<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: writer]]></title>
    <link>http://securityratty.com/tag/writer</link>
    <description></description>
    <pubDate>Tue, 19 Aug 2008 05:34:03 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Links List 11.7.08]]></title>
      <link>http://securityratty.com/article/005aeccf95461397bcc44aae9976e6f2</link>
      <guid>http://securityratty.com/article/005aeccf95461397bcc44aae9976e6f2</guid>
      <description><![CDATA[Government contractors spill their thoughts about how Obamas historic win will affect the industry. A majority of those questioned agreed to the fact that nothing will change overnight and everything...]]></description>
      <content:encoded><![CDATA[<p>Government <a href="http://www.bisnow.com/washington_dc_tech_news_story.php?p=1744">contractors spill their thoughts</a> about how Obama’s historic win will affect the industry. A majority of those questioned agreed to the fact that nothing will change overnight and everything will occur within 2-3 years. Others expressed thoughts on who will lead procurement and acquisition policy at GSA and OMB, as well as a possible hiring freeze for the government workforce. We’re also waiting to see what will happen to <a href="http://blog.sciencelogic.com/government-sent-home-with-a-c-on-fisma-report-card/08/2008">FISMA</a> and<a href="http://blog.sciencelogic.com/times-up-ipv6-omb-mandate/06/2008"> IPv6</a> compliance going forward as a new administration and new OMB management sets their own agendas and mandates.<strong></strong></p>
<p>Due to the slow economy, most tech companies are being cautious and ratcheting back sales forecasts for software and hardware. <a href="http://blogs.wsj.com/biztech/2008/10/31/how-to-survive-the-downturn-sell-tech-to-bankruptcy-lawyers/?mod=djemTECH">The exception: Infra-Strategy</a>, a company that operates a group of Web sites that help people find a lawyer and info to deal with bankruptcies, divorces and DUI cases. Visits to the sites are booming – with visits to <a href="http://www.totaldivorce.com/">totaldivorce.com</a>, for example, up 112% in October 2008 (I found the picture on the website particularly compelling). Apparently, in bad times, divorce rates go up. Who knew?</p>
<p>Is it always a recession when it comes to IT Operations? <a href="http://blogs.forrester.com/it_infrastructure/2008/10/how-is-the-econ.html">Companies are constantly trying to find ways to do more with less in IT – reducing costs but keeping the same or even adding functionality</a> – deploying technologies that drive IT consolidation such as mobile and remote access, unified communications and virtualization. Chris Silva of The Forrester Blog for IT Infrastructure &amp; Operations Professionals is looking for a research panel to find out what fellow IT companies are doing to keep their IT budgets in check. To join the research panel visit: <a href="http://itpanel.forrester.com/">http://itpanel.forrester.com/</a>.</p>
<p>The Cloud Computing Monopoly debate continues. O’Reilly Media founder Tim O’Reilly and technology writer Nicholas Carr (of <a href="http://www.computerworld.com/managementtopics/roi/story/0,10801,81045,00.html">“IT Doesn’t Matter”</a> fame/infamy) have been <a href="http://www.informationweek.com/blog/main/archives/2008/11/the_cloud_compu.html?cid=RSSfeed_IWK_ALL">discussing the ‘potential for a single company to achieve monopoly control of the world of cloud computing</a>.’ But what’s even more interesting is the “who will make a lot of money” in cloud computing question.</p>
]]></content:encoded>
      <pubDate>Fri, 07 Nov 2008 19:49:59 +0000</pubDate>
      <category domain="http://securityratty.com/tag/research panel visit">research panel visit</category>
      <category domain="http://securityratty.com/tag/research panel">research panel</category>
      <category domain="http://securityratty.com/tag/monopoly">monopoly</category>
      <category domain="http://securityratty.com/tag/achieve monopoly control">achieve monopoly control</category>
      <category domain="http://securityratty.com/tag/tech companies">tech companies</category>
      <category domain="http://securityratty.com/tag/omb management sets">omb management sets</category>
      <category domain="http://securityratty.com/tag/companies">companies</category>
      <category domain="http://securityratty.com/tag/omb">omb</category>
      <category domain="http://securityratty.com/tag/forrester">forrester</category>
      <source url="http://blog.sciencelogic.com/links-list-11708/11/2008">Links List 11.7.08</source>
    </item>
    <item>
      <title><![CDATA[The Morphs of Bentham]]></title>
      <link>http://securityratty.com/article/4567ecd7eda5a9658148029e874e8d34</link>
      <guid>http://securityratty.com/article/4567ecd7eda5a9658148029e874e8d34</guid>
      <description><![CDATA[by Andy Oram10/30/2000 In honor of Halloween, and in memory of New Englands classic horror writer, H. P. Lovecraft, Andy Oram offers this little skit, which promises to scare the wits out of any...]]></description>
      <content:encoded><![CDATA[by Andy Oram10/30/2000
In honor of Halloween, and in memory of New England&#8217;s classic horror writer, H. P. Lovecraft, Andy Oram offers this little skit, which promises to scare the wits out of any network administrator.
http://oreilly.com/news/halloween_1000.html
&#160;&#160;&#160;&#160;&#160;&#160;     ]]></content:encoded>
      <pubDate>Fri, 31 Oct 2008 07:23:16 +0000</pubDate>
      <category domain="http://securityratty.com/tag/andy oram offers">andy oram offers</category>
      <category domain="http://securityratty.com/tag/network administrator">network administrator</category>
      <category domain="http://securityratty.com/tag/andy oram10302000">andy oram10302000</category>
      <category domain="http://securityratty.com/tag/promises">promises</category>
      <category domain="http://securityratty.com/tag/oreilly">oreilly</category>
      <category domain="http://securityratty.com/tag/skit">skit</category>
      <category domain="http://securityratty.com/tag/scare">scare</category>
      <category domain="http://securityratty.com/tag/honor">honor</category>
      <category domain="http://securityratty.com/tag/lovecraft">lovecraft</category>
      <source url="http://securitybuddha.com/2008/10/31/the-morphs-of-bentham/">The Morphs of Bentham</source>
    </item>
    <item>
      <title><![CDATA[PasswordTextBox]]></title>
      <link>http://securityratty.com/article/4e1580792b56914339b6489792b99933</link>
      <guid>http://securityratty.com/article/4e1580792b56914339b6489792b99933</guid>
      <description><![CDATA[Chris Sells used to poke fun at me when we worked together in my former life . He used to call my security class, &quot;Essential Access Denied&quot;. His point was a good one: when they aren't applied...]]></description>
      <content:encoded><![CDATA[<p><a href="http://www.sellsbrothers.com/" target="_blank">Chris Sells</a> used to poke fun at me when we worked together in my <a href="http://www.flickr.com/photos/andyrs/240203382/" target="_blank">former life</a>. He used to call my security class, &quot;Essential Access Denied&quot;. His point was a good one: when they aren&#39;t applied carefully, security countermeasures often just get in the way of getting work done. I don&#39;t know about you, but password-mode text boxes in web forms have always been one of those annoyances.</p> <p>I&#39;m not complaining about the fact that I can&#39;t see what I&#39;m typing. I understand and laud that feature, because I don&#39;t want someone looking over my shoulder at the password I&#39;m typing, and this even applies when I&#39;m at home. I love my children, but I certainly don&#39;t want them knowing the password to my bank account!</p> <p>No, what I&#39;m bothered by is how a typical password text box behaves on a form that may incur multiple post-backs before it&#39;s finally submitted. If you use the built in ASP.NET TextBox control, it purposely does not repopulate the password text, which means if you press a button on the form that performs a post-back, or if you have a multi-page form that posts back on every step, that password disappears, and the user typically has to re-enter it. You could solve this with liberal use of ASP.NET Ajax UpdatePanels, but that adds its own complexities. I wanted a simpler solution.</p> <p>So I did a little research to see what others had discovered about this problem, and I ended up deriving my own custom control from TextBox to make a much more user-friendly (and developer-friendly) TextBox control. I called it PasswordTextBox, and it acts just like a TextBox in password mode, but it retains the password while still giving the user the same level of protection the standard TextBox supplies.</p> <p>My PasswordTextBox operates very simply: it stores the password in control state, and renders a series of fixed characters (with the same length as the actual password) into the text box so that it &quot;looks&quot; like the user&#39;s password has been rendered. Since control state is part of view state, and since view state is stored in a hidden field on the form, I encrypt the password before putting it into control state.</p> <p>The result is quite nice - the user can post your form back as many times as she needs to, perhaps moving back and forth across wizard steps or tabs, and when she finally presses the &quot;Finish&quot; button (or whatever you call the last step of your input form), your code will be able to read the password by simply accessing the Text property on the PasswordTextBox. The user will believe that her password is sitting there on the form while she&#39;s working, as the same number of obfuscated characters will show up in the field as she typed in originally (what she doesn&#39;t know is that those characters aren&#39;t her real password anymore, but what she doesn&#39;t know won&#39;t hurt her!)</p> <p>Note that to keep this simple, I used DPAPI to encrypt the password, which suited my purposes. But if you have a web farm, that won&#39;t work well at all if you don&#39;t know which machine the user&#39;s going to post back to, so you&#39;ll want to replace that with something more robust. I could see looking up the &lt;machineKey&gt; for entropy, as that tends to be sync&#39;d already across the farm, but I&#39;ve not yet spent the cycles to go down that road, since unfortunately all of the code for generating keys based on that config section are off limits in ASP.NET (most of the useful stuff is marked internal). I don&#39;t think it&#39;d be that hard to do though.</p> <p>Anyway, without further ado, here&#39;s the code, which you&#39;ll see is quite simple. I&#39;d love feedback, especially if you see any glaring problems with the idea or the implementation!</p><pre class="csharpcode"><span class="kwrd">public</span> <span class="kwrd">class</span> PasswordTextBox : TextBox
{
    <span class="rem">// unlikely that a string of these would be used for a password</span>
    <span class="kwrd">const</span> <span class="kwrd">char</span> PasswordPlaceholderChar = <span class="str">&#39;}&#39;</span>;

