Friday, July 25, 2003

Diebold Election Systems on their Touchscreen Units


Company Defends Electronic Voting System

Diebold Election Systems said computer security experts at Johns Hopkins University in Baltimore reached their conclusions by using outdated computer code for its touchscreen software. The company also said the researchers ran the software on a device on which it was not designed to work.

In addition, Diebold said many of the weaknesses attributed to the operating system on which the software was tested are inapplicable to the operating system used by the North Canton, Ohio-based company.



OK. I just read the report, and I'm not done digesting it. The analysis covers a different area of the overall e-voting system than my last blog entry on GEMS, which is on the ballot server, not the touchscreen units that would be deployed in the field. This report focuses on the actual touchscreen units, which are discussed somewhat in Bald-Faced Lies about Black Box Voting Machines -- and according to one of the technicians interviewed, the touchscreen units are running Windows CE.

Some things to keep in mind:

When you install upgrade software on your computer, you use a floppy disk, CD, or download an archive from some location on line.

Installing or upgrading software on an embedded system (your DVD player is an embedded system) you frequently save the new software to a PCMCIA or other kind of 'smart card', and insert that card into the device. An area of memory ('flash') on the device is overwritten, and that constitutes installation. So the card is like your upgrade CD.

My recent blog entry focused on GEMS, Diebold's back-end server (ballot server). This entry and probably a much longer one will discuss the touchscreen units and precinct-ballot server communications, as analyzed in the John Hopkins ISI report.

Diebold is currently protesting that the analysts ran the allegedly Diebold source code on a Win2K machine, which was not the correct OS.

I'm going to go out on a limb here, but the differences between WinCE and Win2K are probably smaller than the differences between RedHat linux and BeOS. The code compiled on the 2K box, and after reading the John Hopkins ISI report, nothing they discuss concerns the compile OS, beyond the broad discussion of the implications of using an unsafe OS -- such as any version of Windows.

The OS protest is bull. I'm sorry, guys. My best advice to you right now is to pull your methodologies together, get a serious QA and project management team in place if you haven't found one by now, and completely redesign and rewrite the application, including tossing legacy code. It's obvious the older stuff had minimal oversight in development (this, by the way, is typical for software teams' first projects, and the reason why I'm not an early adopter of any technology that might come near my money, in fact, why I've been known to laugh out loud when discussing 'emerging' software).

The report does discuss certain distinctions between Windows and WinCE with regards to CE's treatment of smartcards, that is, how smartcards 'appear' when mounted on a system running CE, and what dangers may be present in a touchscreen box running the e-voting system they analyze. That's the only OS-specific discussion, and it's about the 'right' (runtime) OS.


Some initial notes:

The language of choice of the analyzed application, which is allegedly a version of the current Diebold application, was C++, which, like C, makes it easy to induce errors in memory management. Not on purpose.

Each instance of a voter corresponds to a voter card, a 'smartcard' provided to the voter either via mail or at the time of sign-in at the precinct (the process is not defined).

There are multiple ways to attack one of these systems, as discussed in the JH ISI report, and *not all of them* require advanced computer knowledge. Some of the CS-experience-required include reordering ballot lists so candidate 1 gets swapped with candidate 2 and gets their votes, creating a fake admin/ender card to terminate the election prematurely, generating fake cards that ignore the 'this card's vote complete, cancel card' function call, to permit substantial re-use and multiple votes. Flaw in e-voting software? by Randall Edwards mentions reprogramming a smart card to enable a voter to cast multiple votes for one candidate. The scary thing about this idea is that once programmer A has created this card, they're easy to duplicate and don't take any technical savvy to actually use. The Hopkins report discusses different scenarios, including (shudder) taking advantage of code that appears to permit use of the preinstalled 'manufacturers' password present on every smartcard at the time of sale. So you don't even need the 'real' password to use a smartcard.

In addition, whether you try to hack the touchscreen end of the system, by building fake smartcards, or whatever, when all is said and done, election data is transmitted IN THE OPEN, in this version of the application. Not to mention the passwords in the open between the touchscreen and the card.

You know how when you go shopping online, your browser changes from http to https, thus indicating you're now about to transmit your credit card data via a secure connection (SSL)?

