Shared posts

08 Mar 01:44

Blix Rider Story: Tony loves Blix date nights!

by Blix PR

Tony and his wife love spending time together outdoors, exploring Santa Cruz and Aptos, California. Last month, Tony was the lucky winner of a Blix Bike giveaway held by Monterey Bay Community Power. Since he immediately loved his Blix Aveny high step, he decided he would enjoy riding even more if his wife was able to keep up on her own Aveny step-through! We are excited to share Tony and his wife's story with you this month as well as encourage others to find ways to get active and outside with loved ones.

                                                                                                      

Working with our local Blix dealer Epicenter Cycling, Tony and his wife were able to ride away on their Aveny models, ready for every adventure! Lucky for them, Nicene Marks state park is located near their home. Tony says this is their favorite ride to complete together. They also enjoy riding through Wilder Ranch, which is located up the coast off Highway 1. In addition to local rides, Tony says he and his wife would love to ride "anywhere its 70+ degrees or around Lake Tahoe."  What a perfect date! 

Tony and Wife ride Blix Aveny electric bikes

Not only have their Blix electric bikes increased the distances they ride together, the bikes have also increased Tony's wife's mobility As Tony explains, "My wife had knee replacement surgery, so this is helping her get rehabilitated. My wife can go along more often now." By having an electric motor, varying pedal assist levels, and a throttle, Tony and his wife are able to ride farther, faster, and find a new activity to add to date nights!

                                                                                                      

A big thank you to Tony for sharing his story with us!
If you would like to share your experience click here! 
We love to see our Blix Community in action!
Follow us:
Facebook            Instagram
 
08 Mar 01:43

"In Berlin, you can be whatever you want..."

by peter@rukavina.net (Peter Rukavina)

From David Noel’s Friday’s Five newsletter, a pointer to a video love letter to Berlin by Bob Mould.

We spent most of August 2011 living in Berlin; the way I’ve long-described that amount of time was that in the middle of the month it was far enough both from arriving and departing that it felt like we were really there.

I’ve been back to Berlin several times since then, but only for short 2 or 3 days jaunts; they’ve been lovely trips, but they haven’t had the magic of 2011.

Somewhere in the back of my mind I think I’ve decided the one day someday I will actually live in Berlin. I don’t know when this will be. But I hope it comes true. In the meantime, we will continue to flirt.

08 Mar 01:43

Cycle 5: Feb blood test results – Cancer levels dropped

by tyfn

Good News!

My February blood test results show that my cancer levels dropped. They are now 3 down from between 5 and 6 in January.

I’m super happy my numbers are back on track. Feeling optimistic about March.

M protein (g/L) (if 0, then no cancer detected)
Feb = 3
Jan = between 5 and 6
Dec = between 5 and 6
Nov = 11
Late Oct = 27
Early Oct = 48

Cycle 5: Feb blood test results - Cancer levels dropped

Weekly chemo-inspired self-portraits can be viewed in my flickr album.

I have multiple myeloma and anemia, a rare cancer of the immune system. Multiple myeloma affects the plasma cells, a type of immune cell that produces antibodies to fight infection. These plasma cells are found in the bone marrow. As a blood cancer, it is incurable, but treatable.

Since mid-October, I’m being treated with Kyprolis (carfilzomib), an IV chemo, Cyclophosphamide, and dexamethasone.

Lonsdale Quay Market - North VancouverMay 2014: Lonsdale Quay – North Vancouver

The post Cycle 5: Feb blood test results – Cancer levels dropped appeared first on Fade to Play.

08 Mar 01:41

Surface Pro unter 1000 Euro

by Volker Weber

ZZ7814A156

Aktuell gibt es Surface Pro zu attraktiven Preisen unter 1000 Euro. Interessant sind die Konfigurationen ohne Lüfter aber guter Ausstattung mit Speicher und Prozessor. Hauptunterschied zwischen Surface Pro "5" aus 2017 und Surface Pro 6 aus 2018 ist der Prozessor: 7. und 8. Generation. Auch zu beachten: Die 2017er kommen mit Windows Pro. Das hat Bitlocker Device Protection, was mir wichtiger ist als ein neuerer Prozessor.

Dazu muss man noch eine Tastatur kaufen. Die mit Alcantara Bezug kostet je nach Farbe ab 20 € mehr. Ich benutze Windows Hello zur Anmeldung mit der eingebauten Kamera. Es gibt aber auch ein Type Cover mit Fingerabdruckleser.

Surface Pro ist ideal für Leute, die nicht einen Laptop und ein Tablet mitschleppen wollen, dabei aber trotzdem mit Microsoft Office arbeiten wollen. Die Type Cover sehe ich als Verbrauchsmaterial. Wenn einem da mal ein Getränk drauffällt, ist nicht der ganze Rechner hin.

08 Mar 01:41

Toronto Bike Show 2019

by dandy

Words and pictures by Jun Nogami

Today was the first day of the annual spring Toronto Bike Show. A lot of the trends that were apparent last year are continuing. There is a lot of activity in the e-bike area, and the technology is incrementally improving.

The Amego booth had their usual broad range of e-bikes.

These Riese and Müller cargo bikes caught my eye.

This one has a rear facing child seat for a larger kid.

Speaking of cargo bikes, Bob Bell from Wike was proud that their Salamander convertible bike won a gold award at Eurobike 2018. They are starting to sell into Europe as well.

Even Bianchi's kids bikes come in celeste.

This is Tern's 2nd generation Vektron. They revised the battery mounting position so that the rear rack could be lengthened. It also has feet on the rack so that the bike can be stood on end when its is folded to save floor space.

Speaking of floor space, Revelo was back with a prototype of a 700c wheel size folding bike. It is due to be released this spring.

It is also equipped with their thin stem so that it folds to a very small depth.

Industrial Bicycles is a large recumbent dealer in Dearborn, MI. Apparently they have a lot of Canadian customers. They were representing Terratrike at the show.

Blacksmith Cycles had their usual stand of high end bicycles. This one was very pretty and it was marked down as well.

This bike had a carbon fibre leaf spring fork.

There were plenty of accessories also. Yakima now makes a tent platform.

I'm a big fan of rain capes, some of the best ones are made by Cleverhood. It was great to talk to Susan, who designs their products. I told her about how I've modified my capes with a little patch of velcro on the front hem. All their products are sewn in New England. Their capes are carried locally by the Spacing store, but they are cheaper this weekend at the show.

She said that if you drop by their booth and mention that you heard about them on Dandyhorse, you'll get a free bandana or hat (until she runs out).

Krys from Grupetto Coffee in Dundas was serving the best coffee at the show, and raising funds for  World Bicycle Relief, IMBA Canada and Share The Road.

In addition to all of the vendors and booths, there are always BMX and bike polo events running throughout the day.

Lots to see, people to talk to, and some opportunities for deals as well. The show runs through Sunday.

08 Mar 01:41

ELECTRIC

by Emily Chang

ELECTRIC

Photo Caption: ELECTRIC

Photo taken at: San Francisco, California

Instagram filter used: Lark

View in Instagram ⇒

08 Mar 01:41

Unschooling myself: traces through time

by Lilia

Something I find amazing every time I experience it – how unschooling as an educational choice for the kids turns to be a personal learning trajectory for us, as parents.

Over the years it made me face my worst fears and imperfections, to see and accept things as they are and to learn from that point. Last year was very much about uncovering all sorts of implicit things about my relations with people and groups, and choices I make between taking care of myself and the others. Now, with a school for Alexander as a feasible option, it is very much about relations with external organisational structures and capability to be yourself independently of their boundaries and demands.

Some of this stuff is pretty personal and I write about it in friends-only LJ, but there are enough “tips of the iceberg” visible here as well. Since I went back to look at the traces of it anyway, I put a selection on links and quotes here as well.

Unschooling myself and project-based learning, December 2013

In a sense it feels like starting from scratch. Like I forgot everything I knew from theory and practice under the weight of the responsibility of helping my own kids to learn. At times I feel that I’ve never learnt so intensely and so transformatively as I learn now. It’s very much true that unschooling is not only about education, but about life choices and that it starts not from your kids, but from yourself.

Things you learn while homeschooling, February 2015

I had a burn-out once, so I know the symptoms. It’s easy to be overwhelmed by the responsibility, ‘to do’ lists or time slipping between my fingers. I’m learning to recognise when I need a break, how to help myself (with sleep, meditation, physical activity or whatever works in the moment), how to communicate it to others and arrange for help. I learn to recognise my own boundaries and to accept them. And then stretch them a little bit further 🙂

Family bias and what to do about it when homeschooling, March 2015

One of the things you see when you meet in a group of homeschooling families regularly is what I call “family bias”. While all of us aim at well rounded education for our kids, when you dig deeper it’s sometimes visible how parents’ interests and preferences shape learning environment for their kids.

