Jose Airport -- which has no premium lines and where the line for early morning flights can be crazy long -- is one of the Clear supported airports.
  • I travel often enough that the time savings, even if small, is worth it (in my opinion).

Of course, about 2 weeks after signing up (and paying), I received an email from Marriott (where I am a Platinum member, of course) with the following offer:

So, after I signed up I found out I could have gotten it for free. I called them expecting to get the "Gosh, I'm sorry, but it's too late now" and was pleasantly surprised to hear "No problem sir, we'll just extend you another year". Good deal!

You might be wondering what I think now that I'm a member. I've used it on 5 of my last 8 flights (Portland International Airport does not yet participate in the Registered Traveler program), nor is it available at foreign airports. In Dulles it's down with the employee security line it workes great -- in fact, the people from Clear are almost too helpful (trying to help gather things ready to go through security). I've timed it with another person who was going through the premium security line and I was about 10 minutes faster then them at a time when the lines were short. In San Francisco the clear area opens at the front end of the regular security line, emptying directly into the xray scanners (so, essentially, you jump to the front of the line).

One thing on the negative side, if you're traveling with people, you can't bring them with you, so either you have to go through the regular lines, or you have to split up. That already happened to me when I was traveling with George on our way to the European Identity Conference in Munich -- that's how I figured out that there was a 10 minute difference (it was an experiment!). Not sure what I'm going to do when I am traveling with my family to England & Ireland this summer -- I don't think my wife will be as easy going about it as George was :-).

All-in-all, I'm a happy customer..... And remember, if you want to sign up, use the discount code "DSCAM1142273" so we both can get a free month :-).

Tags : / /

Monday, February 18, 2008

Updated Liberty Open Source

I've updated my Liberty ID-WSF Open Source Toolkits again. This time to reflect the minor changes made in the Advanced Client specifications as they were finalized within the Alliance.

For those of you who aren't familiar with this code, I have two toolkits available -- a C++ client and an Axis1/Java Server -- which implement the Liberty ID-WSF protocols (both the basic framework and substantial portions of several services).

This new release of the toolkit does not add new functionality -- it only brings the code up to match the final specifications.

Have fun!

Tags : / / / / / /

Saturday, February 16, 2008

What's wrong with this picture?

I went to login to my discover card account to review my account activity (something I try to do on a regular basis). Using a bookmark (to make sure I don't accidentally enter a typo that gets me to a hackers site -- plus I'm lazy and a single click is easier than typing in the URL), I get to the web site and I notice something that isn't right (in my opinion). Take a look at the picture below and tell me if you see it before reading past it.

Look at the URL. It's non-SSL (http: vs https:). When I noticed that, I figured that somehow my bookmark was messed up, but looking at the bookmark, it does specify https:. What happens is that Discover is redirecting you from the SSL endpoint to the non-SSL endpoint. This happens with IE and with Mozilla whether directly connected or through a proxy server, so it's clearly something done on the server and not a side effect of the client.

That wouldn't be all that bad if Discover just had a link on the home page directing me to a login page that was SSL protected. That isn't the case. The home page prompts for the user's credentials. Now the technical people out there might say that the data from the login form is probably submitted via an SSL endpoint so the data is protected. However, without looking at the source code, the user can't know that.

In addition, since the URL itself isn't protected, the user (me in this case) doesn't have any way to know that they are actually talking to Discover. This could be a MITM phishing site.

So, if you do go to Discover's site to view your account, I suggest that you select the login link in the upper right corner before you enter your credentials. This will bring you to an SSL protected page where you can verify that the host you are talking to is discovercard.com and not some MITM.

Tags : / /

Monday, November 19, 2007

Time Machine

One of the current "joke" emails flooding the internet is an email showing pictures from a 1977 JC Penny catalog. Given that the email referred to "blog fodder" I decided to search around and I've found the original post. Definitely worthy of a read.

Strap In, Shut up and hold on -- we're going back.

If you remember this stuff... If you wore this stuff... I'd suggest that you not share those identity attributes -- unless you don't mind being the butt end of many jokes for the rest of your life.