Not in use, here. Should be in use. Without that kind of protection, someone can perform a 'man in the middle' attack and intercept data sent from a precinct to the main ballot server via the Internet (dialup too, if you know the right kind of person), and

a. simply keep it from getting to the final destination (if the ballot server doesn't have builtin checks for precincts, this would drop a balloting station off the map)
b. replace the ballot data with a modified set, thus falsifying election results.

This one flaw by itself is enough to warrant not using the application.

Transmission of election results, if made online, must be encrypted. Further, no handshake or data integrity analysis is performed when data from a precinct station is transmitted 'home', which means that data could be intercepted, its format parsed, and replaced with a false data stream. Worse, a precinct could be simulated entirely, sending false returns to the ballot server.

I heard on the radio that e-voting (I assume, Diebold) units are slated to appear in San Diego elections in the not too distant future. I am thoroughly opposed to the introduction of these systems without substantial oversight, and that means a non-partisan, non-corporate affiliate group analyzing both the code and the process. Where's a standards Working Group when you need one?

I'll say two final things on this subject (for now):

I'd feel a lot more comfortable if the source for these systems were in the open - because e-voting is an emerging technology, and involves a critical process concerning the government of this and other nations. It needs to be secure.

Failing that, I'd feel a lot more comfortable if I were one of the people working on this application.

Possibly both.

John Hopkins Information Security Institute: Analysis of an Electronic Voting System
Diebold Election Systems
Bald-Faced Lies about Black Box Voting Machines
Company Defends Electronic Voting System
Flaw in e-voting software?






Go Read


The President Has Misled Us -- an excellent, albeit chilling, compilation of promises and statements made by Bush, and the actions of the Administration. Some of the smaller, but more disturbing, in my opinion, contrasts:

promising money for HUD Hope VI homes, and cutting all funding
promising money to Boys and Girls Clubs, and slashing funding
lauding Teach For America and AmeriCorps, and slashing funding or cutting it entirely

Honestly, it seems like when you're dealing with Bush, if a promise is made, expect the exact opposite.

The Truth IS Out There


9/11 report: No Iraq link to al-Qaida

The report of the joint congressional inquiry into the suicide hijackings on Sept. 11, 2001, to be published Thursday, reveals U.S. intelligence had no evidence that the Iraqi regime of Saddam Hussein was involved in the attacks, or that it had supported al-Qaida...

"The report shows there is no link between Iraq and al-Qaida," said a government official who has seen the report.

Former Democratic Georgia Sen. Max Cleland, who was a member of the joint congressional committee that produced the report, confirmed the official's statement.

Asked whether he believed the report will reveal that there was no connection between al-Qaida and Iraq, Cleland replied: "I do ... There's no connection, and that's been confirmed by some of (al-Qaida leader Osama) bin Laden's terrorist followers." [emphasis added - sid]

The revelation is likely to embarrass the Bush administration, which made links between Saddam's support for bin Laden -- and the attendant possibility that Iraq might supply al-Qaida with weapons of mass destruction -- a major plank of its case for war.



Cleland goes on to assert (quite correctly, in my view), that the Bush Administration manipulated intelligence "for political ends", to scare the American people and justify war on Iraq.

ref snagged from Medley.

Wednesday, July 23, 2003

Best Programming Quote Ever


"OS X: Because making Unix user-friendly was easier than debugging Windows."
-- Simon Slavin, on a.f.c

(spotted in someone's .sig)

Sunday, July 20, 2003

Genetic Vulnerability to Depression?


Gene Variant Keeps Stress from Becoming Depression

Research published today in the journal Science indicates that variation in a single gene more than doubles a person's chances of succumbing to depression in response to life's stresses.
Although the findings are promising, the authors caution that they cannot yet form the basis for screening for depression. Says Moffitt: "If replication studies confirm that genotypes can predict in advance who is vulnerable to life stresses that bring on depression, this new knowledge could advance efforts to develop a diagnostic test of vulnerability to depression."


Hm! Very interesting. It's too bad there so little long-term clinical data to work with on depression. By long term, I mean, you don't have Egyptian hieroglyphs describing so-n-so's depression, detailing that in the spring they'd perk up and in the autumn they'd be all down in the mouth again.





Spinning Yarn


Janis finally sat and did a Navajo three-ply in front of my face and proved it works, so I went and three-plied a small ball of some of my famous loaves-and-fishes single. It was called that because the ball of roving never seemed to get smaller. I've spun this stuff into some serious bulkyweight yarn needing size 13-17 needles, and singles that you could weave with, or, say, three-ply into a nice sportweight/dk yarn that would use size 3-5 needles to knit up. That what's so cool about spinning. The same two spinners, sitting at the same two spinning wheels/drop spindles/whatever, can produce drastically different yarns from the exact same stuff.