Holding the space, April 2015

I don’t really give lessons. And I do less focused facilitation than I’d like to. Often it feels that Robert has more intense sessions with the kids than I do, helping them to learn programming, looking into space missions or exploring ancient myths. So sometimes I feel not fully satisfied because I’m not able to pinpoint in traditional terms what exactly I do.

Not back to school insights, August 2016

it’s scary to see how much the fear of “not complying” sits ingrained inside. How easy it is, just by looking at external requirements, to start bending here and there, starting on a slippery slope of loosing sight of the values that are the most essential. I’m so happy to have three little reminders running around, so I stay on the track

On socialisation and education, December 2017

We also talked about our homeschooling community. About the effort that it takes to build that village that we all need to raise our children. About newcomers and lurkers. About the challenges of staying open and having an environment build on trust and knowledge of each other. About the choices that everyone of us has to make, because to be fair it’s both education and socialisation that we create the conditions for. And yes, socialisation is an issue and it requires deliberate work.

Dealing with resistance and difficulties, September 2018

Yesterday we had a discussion with other homeschooling parents about “everything is cool and easy” picture that you usually get from the social media profiles of others and the importance of talking about the reality which is challenging enough. And I thought that I should start with myself and share a bit more of the “difficult” stuff that we have to deal with.

The post Unschooling myself: traces through time appeared first on Mathemagenic.

08 Mar 01:41

“In the days before selfies, THIS was a cool selfie.”

by Andrea

Wired: Astronaut Chris Hadfield on 13 Moments That Changed His Life. (YouTube, 16:31min) “Astronaut Chris Hadfield reflects on 13 important moments from his life and career, from learning to fly to being blinded temporarily in space to recording his famous cover of David Bowie’s “Space Oddity.””

08 Mar 01:41

Now Trending: The Future

by mayaganesh

Poster spotted in the Geoengineering and Geosciences department
at the University of Quebec at Abitibi and Temiscamingue. However, the author believes the future is not just about robots. (Image: Maya Ganesh, 2017)

It seems like there is a flowering of interest in speculating about the future. Of course SF writers, the RAND Group, and Trekkies, have been doing this for much longer. (An interesting side note: SF writers are now enjoying new income streams by working with multinational corporations to imagine the future.)

It is possible that as consumer technologies began to appear as if from ‘the future’, as presented to us in dystopian movies such as Bladerunner and Minority Report,  speculating about the future increasingly became a topic of interest. As the phrase ‘surveillance capitalism’ has gained visibility thanks to devices just as the Echo. And maybe things started to appear ‘Orwellian’ after the Snowden revelations. I would like to think that Intergovernmental Panel on Climate Change reports generate concern about the future; but the continued rising temperature of the planet suggests that this is not the case. Possibly for people in the US, the election of Donald Trump, for Brazilians of Jair Bolsonaro, The Future has become a thing to be worried about (‘now more than ever’).

I spent last weekend at a workshop called Designing Tomorrow organised by the great folks behind the Utopia Film Festival in Tel Aviv, and re:publica in Berlin. The workshop was about testing various methodologies to actually speculate about the future; and they drew heavily from Peter Frase’s Four Futures. It got me thinking about the different narratives to thinking about the future. Here is a quick overview of some of these that I’ve encountered through recent arts and culture projects, and in the tech news (These do not necessarily line up as perfectly nested Russian dolls, however.)

  1. The planet is a mess! Things are going extinct! Life as we know it is over! We can do nothing to stop it, except to come up with a beautifully designed ending. 
  2. So let us use reason, rationality and technology to transcend the mortal coil and start over on Mars.
  3. But why are we talking about extinction as a something about the future when it is already happening? Like, for example, a million indigenous people in India were just evicted from the forests that they have always lived in. This has “resurrected an old debate between forest rights groups and the conservation lobby.” The future is actually the past.
  4. Framed in terms of both the future and a catastrophic present, theorist Orit Halpern’s Planetary Futures Summer School project asked: “how we might imagine, and design, a future earth without escaping or denying the ruins of the one we inhabit? How shall we design and encounter the ineffable without denying history, colonialism, or normalizing violence? What forms of knowledge and experiment might produce non-normative ecologies of care between life forms? How shall we inhabit the catastrophe?” (Projects here)
  5. Mushon Zer-Aviv says we need to consider  Canceling the Apocalypse in favour of a different perception of the future(s). We need “to think beyond our dark visions, beyond Silicon Valley’s techno determinism, beyond dystopian dreams, beyond the resistance framework that leaves us always playing defence… we will reignite our political imagination… we will explore the futures as an open set of political possibilities rather than a predetermined algorithmic prediction.” .
  6. One of the ways Mushon and his collaborator  Shalev Moran have done this is through their Speculative Tourism project, a set of audio guides taking you through a Jerusalem 50 years into the future as imagined by a group of authors and artists.
  7. What you imagine is what you get, argue Mushon and Shalev. In terms of a planetary future, what if we imagined something “digitally inclined but unafraid of dirt. Think post-apocalyptic hacker aesthetics, but with a sunnier disposition.” Enter: Solarpunk.
  8. Another set of people are doing the work of creating new political imaginaries. They are thinking about the future in terms of the world we want, and have, now, rather than about the persistent theme of exit. Who gets to exit, as Sarah Sharma might ask? Octavia’s Brood is an anthology of  ‘visionary fiction’ because it “pulls from real life experience, inequalities and movement building to create innovative ways of understanding the world around us, paint visions of new worlds that could be, and teach us new ways of interacting with one another.”
  9. This is a theme echoed by other fellow travelers who ask why have certain narratives been privileged over others? Situated at the intersection of Art, Science and Technology they ask, what it would look like if “feminist, queer, de-colonial, disabled and historically marginalized artists…offer visions of the future outside and beyond the dominant discourse…” Might we find new possibilities of “Re-figuring The Future?
  10. Narratives about speculation about the future are situated. What do Asian speculations about the future look like?
  11. And critically, Ingrid Burrington asks how speculating about the future has been used and abused. How might the ‘inevitabilities of certain doom’ contained in the notion of a Future Perfect be challenged? How might “life find a way”?

What narratives about speculative futures are you noticing where you are?

*Thanks to participants at the Designing Tomorrows workshop who contributed some of these links at the workshop and in the group’s Slack channel. 

Maya Ganesh is a technology researcher and writer living in Berlin.  She is working on a PhD about how automated decision-making is playing out against the backdrop of  future imaginations of machine autonomy. She may be found on Twitter @mayameme

 

 

08 Mar 01:41

One place I will probably not buy a car.

(Update 23 Apr 2019: I wrote to ask this dealership how they got my info and didn't get an answer to my question. But they did put me on their email list in time to get the "April Shower of Savings" email so I've got that going for me which is nice.)

One place I will probably not buy a car: Franklin Sussex Auto Mall, in New Jersey.

I still have a Facebook account, I don't check Facebook often enough for it to be a good way to reach me. See the page footer here for contact info. mostly to keep up on the ad scene there. When I checked Facebook's page of ads targeting me, this company is listed under advertisers "Who use a contact list added to Facebook."

New Jersey car dealer

Somehow, Franklin Sussex Auto Mall got a hold of my email address or phone number, and uploaded it to Facebook. Have I ever shopped for a car in New Jersey? No. If I was shopping for a car, would I fly to New Jersey to buy it and then drive it home? No.

And now that I look at it, when I go through the advertisers that Facebook lists as having uploaded my info, most of them are car dealers I have never visited or contacted. Someone has a pretty good racket going here. How much are they making from the car dealers? (Yes, this is a bad thing, because car dealers could be spending that money to build positive reputation by funding local news, or other ad-supported resources with positive externalities, but we knew that already.)

Maybe when they write the history of the big social site era, it won't be about some all-seeing panopticon, but more about a bunch of people in a highly paid California bubble, mostly young guys who have been told they're smart their whole lives, getting out-hustled at a direct marketing business they don't really care about.

Bonus links

Let’s Talk About Fraud In Digital Advertising

Confessions of a location data exec: ‘It’s a Ponzi scheme’

Consent Fraud: A Simmering Problem That Could Scald The Ecosystem

You’re being used to steal $50 billion in digital advertising

The New York Times’ Mark Thompson on how he’d run a local newspaper: “Where can we stand and fight?”