Tags : /

Thursday, November 15, 2007

Anti-gulllibility training

I've always felt that one of the most important tasks for a parent is to teach their kids to not be gullible. I routinely work on such training with my kids. In fact the other day, I was way into the story about how Los Angeles schools, while not getting many snow days, do get closed for bad hair days. Unfortunately, while my daughter was well into the "realy?" stage, my wife piped up with "They do not!" cutting me off at the knees.

Nothing is a better example of the importance of such training than the comment in response to Paul's revealing post about Microsoft's Identity Assistants.

So parents, take this as a warning. Train your kids in anti-gullibility before they make a fool of themselves publicly.

Tags : / /

Wednesday, November 07, 2007

Madsen's Lemmas (or is it Lemmi)

Paul writes about attributes and how they won't be trusted for self assertion when the value of the attributes is used to distinguish levels of service.

In the context of any given application, a Relying Party will be unwilling to accept a self-asserted identity attribute without verification if there exists the possibility of differentiated advantage to the user in claiming one value for that attribute over another.
And follows with the corollary:
For any given identity attribute, there exists an application context in which there can be differentiated advantage to the user in claiming one value for that attribute over another.

Combining the two would make one think that Paul is arguing that self asserted identity attributes will never be accepted, but I'm pretty sure he didn't mean that.

In any case, I think there's another side to this puzzle in that the self asserted attributes can be accepted and used when the result makes it useless for the user to lie about them. If I order something with Paul's credit card, name, address and phone number, it generally will be accepted, the transaction will complete, and the vendor will ship the product -- it will just end up at Paul's house rather than mine, so I won't benefit from it (but I bet Paul was surprised when those enlargement pills showed up :-)).

So I would write the lemma more along the lines of:

There exist some set of cases where a Relying Party provides such differentiated levels of service that they will require third party attestation and/or confirmation of attributes in order to enable access to such differentiated levels of service.

PS. Paul, if you need to fake your IP address to make it look like you're coming from the US, let me know... I can give you access to my proxy server (without, of course, any guarantees as to snooping on the traffic :-)).

Tags : / /

Friday, November 02, 2007

Living without flash....

Back in March, I wrote about finally succumbing to the need for add blocking when flash adds on several sites were measurably impacting the performance of my system. When I reloaded my system I decided to forgo installing the flash player as my solution as the add blocking software was still kind of a pain.

Well, after a month or so of living without a flash plugin it seems I have to reverse my decision. Too many sites out there are totally unusable without flash. Many use it as an integral component in their site navigation (try researching Dish Network's offerings or look at SciFi's channel info (2/3rds of the home page is blank with "this section requires flash")... Others use it for processing particular functions (I can't us discover's secure credit card number generator because it only works with flash, I couldn't order my daughter's school yearbook from Jostens because the required personalization step requires flash with no alternative).

While all this glitz is nice for the marketing guys, I think that this is a bad thing. Especially when you consider that flash doesn't work all that well for accessibility (just imagine the blind person trying to make sense of the glitzy flash driven site navigation system). The Web Accessibility in Mind folks have a good article on accessibility programming with flash but they note that it's hard to do well.

My suggestions:

  • Never use flash for site nagivation. Javascript works well enough.
  • If you do use flash, provide reasonable alternative, keyboard based, means to obtain information from your site.
  • Evaluate the accessibility of the information and make use of the suggestions provided by WebAIM.

Ideally what I would like to see is an option in Firefox to manually enable flash processing on a site by site basis -- those sites that abuse the privilege by writing CPU intensive flash apps would be blocked, while the more typical mundane implementations could be allowed.

BTW - Given that no browser includes flash out-of-the-box (it's always an add-in plugin as far as I'm aware) I now have some good ammunition to use when I run up against those that resist authentication models requiring software on the client.

Tags : / / / / / / / /

Monday, October 22, 2007

New Gadget #13

My latest gadget is an update on a previously reported gadget.

This week I bought the latest and greatest Western Digital Passport external hard drive. A drive with a honking 250GB of space on it in the same packaging that my older 120GB and later 160GB drive used. In fact side by side with my prior 160GB drive you can't tell which is which:

Interestingly, they came out with this quick enough that they are still using the 160GB retail packaging with just a sticker over the 16GB on the front of the package. When I first looked at the back of the package (which listed only 120GB and 160GB) I was worried about a bait/switch from the retailer. However, that wasn't the case, it was a real deal.