So, to date I've spun with a drop spindle, a spinning wheel, and have done some passable plying with an Andean plying bracelet (into a two-ply yarn), and much nicer looking stuff with my wheel and a crochet hook and the Navajo technique.

A drop spindle is a fancy term for a stick with a weight at one end. You hold the ball of fluff you want to spin, 'draw out' some from the edge to kind of loosen and thin it, and twist it in your hands. Pouf, you just made a bit of yarn, a 'single'. Use that to tie a loop around the stick just under the weight. Spin the stick to generate more twist, and thus more yarn. Then take up the new yarn onto the stick. The direction you spin the stick in is important -- be consistent until you're done with this patch of yarn. Basically, be consistent in general, so you don't have to think later. You can then 'ply' the 'singles' into yarn, or work with them as-is. When you ply, you'll hold two or more singles parallel to one another and twist them together in the opposite direction. Doesn't matter which direction you choose for spinning versus plying, just so long as you go one way for producing singles and one way for plying them into yarn. If you use a spinning wheel, the direction is pretty much chosen for you.

A spinning wheel looks far more complicated but does exactly the same thing as your hands, or a drop spindle: applies twist to some fluff (roving) that you're holding in your hands. A drop spindle uses gravity to apply tension and you to apply twist, as you spin the spindle with your hand, say, against your leg. A spinning wheel takes a more mechanistic approach, using the big wheel bit -- the part everyone notices -- to spin a bobbin (like a bobbin for thread, only you're putting on thread instead of using it up) and a 'flyer' that rotates around the bobbin at a slightly different speed (and actually wraps your single onto the bobbin). I like the wheel because my feet keep everything 'spinning', applying twist, instead of me having to grab my drop spindle and start it going again. A drop spindle is great for travelling, for introducing kids to the art, and I use it a lot for plying. Though, know that Janis has demo'd Navajo three-ply, that may change.

So, plying? Wha?

Modern yarn is all 'plied', you rarely see singles unless you shop for custom yarns or spin yourself. If you pick apart yarn, it'll split up into 2 or 3 or 4 strands. Those are the singles, and they were spun up first, then twisted all together to form the plied yarn. It's a completely separate step.

I've mentioned two methods, but I'm going to gloss over the first (and link to a great description, with photos):

An Andean plying bracelet is a method of holding a long single on one hand in such a way that you can

1. get at both ends at the same time;
2. keep the stuff in some kind of order as you ply up the ends.

Otherwise you end up with a right holy mess. Note that there are two ends getting twisted together, thus you create two-ply yarn. All you're really doing is folding a single in half around your hand and twisting the two ends together -- in the opposite direction of the spin used to create the singles in the first place! Attach the new piece of two-ply yarn to the base of your spindle, twist up the next section, and eventually you'll work through the whole folded single.

Navajo three-ply is a clever way of twisting very long chain stitchs made out of one single -- again in the opposite direction of the spin used to create the singles. The more singles that go into a plied yarn, the smoother and more even it appears. The chain stitch bit lets you lay three sections of the same single next to one another, and apply twist to them.

Take the end of your single in your hand. Draw out a length (doesn't matter how long). Double and then triple the single up so that you have three strands side by side. Keep your finger, or a crochet hook in the loop that is closest to your bobbin or ball. Apply "contrary" twist to the other end (the start of your new yarn) and attach the end of this new yarn to your bobbin or the base of your drop spindle. Now, go look at the other end. There's a loop with your crochet hook dangling from it, and a strand leading back to the ball/bobbin. Use the crochet hook to draw that strand through the loop, thus creating a new chain stitch. Stretch it as long as the spirit, variation in color, whatever, moves you. You now have three parallel sections waiting for twist. So twist! You've just created the next section of three-plied yarn. Repeat until you've used up the bobbin/ball/whatever.

You don't really need a hook, just a stick or your finger or whatever will do, anything to pull up the next chain stitch.


Andean Plying Bracelet
Navajo Three Ply
Spinning and Navajo 3-ply Instructions Using a drop spindle.