    <span class="kwrd">string</span> password; <span class="rem">// stored encrypted in control state</span>

    <span class="kwrd">protected</span> <span class="kwrd">override</span> <span class="kwrd">void</span> OnInit(EventArgs e)
    {
        <span class="kwrd">base</span>.OnInit(e);
        Page.RegisterRequiresControlState(<span class="kwrd">this</span>);
    }

    <span class="kwrd">protected</span> <span class="kwrd">override</span> <span class="kwrd">object</span> SaveControlState()
    {
        <span class="kwrd">byte</span>[] encryptedPassword = ProtectPassword(password);

        <span class="kwrd">object</span> baseControlState = <span class="kwrd">base</span>.SaveControlState();
        <span class="kwrd">if</span> (<span class="kwrd">null</span> == baseControlState)
            <span class="kwrd">return</span> encryptedPassword;
        <span class="kwrd">else</span> <span class="kwrd">return</span> <span class="kwrd">new</span> Pair(baseControlState, encryptedPassword);
    }

    <span class="kwrd">protected</span> <span class="kwrd">override</span> <span class="kwrd">void</span> LoadControlState(<span class="kwrd">object</span> savedState)
    {
        <span class="kwrd">byte</span>[] encryptedPassword;

        Pair pair = savedState <span class="kwrd">as</span> Pair;
        <span class="kwrd">if</span> (<span class="kwrd">null</span> != pair)
        {
            <span class="kwrd">base</span>.LoadControlState(pair.First);
            encryptedPassword = pair.Second <span class="kwrd">as</span> <span class="kwrd">byte</span>[];
        }
        <span class="kwrd">else</span> encryptedPassword = savedState <span class="kwrd">as</span> <span class="kwrd">byte</span>[];

        password = UnprotectPassword(encryptedPassword);
    }

    <span class="rem">/// &lt;summary&gt;</span>
    <span class="rem">/// This control always uses TextMode=Password</span>
    <span class="rem">/// &lt;/summary&gt;</span>
    <span class="kwrd">public</span> <span class="kwrd">override</span> TextBoxMode TextMode
    {
        get
        {
            <span class="kwrd">return</span> TextBoxMode.Password;
        }
        set { }
    }