The drive comes formatted with a FAT filesystem and has software for doing automated backups and synchronization with your primary hard drive. I immediately reformatted it for NTFS so I could use encryption and such on the drive. I don't need the backup or synchronization stuff as I use this drive as an extended primary drive rather than a backup drive. I use rsync to backup my system (including the WD drive) to my server regardless of my location (remote or at home).

Some who have used this device have complained about the fact that it sometimes won't work in their USB port. WD does document that it requires a full power USB port (though I can't find any documentation on exactly what is a full power USB port and how do you know you have one). I have had problems when I plug this device into some ports and found that on my laptop only one of the ports works reliably. Even the ports on my external powered hub are not sufficient to power the device alone. So when at home using the hub, I use a Y cable that grabs power from a second USB port to power the WD drive. I'm not sure where I got the cable, it was lying about in my USB cables collection, but WD does sell one.

The only other thing is that I suggest you buy the slipcase sold by WD to protect the drive when on the road. I had one lying about from my 160GB drive, so I just used that one.

Tags : / / / /

Sunday, October 21, 2007

Subversion end-of-line style

In my work with the Liberty Alliance, I'm the editor for several documents in the upcoming Advanced Client specification set. We use subversion as our source code revision control system.

Recently, when I was working on a new draft of the specs and committing a set of files that included a number of Visio drawings and the equivalent Encapsulated Postscript file images, I ran into problems. After all the files were uploaded during the commit, which failed with the error message:

svn: File "xxx.vsd" has inconsistent newlines svn: Inconsistent line ending style

A quick look at the file and I saw that the files had the typical windows line terminator CRLF rather than the UNIX typical LF. So I hand edited the file removing the CRs and tried the commit again. The same thing happened just with the next file in the list. So clearly this was going to go on for each file. So I did what any other UNIX weenie would do -- entered a one line shell script for loop on the command line using tr to delete the CRs in each file.

This got me past the problem and the commit succeeded. However, I was not totally satisfied as I wasn't sure that if they could be edited in Visio with these changes. So I dug a bit deeper into the problem looking into Subversion.

It turned out that subversion has attributes on files, one of which is "svn:eol-style". In this case, the files I was working with had gotten this attribute set to "native" which on the UNIX system I was on would be "LF". Not good for a file from Visio. I thought about changing the svn:eol-style to CRLF which would get around my specific problem at this time (until Visio changed their file format), but the better solution ended up being to just delete this attribute on the file with the following command:

svn propdel svn:eol-style *.vsd *.eps

Then I copied in the files from my Windows partition (where they still had the CRLFs) and committed the files without a problem.

Tags : /

Tuesday, October 16, 2007

Checking in too early

Like most airlines, United has, and strongly encourages the use of, an online check-in tool so that passengers can check-in for their flight before leaving home. This is seen as a win-win situation for everyone. United gets the user to do the manual labor of checking in and paying for the paper stock for printing the boarding pass while the user gets to avoid check-in lines at the airport.

I am a big fan of using this and typically check in near the limit of 24 hours before departure. I check in this early in part so that I don't forget to check-in in the mad rush out of the house on the day of my flight and in part so I can check to see if there's a better seat available at check-in.

However, this has led to one problem. On several recent flights, I was upgraded sometime between my early check-in and my departure for the airport. Because I was already checked-in in coach, I was unable to select a seat in the first class section. Theoretically I should be able to un-check-in and then re-check-in, or I should be able to get the customer service people to do the same for me, but neither worked and I had to wait till I got to the airport and the gate agent opened the flight at the gate (even the Red Carpet Club agents were unable to help me).

Moral of the story: If you're on the upgrade list, don't check in till you're close to leaving for the airport.

Update (10/21/07): Not learning from my own mistakes, I checked in around 11:30 PM the night before a flight to Tokyo as it appeared that there was no chance that it would clear before leaving for the airport in the morning (it was a 12:41PM departure). Of course, I was wrong and the upgrade cleared at 5:03 AM. But, since I was already checked in, I couldn't select seats in business class. Checking the site (by the usual trick of trying to purchase a business class ticket) showed that there were still 4 seats open including a coveted aisle seat (8D). By the time I got to the airport and checked in, the only seat left was 13E (a middle seat). Hopefully you'll learn from my mistakes better than I do.