The secret lives of Facebook moderators in America

AT&T pulls ads from YouTube over predatory comments on children

Even the IAB warned adtech risks EU privacy rules

Intelligent Tracking Prevention 2.1

Epic Games pulls Fortnite pre-roll ads on YouTube following child predator controversy

YouTube still can’t stop child predators in its comments

Meet DrainerBot, the Ad-Fraud Operation That Could Be Stealing Your Mobile Data

Why The Birth Of Surveillance Capitalism Signals The End Of Behavioral Targeting

Pinterest blocks vaccine-related searches in bid to fight anti-vaxx propaganda

Want to reduce political polarization? Save your local newspaper

08 Mar 01:41

Expedition to Colma BART station

by Liz

The Daly City DMV turns out to be half a mile’s easy walk from the Colma BART station so I headed on down there (holding my nose) to apply for a REAL ID driver’s license. I took an ancient (original?) copy of my birth certificate, my passport, my social security card, and some tax returns to prove residency — carefully sealed in a folder in a bag tucked in the undercarriage basket of my wheelchair.

Taking the J to Balboa Park station is now kind of fun. At the front of the car, I can see out the front window (in the old style cars) during the lovely part of the trip going around the rivery curves of San Jose Avenue Hello, Islais Creek! Hello, Little Boxes! (I think Malvinia Reynolds is rude and condescending… .people live there! it’s their homes! Chill out! You don’t know what they’re like! I bet they’re nice! So judgey.)

Balboa Park has a nice little convenience store and flower shop tucked between the two BART entrances, by the way!

One of my favorite things about above ground train lines is when they go past people’s back yards. You look past the entry of their intimacy gradient and right into the dreams of the private park of their family castle. Clotheslines with washing hung out, little chairs set out in hopeful groupings, shacks that might be garden sheds or someone might be living in there, kids’ toys scattered around. Just as you start turning to Daly City there are some sweet back yards that will make you love all of humanity. There was also some interesting graffiti. Following along on the map, I mark down any nifty looking bits of a neighborhood, with cafes or restaurants or parks for future visits.

The Daly City station is surrounded by parking lots and is airy and beautiful with a view of the ocean. I look forward to exploring it.

On the way to Colma, you go underground a couple of times, through open canyon-like cuts with interesting concrete textures on the sides – I kept expecting to see vines trailing down or some swallow nests. But no, just concrete. There are nice views of the west side of San Bruno Mountain with its lights and cell towers. I thought about how to put it into my game (in the time travel to the past, probably.) When the Spanish of the Rivera y Moncada party (including Padre Francisco Palóu) arrived from the south, they camped near here and met the Urebure people (among many others).

Diarist Palou recorded visits by friendly villagers, probably the Urebure people from their bay shore village of Siplichiquin, on December 3: About two in the afternoon twenty-four heathen came to visit us from villages other than the preceding, although they speak the same language and use many of the same words as those of Monterey. They brought us their present of large tamales, more than a span across and correspondingly thick, kneaded of a dough made of very black wild seeds, resembling tar … I returned their gift with strings of beads, and the captain did the same. (from Milikin’s book)

Urebure is sometimes listed as a place name or the name of the group of people who lived in this area. I have been doing a fair bit of reading about the Ohlone aka Costanoans aka Yelamu depending on who’s naming them (in San Francisco itself, the people were the Ramaytush but they apparently hung out with the Huchiun or Chochenyo folks from the East Bay and the Miwok from the north).

San Bruno mountain itself has an Ohlone “prayer circle” somewhere (I think on the Bay side). And, here’s some info on its geology. I’d like to take a drive through its canyon road and see what I can access from a wheelchair when the weather is nicer.

OK, so, more about that later. Back to Colma.

Colma station itself opens out into a large railyard. There are bright blue buildings kind of clustered around the rows of tracks. The station itself is half underground, half exposed, like Balboa Park. There are these things like holographic rainbow reflector panels – maybe simply meant to light the underground parts of the station? Or maybe an old art project? I couldn’t figure it out. Ingress showed them as a portal called “Arcoiris”, rainbow, with mention of a descriptive plaque which I couldn’t find on the lower platform. The elevator has 2 glass sides (doors opening either direction), making the ride entertaining. Bonus: it doesn’t smell like pee! The concourse level is also the street level, and has a giant metal things hanging from the high ceiling that looks like dirty chainmail, if shrimp wore chainmail. Poking around led me to discover this is called “Leonardo’s Dream“.

Goldstein’s sculpture, a series of eight spiral shapes called “Leonardo’s Dream,” is one of the biggest pieces of public art commissioned in the Bay Area in many years. He said its hundreds of blue and green aluminum panels will be blown by the wind coming off the ocean a few miles away.

“I looked at a Leonardo drawing called ‘Deluge’ and thought it was a wonderful image for a place with all this movement,” Goldstein said. “I’m hoping that as you rush off the train in a minute or 30 seconds, you might somehow be soothed and uplifted.”

Apologies to the artist but 20 years later it did not uplift. I thought of fly swatters, I thought of gnat-speckled grease-smoked screen doors in an old diner without air conditioning where they’ve been cooking hamburgers, I thought of bug zappers and ashtrays. Someone needs to hose that sucker off. Totally crusty.

But I tried to appreciate it. Old dudes hanging around the station gawked at me as I tried to take photos of the swoopy screen doors high over head. There was one guy with an enormous reclining powerchair with a huge wagon nicely attached at the back but he didn’t return my nod (that disabled people nod… you know!) so I didn’t ask him about it as I would have liked to.

The Colma station looks to have been designed for much greater ridership than they actually see. People definitely want to get to the airport on BART but I think this station didn’t become the intermodal commuter hub it was meant to be. In fact I don’t think I’ve ever known someone to use Colma as a jumping off point to park from the Peninsula and come to SF, for that, Millbrae seems more popular.

Coming out of Colma station there is a bridge leading to a huge parking garage and then if you pass that, another pedestrian bridge across the tracks with a magnificent view of the trains, the railyard, and the huge bright blue buildings.

colma bart

There is an interesting cluster of businesses including a gym, Los Metates taqueria, a Cybele’s Pizza (pizza + brazilian food; intriguing!), Keith’s Chicken N Waffles (sweet potato & red velvet waffles?!), and Pacifica Archery which has an indoor archery range. Cross highway 280 and you will pass by an In and Out Burger and Krispy Kreme on the way to the DMV. (2 hours total waiting, not really too bad – once I had a number assigned I went outside and did some work, getting online over my phone.) Strikingly, everyone was friendly – guys from auto body shops half out in the street working on cars, people who seemed nicely concerned that I have enough room on the sidewalk (not leaping to pull each other out of the way, just regular, nice courtesy). Everyone said hello or returned my smile and nod. (Of course, smiling, because of having such a nice expedition & happy to be out in the sunny day.)

Since I had my errand to do, I didn’t explore much. There is a street of restaurants in Colma and then all the cemeteries — I hear the Italian Cemetery is amazing to visit & it’s extremely close to the BART station. So, definitely worth more visits. Next time I’ll go to the Italian Cemetery and try the chicken n waffles.

Index to all posts describing my BART station visits

08 Mar 01:39

Managing personal learning in a VUCA world

by Jim

man hiking in forestSpinning a new consulting firm out of older, bigger, ones is a common story—no different from the founding of a new religious sect in a schism with the past. A charismatic leader and a few faithful followers declare a new revelation and start preaching from a new street corner.

When we started Diamond we all had experience in large professional service firms.  We were driven by things we didn’t like and wanted to fix and by opportunities we saw being ignored. We were less aware of the unique issues connected with being small and vulnerable.

Coming from big firms, we knew that training and knowledge management were important capabilities. As the only person who seemed marginally qualified, I was handed both problems and the hats of Chief Knowledge Officer and Chief Learning Officer. I had no staff and only the promise of a budget.

We lumped these two functions out of the reality of limited resources. In the organizations we had come from and knew, these functions were distinct. They demanded lots of resources and had grown from different origins and histories.

The decision rooted in our constraints generated insights that have become more relevant over the past twenty plus years. I want to start with the individual consultant—one of the prototypical knowledge workers that drive today’s organizations.

Alvin Toffler predicted that successful knowledge workers would be those who could “learn, unlearn, and relearn.” We live in the world he predicted. What we need to know as knowledge workers continues to grow at the same time that the half-life of our knowledge base continues to shrink.

The reality of this environment means that as a knowledge worker, you can’t count on organizations to be responsive enough to support your learning needs. They face the same problem you do and their problem is magnified by issues of scale.

Conventional strategies for learning break down. You can’t keep going back to school. You can’t afford the time and schools are as slow or slower to adapt their curricula to morphing demands as the organizations you inhabit.