Tuesday, July 15, 2003

Inka Data Keeping


From a recent University of Texas Press update:

Gary Urton, SIGNS OF THE INKA KHIPU: Binary Coding in the Andean Knotted-String Records. Gary Urton sets forth a pathbreaking theory that the manipulation of fibers in the construction of khipu created physical features that constitute binary-coded sequences which store units of information in a system of binary recordkeeping that was used throughout the Inka empire.

Signs of the Inka Khipu
Excerpts and TOC

Have I blogged about this before? Given the recent lecture on different bases in math, it seemed apropos. The bottom line, with these Inka khipu, that these knotted string doohickeys many people wrote off as decorative may instead have been carriers of great amounts of information, to those trained to 'read' the binary data storage format. Terrribly interesting stuff. A human being, you see cannot read machine code (what computers actually 'run' when you fire up your web browser, or word processor, or what have you). That's OK, computers can't read human languages, either. That's why the role of programmer or software engineer exists at all -- people who know how to speak one or more of the standardized languages that lay 'between' computer and human, and are used to generate machine-readable code in order that the machine achieve human-specified results. Khipu, apparently, may have been used to store data in a binary format, and thus would require some specialized training (a khipu scientist instead of a computer scientist) to get useful information back out.

From the excerpt:

"It is one of the great ironies of the age in which we live that the cacophony of computer-based, electronically produced information that suffuses our every waking moment is carried into our consciousness on patterned waves of just two signs: 1 and 0. This, of course, is no news. We have all been made aware since the dawn of the present Information Age that the ongoing revolution in computing technology rests on a system of binary coding. I discuss the matter at length below, but I would clarify here that by "binary coding," I mean a system of communication based on units of information that take the form of strings of signs or signals, each individual unit of which represents one or the other of a pair of alternative (usually opposite) identities or states; for example, the signal may be on or off (as in a light switch), positive or negative (as in an electrical current), or 1 or 0 (as in computer coding). One can argue that it is the simplicity of binary coding that gives computing technology and its information systems their great flexibility and seemingly inexhaustible expansiveness. In this study, I explore an earlier and potentially equally powerful system of coding information that was at home in pre-Columbian South America and which, like the coding systems used in present-day computer language, was structured primarily as a binary code."


Beach!


Say, did you know when you're unemployed you can just up and go to the beach? Just whenever you feel like it? Woo-hoo!

*splash*splash*frolic*

My goodness, this is fun!

Sunday, July 13, 2003

Inside a US Election Vote Counting Program


Inside a US Election Vote Counting Program

As a software developer with a keen interest in such constitutionally-guaranteed rights as the right to vote in this country, this is exactly the kind of information I've wanted to get my hands on for*ever*.

But, I'm having difficulty reading the article because I keep falling down in an epileptic fit and choking to death on my tongue every time I read the words "Microsoft Access".

*thud*choke*choke*die*

Oh, and while I'm dying, someone buy Bev Harris's book for me, wouldja? I'll thumb through it while waiting for my loved ones to gesture me into the light. No, really.

What it looks like, at a glance, is that GEMS security is based on two things: ignorance, and restricted access to the ballot server. Anyone, apparently, with sysadmin skills and access to the machine could do some damage. Most of the people involved in a balloting process, however, do not fit that bill. Still, any programmer will tell you relying on ignorance is not a very robust security scheme.

The first thing that caught my eye is that there was no mention of enforced password changes on the part of the application, meaning it is humanly possible that there are dozens of implementations of this software running that use the default password.

The second is the description of working around user passwords by using Access directly and copying their encrypted password into the GEMS login. Only someone who has access to Access (by having physical and username access to the machine in question, or the Access DB for GEMS being mounted on a network, among others) would be able to do this, because you need to be able to look at the underlying database to pull this off. Ideally, the number of people with that level of access would be very small. In practice, however, that number of people is always higher than you think it is.

The fact that the audit log is editable in any way really worries me. I design and build software systems, frequently web applications using SQL databases, which means I spend a lot of time using tools that include the ability to edit db info at exactly the kind of level this this data is being manipulated at. If I may go off on a tangent for the confused:

This kind of software is multi-layered, just like my funk, baby. The bottommost layer is the information repository, the "database". The next layer up is usually referred to as an API - an established set of functions provided to perform common tasks such as "add record to database", "delete record from database", that kind of thing, which the software developers writing this application use in order to avoid reinventing the wheel constantly and instead focus on the next level up, the User Interface. Where Stuff Actually Happens, from your perspective.