Tags : / / /

Sunday, October 14, 2007

A broken Washer

This is a long story, feel free to just cut to the end.

A little over a year ago, we bought one of Sears top-of-the-line washing machines (the Kenmore Elite Oasis Canyon) for several reasons including that it was EnergyStar compliant while also being very large (so we could do our laundry in less loads while saving energy).

We really like the washer. It does a great job on our clothes, does it quickly, and does lots and lots of clothes at the same time, while also being very efficient at doing small loads.

However, we didn't like the fact that the thing just up and died mid-load with no sign of life in it. None of the lights were lit, none of the buttons did anything. On top of that, the lid was locked and there was nothing I could do to unlock it, so our clothes were stuck in there. Power cycling it did nothing (though I was able to use a meter to verify that it was not only getting power, but also consuming some small amount of wattage). Just in case you're wondering, no, the there was no surge on the line as the weather was clear (we're in the middle of a drought) and I have UPSs all over the house which beep like crazy for any power line problems -- none of that happened, so I'm pretty convinced it was not a surge.

Of course, the warranty was over (1 year) and, given that it was a top-of-the-line system I thought it wouldn't be necessary to buy the extended warranty (especially since they almost always are a waste of money). So the repair was going to be on us.

We called Sears Home Repair and they couldn't schedule someone to come out and fix the washer for 2 weeks. When he did get here, he determined that the electronics module behind the console was bad, ordered a replacement and scheduled someone to come out and install it (another 2 weeks later). This at a cost of $346.77.

The part came in a few days and since I didn't want to wait another week to get a working washer (we had already been to the public laundromat once) I tried to install it (something not all that unexpected if you read my blog). However, the cover over the board was screwed down with 3 screws and had 2 locking tabs. I was unable to get the locking tabs to release no matter what I did. I gave up and decided to wait for the repair guy to show up.

This past Thursday he shows and he had the same problem with the tabs and ended up cutting them off. After installing the board, the washer was still dead. He then said that the problem was most likely the main electronics unit (motherboard to the rest of us) and ordered one with "Emergency" delivery and scheduled a return visit the following week. He also noted that the replacement board was a different part and therefore they probably had fixed something in there. This at an additional cost of just under $300, bringing the total to $625.25. Needless to say I was NOT happy.

I poked around on the web and on Sears own site, found several people who had complained about this same exact failure just after the warranty expired. It seems like this was more of a general problem than a unique failure.

Armed with all of this information, I called customer relations and after about 40 minutes on the phone I was asked if they could call me back. I was hesitant because I was afraid of not getting a call and having to start over, but I went along with them. About an hour later, she called back and said that she had found that the electronics were covered by a 2 year warranty and the repair would cost us nothing (and she arranged for a refund of the initial charge on the first visit).

The part came in on Friday and since I didn't want to wait another week for a working washer, I decided to install it myself. This was a bit more complicated than the first board as it had many wires running about, but I took a few pictures so I could verify where all the wires should be and off I went. After about 15 minutes, the module was in, the washer was all back together and magic, I had a working washing machine. Of course, I was again proud of myself for doing the repair (though it was much easier than when I replaced the LCD on my camera).

One thing I did note once I had the washer working again: when I do a load a bleach load of whites on hot, steam comes out around the lid of the washer. Some of this steam could leak into the area with the electronics if the seals aren't tight enough. It was a similar load/settings on the washer when it died.

Things to learn from this

  • The squeaky wheel definitely gets the oil. It was only after calling and talking to 3 people at customer relations did I get to someone who magically said "oh, that should be covered by warranty". I do have to admit that I can't find any such warranty statement with the documents for my washer, but I'm happy to get the part fixed.
  • I was amazed about how little trouble-shooting was done on the phone prior to rolling a truck. Dell is a pretty good example for how to do this right, they will work quite well over the phone to figure out the exact problem to save a truck roll if possible. A little diagnosis over the phone and they would have known that the problem was with the electronics and could have sent the parts so that the unit would have been fixed the first time (note that Dell will even let you install the parts if you feel comfortable doing so -- which I've done several times for keyboards and such stuff).
  • Sears definitely has a problem with the electronics module for this unit. When something like that happens to a car, they do a recall, or they do a proactive warranty extension to keep their customers happy. Sears doesn't appear to be doing this and that's problematic given that they risk loosing a customer who is buying their top-of-the-line (probably widest margin) goods.
  • The lid-lock should release when power is removed from the machine. Having it stay locked like that meant that we were unable to remove our clothes from it until the repair guy came and took the machine apart (and the lid was still locked when he was done, but we did get our clothes out).