Old avenues for learning in smaller, more up-to-date, chunks still exist and new avenues are appearing. If anything, the proliferation of options—YouTube, Udemy, EdX, Coursera, Khan Academy, workshops, seminars, webinars, ebooks—threatens overload more than relief.

What’s a reasonable path forward? I think it includes an explicit and dynamic personal learning plan coupled with a coherent set of supporting learning processes and practices. A learning plan should build on understanding how learning works, a view of your base of knowledge, and expectations of what skills and knowledge need developing.

Learning processes and practices provide the scaffolding and support structures that would otherwise be provided by the formal schooling environments that aren’t available. They will likely include:

  • reflective practice
  • cohort of co-learners
  • journals/journaling practice
  • reference management system
  • systematic note taking and management

What you might correctly infer from this is that I am actively engaged in updating and formalizing my own plans and practices. I’m curious who else finds this a journey they might like to join?

The post Managing personal learning in a VUCA world appeared first on McGee's Musings.

08 Mar 01:39

50 Stockwerke

by Volker Weber

e42c057bfbe5d1d7fab0a0edc04ad4c1

08 Mar 01:39

Simple, but Hard

by Eric Karjaluoto

TL;DR: The solutions to many problems are simple. That doesn’t make them easy to act on, though. I’m fat. I hate that word. I hate how some think it’s OK to comment on others’ weight. I hate that Homer Simpson and I share the same silhouette. And, I hate that no matter how good I […]

The post Simple, but Hard appeared first on Eric Karjaluoto.

08 Mar 01:38

Mark Hollis, R.I.P.

by Caterina Fake

Mark Hollis has died, I recently learned from Brian Behlendorf’s post on Twitter, the frontman for Talk Talk, a band that started out with some easy pop hits, toured with Duran Duran and then diverted their talents into incredible albums like Spirit of Eden, on which this song, The Rainbow, appeared.

Beautiful, tentative singing by Mark Hollis. And here’s a somewhat ponderous interview with him talking about the making of the album.

 

08 Mar 01:38

Verrottet

by Volker Weber

Da kann man leider gar nichts machen. Ohne Facebook, Instagram und WhatsApp ist das Leben ja nichts mehr wert.

08 Mar 01:38

Supertrain

by peter@rukavina.net (Peter Rukavina)

I viscerally remember the 1979 NBC show Supertrain: more so than any TV show or movie I’d seen before, it showed a tantalizing vision of the future that I could get behind. A train with a swimming pool: imagine.

Nothing in the real world had ever come close to Supertrain until I saw this tour of the E001系, an amazing Japanese luxury train that features two-level suites, fireplaces, and an observation car that puts VIA Rail’s dome car to shame.

,
08 Mar 01:38

Found Objects

In the tradition of the Internet I don't build new networks nor new special environments for each application but rather repurse existing devices and services. The key is an architcture which limits complexity.
08 Mar 01:38

Good Mail Day! Workshop

by peter@rukavina.net (Peter Rukavina)

Jennifer Brown (you’ll remember her from the Japanese Bookbinding Course and its sequel, as well as from her role as Oliver’s artistic spirit guide) is holding a workshop on Saturday, March 23, 2019 called Good Mail Day! From the poster:

Good Mail Day Art Workshop

The international movement celebrating fun snail mail.

Decorate envelopes and postcards in collage and more.
Make unusual folder letters and envelopes.
Send a surprise to a grandchild, senior of friend!
Each participant works at own comfort zone.

Brown bag lunch. Teas, Coffee and Snacks Provided.

I know, both from personal experience and from watching Jennifer work with Oliver over the past two years, that she is a skilled and creative art educator. If you’ve an interest in mail art, this is your chance to get together with a great group of people in a bright, sunny Crapaud studio, on a March afternoon.

The workshop runs from 10:00 a.m. to 3:30 p.m. and the cost is $60. You can register by contacting Jennifer at 902-658-2354 or by email at browniferjen@gmail.com.

08 Mar 01:38

2019 Goals - Two months check in

Checking in with my two month goals.

  • Lost a couple of pounds but keep going up and down.

  • Diet has fallen completely and this is where I need to get back on track.

  • Running has improved again. The training runs are getting longer and longer. I did my longest run 11.2km and broke 30km a week twice.

  • I thought I did the West Van Run in 29 minutes last year. Turns out it was over 30 minutes. This year I came in 27.29, which puts me at a solid 5:30 pace. Faster than last time.

  • Gym work has picked up a little, mostly a chance to do long slow bike rides and focus on keeping my heart in zone 1.

  • Haven't had alcohol since 2018 even though I've been to some pubs.

More to do, especially on the weight loss.

08 Mar 01:36

Plantronics 6200 UC :: Zwei Wochen in den Ohren

by Volker Weber

ebb4dd4d10c3962fc612ce758d7c73bf

Vor zwei Wochen habe ich schon mal über das Voyager 6200 UC geschrieben. Seit dem habe ich es so viel getragen, dass ich meine Eindrücke noch mal ergänzen will.

Bei einigen Headsets braucht es ein bisschen, bis ich sie so richtig schätzen lerne. Die PLT Voyager 6200 gehören dazu. Das lag wohl daran, dass ich zunächst die mittelgroßen Gels auf den Ohrstöpseln hatte. Damit waren sie nicht perfekt dicht und das Headset entwickelte nicht genügend Bass. Außerdem saßen die Stöpsel zu tief im Ohr und das war auf die Dauer unbequem.

Seit ich die großen Gels montiert habe, benutze ich fast nichts anderes mehr. Morgens lege ich den Bügel um den Hals und schalte das Headset ein. Abends nehme ich es wieder ab und lege es auf die kleine Ladebasis. Zwischendurch höre ich dann Musik oder telefoniere. Je nach Lautstärke der Musik bin ich total isoliert oder höre noch ein bisschen, was auf der Straße um mich herum passiert. In Mailand habe ich sie zum Beispiel drei Tage lang getragen und sie nur zum Schlafen abgelegt. Meine Wahl war eigentlich darauf gefallen, weil es sich viel kleiner als Beats verpacken lässt, aber dann war es nicht einmal in der Tasche.

Das ANC des 6200 ist eher sanft. Kein Cabin Pressure, aber es verbessert die Basswiedergabe. Ich habe es dauernd eingeschaltet. Ein bisschen Sorgen bereiten mir die sehr dünnen Strippen. Die sollte man wohl besser nicht knicken oder gar darauf kauen. Im Etui des Headsets sind sie perfekt geschützt.

Diese Woche werde ich mal ein neues Over-The-Ear Headset testen. Aber wenn das zurückgeht, dann hole ich wieder dieses Voyager raus.

More >

08 Mar 01:36

Can you handle disruption?

by Charlene Li

Can your company handle the disruption that it needs? If you’re not sure about that answer then let’s work on it. What is culture? Culture is simply a system of beliefs. And if your beliefs are holding you back from moving into the disruption, it’s the beliefs that you don’t have permission, you don’t have […]

The post Can you handle disruption? appeared first on Charlene Li.

08 Mar 01:36

Early astronomer commitment schemes

by Liz

Today I learned that early astronomers were hella clever. I was looking up good colony sites or just interesting topographic features for each planet or other solar body that I think would make a good future BART stop in Transitory and came across this:

Early astronomers used anagrams as a form of commitment scheme to lay claim to new discoveries before their results were ready for publication. Galileo used smaismrmilmepoetaleumibunenugttauiras for Altissimum planetam tergeminum observavi (“I have observed the most distant planet to have a triple form”) for discovering the rings of Saturn.

Working on this game is an endless delight!

Huygens did it too.

Huygens observed Saturn and in 1656, like Galileo, had published an anagram saying “aaaaaaacccccdeeeeeghiiiiiiillllmmnnnnnnnnnooooppqrrstttttuuuuu”. Upon confirming his observations, three years later he revealed it to mean “Annuto cingitur, tenui, plano, nusquam coherente, ad eclipticam inclinato”; that is, “It [Saturn] is surrounded by a thin, flat, ring, nowhere touching, inclined to the ecliptic”

The Terraforming Wiki is very useful for my descriptions of the Solar Line stations.

Meanwhile, have a look at this cool delta-v subway map of the solar system!

I also direct your attention to the fabulous Interplanetary Transport Network wikipedia page.

08 Mar 01:35

CRAN Mirror “Security”

by hrbrmstr

In the “Changes on CRAN” section of the latest version of the The R Journal (Vol. 10/2, December 2018) had this short blurb entitled “CRAN mirror security”:

Currently, there are 100 official CRAN mirrors, 68 of which provide both secure downloads via ‘https’ and use secure mirroring from the CRAN master (via rsync through ssh tunnels). Since the R 3.4.0 release, chooseCRANmirror() offers these mirrors in preference to the others which are not fully secured (yet).