When you register at yahoo, you the user fill out a web form (UI) which, maybe, error-checks your input & comes up with a password (API) and then adds your info into a database (DB).

If you develop software, you may need to test or 'workaround' a known bug or any number of things that require you to edit data in the database by hand. So, varying somewhat from database to database, there are multiple tools to help you do that. In some ways, I think, Microsoft Access blurs the line between UI and DB by making it so easy for a user to touch data directly in the database. MS Access as I understand it targets the development of simple systems, where the user and the developer are frequently the same person, and not terribly technical. That makes it easy to mess up, by virtue of that apparent transparency. It can also make it easy to hack someone else's work. Anyone who wants to screw around with data on a system I develop had better have a password to the db, permission to access the db server from the machine they're on, and a healthy dose of experience programming relational databases and in the use of the relevant db's command-line interface.

So, most of these screenshots and whatnot, they are of the MS equivalent of 'low-level database access', not of the GEMS application itself. Someone who is using GEMS is probably having a very different experience.

Now, back to the audit log. From a design perspective it makes perfect sense to have event tracking or an audit log in the same database as the data itself. I do it that way all the time...when writing using an SQL database. But Access makes it so easy for non-admin personnel to edit info in a database -- makes it seem so much like part of the normal user experience -- that now that I've considered the situation, I would argue strongly against an audit log in the same database as the data. Since, for this app, complete records of the manipulations to the data are so vital.

I would argue for the application requiring a second (thus, obfuscated, yes, not the best approach) db for that info, or store audit information (user X logged on, user X modified record Y, user X ran report ABC....) in a completely different medium -- a flat file, XML streamed to another server, in such a way that no access to the log is permitted. Encrypt it.

"Access encourages those who create audit logs to use auto-numbering, so that every logged entry has an uneditable log number. Then, if one deletes audit entries, a gap in the numbering sequence will appear. However, we found that this feature was disabled, allowing us to write in our own log numbers. We were able to add and delete from the audit without leaving a trace."


This quote makes it sound like the audit trail isn't driven by the GEMS application but by Access itself, in which case, disabling the auto-number sequencing was A Bad Idea™ and was either the GEMS application's responsiblity, or, possibly, that of the installer.

On the whole, it's difficult to assess exactly how endangered specific balloting servers might be -- so much relies on the people restricting access to machines, making sure the ballot server is not on a network, making sure only authorized personnel can sit down in front of the machine, etc., that it's really hard to tell exactly how hackable a balloting process would be that is using this system. That, in itself, is Very Bad News.


Bigger Than Watergate! - How To Rig An Election In The United States
Inside a US Election Vote Counting Program
Bald-Faced Lies About Black Box Voting Machines
Black Box Voting Ballot Tampering in the 21st Century

Thursday, July 10, 2003

Math in Babylon


(Another spiffy ref courtesy of Making Light)

Counting in Babylon

Be sure to read all the way down to the number systems stuff. While you're at it, read the rest of the lecture series info pages (here). If you're afraid of math or science, it'll do you good. Builds character.

Back to my point. Apparently, Babylonians used base sixty instead of base ten. This is hard to describe, because unless you work with computers on daily basis, you have no need to think about different 'bases'. Western civ is built on base ten, baby, but computers run on binary* (base two). We've so completely internalized base 10 that it's hard to even think about thinking about another base system.

Base 10 means you count on your fingers from one to 10.

Now you've used up all your fingers, what do you do? Assuming you're wearing shoes, you put a rubber band on your pinky. Or hold your left hand behind your back. Or turn your hands towards your face instead of away. Anything to indicate that although you are using the exact same fingers that you just counted 1 through 10 on, you are now counting 11 to 20.

Now, suppose you're a little kid during summer. You won't run out of digits to count on until you get all the way to twenty, because,

1. you took your shoes off the second summer vacation started;
2. you're flexible enough to touch your toes to begin with.

So, now you can count all the way up to 20 before you need to 'mark' that you've overlapped your digits and when you get to your thumb this time it means 5+20, not just 5.

That's base 20.

How do we write this down? Well if I write it down, (20), I'm writing in base ten, not 20, and I'm screwed up already. Can I say the alphabet instead, on my fingers and toes?