Update (10/21/07) - apparently things were not as well worked out as they appeared. The service guy still tried to come out to my house for the installation of the part even after I had twice called to tell them that I had installed the part and they had said something to the effect of "Cool, then no need for us to come out. I'll cancel the service call". The service guy said he still had to come out to collect payment. I told him that customer relations had said that this was a warranty repair as the electronics were warrantied for 2 years. He went off the check on this and called me back about a half our later saying that that was a parts-only warranty and that since I had installed it myself that voided the warranty and that I would have to pay both for the service call and the parts. I told them to give it a shot, but that there was no way in hell I was going to pay for this work. We'll see how this works out.

What I can't understand is how Sears is showing that they have no interest whatsoever in smoothing things over with a customer who has routinely purchased their top-of-the-line appliances. Ruining a relatitonship like that over $65 or so just doesn't make sense to me, but that's what they appear to want to do.

Tags : / / / /

Saturday, October 06, 2007

The Case for Federation and SSO

To date, the vast majority of real-world federation roll-outs have been internal or enterprise type deployments. Things like an enterprise authenticating its users out to an outsourced provider (such as a Fidelity 401K, or AOL's Radio Service). Yes there are many exceptions to this general statement (you can see many of them on Liberty's Adoption Page), but that is the general view of the industry and I certainly don't knowingly use federation in any cross-provider operations.

The time has come for federation and Single-Sign-On to be adopted in a more general fashion. I say this for many reasons and hope that the various vendors and providers out there will not be stubborn and/or resistant about it. I think this is valuable to parties that will wish to assert identity. I think this is valuable to the people who will accept identity federations and I think this is valuable to the users themselves.

When I say it is valuable to the user, I don't mean the often quoted "that way you can reduce the number of passwords you need to remember" -- though I still think that is a reasonable benefit. The real value for the user is that they will be able to share their data across multiple providers without the need to give their credentials to the other party.

Examples that already exist today include:

  • On LinkedIn, if I want them to pull my contact information from my contact book in several mail services (e.g. GoogleMail, HotMa il, etc.) I have to provide LinkedIn with my username and password on the mail service. LinkedIn logs in as me (either through their web interface and does screen scraping, or directly via an exposed web service) and extracts my contacts. Since I gave them my login information, I'm hoping that they don't do anything wrong with the data (like expose it), and that they don't mis-use the access to my account (e.g. sending spam in my name).
  • On Etrade, when I want to setup a new bank account for transferring funds from my Etrade account, one of the options provided is for ETrade to be provided with my username and password for online access to my bank account so that they can verify that I have control of the account and that it is in my name. Like LinkedIn, I'm hoping that they don't do anything wrong with the credentials while they have them (and in the case of ETrade, hoping that they do not store them like they claim they won't do).

I could go on with this list, but you get the idea. The user is already federating their data together across different providers. It's just in a very broken way that can lead to cascading security failures as any security failure at one site can lead to security failures at other sites.

With federation, I wouldn't need to give my credentials to LinkedIn. My mail provider could also differentiate the access provided (letting LinkedIn see the set of contacts that I chose to share with LinkedIn without being able to send mail in my name or being able to change contacts). LinkedIn could maintain that federation so that they could periodically check for updates. A break-in at LinkedIn would mean that someone could perform the same operations that I've already OK'd for LinkedIn -- get the data that LinkedIn already has -- so no additional exposure.

Why would GMail, HotMail, or even my bank, want to do this? First off, they are already doing it in an insecure way (I can always give my login credentials to the other party) and with the expanded access at their service. This would be a much better solution from a security and least priviledge point of view.

Another issue that might be raised with regards to the service providers is why would they want to expose a web service with this data. In many cases that's a new thing for them to do. But I think it's worth it becuase today, when they don't expose such an interface, theh other parties just walk though their standard user web interface and do screen scraping of the data -- I'm sure that data via a web page is more costly than exposing it through a programmatic web service.