I would have linked to the R Journal section quoted above but I can’t because I’m blocked from accessing all resources at the IP address serving cran.r-project.org from my business-class internet connection likely due to me having a personal CRAN mirror (that was following the rules, which I also cannot link to since I can’t get to the site).

That word — “security” — is one of the most misunderstood and misused terms in modern times in many contexts. The context for the use here is cybersecurity and since CRAN (and others in the R community) seem to equate transport-layer uber-obfuscation with actual security/safety I thought it would be useful for R users in general to get a more complete picture of these so-called “secure” hosts. I also did this since I had to figure out another way to continue to have a CRAN mirror and needed to validate which nodes both supported + allowed mirroring and were at least somewhat trustworthy.

Unless there is something truly egregious in a given section I’m just going to present data with some commentary (I’m unamused abt being blocked so some commentary has an unusually sharp edge) and refrain from stating “X is 👍|👎” since the goal is really to help you make the best decision of which mirror to use on your own.

The full Rproj supporting the snippets in this post (and including the data gathered by the post) can be found in my new R blog projects.

We’re going to need a few supporting packages so let’s get those out of the way:

library(xml2)
library(httr)
library(curl)
library(stringi)
library(urltools)
library(ipinfo) # install.packages("ipinfo", repos = "https://cinc.rud.is/")
library(openssl)
library(furrr)
library(vershist) # install.packages("vershist", repos = "https://cinc.rud.is/")
library(ggalt)
library(ggbeeswarm)
library(hrbrthemes)
library(tidyverse)

What Is “Secure”?

As noted, CRAN folks seem to think encryption == security since the criteria for making that claim in the R Journal was transport-layer encryption for rsync (via ssh) mirroring from CRAN to a downstream mirror and a downstream mirror providing an https transport for shuffling package binaries and sources from said mirror to your local system(s). I find that equally as adorable as I do the rhetoric from the Let’s Encrypt cabal as this https gets you:

  • in theory protection from person-in-the-middle attacks that could otherwise fiddle with the package bits in transport
  • protection from your organization or ISP knowing what specific package you were grabbing; note that unless you’ve got a setup where your DNS requests are also encrypted the entity that controls your transport layer does indeed know exactly where you’re going.

and…that’s about it.

The soon-to-be-gone-and-formerly-green-in-most-browsers lock icon alone tells you nothing about the configuration of any site you’re connecting to and using rsync over ssh provides no assurance as to what else is on the CRAN mirror server(s), what else is using the mirror server(s), how many admins/users have shell access to those system(s) nor anything else about the cyber hygiene of those systems.

So, we’re going to look at (not necessarily in this order & non-exhaustively since this isn’t a penetration test and only lightweight introspection has been performed):

  • how many servers are involved in a given mirror URL
  • SSL certificate information including issuer, strength, and just how many other domains can use the cert
  • the actual server SSL transport configuration to see just how many CRAN mirrors have HIGH or CRITICAL SSL configuration issues
  • use (or lack thereof) HTTP “security” headers (I mean, the server is supposed to be “secure”, right?)
  • how much other “junk” is running on a given CRAN mirror (the more running services the greater the attack surface)

We’ll use R for most of this, too (I’m likely never going to rewrite longstanding SSL testers in/for R).

Let’s dig in.

Acquiring Most of the Metadata

It can take a little while to run some of the data gathering steps so the project repo includes the already-gathered data. But, we’ll show the work on the first bit of reconnaissance which involves:

  • Slurping the SSL certificate from the first server in each CRAN mirror entry (again, I can’t link to the mirror page because I literally can’t see CRAN or the main R site anymore)
  • Performing an HTTP HEAD request (to minimize server bandwidth & CPU usage) of the full CRAN mirror URL (we have to since load balancers or proxies could re-route us to a completely different server otherwise)
  • Getting an IP address for each CRAN mirror
  • Getting metadata about that IP address

This all done below:

if (!file.exists(here::here("data/mir-dat.rds"))) {
  mdoc <- xml2::read_xml(here::here("data/mirrors.html"), as_html = TRUE)

  xml_find_all(mdoc, ".//td/a[contains(@href, 'https')]") %>%
    xml_attr("href") %>%
    unique() -> ssl_mirrors

  plan(multiprocess)

  # safety first
  dl_cert <- possibly(openssl::download_ssl_cert, NULL)
  HEAD_ <- possibly(httr::HEAD, NULL)
  dig <- possibly(curl::nslookup, NULL)
  query_ip_ <- possibly(ipinfo::query_ip, NULL)

  ssl_mirrors %>%
    future_map(~{
      host <- domain(.x)
      ip <- dig(host, TRUE)
      ip_info <- if (length(ip)) query_ip_(ip) else NULL
      list(
        host = host,
        cert = dl_cert(host),
        head = HEAD_(.x),
        ip = ip,
        ip_info = ip_info
      )
    }) -> mir_dat

  saveRDS(mir_dat, here::here("data/mir-dat.rds"))
} else {
  mir_dat <- readRDS(here::here("data/mir-dat.rds"))
}

# take a look

str(mir_dat[1], 3)
## List of 1
##  $ :List of 5
##   ..$ host   : chr "cloud.r-project.org"
##   ..$ cert   :List of 4
##   .. ..$ :List of 8
##   .. ..$ :List of 8
##   .. ..$ :List of 8
##   .. ..$ :List of 8
##   ..$ head   :List of 10
##   .. ..$ url        : chr "https://cloud.r-project.org/"
##   .. ..$ status_code: int 200
##   .. ..$ headers    :List of 13
##   .. .. ..- attr(*, "class")= chr [1:2] "insensitive" "list"
##   .. ..$ all_headers:List of 1
##   .. ..$ cookies    :'data.frame':   0 obs. of  7 variables:
##   .. ..$ content    : raw(0) 
##   .. ..$ date       : POSIXct[1:1], format: "2018-11-29 09:41:27"
##   .. ..$ times      : Named num [1:6] 0 0.0507 0.0512 0.0666 0.0796 ...
##   .. .. ..- attr(*, "names")= chr [1:6] "redirect" "namelookup" "connect" "pretransfer" ...
##   .. ..$ request    :List of 7
##   .. .. ..- attr(*, "class")= chr "request"
##   .. ..$ handle     :Class 'curl_handle' <externalptr> 
##   .. ..- attr(*, "class")= chr "response"
##   ..$ ip     : chr "52.85.89.62"
##   ..$ ip_info:List of 8
##   .. ..$ ip      : chr "52.85.89.62"
##   .. ..$ hostname: chr "server-52-85-89-62.jfk6.r.cloudfront.net"
##   .. ..$ city    : chr "Seattle"
##   .. ..$ region  : chr "Washington"
##   .. ..$ country : chr "US"
##   .. ..$ loc     : chr "47.6348,-122.3450"
##   .. ..$ postal  : chr "98109"
##   .. ..$ org     : chr "AS16509 Amazon.com, Inc."

Note that two sites failed to respond so they were excluded from all analyses.

A Gratuitous Map of “Secure” CRAN Servers

Since ipinfo.io‘s API returns lat/lng geolocation information why not start with a map (since that’s going to be the kindest section of this post):

maps::map("world", ".", exact = FALSE, plot = FALSE,  fill = TRUE) %>%
  fortify() %>%
  filter(region != "Antarctica") -> world

map_chr(mir_dat, ~.x$ip_info$loc) %>%
  stri_split_fixed(pattern = ",", n = 2, simplify = TRUE) %>%
  as.data.frame(stringsAsFactors = FALSE) %>%
  as_tibble() %>%
  mutate_all(list(as.numeric)) -> wheres_cran

ggplot() +
  ggalt::geom_cartogram(
    data = world, map = world, aes(long, lat, map_id=region),
    color = ft_cols$gray, size = 0.125
  ) +
  geom_point(
    data = wheres_cran, aes(V2, V1), size = 2,
    color = ft_cols$slate, fill = alpha(ft_cols$yellow, 3/4), shape = 21
  ) +
  ggalt::coord_proj("+proj=wintri") +
  labs(
    x = NULL, y = NULL,
    title = "Geolocation of HTTPS-'enabled' CRAN Mirrors"
  ) +
  theme_ft_rc(grid="") +
  theme(axis.text = element_blank())

Shakesperian Security

What’s in a [Subject Alternative] name? That which we call a site secure. By using dozens of other names would smell as not really secure at all? —Hackmeyo & Pwndmeyet (II, ii, 1-2)