    <span class="rem">/// &lt;summary&gt;</span>
    <span class="rem">/// TextBox doesn&#39;t render value attribute for TextMode=Password</span>
    <span class="rem">/// So we add code that renders a placeholder text instead</span>
    <span class="rem">/// &lt;/summary&gt;</span>
    <span class="rem">/// &lt;param name=&quot;writer&quot;&gt;&lt;/param&gt;</span>
    <span class="kwrd">protected</span> <span class="kwrd">override</span> <span class="kwrd">void</span> AddAttributesToRender(HtmlTextWriter writer)
    {
        <span class="kwrd">base</span>.AddAttributesToRender(writer);

        <span class="kwrd">string</span> text = Text;
        <span class="kwrd">if</span> (text.Length &gt; 0)
            writer.AddAttribute(HtmlTextWriterAttribute.Value,
                GetPlaceholderPassword(text));
    }

    <span class="rem">/// &lt;summary&gt;</span>
    <span class="rem">/// TextBox doesn&#39;t save the &quot;Text&quot; viewstate in</span>
    <span class="rem">/// TextMode=Password and we don&#39;t want our behavior to break</span>
    <span class="rem">/// if ViewState is turned off so we store the password in</span>
    <span class="rem">/// Control State, encrypted with MachineKey</span>
    <span class="rem">/// &lt;/summary&gt;</span>
    <span class="kwrd">public</span> <span class="kwrd">override</span> <span class="kwrd">string</span> Text
    {
        get
        {
            <span class="kwrd">return</span> password ?? <span class="kwrd">string</span>.Empty;
        }
        set
        {
            <span class="rem">// this prevents us overwriting the actual</span>
            <span class="rem">// password with a placeholder</span>
            <span class="kwrd">if</span> (!<span class="kwrd">string</span>.IsNullOrEmpty(password) &amp;&amp;
                <span class="kwrd">value</span>.Equals(GetPlaceholderPassword(password)))
                <span class="kwrd">return</span>;

            password = <span class="kwrd">value</span>;
        }
    }

    <span class="kwrd">private</span> <span class="kwrd">string</span> GetPlaceholderPassword(<span class="kwrd">string</span> realPassword)
    {
        <span class="kwrd">int</span> length = 12;
        <span class="kwrd">if</span> (!<span class="kwrd">string</span>.IsNullOrEmpty(realPassword))
            length = realPassword.Length;

        StringBuilder sb = <span class="kwrd">new</span> StringBuilder();
        sb.Append(PasswordPlaceholderChar, length);

        <span class="kwrd">return</span> sb.ToString();
    }

    <span class="kwrd">public</span> <span class="kwrd">byte</span>[] ProtectPassword(<span class="kwrd">string</span> password)
    {
        <span class="kwrd">if</span> (<span class="kwrd">string</span>.IsNullOrEmpty(password))
            <span class="kwrd">return</span> <span class="kwrd">null</span>;
        <span class="kwrd">byte</span>[] cleartext = Encoding.UTF8.GetBytes(password);
        <span class="kwrd">return</span> ProtectedData.Protect(cleartext, <span class="kwrd">null</span>,
            DataProtectionScope.LocalMachine);
    }