Of course, LinkedIn would want to do this as they already do, but within the restricted capabilities of today that open them to some liability as well (should my data be misued at their site).

While I spoke heavily about LinkedIn in this post, this clearly applies to any and all cases where I want to do things across sites -- this is becomming more and more important in the Web2.0 world more interesting applications join togetether information from various parties. I can see how Dopplr would want to access my LinkedIn account to get my list of friends to pre-populate my traveling buddies rather than me having to establish new connections. I can also see how Dopplr would want to get access to my United Airlines itineraries so that they could auto-populate my trips.

The list goes on and on and it's a win-win-win for everyone, users and providers.

You might then have the decision as to what token format one should use for the federation and what web services structure one should use for the service access. I, of course, would recommend SAML and Liberty's Identity based Web Services Framework (ID-WSF), respectively, but that isn't as much the issue as is getting this up and running for the users.

You might notice that in this case, I haven't been advocating a large Circle of trust with centralized IdPs. Most of the examples I gave were point to point federations where, essentially, the relying parties and the IdPs were the same entity. The advantage with this model is that you have no need for extended business agreements so it's much easier to roll out. I do think that as more and more people start adopting and using this, it will be a natural evolution to environments where there are separated IdPs and Relying Parties, but we don't need to start there.

Tags : / / / / / / / / /

Wednesday, October 03, 2007

A painful Vista

My Dell Latitude D830 came with Microsoft Vista which, for the most part, has seemed like a prettied up XP without a lot of added useful functionality nor a substantial increase in stability. At the time I upgraded, I wrote that I was like so close to buying a Macbook Pro. I am sorry to say that I regret that decision even more today.

What got me to that stage? Well, it's a long painful path and to be honest, I'm not at the stage (yet) that I'm ready to just give in and replace my fairly new laptop.

The problems all started about 2 months after receiving the laptop. On July 14th, the day before I left for a trip to Shanghai, my email program (Thunderbird) locked up. When I restarted it, it still had problems and wouldn't pull mail from nfthe server, so I shutdown and restarted the computer.

During the reboot, the OS decided a chkdsk of the NTFS filesystem was necessary and it found and fixed many problems. When I got back to the running OS, all of the files that were actively open at the time I cleanly shutdown the system were gone. Totally gone. Not in the found.* directories (the NTFS equivalent of the UNIX lost+found directory).

Luckily I had the data backed up earlier that day as well as an offline backup on an external drive from a week before that. Since I was taking off for Shanghai, I copied both backups onto my system so I could pick the files (as I wasn't sure if the backup earlier that day wasn't corrupt as well).

I was able to get up and running again on my way to Shanghai without a problem and things were working fine. I assumed it was just some freak accident.

About a month later (mid-August) the same thing happened. This time I dug into it further and found that there had been a series of events in my event log (both then and back in July). It seems the problem starts with an NTFS event (which is flagged as an "Error" rather than a "Critical" event) with the event code of 137. The message from the event was extremely helpful... NOT!:

The default transaction resource manager on volume D: encountered a non-retryable error and could not start. The data contains the error code.

Microsoft's online help for the event was no help:

Results for: Microsoft product: Windows Operating System; Version: 6.0.6000.16386; ID: 137; Event Source: Ntfs;

No results were found for your query. Please see Search Help for suggestions.

Googling on "Default transaction resouce manager" found little results as well, but there was at least a possible link to another's problem. Apparently some had discovered that Acronis True Image had led to similar problems. I had installed Acronis Disk Director to reorganize my disk partitions, so I uninstalled it to see if that would alleviate the problem. And, of course, I did the same restoration process to get back all the lost files.

I did find one interesting discussion on resource managers in Vista, but that didn't provide any information that would help solve my problem.

Given that the error message just showed up in the event log (and in both cases, was close to 24 hours before the system crashed -- allowing me to open/use many files that disappeared), I added an event alert task which would send a message to the console should this error occur again. This is really important so that you can catch the problem as it starts, minimizing the potential damages.

Things went well for about another month and then it happened again in Mid-September, so it clearly wasn't the Acronis product. I was busy getting some heavy work done, so i didn't have the time to explore the problem other than to restore the files again.

