<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0"><channel><atom:link rel="hub" href="http://tumblr.superfeedr.com/" xmlns:atom="http://www.w3.org/2005/Atom"/><description>Eric Kolb is a husband, an information security professional, a gamer, a runner, a dandy, and a wordy such-and-such.</description><title>Verbose Curmudgeon</title><generator>Tumblr (3.0; @erickolb)</generator><link>http://erickolb.me/</link><item><title>explodingdog:

My friend Chris has his Bafflers on sale this...</title><description>&lt;img src="http://24.media.tumblr.com/4f9d13603e755a268a6edd31e694532b/tumblr_mlfb6gNIS11qzs63fo1_500.jpg"/&gt;&lt;br/&gt;&lt;br/&gt;&lt;p&gt;&lt;a class="tumblr_blog" href="http://explodingdog.tumblr.com/post/48235120497/my-friend-chris-has-his-bafflers-on-sale-this"&gt;explodingdog&lt;/a&gt;:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;My friend Chris has his &lt;a href="http://www.chrisyates.net/store/puzz.html"&gt;Bafflers&lt;/a&gt; on sale this week. These are handmade puzzles. I own a few of them and they are wonderful. You should get one for yourself, even if you don’t just go look at them, they are fantastic.&lt;/p&gt;
&lt;p&gt;(via &lt;a href="http://www.chrisyates.net/store/puzz.html"&gt;&lt;a href="http://www.chrisyates.net/store/puzz.html"&gt;http://www.chrisyates.net/store/puzz.html&lt;/a&gt;&lt;/a&gt;)&lt;/p&gt;
&lt;/blockquote&gt;</description><link>http://erickolb.me/post/48236754895</link><guid>http://erickolb.me/post/48236754895</guid><pubDate>Wed, 17 Apr 2013 20:03:02 -0400</pubDate></item><item><title>#PrayforBoston</title><description>&lt;p&gt;Today, families gathered in one of America&amp;#8217;s oldest, greatest cities to support their loved ones as they accomplish something incredible, something they&amp;#8217;re already had to work very hard to even attempt. For some, it was another run in the city. For others, it was a first.&lt;/p&gt;
&lt;p&gt;A marathon is a celebration of life. The legend, of course, is that an Athenian soldier ran all the way from Athens to the allied city-state of Marathon - 26.2 miles - to warn them of an impending invasion. The soldier arrived in time, but collapsed dead after gasping his precious message. To run this kind of distance is no easy feat. To run it competitively is nothing short of amazing. But whether you finish in 2:15 or 5:21, it&amp;#8217;s a feat that should be celebrated.&lt;/p&gt;
&lt;p&gt;Some of these families will be going home without everyone. Literally unwhole. Their faith and their support has been repaid with senseless bloodshed.&lt;/p&gt;
&lt;p&gt;I can&amp;#8217;t pretend like today&amp;#8217;s events in Boston haven&amp;#8217;t affected me pretty deeply, much more so than these things usually do. I can&amp;#8217;t help but be incredibly angry about this, because it&amp;#8217;s not just people like me that were being targeted &amp;#8212; it&amp;#8217;s the people whom I love and who support me that were targeted.&lt;/p&gt;
&lt;p&gt;Not in Boston, but I&amp;#8217;ve been there&amp;#8230; Four hours into the race with family waiting by the finish line. Yes, in a very real sense, that could have been me and mine. And that makes me very, very angry.&lt;/p&gt;
&lt;p&gt;As I write this, we&amp;#8217;ve reached the &amp;#8220;no-nothing&amp;#8221; phase of news coverage. We aren&amp;#8217;t learning anything new, but the incessant review of the carnage and the footage and the footage of the carnage must carry on.&lt;/p&gt;
&lt;p&gt;It&amp;#8217;s not that I don&amp;#8217;t care anymore, it&amp;#8217;s that I&amp;#8217;m already exhausted. I&amp;#8217;d like to know why, but I wish we could continue learning about this horrible affair without giving the perpetrators the attention they do not deserve.&lt;/p&gt;</description><link>http://erickolb.me/post/48082376326</link><guid>http://erickolb.me/post/48082376326</guid><pubDate>Mon, 15 Apr 2013 20:42:23 -0400</pubDate><category>running</category><category>Boston</category><category>Boston Marathon</category><category>PrayForBoston</category></item><item><title>The front door after the break-in a couple weeks back and the...</title><description>&lt;img src="http://25.media.tumblr.com/465436ceabfa9aac4b0b68c3ca2603df/tumblr_mla1noQLxd1rnlkzoo1_500.jpg"/&gt;&lt;br/&gt;&lt;br/&gt;&lt;p&gt;The front door after the break-in a couple weeks back and the temp repair job. This is what not having a deadbolt gets you.&lt;/p&gt;</description><link>http://erickolb.me/post/48015090746</link><guid>http://erickolb.me/post/48015090746</guid><pubDate>Sun, 14 Apr 2013 23:28:29 -0400</pubDate></item><item><title>A Lesson in Home Security</title><description>&lt;p&gt;I work in network and application security, so you&amp;#8217;d think I&amp;#8217;d have my home in order. And when it comes to my digital presence, you&amp;#8217;d be right. But my home? Well, let&amp;#8217;s just say that&amp;#8217;s been a lesson learned&amp;#8230;&lt;/p&gt;