    <span class="kwrd">public</span> <span class="kwrd">string</span> UnprotectPassword(<span class="kwrd">byte</span>[] ciphertext)
    {
        <span class="kwrd">if</span> (<span class="kwrd">null</span> == ciphertext)
            <span class="kwrd">return</span> <span class="kwrd">null</span>;
        <span class="kwrd">byte</span>[] cleartext = ProtectedData.Unprotect(ciphertext, <span class="kwrd">null</span>,
            DataProtectionScope.LocalMachine);
        <span class="kwrd">return</span> Encoding.UTF8.GetString(cleartext);
    }
}
</pre><div style="clear:both;"></div><img src="http://www.pluralsight.com/community/aggbug.aspx?PostID=54154" width="1" height="1">]]></content:encoded>
      <pubDate>Wed, 29 Oct 2008 16:49:54 +0000</pubDate>
      <category domain="http://securityratty.com/tag/password-mode text boxes">password-mode text boxes</category>
      <category domain="http://securityratty.com/tag/text">text</category>
      <category domain="http://securityratty.com/tag/return null">return null</category>
      <category domain="http://securityratty.com/tag/return">return</category>
      <category domain="http://securityratty.com/tag/net">net</category>
      <category domain="http://securityratty.com/tag/net ajax updatepanels">net ajax updatepanels</category>
      <category domain="http://securityratty.com/tag/net textbox control">net textbox control</category>
      <category domain="http://securityratty.com/tag/password">password</category>
      <category domain="http://securityratty.com/tag/textbox control">textbox control</category>
      <source url="http://www.pluralsight.com/community/blogs/keith/archive/2008/10/29/passwordtextbox.aspx">PasswordTextBox</source>
    </item>
    <item>
      <title><![CDATA[Outsourcing Infrastructure Management]]></title>
      <link>http://securityratty.com/article/ada5b9e1480c667e87cda8df368d3eae</link>
      <guid>http://securityratty.com/article/ada5b9e1480c667e87cda8df368d3eae</guid>
      <description><![CDATA[Have you experienced this? You call [fill in the blank] tech support and reach Bob Smith whose accent doesnt quite match the name. If youre like me, you wonder two things: is his name really Bob...]]></description>
      <content:encoded><![CDATA[<p>Have you experienced this? You call [fill in the blank] tech support and reach “Bob Smith” whose accent doesn’t quite match the name. If you’re like me, you wonder two things: is his name really Bob Smith? And if it’s not, why is he lying?
<p>Is it supposed to make me feel better about getting my problem fixed if I’m talking to someone in the <a href="http://dealarchitect.typepad.com/deal_architect/2008/10/the-cultural-impediments-to-offshore-infrastructure-services.html" target="_blank">Midwest versus someone in Bangalore</a>? (Please no hate mail – I’m from the Midwest.) Honestly, I just want my computer to stop showing me a blue screen of death.
<p>But apparently, I might be in the minority. According to the <a href="http://www.theblackbookofoutsourcing.com/" target="_blank">Black Book of Outsourcing</a> (yes, outsourcing has a black book), <a href="http://blogs.zdnet.com/BTL/?p=10388" target="_blank">reverse outsourcing</a> is <a href="http://www.informationweek.com/news/management/outsourcing/showArticle.jhtml?articleID=210602256" target="_blank">on the rise</a> with “India’s leading service providers opening offices on Main Street, USA” to be closer to customers (mainly North American) and draw from the “local talent pools”.
<p>The one area of outsourcing bucking this trend – infrastructure management. Co-writer Scott Wilson says that infrastructure management is largely automated, low touch and does not involve a lot of interaction.
<p>Speaking as a vendor of infrastructure management tools, that’s a bunch of malarkey. Perhaps at a very low level this is true (i.e., is the device responding), but that’s just the tip of the iceberg when it comes to monitoring performance, availability and SLAs for today’s networks, systems and applications.
<p>Certainly as vendors, we try to put as much automation as possible into our toolsets – helping our customers to simplify IT management wherever possible, enabling them to be proactive by setting up “intelligent” alarms and thresholds that warn of problems before they become showstoppers and reacting at a speed in this increasingly virtual world that simply is not possible for human manual interaction.
<p>But infrastructure management doesn&#8217;t happen in a vacuum and you can bet when something goes wrong which affects some mission-critical app state-side, that there is a LOT of communication and interaction. And it takes a lot of work and setup to get to a level of automation where the alerting is proactive and intelligent and customized for each business.
<p>One of the main points of tools like ours is to automate where possible in order to free up the valuable time of the sysadmins, network engineers, IT managers, etc to do the higher order work – which is how they’ll get to the next level of infrastructure management. Beyond “is it up”, infrastructure management should be providing answers to questions like: “is it always up”, “is it doing what I expected it to do” and “will it still be working as expected as my company grows”.</p>
]]></content:encoded>
      <pubDate>Fri, 17 Oct 2008 12:30:15 +0000</pubDate>
      <category domain="http://securityratty.com/tag/management">management</category>
      <category domain="http://securityratty.com/tag/infrastructure management">infrastructure management</category>
      <category domain="http://securityratty.com/tag/trend infrastructure management">trend infrastructure management</category>
      <category domain="http://securityratty.com/tag/infrastructure management tools">infrastructure management tools</category>
      <category domain="http://securityratty.com/tag/human manual interaction">human manual interaction</category>
      <category domain="http://securityratty.com/tag/bob smith">bob smith</category>
      <category domain="http://securityratty.com/tag/reach bob smith">reach bob smith</category>
      <category domain="http://securityratty.com/tag/interaction">interaction</category>
      <category domain="http://securityratty.com/tag/tools">tools</category>
      <source url="http://blog.sciencelogic.com/outsourcing-infrastructure-management/10/2008">Outsourcing Infrastructure Management</source>
    </item>
    <item>
      <title><![CDATA[Of Planes and Ships]]></title>
      <link>http://securityratty.com/article/47dfbf92b3eaba317f07cfa2064d0a9b</link>
      <guid>http://securityratty.com/article/47dfbf92b3eaba317f07cfa2064d0a9b</guid>
      <description><![CDATA[Tom Barnett is consistently the most interesting writer on globalization and econo-security seam. This weeks piece confronts a problem every security architect can relate to (emphasis added on the...]]></description>
      <content:encoded><![CDATA[<p><a href="http://www.thomaspmbarnett.com/weblog/2008/09/column_121.html">Tom Barnett</a> is consistently the most interesting writer on globalization and econo-security seam. This weeks piece confronts a problem every security architect can relate to (emphasis added on the &quot;nail it to the wall&quot; quote at the end):</p><p><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">One of the main problems in counterterrorism today is that there are so many people and vehicles, and so much data and material, moving through globalization&#39;s myriad networks that it seems virtually impossible to track it all effectively. Nowhere has this problem been more acute than on the high seas.</span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">In 2006, Adm. Harry Ulrich, then U.S. commander of NATO Naval Forces Europe, decided to do something about it. Despite having virtually no resources, his dream was to transpose the global air-traffic control system onto sea traffic.</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Worldwide, aircraft are transparent, because they&#39;re all required to carry an identification beacon that allows them to be tracked leaving and entering airports, and monitored between airports, by a global network of sensors. Act suspiciously and somebody&#39;s fighter aircraft will soon be on your tail.</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">No such pervasive system currently exists globally for maritime traffic. While bigger ships carry an ID beacon similar to aircraft, without a shared monitoring network, that&#39;s like tracking only selected commercial jets and giving everyone else a pass.</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">So Ulrich, upon taking command, asked a simple question: &quot;If we can do that in the air, why can&#39;t we do it on the sea?&quot; He made a point of pioneering his sea-traffic-control effort first inside the Mediterranean, where NATO&#39;s southern naval forces have historically been concentrated, but his real target was waters off Africa -- the most ungoverned maritime space in the world.</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Ulrich knew the U. S. Navy couldn&#39;t do it alone, much less bring Africa&#39;s meager coast-guard-like navies up to snuff so they could do it on their own. So he quickly created a network of assets -- both public and private -- to manage that space, modeling his monitoring system on international air-traffic control.</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Ulrich began stitching together a network of shore-based sensors ringing the Mediterranean. His naval command then began initial monitoring by tapping into the International Maritime Organization&#39;s existing Automated Identification System, transforming NATO&#39;s ability to track ship traffic in the Med.</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Almost overnight, NATO went from tracking dozens of ships on the Mediterranean to thousands, and instead of getting the data sometimes up to 72 hours late, now the contacts were being tracked in one to five minutes -- to an accuracy within 50 feet on the earth&#39;s surface.</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">When the classic big-firm systems integrators told Ulrich it would be too costly to pull it off, the admiral turned to the Volpe Center in Cambridge, Massachusetts, a U.S. Department of Transportation research center. Instead of hundreds of millions of dollars, Ulrich&#39;s initial network cost $900,000. The shore-based receivers are small, roughly the size of a radar dish you might find on a pleasure craft.</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">The strength of the system is a function of its reach: the more countries join, the larger the shared operational picture. By the time Ulrich retired at the end of 2007, he had enlisted 32 countries throughout the Mediterranean, the North Atlantic, along the west coast of Africa, around the Black Sea, and in the Pacific. Today, the network continues to spread around the planet.</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="border-collapse: collapse; font-size: 14px; line-height: 20px; "><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">With Ulrich&#39;s system in place, local police, coast guards, and border patrols catch most bad guys, obviating American military responses. As Harry told me for an article I wrote about his work in a fall 2007 issue of Esquire, </span><span style="font-weight: bold; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">&quot;I don&#39;t do defense; I do security. When you talk defense, you talk containment and mutually assured destruction. When you talk security, you talk collaboration and networking. This is the future.&quot;</span></span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">The admiral&#39;s legacy program, the Maritime Safety and Security Information System, earned the Volpe Center a prestigious &quot;Innovations in American Government&quot; award this month from Harvard University&#39;s Ash Institute for Democratic Governance and Innovation.</span></p></blockquote><p><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p><div><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Security Collaboration + Networking &#160;= Federation. This is indeed the future - SAML came along just at the nick of time.</span></div><div><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></div><div><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">When you assume that to do access control you must have &quot;Complete Mediation&quot; in Saltzer and Schroeder&#39;s terms of the subject (users), the objects (data), the session, and the roles, then you are going to have an interesting life trying to deliver anything. And if you do it will mucho expensive.</span></div><div><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></div><div><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">if you take the federated autonomous nodes approach, agree upon an attribute schema plus a protection model for same, and basic protocol, you are then free to move about the country. Security doesn&#39;t have to equal centralization or high cost. Get the attributes from point a to point b securely.</span></div>]]></content:encoded>
      <pubDate>Sun, 28 Sep 2008 19:04:11 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security architect">security architect</category>
      <category domain="http://securityratty.com/tag/system">system</category>
      <category domain="http://securityratty.com/tag/identification system">identification system</category>
      <category domain="http://securityratty.com/tag/initial network cost">initial network cost</category>
      <category domain="http://securityratty.com/tag/initial">initial</category>
      <category domain="http://securityratty.com/tag/cost">cost</category>
      <category domain="http://securityratty.com/tag/ulrich">ulrich</category>
      <category domain="http://securityratty.com/tag/time ulrich">time ulrich</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/09/of-planes-and-ships.html">Of Planes and Ships</source>
    </item>
    <item>
      <title><![CDATA[In-Flight VoIP Ban: Against FCC Rules? Highly Desirable?]]></title>
      <link>http://securityratty.com/article/04edfe3e5a28bd63c48bc3f4ded28db4</link>
      <guid>http://securityratty.com/article/04edfe3e5a28bd63c48bc3f4ded28db4</guid>
      <description><![CDATA[Think-tank wonders whether banning in-flight VoIP constitutes a violation of FCC rules about blocking services: The Progress and Freedom Foundation's Barbara Espin uses the ban on in-flight VoIP by...]]></description>
      <content:encoded><![CDATA[<p><img src="http://wifinetnews.com/images/plane.jpg" align="right" border="0" hspace="5" /><a href="http://blog.pff.org/archives/2008/09/does_disclosure.html"><strong>Think-tank wonders whether banning in-flight VoIP constitutes a violation of FCC rules about blocking services:</strong></a> The Progress and Freedom Foundation's Barbara Espin uses the ban on in-flight VoIP by American Airlines (facilitated by provider Aircell) to make a broader argument about what she calls the FCC's "ad hoc approach to broadband network management issues." It's clever. American discloses that calling isn't allowed, and VoIP isn't even technically within the FAA or FCC's purview, as far as I can determine. The FAA could choose to regulate it as a safety issue. PFF generally tilts anti-regulation, and has as what it calls its "supporters" a broad area of multiple system cable operators and telecom firms, including Comcast, which was singled out and fined by the FCC for its undisclosed network disruption of P2P connections.</p>