About a week later, it happened again. This time it started going into an almost daily problem, sometimes happening again just after I had fixed things and ran chkdsk to fix the problems.

The pain had passed the threshold and I decided to do a total reinstall of the system. Prior to doing that, I did a complete backup. I copied my data files to a portable drive. I ran the extensive system diagnostics including the full suite of hard disk diagnostics to see if there was some form of a hardware problem. All diagnostics passed.

So, this past weekend, I reinstalled vista. I've been installing each of my former tools (there are many of them) and so far, so good. Given that this didn't turn up until I had had the computer for about 60 days the first time, I guess I won't know for sure if I've gotten around the problem till early Dec.

And, of course, I went and added the event task to generate a message should this occur again.

Wish me luck!

Tags : / / / / / /

Monday, September 10, 2007

Mistaken Identity

In a case of mistaken identity (of a place rather than a person) my United flight to Portland last night was delayed and had to re-connect the jetway and switch passengers.

As we were getting ready to push back, one of the passengers got up and talked to the flight attendant in the front of the plane. They talked, she talked to the pilot, they talked some more. All I could here was "I'm really sorry" coming from the passenger.

The jetway re-connected and the guy got off the plane (while another passenger, who had been denied boarding because the plane was oversold, got on -- lucky him).

Apparently, the departing passenger had booked the tickets, checked in, and boarded the plan without realizing that he hat ticketed himself to go to Portland, OR, rather than Portland ME. I would have thought that the 5 hour flight time would have given him a hint, but perhaps the fact that the 3 hour time difference made the apparent time difference (if you didn't pay attention to timezones) appear to be just 2 hours.

Anyway, luckily we hadn't gone far and he didn't have any checked baggage (nor, from what I could see, much carry-on luggage -- just a small laptop case). So after the quick switch we were on our way.

Tags : /

Wednesday, September 05, 2007

Advanced Client Take 2

The second draft of the Liberty Advanced Client Technologies set of specifications has been published on the Liberty Alliance web site.

For those who aren't aware, the Advanced Client Technologies work is the 3rd generation of client technologies coming out of Liberty. The first generation was work that enabled a Liberty-aware client and/or proxy to participate in the SSO transactions (similar to what Cardspace does today). The second generation enabled active clients to act as WSC's in identity transactions (such as a radio or mail client authenticating with an IdP, discovering and accessing a service provider).

This third generation enables clients acting as an extension of network providers such as an IdP, and addresses the issues related to hosting full-fledged service providers (such as my own IdP, or my own Contact Book Service) on my personal client.

So, this is your chance to nail me to the wall and point out how many stupid things I've done in there (though I'm not the only contributor, I'm sure that if something stupid is in there it is my doing). Please take a look-see and let us know of any interesting things you find in there (even pointing out the many, I'm sure, English mistakes would be helpful).

Go for it!

Tags : / / /

Tuesday, September 04, 2007

Portals and IdP Discovery

I recently received a comment on my SAML Bashing blog entry. "Jeremy" (not sure which Jeremy as he was otherwise anonymous in his comment -- I wonder if it's really James in disguise -- this seems the kind of comment James would leave, but James is usually quite blatant about it, not hiding behind an identity pseudonym) asked:

Kim stated "The question of how the relying party knows which identity provider URL to use is open ended. In a portal scenario, the address might be hard wired, pointing to the portal’s identity provider. ". What are your thoughts on that?

In the early days of Liberty ID-FF, we paid a good amount of attention to what solutions would fit into the various portal solutions. Must of this has to do with the configuration and structure of the portal. We saw different portals using different solutions including:

  • Push SSO

    In "push SSO" the portal, when creating links to the various components that make up the portal, generate redirection links that send the user directly to the IdP with some additional information causing the IdP to initiate an SSO to the third party.

    This is a common solution used in enterprise portals when the user selects a link provided by an outsourced third party (such as Fidelity providing 401K or stock purchase account management for employees).

  • Well-known IdP

    This is the solution mentioned in your quote of Kim. The members of the portal know which entity provides IdP services for the portal and can send the user to the IdP to get them authenticated. This is how most portals work today (e.g. Yahoo's IdP is known as the IdP for all Yahoo services at the Yahoo portal, so when I go to Yahoo Games, I get authenticated by the Yahoo IdP).