The average internet user likely has no idea that one SSL certificate can front a gazillion sites. I’m not just talking a wildcard cert (e.g. using *.rud.is for all rud.is subdomains which I try not to do for many reasons), I’m talking dozens of subject alternative names. Let’s examine some data since an example is better than blathering:

# extract some of the gathered metadata into a data frame
map_df(mir_dat, ~{
  tibble(
    host = .x$host,
    s_issuer = .x$cert[[1]]$issuer %||% NA_character_,
    i_issuer = .x$cert[[2]]$issuer %||% NA_character_,
    algo = .x$cert[[1]]$algorithm %||% NA_character_,
    names = .x$cert[[1]]$alt_names %||% NA_character_,
    nm_ct = length(.x$cert[[1]]$alt_names),
    key_size = .x$cert[[1]]$pubkey$size %||% NA_integer_
  )
}) -> certs

certs <- filter(certs, complete.cases(certs))

count(certs, host, sort=TRUE) %>%
  ggplot() +
  geom_quasirandom(
    aes("", n), size = 2,
    color = ft_cols$slate, fill = alpha(ft_cols$yellow, 3/4), shape = 21
  ) +
  scale_y_comma() +
  labs(
    x = NULL, y = "# Servers",
    title = "Distribution of the number of alt-names in CRAN mirror certificates"
  ) +
  theme_ft_rc(grid="Y")

Most only front a couple but there are some with a crazy amount of domains. We can look at a slice of cran.cnr.berkeley.edu:

filter(certs, host == "cran.cnr.berkeley.edu") %>%
  select(names) %>%
  head(20)
names
nature.berkeley.edu
ag-labor.cnr.berkeley.edu
agro-laboral.cnr.berkeley.edu
agroecology.berkeley.edu
anthoff.erg.berkeley.edu
are-dev.cnr.berkeley.edu
are-prod.cnr.berkeley.edu
are-qa.cnr.berkeley.edu
are.berkeley.edu
arebeta.berkeley.edu
areweb.berkeley.edu
atkins-dev.cnr.berkeley.edu
atkins-prod.cnr.berkeley.edu
atkins-qa.cnr.berkeley.edu
atkins.berkeley.edu
bakerlab-dev.cnr.berkeley.edu
bakerlab-prod.cnr.berkeley.edu
bakerlab-qa.cnr.berkeley.edu
bamg.cnr.berkeley.edu
beahrselp-dev.cnr.berkeley.edu

The project repo has some more examples and you can examine as many as you like.

For some CRAN mirrors the certificate is used all over the place at the hosting organization. That alone isn’t bad, but organizations are generally terrible at protecting the secrets associated with certificate generation (just look at how many Google/Apple app store apps are found monthly to be using absconded-with enterprise certs) and since each server with these uber-certs has copies of public & private bits users had better hope that mal-intentioned ne’er-do-wells do not get copies of them (making it easier to impersonate any one of those, especially if an attacker controls DNS).

This Berkeley uber-cert is also kinda cute since it mixes alt-names for dev, prod & qa systems across may different apps/projects (dev systems are notoriously maintained improperly in virtually every organization).

There are legitimate reasons and circumstances for wildcard certs and taking advantage of SANs. You can examine what other CRAN mirrors do and judge for yourself which ones are Doing It Kinda OK.

Size (and Algorithm) Matters

In some crazy twist of pleasant surprises most of the mirrors seem to do OK when it comes to the algorithm and key size used for the certificate(s):

distinct(certs, host, algo, key_size) %>%
  count(algo, key_size, sort=TRUE)
algo key_size n
sha256WithRSAEncryption 2048 59
sha256WithRSAEncryption 4096 13
ecdsa-with-SHA256 256 2
sha256WithRSAEncryption 256 1
sha256WithRSAEncryption 384 1
sha512WithRSAEncryption 2048 1
sha512WithRSAEncryption 4096 1

You can go to the mirror list and hit up SSL Labs Interactive Server Test (which has links to many ‘splainers) or use the ssllabs🔗 R package to get the grade of each site. I dig into the state of config and transport issues below but will suggest that you stick with sites with ecdsa certs or sha256 and higher numbers if you want a general, quick bit of guidance.

Where Do They Get All These Wonderful Certs?

Certs come from somewhere. You can self-generate play ones, setup your own internal/legit certificate authority and augment trust chains, or go to a bona-fide certificate authority to get a certificate.

Your browsers and operating systems have a built-in set of certificate authorities they trust and you can use ssllabs::get_root_certs()🔗 to see an up-to-date list of ones for Mozilla, Apple, Android, Java & Windows. In the age of Let’s Encrypt, certificates have almost no monetary value and virtually no integrity value so where they come from isn’t as important as it used to be, but it’s kinda fun to poke at it anyway:

distinct(certs, host, i_issuer) %>%
  count(i_issuer, sort = TRUE) %>%
  head(28)
i_issuer n
CN=DST Root CA X3,O=Digital Signature Trust Co. 20
CN=COMODO RSA Certification Authority,O=COMODO CA Limited,L=Salford,ST=Greater Manchester,C=GB 7
CN=DigiCert Assured ID Root CA,OU=www.digicert.com,O=DigiCert Inc,C=US 7
CN=DigiCert Global Root CA,OU=www.digicert.com,O=DigiCert Inc,C=US 6
CN=DigiCert High Assurance EV Root CA,OU=www.digicert.com,O=DigiCert Inc,C=US 6
CN=QuoVadis Root CA 2 G3,O=QuoVadis Limited,C=BM 5
CN=USERTrust RSA Certification Authority,O=The USERTRUST Network,L=Jersey City,ST=New Jersey,C=US 5
CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE 4
CN=Trusted Root CA SHA256 G2,O=GlobalSign nv-sa,OU=Trusted Root,C=BE 3
CN=COMODO ECC Certification Authority,O=COMODO CA Limited,L=Salford,ST=Greater Manchester,C=GB 2
CN=DFN-Verein PCA Global – G01,OU=DFN-PKI,O=DFN-Verein,C=DE 2
OU=Security Communication RootCA2,O=SECOM Trust Systems CO.\,LTD.,C=JP 2
CN=AddTrust External CA Root,OU=AddTrust External TTP Network,O=AddTrust AB,C=SE 1
CN=Amazon Root CA 1,O=Amazon,C=US 1
CN=Baltimore CyberTrust Root,OU=CyberTrust,O=Baltimore,C=IE 1
CN=Certum Trusted Network CA,OU=Certum Certification Authority,O=Unizeto Technologies S.A.,C=PL 1
CN=DFN-Verein Certification Authority 2,OU=DFN-PKI,O=Verein zur Foerderung eines Deutschen Forschungsnetzes e. V.,C=DE 1
CN=Go Daddy Root Certificate Authority – G2,O=GoDaddy.com\, Inc.,L=Scottsdale,ST=Arizona,C=US 1
CN=InCommon RSA Server CA,OU=InCommon,O=Internet2,L=Ann Arbor,ST=MI,C=US 1
CN=QuoVadis Root CA 2,O=QuoVadis Limited,C=BM 1
CN=QuoVadis Root Certification Authority,OU=Root Certification Authority,O=QuoVadis Limited,C=BM 1

That first one is Let’s Encrypt, which is not unexpected since they’re free and super easy to setup/maintain (especially for phishing campaigns).

A “fun” exercise might be to Google/DDG around for historical compromises tied to these CAs (look in the subject ones too if you’re playing with the data at home) and see what, eh, issues they’ve had.

You might want to keep more of an eye on this whole “boring” CA bit, too, since some trust stores are noodling on the idea of trusting surveillance firms and you never know what Microsoft or Google is going to do to placate authoritarian regimes and allow into their trust stores.

At this point in the exercise you’ve got

  • how many domains a certificate fronts
  • certificate strength
  • certificate birthplace

to use when formulating your own decision on what CRAN mirror to use.

But, as noted, certificate breeding is not enough. Let’s dive into the next areas.

It’s In The Way That You Use It

You can’t just look at a cert to evaluate site security. Sure, you can spend 4 days and use the aforementioned ssllabs package to get the rating for each cert (well, if they’ve been cached then an API call won’t be an assessment so you can prime the cache with 4 other ppl in one day and then everyone else can use the cached values and not burn the rate limit) or go one-by-one in the SSL Labs test site, but we can also use a tool like testssl.sh🔗 to gather technical data via interactive protocol examination.

I’m being a bit harsh in this post, so fair’s fair and here are the plaintext results from my own run of testssl.sh for rud.is along with ones from Qualys:

As you can see in the detail pages, I am having an issue with the provider of my .is domain (severe limitation on DNS record counts and types) so I fail CAA checks because I literally can’t add an entry for it nor can I use a different nameserver. Feel encouraged to pick nits about that tho as that should provide sufficient impetus to take two weeks of IRL time and some USD to actually get it transferred (yay. international. domain. providers.)