<p><a href="http://www.nytimes.com/2008/09/14/business/14essay.html?_r=2&ei=5070&emc=eta1&oref=slogin&oref=slogin"><strong>Espin references Joe Sharkey's excellent column on in-flight calling in Sunday's New York Times:</strong></a> Sharkey, a veteran travel writer, who survived a mid-air collision over the Brazilian Amazon a few years ago, looks at varying attitudes about calls made during flights. He quotes Aircell's Jack Blumenstein saying what I've telling folks for months: Aircell has a lot of techniques to block VoIP calls already, and "as we identify new ways that people are trying to do voice calls on the airplane, we just kind of zero in and knock those off." Many geeks have assumed Aircell is a bunch of unsavvy folks who wouldn't be able to figure out how to disrupt their clever workarounds for making VoIP. (I keep noting that introducing jitter for suspicious data connections wouldn't disrupt legitimate applications, but would destroy VoIP call quality.)</p>]]></content:encoded>
      <pubDate>Tue, 16 Sep 2008 05:50:22 +0000</pubDate>
      <category domain="http://securityratty.com/tag/voip">voip</category>
      <category domain="http://securityratty.com/tag/in-flight voip constitutes">in-flight voip constitutes</category>
      <category domain="http://securityratty.com/tag/in-flight">in-flight</category>
      <category domain="http://securityratty.com/tag/in-flight voip">in-flight voip</category>
      <category domain="http://securityratty.com/tag/block voip calls">block voip calls</category>
      <category domain="http://securityratty.com/tag/fcc rules">fcc rules</category>
      <category domain="http://securityratty.com/tag/fcc">fcc</category>
      <category domain="http://securityratty.com/tag/voice calls">voice calls</category>
      <category domain="http://securityratty.com/tag/calls">calls</category>
      <source url="http://wifinetnews.com/archives/008444.html">In-Flight VoIP Ban: Against FCC Rules? Highly Desirable?</source>
    </item>
    <item>
      <title><![CDATA[Wee-Fi: Share Cell Connections over Wi-Fi; Mile High-Fi Salaciousness; Giga-Fi; and More]]></title>
      <link>http://securityratty.com/article/457365225a8b72096232f2b375549cff</link>
      <guid>http://securityratty.com/article/457365225a8b72096232f2b375549cff</guid>
      <description><![CDATA[New version of Windows Mobile software to share cell data connections over Wi-Fi: Morose Media ships version 1.20 of WMWifiRouter, a Windows Mobile 5 and 6 application that routes cellular data...]]></description>
      <content:encoded><![CDATA[<p><img src="http://wifinetnews.com/images/weefi.jpg" align="right" border="0" hspace="5" /><a href="http://www.wmwifirouter.com/"><strong>New version of Windows Mobile software to share cell data connections over Wi-Fi:</strong></a> Morose Media ships version 1.20 of WMWifiRouter, a Windows Mobile 5 and 6 application that routes cellular data connections over Wi-Fi, turning your phone into a micro-hotspot. The software can also share a cell connection via Bluetooth or USB. The software costs $30 or &euro;20, and requires Internet (Connection) Sharing (ICS), which some providers may have removed from your phone. (The company set the price at US$30 before the euro drop, so is offering a kind of discount over their real &euro;20 price for the moment.)</p>