Sure. Why not. A,B,C,D,E,F,G,H,I,J,K,L,M,N,O,P,Q,R,S,T -- there, that's my 20 symbols, A-J for my fingers and K-T for my toes.

So, what happens when I need to count forty bottlecaps by the side of the road? (Hey, I'm a kid on summer vacation.)

I can get up to 20, or T, with my fingers and toes, and then I'm back to that starting left-side pinky. Right-side, maybe, depending on which hand I write with. What do I do?

Maybe I draw a line underneath the T bottlecap, and then count up another T (or twenty) bottlecaps and mark underneath it. I then skip past my row and say " there are 2 lines, so that's 2 sets of T (twenty), which means a grand whopping total of forty bottlecaps. I'm rich!"

But then a car drives past, splashes muddy water all over me and the bottle caps, erases all my careful marks, and even gets specks on my glasses.

Well, maybe, I scoop up all the bottlecaps I can grab in the mud and run home, because it's lunchtime already, and I got Important Kid Stuff to do.

Maybe, just maybe, after lunch, I grab a crayon and the back of mom's phone bill and haul out the mess of bottlecaps and start counting them all over again from the beginning.

This time, though, I count J (ten) bottlecaps using my fingers, and write with the crayon:

 J

On the back of mom's phone bill. That's my mark for ten. J bottlecaps.

I count more bottlecaps, using my toes, and get all the way up to T bottlecaps (twenty). So I cross out the J and write:

 T

Well, once again, I'm at point where I need to re-use fingers and toes in order to count past T. What to do, what to do?

I could do this. Make two columns on the paper, one for individual fingers and toes, and one for the second time around on those same fingers and toes.

How would I write T+A (twenty+one) bottlecaps, then?

AA

Reading from left to right, that's one full set of fingers and toes (the 'A' on the left) and one pinky finger.

The leftmost column is the number of twenties I've counted (just one), and the rightmost column is the number of individual fingers-n-toes I've counted. Which in this case, is also one.

I count another bottlecap:

AB

One twenty plus two fingers.

I count three more bottlecaps. I've just used up one hand and embarked on the other, I'm at:

AE

I count more bottlecaps, using up all my fingers:

AJ

That's one twenty, plus ten fingers. If I was counting out loud I would have said "twenty-one, twenty-two, twenty-three, twenty-four, twenty-five, twenty-six, twenty-seven, twenty-eight, twenty-nine, thirty!" by now.

So, I embark on the toes and use them up, going from

AK to AL to AM to AN to AO to AP to AQ to AR to AS to

two whole sets of twenty

And how to write that? Not AT, but B0, where 0 is just a placeholder for "nuthin in the onesies column yet". Because the B in that left-column location tells us "two 'sets' of twenty".

So,

BA

would be what, then? Two sets of twenty plus one, or A. Forty-one. BA. All just different ways of saying the same thing. Why I could add another left column if I had gobs and gobs more bottlecaps and I had to count more than twenty sets of twenty.

SS = nineteen sets of twenty plus nineteen fingers-n-toes. I count one more bottlecap, and....

ping

A00

One 'batch' of "twenty sets of twenty" (ain't that a mouthful), plus zero 'sets' of twenty, plus zero 'onesies'. Phew. Time for some cookies and milk in another minute.

Now, we've just talked about base 20 counting (hey, look at that 20, that's a number in base ten isn't it? The 0 is a placeholder, right? And the 2 in that left column means "two sets of ten", doesn't it? Doesn't it? Hot dog!).

But the Babylonians apparently used base 60.

In base sixty BA wouldn't mean "two sets of twenty plus one", and 21 wouldn't mean "two sets of 10 plus one", but two sets of sixty plus one. How's that for a lot? How's that for different bases? Why A00 would be a batch of sixty sixties, or 3600 bottlecaps, which would blanket the floor of my bedroom up to my ankles and have plenty left over to taunt my friends with.

Base 60. Wow. I'd be richest!


* Why are computers binary, you ask? Ah, because computers are very primitive devices, compared to human beings. They can 'conceptualize' only "on" or "off". If on=1, and off=0, computers can only think in ones and zeroes. Think of it as if they only have thumbs and no fingers or toes. So, they wrap around back to the first hand when counting, very very quickly, poor things. No flexibility at all.
I'll Be Ding-Dong-Darned


Theresa Nielson Hayden believes she's found a new variation on the vanity publishing scam theme, one that relies not so much on large amounts of money from you the author (requests for which should ring such large alarm bells in your mind that you FLEE the scene SCREAMING immediately), but on the average number of your friends and family who are likely to buy a book simply because you wrote it. And maybe pay...a little extra...for the privilege. But not a lot, and that's the trick.