The project repo has all the results from a weekend run on the CRAN mirrors. No special options were chosen for the runs.

list.files(here::here("data/ssl"), "json$", full.names = TRUE) %>%
  map_df(jsonlite::fromJSON) %>%
  as_tibble() -> ssl_tests

# filter only fields we want to show and get them in order
sev <- c("OK", "LOW", "MEDIUM", "HIGH", "WARN", "CRITICAL")

group_by(ip) %>%
  count(severity) %>%
  ungroup() %>%
  complete(ip = unique(ip), severity = sev) %>%
  mutate(severity = factor(severity, levels = sev)) %>% # order left->right by severity
  arrange(ip) %>%
  mutate(ip = factor(ip, levels = rev(unique(ip)))) %>% # order alpha by mirror name so it's easier to ref
  ggplot(aes(severity, ip, fill=n)) +
  geom_tile(color = "#b2b2b2", size = 0.125) +
  scale_x_discrete(name = NULL, expand = c(0,0.1), position = "top") +
  scale_y_discrete(name = NULL, expand = c(0,0)) +
  viridis::scale_fill_viridis(
    name = "# Tests", option = "cividis", na.value = ft_cols$gray
  ) +
  labs(
    title = "CRAN Mirror SSL Test Summary Findings by Severity"
  ) +
  theme_ft_rc(grid="") +
  theme(axis.text.y = element_text(size = 8, family = "mono")) -> gg

# We're going to move the title vs have too wide of a plot

gb <- ggplot2::ggplotGrob(gg)
gb$layout$l[gb$layout$name %in% "title"] <- 2

grid::grid.newpage()
grid::grid.draw(gb)

Thankfully most SSL checks come back OK. Unfortunately, many do not:

filter(ssl_tests,severity == "HIGH") %>% 
  count(id, sort = TRUE)
id n
BREACH 42
cipherlist_3DES_IDEA 37
cipher_order 34
RC4 16
cipher_negotiated 10
LOGJAM-common_primes 9
POODLE_SSL 6
SSLv3 6
cert_expiration_status 1
cert_notAfter 1
fallback_SCSV 1
LOGJAM 1
secure_client_renego 1
filter(ssl_tests,severity == "CRITICAL") %>% 
  count(id, sort = TRUE)
id n
cipherlist_LOW 16
TLS1_1 5
CCS 2
cert_chain_of_trust 1
cipherlist_aNULL 1
cipherlist_EXPORT 1
DROWN 1
FREAK 1
ROBOT 1
SSLv2 1

Some CRAN mirror site admins aren’t keeping up with secure SSL configurations. If you’re not familiar with some of the acronyms here are a few (fairly layman-friendly) links:

You’d be hard-pressed to have me say that the presence of these is the end of the world (I mean, you’re trusting random servers to provide packages for you which may run in secure enclaves on production code, so how important can this really be?) but I also wouldn’t attach the word “secure” to any CRAN mirror with HIGH or CRITICAL SSL configuration weaknesses.

Getting Ahead[er] Of Myself

We did the httr::HEAD() request primarily to capture HTTP headers. And, we definitely got some!

map_df(mir_dat, ~{

  if (length(.x$head$headers) == 0) return(NULL)

  host <- .x$host

  flatten_df(.x$head$headers) %>%
    gather(name, value) %>%
    mutate(host = host)

}) -> hdrs

count(hdrs, name, sort=TRUE) %>%
  head(nrow(.))
name n
content-type 79
date 79
server 79
last-modified 72
content-length 67
accept-ranges 65
etag 65
content-encoding 38
connection 28
vary 28
strict-transport-security 13
x-frame-options 8
x-content-type-options 7
cache-control 4
expires 3
x-xss-protection 3
cf-ray 2
expect-ct 2
set-cookie 2
via 2
ms-author-via 1
pragma 1
referrer-policy 1
upgrade 1
x-amz-cf-id 1
x-cache 1
x-permitted-cross-domain 1
x-powered-by 1
x-robots-tag 1
x-tuna-mirror-id 1
x-ua-compatible 1

There are a handful of “security” headers that kinda matter so we’ll see how many “secure” CRAN mirrors use “security” headers:

c(
  "content-security-policy", "x-frame-options", "x-xss-protection",
  "x-content-type-options", "strict-transport-security", "referrer-policy"
) -> secure_headers

count(hdrs, name, sort=TRUE) %>%
  filter(name %in% secure_headers)
name n
strict-transport-security 13
x-frame-options 8
x-content-type-options 7
x-xss-protection 3
referrer-policy 1

I’m honestly shocked any were in use but only a handful or two are using even one “security” header. cran.csiro.au uses all five of the above so good on ya Commonwealth Scientific and Industrial Research Organisation!

I keep putting the word “security” in quotes as R does nothing with these headers when you do an install.packages(). As a whole they’re important but mostly when it comes to your safety when browsing those CRAN mirrors.

I would have liked to have seen at least one with some Content-Security-Policy header, but a girl can at least dream.

Version Aversion

There’s another HTTP response header we can look at, the Server one which is generally there to help attackers figure out whether they should target you further for HTTP server and application attacks. No, I mean it! Back in the day when geeks rules the internets — and it wasn’t just a platform for cat pictures and pwnd IP cameras — things like the Server header were cool because it might help us create server-specific interactions and build cool stuff. Yes, modern day REST APIs are likely better in the long run but the naiveté of the silver age of the internet was definitely something special (and also led to the chaos we have now). But, I digress.

In theory, no HTTP server in it’s rightly configured digital mind would tell you what it’s running down to the version level, but most do. (Again, feel free to pick nits that I let the world know I run nginx…or do I). Assuming the CRAN mirrors haven’t been configured to deceive attackers and report what folks told them to report we can survey what they run behind the browser window:

filter(hdrs, name == "server") %>%
  separate(
    value, c("kind", "version"), sep="/", fill="right", extra="merge"
  ) -> svr

count(svr, kind, sort=TRUE)
kind n
Apache 57
nginx 15
cloudflare 2
CSIRO 1
Hiawatha v10.8.4 1
High Performance 8bit Web Server 1
none 1
openresty 1

I really hope Cloudflare is donating bandwidth vs charging these mirror sites. They’ve likely benefitted greatly from the diverse FOSS projects many of these sites serve. (I hadn’t said anything bad about Cloudflare yet so I had to get one in before the end).

Lots run Apache (makes sense since CRAN-proper does too, not that I can validate that from home since I’m IP blocked…bitter much, hrbrmstr?) Many run nginx. CSIRO likely names their server that on purpose and hasn’t actually written their own web server. Hiawatha is, indeed, a valid web server. While there are also “high performance 8bit web servers” out there I’m willing to bet that’s a joke header value along with “none”. Finally, “openresty” is also a valid web server (it’s nginx++).

We’ll pick on Apache and nginx and see how current patch levels are. Not all return a version number but a good chunk do:

apache_httpd_version_history() %>%
  arrange(rls_date) %>%
  mutate(
    vers = factor(as.character(vers), levels = as.character(vers))
  ) -> apa_all

filter(svr, kind == "Apache") %>%
  filter(!is.na(version)) %>%
  mutate(version = stri_replace_all_regex(version, " .*$", "")) %>%
  count(version) %>%
  separate(version, c("maj", "min", "pat"), sep="\\.", convert = TRUE, fill = "right") %>%
  mutate(pat = ifelse(is.na(pat), 1, pat)) %>%
  mutate(v = sprintf("%s.%s.%s", maj, min, pat)) %>%
  mutate(v = factor(v, levels = apa_all$vers)) %>%
  arrange(v) -> apa_vers

filter(apa_all, vers %in% apa_vers$v) %>%
  arrange(rls_date) %>%
  group_by(rls_year) %>%
  slice(1) %>%
  ungroup() %>%
  arrange(rls_date) -> apa_yrs

ggplot() +
  geom_blank(
    data = apa_vers, aes(v, n)
  ) +
  geom_segment(
    data = apa_yrs, aes(vers, 0, xend=vers, yend=Inf),
    linetype = "dotted", size = 0.25, color = "white"
  ) +
  geom_segment(
    data = apa_vers, aes(v, n, xend=v, yend=0),
    color = ft_cols$gray, size = 8
  ) +
  geom_label(
    data = apa_yrs, aes(vers, Inf, label = rls_year),
    family = font_rc, color = "white", fill = "#262a31", size = 4,
    vjust = 1, hjust = 0, nudge_x = 0.01, label.size = 0
  ) +
  scale_y_comma(limits = c(0, 15)) +
  labs(
    x = "Apache Version #", y = "# Servers",
    title = "CRAN Mirrors Apache Version History"
  ) +
  theme_ft_rc(grid="Y") +
  theme(axis.text.x = element_text(family = "mono", size = 8, color = "white"))

O_O

I’ll let you decide if a six-year-old version of Apache indicates how well a mirror site is run or not. Sure, mitigations could be in place but I see no statement of efficacy on any site so we’ll go with #lazyadmin.