<p><a href="http://www.nytimes.com/2008/09/11/technology/personaltech/11smart.html?_r=1&8cir&emc=cirb1&oref=slogin"><strong>The New York Times rounds up using cell phones as hotspots:</strong></a> Though the reporter, Bob Tedeschi, mentions the issue of having to have an unlimited data plan to avoid unpleasant charges, and worries about bad drains and malicious users, he doesn't note that many carriers don't allow this kind of sharing or routing without a separate "tethering" plan, that can run $20 or more per month. Also, U.S. carriers have now all imposed a 5 GB per month reasonable use cap; some will cut you off, some charge you more, some cancel your service based on exceeding this use.</p>

<p><a href="http://www.networkworld.com/news/2008/090908-ieee-considers-gigabit.html?hpg1=bn"><strong>Gigabit Wi-Fi? Someday:</strong></a> TechWorld considers the IEEE's Very High Throughput (VHT) study group, which wants to start work on 1 Gbps or faster Wi-Fi standard for completion in 2012. With 802.11n offering raw symbol rates up to 600 Mbps--even though no devices have shipped with the radios and antennas to offer that optional high speed yet--there's interest in other frequencies that would allow faster encodings, as well as aggregating multiple links to achieve high speed rates. My experience in testing and using 2.4 GHz with Draft N would show that wide or aggregated channels doesn't work very well. The article's writer, Peter Judge, notes that ultrawideband had potential (over short distances) to approach the gigabit mark, but that UWB hasn't really reached the market in any substantive way years after it was promised to be a big technology.</p>

<p><a href="http://www.nbc5i.com/news/17435300/detail.html"><strong>Flight attendants express concerns about in-flight broadband porn:</strong></a> When I've spoken to airlines, industry experts, and service providers, I find that they all have stories about how porn is viewed on computers, through DVD players, and in convenient magazine form on planes today. Adding the Internet may provide new salacious imagery, but the problem predates Internet access, and filtering Internet service is never as good a solution as a social one. Someone idiotic enough to view porn on a plane over the Internet is also stupid enough to bring along inappropriate DVDs they watch while seated next to children. Flight attendants already have the power vested in them to take care of this. The flight attendants for American might be expressing this concern as part of a bargaining issue, where their responsibilities but not commensurate pay have increased.</p>

<p><a href="http://www.kxly.com/Global/story.asp?S=8989329"><strong>Spokane ends free Wi-Fi:</strong></a> Remember Vivato? Boy, I sure do. A company with a reach far exceeding its grasp, Vivato initially powered Spokane's downtown network. The network has continued to run on some basis--I'm not sure using what equipment--and now will move from free to fee. OneEighty Networks will charge about $10 per month to cover the costs of the network, for which local businesses at one point chipped in.</p>

<p><a href="http://www.onair.aero/"><strong>Brazilian TAM airline signs up for in-flight calling, messaging:</strong></a> OnAir has signed up the Brazilian carrier TAM, which will deploy the service on its Airbus A320 craft. Brazil hasn't yet provided regulatory approval, so no launch date is noted. TAM is the largest domestic and international carrier for Brazil.</p>]]></content:encoded>
      <pubDate>Thu, 11 Sep 2008 07:02:26 +0000</pubDate>
      <category domain="http://securityratty.com/tag/wi-fi">wi-fi</category>
      <category domain="http://securityratty.com/tag/internet service">internet service</category>
      <category domain="http://securityratty.com/tag/faster wi-fi standard">faster wi-fi standard</category>
      <category domain="http://securityratty.com/tag/service">service</category>
      <category domain="http://securityratty.com/tag/internet">internet</category>
      <category domain="http://securityratty.com/tag/internet access">internet access</category>
      <category domain="http://securityratty.com/tag/software">software</category>
      <category domain="http://securityratty.com/tag/software costs">software costs</category>
      <category domain="http://securityratty.com/tag/free wi-fi">free wi-fi</category>
      <source url="http://wifinetnews.com/archives/008436.html">Wee-Fi: Share Cell Connections over Wi-Fi; Mile High-Fi Salaciousness; Giga-Fi; and More</source>
    </item>
    <item>
      <title><![CDATA[The Real Migration Problem]]></title>
      <link>http://securityratty.com/article/066428c6b802b3676a2c3982d275cbbd</link>
      <guid>http://securityratty.com/article/066428c6b802b3676a2c3982d275cbbd</guid>
      <description><![CDATA[Preview of Tom Friedman's thinking for his new book - Hot, Flat and Crowded. Killer quote (emphasis added