Follow The Money

Nice of friends and family -- yes, thank you for the support -- but lets make sure the money flows in the right direction, hm?
Medical Marijuana in Canada


Still quibbling, but more or less positive, I think: Canada to Sell Medical Marijuana to Seriously Ill

Wednesday, July 09, 2003

Busy Bee, The Drive™,Lilo and Stitch


My former employer offered us laid-off types an interesting two-day seminar from Lee Hecht Harrison, an outplacement/career transisition firm, so I spent Monday and Tuesday doing that and crashing on Janis' sofa to avoid The Drive™. You have to call it The Drive™, if you're going to be on the I-5/805 between Oceanside and parts south of the 163 at that time of day. Sometimes discretion is the better part of wisdom as well as valor, so I just spent the night, thus eliminating huge tracts of frustrated car-idling occasional-swearing morning rush-hour driving.

During all this (not during any driving portions, I assure you), Janis and I watched the film "Lilo and Stitch", one of the most unDisney animated films ever to come out of Disney in the history of the world. It was funny, characters were drawn looking more like human beings than dolls, and the film had a darker theme than other Disney films. Although, that perception may be because it wasn't based directly on a known fairy tale, and fairy tales may in fact be just as dark but not perceived as such because of this cultural association with the idea of a 'fairy tale' being somehow light and fluffy.

Finally, "Lilo and Stitch" is not a musical.

You read that right. Not a musical. One of the characters sings a song, and there is dancing, but it's in the context of singing someone to sleep, and little girls practicing hula for a recital. There is lip sync'ing to Elvis tunes, and a musical interlude where everyone's enjoying surfing and one of the movie's musical themes takes more of a center stage, but no big production numbers.

Ohana means family. The film is definitely worth seeing.

Saturday, July 05, 2003

*bang*bang*bang*"Yes"*bang*bang*"Yes"*bang*bang*


Big Talk [re: Bush's "bring it on" quip]

Patrick Nielson Hayden, in the comments section:

I like Dean, too, not because his positions match mine perfectly (they don't -- I'm further to the left on some issues and more of a cranky libertarian on others), but because he articulates a civic Americanism in which someone like me actually exists. I don't doubt that a President Dean would regularly annoy me. I doubt very much that his decisions would have me wondering whether I wanted to remain an American citizen.


This is where I take my shoe off and pound it on the table, Kruschev-fashion, whilst yelling "Yes" loud enough to frighten the neighbors. (And they're pretty relaxed, for the most part.) The Bush Administration and its attendant Big Christian Money has Unemployed Agnostic Me frickin' scared. Scared they're turning my country into something so different, so contrary to its founding ideals, that I won't be able to subscribe to those ideals and still call myself a patriotic American. And I'll tell you, push comes to shove, it's not the ideals I'll give up.

Not that the Bush Administration is the only thing wrong with this country[*], but I'd sure like to be employed all twelve months of a year, y'know?


[*] There's the lawsuit-feeding frenzy, which itself is an artifact of the refusal to take personal responsibility for anything, which is probably related to a zillion things, and New Math to boot. And there's the desperate need for campaign finance reform, so someone with an idea can run for major office, without making compromising promises. There's the increasing consolidation of media channels and the US's data feeds, with which the aforementioned B.A. isn't exactly helping. Well, it's helping -- in the wrong way. There's the isolationism of the US from the international community's entertainment and culture, thanks to everything from DVD regioning to slashed arts education budgets in schools.

I could go on. And I'm sure I will.





Dean, Bush. Dean, Bush. Choices, choices.


...In recent months he [Dean] has been called "brusque,","brash","blunt" and "belligerent"; a few more choice words on his part and critics will be questioning whether Dean has the diplomatic skills needed to be the leader of the free world.


and Bush does?

Short-Fused Populist, Breathing Fire at Bush, linked via Medley

Y'know, they're just trying to label him as something ignorable so they can then ignore him. Forget it. This is the candidate to watch for a simple reason: this is the candidate with the people behind him. He's not saying what we want to hear -- he's saying what we want to say.