But, it’s gotta be better with nginx, right? It’s all cool & modern!

nginx_version_history() %>%
  arrange(rls_date) %>%
  mutate(
    vers = factor(as.character(vers), levels = as.character(vers))
  ) -> ngx_all

filter(svr, kind == "nginx") %>%
  filter(!is.na(version)) %>%
  mutate(version = stri_replace_all_regex(version, " .*$", "")) %>%
  count(version) %>%
  separate(version, c("maj", "min", "pat"), sep="\\.", convert = TRUE, fill = "right") %>%
  mutate(v = sprintf("%s.%s.%s", maj, min, pat)) %>%
  mutate(v = factor(v, levels = ngx_all$vers)) %>%
  arrange(v) -> ngx_vers

filter(ngx_all, vers %in% ngx_vers$v) %>%
  arrange(rls_date) %>%
  group_by(rls_year) %>%
  slice(1) %>%
  ungroup() %>%
  arrange(rls_date) -> ngx_yrs

ggplot() +
  geom_blank(
    data = ngx_vers, aes(v, n)
  ) +
  geom_segment(
    data = ngx_yrs, aes(vers, 0, xend=vers, yend=Inf),
    linetype = "dotted", size = 0.25, color = "white"
  ) +
  geom_segment(
    data = ngx_vers, aes(v, n, xend=v, yend=0),
    color = ft_cols$gray, size = 8
  ) +
  geom_label(
    data = ngx_yrs, aes(vers, Inf, label = rls_year),
    family = font_rc, color = "white", fill = "#262a31", size = 4,
    vjust = 1, hjust = 0, nudge_x = 0.01, label.size = 0
  ) +
  scale_y_comma(limits = c(0, 15)) +
  labs(
    x = "nginx Version #", y = "# Servers",
    title = "CRAN Mirrors nginx Version History"
  ) +
  theme_ft_rc(grid="Y") +
  theme(axis.text.x = element_text(family = "mono", color = "white"))

🤨

I will at close out this penultimate section with a “thank you!” to the admins at Georg-August-Universität Göttingen and Yamagata University for keeping up with web server patches.

You Made It This Far

If I had known you’d read to the nigh bitter end I would have made cookies. You’ll have to just accept the ones the blog gives your browser (those ones taste taste pretty bland tho).

The last lightweight element we’ll look at is “what else do these ‘secure’ CRAN mirrors run”?

To do this, we’ll turn to Rapid7 OpenData and look at what else is running on the IP addresses used by these CRAN mirrors. We already know some certs are promiscuous, so what about the servers themselves?

cran_mirror_other_things <- readRDS(here::here("data/cran-mirror-other-things.rds"))

# "top" 20
distinct(cran_mirror_other_things, ip, port) %>%
  count(ip, sort = TRUE) %>%
  head(20)
ip n
104.25.94.23 8
143.107.10.17 7
104.27.133.206 5
137.208.57.37 5
192.75.96.254 5
208.81.1.244 5
119.40.117.175 4
130.225.254.116 4
133.24.248.17 4
14.49.99.238 4
148.205.148.16 4
190.64.49.124 4
194.214.26.146 4
200.236.31.1 4
201.159.221.67 4
202.90.159.172 4
217.31.202.63 4
222.66.109.32 4
45.63.11.93 4
62.44.96.11 4

Four isn’t bad since we kinda expect at least 80, 443 and 21 (FTP) to be running. We’ll take those away and look at the distribution:

distinct(cran_mirror_other_things, ip, port) %>%
  filter(!(port %in% c(21, 80, 443))) %>%
  count(ip) %>%
  count(n) %>%
  mutate(n = factor(n)) %>%
  ggplot() +
  geom_segment(
    aes(n, nn, xend = n, yend = 0), size = 10, color = ft_cols$gray
  ) +
  scale_y_comma() +
  labs(
    x = "Total number of running services", y = "# hosts",
    title = "How many other services do CRAN mirrors run?",
    subtitle = "NOTE: Not counting 80/443/21"
  ) +
  theme_ft_rc(grid="Y")

So, what are these other ports?

distinct(cran_mirror_other_things, ip, port) %>%
  count(port, sort=TRUE)
port n
80 75
443 75
21 29
22 18
8080 6
25 5
53 2
2082 2
2086 2
8000 2
8008 2
8443 2
111 1
465 1
587 1
993 1
995 1
2083 1
2087 1

22 is SSH, 53 is DNS, 8000/8008/8080/8553 are web high ports usually associated with admin or API endpoints and generally a bad sign when exposed externally (especially on a “secure” mirror server). 25/465/587/993/995 all deal with mail sending and reading (not exactly a great service to have on a “secure” mirror server). I didn’t poke too hard but 208[2367] tend to be cPanel admin ports and those being internet-accessible is also not great.

Port 111 is sunrpc and is a really bad thing to expose to the internet or to run at all. But, the server is a “secure” CRAN mirror, so perhaps everything is fine.

FIN

While I hope this posts informs, I’ve worked in cybersecurity for ages and — as a result — don’t really expect anything to change. Tomorrow, I’ll still be blocked from the main CRAN & r-project.org site despite having better “security” than the vast majority of these “secure” CRAN mirrors (and was following the rules). Also CRAN mirror settings tend to be fairly invisible since most modern R users use the RStudio default (which is really not a bad choice from any “security” analysis angle), choose the first item in the mirror-chooser (Russian roulette!), or live with the setting in the site-wide Rprofile anyway (org-wide risk acceptance/”blame the admin”).

Since I only stated it way back up top (WordPress says this is ~3,900 words but much of that is [I think] code) you can get the full R project for this and examine the data yourself. There is a bit more data and code in the project since I also looked up the IP addresses in Rapid7’s FDNS OpenData study set to really see how many domains point to a particular CRAN mirror but really didn’t want to drag the post on any further.

Now, where did I put those Python 3 & Julia Jupyter notebooks…

08 Mar 01:35

Another speedbike design meeting

by jnyyz

Today, Calvin presented the near final design for a new bike for WHPSC.

Here I asked Trefor to point at a random point on the screen.

Here, Calvin cooks with a blow torch….

and here is another one of his side projects. This one is still safer than the submarine.

The build starts this week, in parallel with the team’s ASME entry. Hope to have the bike built and tested in time for this September. Which us luck.

08 Mar 01:29

Rewrites of a codebase are bad, right? Maybe it...

Rewrites of a codebase are bad, right? Maybe it’s more complex than that. Herb Caudill looks at six big rewrites and the lessons they teach us.

08 Mar 01:29

Molten salt reactors, prototyped back in the 19...

Molten salt reactors, prototyped back in the 1960s at Oak Ridge, may hold the key for combating climate change and doing something about the 300,000 tons of spent nuclear fuel that will otherwise be hanging around for the next 240,00 years. M. Mitchell Waldrop writes in Knowable Magazine:

Admittedly, it would take centuries for even a large network of molten salt reactors to work through the full backlog. But burning it would eliminate the need to safely store it for thousands of centuries. By consuming the long-lived isotopes like plutonium-239, molten salt reactors could reduce the nuclear waste stream to a comparatively small volume of fission products having half-lives of 30 years or less. By the 10 half-life rule, this waste would then need to be isolated for just 300 years.

The nuclear power question isn’t whether we’re going to continue to run our current reactors with their known deficiencies. Those need to be shut down, and they will be over time. We can’t keep running them forever. The real question, however, is if what we do next will be something that can help with both the current spent nuclear waste and climate problems.

08 Mar 01:20

"Sure there is class war, and it is my class, the rich, who are making it and we are winning."

“Sure there is class war, and it is my class, the rich, who are making it and we are...
08 Mar 01:20

"You are an old man who thinks in terms of nations and peoples. There are no nations. There are no..."

“You are an old man who thinks in terms of nations and peoples. There are no nations. There...
08 Mar 01:20

Feminist writer Rebecca Solnit on mansplaining and #MeToo | Rana Foroohar deflates the Rebecca...

Feminist writer Rebecca Solnit on mansplaining and #MeToo | Rana Foroohar deflates the Rebecca...