FP: And what about drilling? Republican presidential candidate Sen. John McCain, his running...]]></description>
      <content:encoded><![CDATA[<p><a href="http://www.foreignpolicy.com/story/cms.php?story_id=4463">Preview</a> of Tom Friedman&#39;s thinking for his new book - Hot, Flat and Crowded. Killer quote (emphasis added):</p><br /><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: Verdana; font-size: 12px; line-height: 16px; "><span class="fp_red" style="color: #8c182d; font-weight: bold; "><strong>FP:&#160;</strong></span>And what about drilling? Republican presidential candidate Sen. John McCain, his running mate Gov. Sarah Palin, and President George W. Bush are implying that lifting environmental restrictions on drilling is the way to promote energy independence.</span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: Verdana; font-size: 12px; line-height: 16px;"><br /></span><span style="font-family: Verdana; font-size: 12px; line-height: 16px; "><strong>TF:&#160;</strong>Well, I think it’s patent nonsense. No one believes that somehow offshore, there’s enough oil in any near term and even the long term to provide us oil independence. It’s the wrong approach because in a world that’s hot, flat, and crowded, fossil fuels—and particularly crude oil—are going to be expensive and exhausting. Therefore the focus should be on the next great global industry: clean energy technology. <span style="font-weight: bold;">When I hear McCain pounding the table for “drill, drill, drill,” it reminds me of someone pounding the table for IBM Selectric typewriters on the eve of the IT revolution.</span></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: Verdana; font-size: 12px; line-height: 16px;"><br /></span><span style="font-family: Verdana; font-size: 12px; line-height: 16px; ">I’m not against offshore drilling, by the way, because I believe the technology and the safety has improved far beyond where it was back in the 70s, 80s, and 90s, even. What I’m against is making it the centerpiece of our energy policy. If all McCain said was, “Let’s drill, but let’s also throw everything into innovating the next generation of clean-energy technologies,” I’d say, “You’ve got it exactly right, pal.”</span></p></blockquote><p><span style="font-family: Verdana; font-size: 12px; line-height: 16px;"><br /></span></p><div><span style="font-family: Verdana; font-size: 12px; line-height: 16px;">Its funny because as someone who has done a half dozen legacy migration projects (with mental and emotional scars to prove it), I was thinking the same thing. The entrenched mindset. &quot;If we just dig our trench deeper (in this case literally) then we will be ok.&quot;...at least until the person in question retires...</span></div><div><span style="font-family: Verdana; font-size: 12px; line-height: 16px;"><br /></span></div><div><span style="font-family: Verdana; font-size: 12px; line-height: 16px;">One of the legacy migration project I worked on, I was the third consultant that tried to get this company off of mainframe and onto distributed systems (which are no panacea but this company really did need to make the move). The core developers of the mainframe were actively hostile to change, as opposed to simply passive aggressive, which we expect. For example, if you asked about how a piece of functionality worked, say a report writer, the developer would not answer, stand up, walk out of the room, come back with a 800 page &quot;data model&quot;, slam it on the table and walk out of the room. Good times.</span></div><div><span style="font-family: Verdana; font-size: 12px; line-height: 16px;"><br /></span></div><div><span style="font-family: Verdana; font-size: 12px; line-height: 16px;">A chief objection beyond fear of the unknown was the perceived lack of elegance in the distributed systems as opposed to the control from say JCL. Anyway, what progress I made was due to analogizing that we were leaving Greece which has a rich culture, history, philosophy and moving to Rome which maybe was not as elegant as Greece but still people like circuses, roads and acqueducts. So when, several times a day, a perceived go/ no go issue arose, I would gently remind &#160;the developers that &quot;we are now in Rome and things work differently here.&quot;</span></div><div><span style="font-family: Verdana; font-size: 12px; line-height: 16px;"><br /></span></div><div><span style="font-family: Verdana; font-size: 12px; line-height: 16px;">Intransigently digging the trench deeper is not the way, instead we need to better understanding the energy &#160;problem in a larger context, and finding deployable technologies to help address it. If you think drill, drill, drill is the answer, then I think the answer for you is the same as someone who knows COBOL and flat refuses to learn modern languages even when that is required - a nice retirement house on a golf course somewhere.</span></div>]]></content:encoded>
      <pubDate>Tue, 09 Sep 2008 05:38:33 +0000</pubDate>
      <category domain="http://securityratty.com/tag/energy">energy</category>
      <category domain="http://securityratty.com/tag/clean-energy technologies">clean-energy technologies</category>
      <category domain="http://securityratty.com/tag/clean energy technology">clean energy technology</category>
      <category domain="http://securityratty.com/tag/drill">drill</category>
      <category domain="http://securityratty.com/tag/energy policy">energy policy</category>
      <category domain="http://securityratty.com/tag/technology">technology</category>
      <category domain="http://securityratty.com/tag/promote energy independence">promote energy independence</category>
      <category domain="http://securityratty.com/tag/trench deeper">trench deeper</category>
      <category domain="http://securityratty.com/tag/mccain">mccain</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/09/the-real-migration-problem.html">The Real Migration Problem</source>
    </item>
    <item>
      <title><![CDATA[American Launches In-Flight Broadband Pilot]]></title>
      <link>http://securityratty.com/article/5a1252977f7711ca2ccfda8f990edb58</link>
      <guid>http://securityratty.com/article/5a1252977f7711ca2ccfda8f990edb58</guid>
      <description><![CDATA[Welcome back, mile-high Wi-Fi: American Airlines has turned on Internet service in its fleet of 15 767-200s today. These aircraft ply routes between New York's JFK and three cities: San Francisco, Los...]]></description>
      <content:encoded><![CDATA[<p><img src="http://wifinetnews.com/images/plane.jpg" align="right" hspace="5" height="80" width="80" border="0" /><strong><a href="http://www.chicagotribune.com/travel/chicago-american-wifi-aug20,0,7823127.story">Welcome back, mile-high Wi-Fi:</a></strong> American Airlines has turned on Internet service in its fleet of 15 767-200s today. These aircraft ply routes between New York's JFK and three cities: San Francisco, Los Angeles, and Miami. Service is $13 per flight, and bandwidth is expected to be 1.5 Mbps (uncompressed) upstream and downstream, although the service provider, Aircell, claims some advantages above that.</p>