  • Affiliations

    Affiliations are a technical structure used to represent provider membership in a group (such as a portal, but can also be other business groups). When the user "federates" to an affiliation, the members of the affiliation are able to treat the user a a common user providing synchronized services and precluding a multitude of consents and idp interactions.

    The concept of Affiliations was introduced in the ID-FF specifications and was incorporated into SAML 2.0 during the convergence of SAML 1, ID-FF and Shibboleth.

Tags : / / / / / / /

Friday, August 24, 2007

Relatinships and authorization

James McGovern writes about how relationships must include authorization:

Anyway, the notion of relationship is something that belongs to the identity provider and entities such as the Liberty Alliance are defining standards around it. Check out their notion of the people service. The key though is that relationships sometimes require authorization. For example, just because my son can order an insurance card from Amica doesn't mean he is also allowed to cancel the policy for the entire family. Relationship needs authorization especially in domains having to do with medical interactions.

While I like his good words about the Liberty Alliance, I take exception with some of his conclusions.

First off, I don't think that relationships should or must belong to the Identity Provider. This is especially important in a world where my relationships cross the boundaries to many different Identity Providers. Within Liberty's People Service, we took great pains to ensure that the protocols support both a) the People Service be able to be provided by a party other than an IdP (just as LinkedIn provides this type of service to their customers) and b) the relationships contained within a user's People Service must be able to cross identity domains while still protecting the privacy of the users. The latter requirement lead to some rather complex protocol sequence requirements when establishing a connection.

Secondly, I look at authorization as being associated with the object being accessed (where the input parameters may include individuals and/or group memberships) and not with the relationship itself. So in the example provided by James, James would introduce his son to Amica (using the People Service) and then set the associated rights at Amica, not within the People Service. The primary driver for this is that only Amica understands the objects available to Jim and the associated access permissions that may be possible for those objects.

The one place where I see the People Service (and/or any other relationship tracking service) getting involved in authorization is where the user controls what another may do with his relationship (e.g. I can allow Paul to see my relationships (and the fact that I long ago had a coolness link to the ever-cool Joni)).

Tags : / / / / / /

Friday, August 03, 2007

Sniffing Cookies

In Tools to sniff and clone cookies Stephan Brands writes about a scene at a recent Black Hat Security conference where a presenter was able to steal live sessions by sniffing cookies on open internet connections and concludes:

The message for those working on digital identity solutions, in particular “lightweight” identity solutions and plain-vanilla browser identity federation a la ID-FF, should be clear: unless asymmetric cryptographic protection is made an integral part of a solution, users are highly vulnerable to theft of IdP login credentials as well as of identity claims that are issued to them.

First off, to be very clear, there was absolutely *NO* stealing of login credentials. What was actually stolen in that particular case was a session cookie that would enable the hacker to use an existing session for the length of the session. The stolen cookie could not be used to establish new login sessions (as login credentials would allow).

Secondly, in a Liberty ID-FF and/or SAML scenario the authentication protocols are required to take place within an SSL session and we strongly encourage that SSL be used to protect the authenticated session afterwards.

The real example that was shown is that services that do not use SSL to protect communications from the browser to the server are liable to be monitored, recorded, and even hijacked -- regardless of how well the user was authenticated.

Moral of the story: Use SSL to protect communications of sensitive information.

Tags : / / / / /

Monday, July 23, 2007

United announces new Business Class Seats

Today, United Airlines announced their new lay-flat business class seating that will start rolling out into the fleet later this year with a completion of the roll out in 2009.

The new business class seat is a substantial upgrade over the current seats including:

  • Lay-flat 6'4" bed
  • 15.4 inch LCD display
  • 110 volt outlet -- no more need for empower adapter!!!!
  • Apple iPod dock
  • USB power supply to power/recharge devices
  • etc., etc.

You can take a look at the following for more information:

All I can say is "bring it on!!!" I'm ready for it today.

UPDATE: 7/24 - The down side in all this is that there are substantially less business class seats in each of the aircraft: 747 - 53 (down from 72), 767 - 26 (down from 32), and 777 - 40 (down from 45/49). So while the seats are much better, there are less of them making upgrades much more competitive. TANNSTAAFL.

Tags : / / / / /