<p>This is a big day for Aircell, which spent tens of millions to acquire the exclusive spectrum license that allows them to shoot Mbps to and from planes. My big question will be whether coverage remains seamless across an entire flight--how often one has to reconnect their VPN would be a big issue. If Aircell has architected the network correctly, passengers should never be reassigned an IP address, and connections shouldn't be dropped even if there's a hiccup in air-to-ground communication.</p>

<p>I've covered in-flight broadband for several years, and I've been wondering lately whether we'd be waiting until 2009 to see real production service. American is calling this a 3-to-6 month pilot to see what their passengers think. Just yesterday, I <strong><a href="http://wifinetnews.com/archives/008422.html">wrote up</a></strong> veteran travel writer Joe Brancatelli's frustration with the lack of information and some misinformation about in-flight broadband.</p>

<p>You can read more background on American's plans and Aircell's technology in a <strong><a href="http://boingboing.net/2008/06/24/american-airlines-wi.html">post I wrote for BoingBoing</a></strong> on 24-June-2008.</p>]]></content:encoded>
      <pubDate>Wed, 20 Aug 2008 04:33:21 +0000</pubDate>
      <category domain="http://securityratty.com/tag/flight">flight</category>
      <category domain="http://securityratty.com/tag/in-flight broadband">in-flight broadband</category>
      <category domain="http://securityratty.com/tag/service">service</category>
      <category domain="http://securityratty.com/tag/service provider">service provider</category>
      <category domain="http://securityratty.com/tag/american">american</category>
      <category domain="http://securityratty.com/tag/internet service">internet service</category>
      <category domain="http://securityratty.com/tag/real production service">real production service</category>
      <category domain="http://securityratty.com/tag/american airlines">american airlines</category>
      <category domain="http://securityratty.com/tag/aircell">aircell</category>
      <source url="http://wifinetnews.com/archives/008424.html">American Launches In-Flight Broadband Pilot</source>
    </item>
    <item>
      <title><![CDATA[Leading Travel Writer Reams Out In-Flight Internet]]></title>
      <link>http://securityratty.com/article/f64004c5f420a4aa7be1520dea970d4b</link>
      <guid>http://securityratty.com/article/f64004c5f420a4aa7be1520dea970d4b</guid>
      <description><![CDATA[Joe Brancatelli pokes beneath the surface of claims that in-flight Internet is imminent: I've covered some of the same ground, but veteran travel writer Brancatelli connected the dots by checking with...]]></description>
      <content:encoded><![CDATA[<p><img src="http://wifinetnews.com/images/plane.jpg" align="right" border="0" hspace="5" /><a href="http://www.washingtonpost.com/wp-dyn/content/article/2008/08/19/AR2008081901066.html"><strong>Joe Brancatelli pokes beneath the surface of claims that in-flight Internet is imminent:</strong></a> I've covered some of the same ground, but veteran travel writer Brancatelli connected the dots by checking with the FAA to find the status of applications for aircraft certification by Aircell and others. </p>

<p>He's not very positive about it, because his research shows a mismatch between claims and work. He writes that an unnamed American airline executive is frustrated by the delay in launching the 3-to-6 month pilot on their trans-continental fleet; that Aircell hasn't submitted paperwork for Virgin's Airbus models for certification; and that the FAA just received a request to certify Delta's MD-80 craft, which makes a launch with 75 planes this year on that airline less likely.</p>

<p>Competitor Row 44 doesn't fare better in his analysis, as they promised spring and summer 2008 tests that still haven't happened, with Southwest and Alaska Airlines.</p>

<p>I'm a little more positive about the future of in-flight broadband. There's no particular conspiracy. It's hard to make it work. Development and testing is tricky due to FAA limits, and getting in-flight handoffs to work for seamless service at 35,000 feet is far more difficult than, say, cellular handoffs in a moving car at 100 feet above sea level. My suspicion is that tuning the service to be entirely reliable at launch is what's taking so long.</p>

<p>Brancatelli blames the high price of Connexion on its failure, but I don't think the $27 fee for long-haul flights deterred users. Lufthansa, which deployed all its long-haul fleet, apparently had very good usage. Most other airlines had few craft equipped, which didn't allow business travelers, able to expense several hours of work for a $27 fee, the reliability of having on-board Internet when they needed it. Connexion also had many reports of spotty service in certain areas. </p>

<p>Connexion's failure came from deploying technology that was old when it was deployed, which weighed too much, and which was too expensive to install. Connexion's revenue and expenses were forecast based on having several hundred aircraft with Connexion service--recall that it was supposed to be a domestic U.S. service, too. In the end they had about 100, I believe. </p>

<p>Brancatelli is also modest when he says Boeing "lost" $300m. That's part of what they wrote down. My sources say they spent more than a billion in R&D, transponder leases, ground station operation, airline incentives, and payoffs at the end.</p>]]></content:encoded>
      <pubDate>Tue, 19 Aug 2008 05:34:03 +0000</pubDate>
      <category domain="http://securityratty.com/tag/service">service</category>
      <category domain="http://securityratty.com/tag/seamless service">seamless service</category>
      <category domain="http://securityratty.com/tag/spotty service">spotty service</category>
      <category domain="http://securityratty.com/tag/connexion service">connexion service</category>
      <category domain="http://securityratty.com/tag/connexion">connexion</category>
      <category domain="http://securityratty.com/tag/airline incentives">airline incentives</category>
      <category domain="http://securityratty.com/tag/airline">airline</category>
      <category domain="http://securityratty.com/tag/in-flight internet">in-flight internet</category>
      <category domain="http://securityratty.com/tag/ground">ground</category>
      <source url="http://wifinetnews.com/archives/008422.html">Leading Travel Writer Reams Out In-Flight Internet</source>
    </item>
  </channel>
</rss>