&lt;p&gt;A couple of weeks ago, my wife and I left work ad the end of the day and arrived home to find our garage door opener wasn&amp;#8217;t responding to the remote. While that was puzzling, there&amp;#8217;s plenty of plausible explanations for that. Maybe the power was out, or the battery in the remote died&amp;#8230; So, we walked up to the front door to let ourselves in the old fashioned way.&lt;/p&gt;
&lt;p&gt;The front door had been pried open but left propped mostly closed behind the storm door. It was immediately obvious that we&amp;#8217;d been robbed.&lt;/p&gt;
&lt;p&gt;As we looked around the house and assessed what had happened, a few things became clear:&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;The thieves had gone into the garage, pulled the emergency release on the door opened, and used that to get a vehicle in and out to buy themselves more time.&lt;/li&gt;
&lt;li&gt;The thieves had a set list of items they were looking for: TVs, computers, guns, gemstones, watches - things they could fence easily. Items not in their list they left alone.&lt;/li&gt;
&lt;li&gt;They avoided things with extensive cords or wires. They took a laptop and its power brick, but left a superior desktop sitting immediately besides it. They took the audio receiver and DVD player, but left the speakers. &lt;/li&gt;
&lt;/ul&gt;&lt;p&gt;As we worked with the county sheriff&amp;#8217;s office, we learned that the crew that had hit us had also hit at least three other houses in the general area that day &amp;#8212; all during broad daylight.&lt;/p&gt;
&lt;p&gt;And despite the obvious pain points, we were lucky. All of the stuff taken was just that &amp;#8212; stuff. Thanks to the thieves&amp;#8217; selectiveness we didn&amp;#8217;t lose anything of sentimental value, nothing that couldn&amp;#8217;t be replaced by insurance.&lt;/p&gt;
&lt;p&gt;So, I&amp;#8217;ve learned an important lesson about home security. I wouldn&amp;#8217;t be a good Samaritan if I didn&amp;#8217;t share a few tidbits of knowledge&amp;#8230;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;DINKs are an Easy Target&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Dual Income, No Kids. It means you&amp;#8217;re pulling in the bank, but you&amp;#8217;re not investing it into a mini-you. It also means your house is probably conspicuously vacant during the weekday.&lt;/p&gt;
&lt;p&gt;We heard neighbors mention that, prior to the break-in, some folks were going door-to-door to solicit a new lawn care business, but they didn&amp;#8217;t have a brochure, a flyer, or a business card. This was probably the casing job, and it would have been easy to identify that no one was at home during regular business hours.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Your Neighbors Aren&amp;#8217;t a Theft Deterrent&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;You can&amp;#8217;t count on your neighbors to provide an ambient deterrent. There&amp;#8217;s way too many situations where they just won&amp;#8217;t be there to see something happening at your house. My most reliably nosy neighbor was away on errands (though, to hear her tell it, she is &lt;em&gt;terrified&lt;/em&gt; for her personal safety because &lt;em&gt;she&amp;#8217;s at home all day&lt;/em&gt;). Besides, it&amp;#8217;s not you can expect them to be glued to their windows, watching your house. &lt;span&gt;Even if they do, will they realize there&amp;#8217;s a theft in progress? Will they react in a timely fashion?&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Get A Monitored Security System &lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;You aren&amp;#8217;t home, your neighbors aren&amp;#8217;t watching your house&amp;#8230; so do &lt;em&gt;something&lt;/em&gt;! Get yourself a monitored security system.&lt;/p&gt;
&lt;p&gt;First place I looked was the ever-ubiquitous ADT, but after quite a lot of research, I settled on &lt;a href="http://simplisafe.com/" title="SimpliSafe" target="_blank"&gt;SimpliSafe&lt;/a&gt;. For just $25/month, I get the top tier of their monitoring service. That gets me all the remote access I want, a smartphone app, and a number of other really nice features. That&amp;#8217;s $10 cheaper than ADT&amp;#8217;s least expensive and least featured option. True, I didn&amp;#8217;t get a $100 install deal. It was quite a bit more up front and it was self-install. Personally, I prefer that to yet another stranger sussing out the soft spots in my home&amp;#8217;s security.&lt;/p&gt;
&lt;p&gt;The install price pays for itself in time anyway. Having a monitored system gets me a $28/month discount on my homeowner&amp;#8217;s insurance, and I haven&amp;#8217;t even added fire sensors yet. Once I do, that discount increases. At that rate, the installation will be paid for inside of two years&amp;#8217; time.&lt;/p&gt;
&lt;p&gt;Once you&amp;#8217;ve got it installed, train yourself to use it. I&amp;#8217;ve got a reminder on my iPhone to arm the system set to trigger whenever I leave.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Deadbolts Really Are A Must&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;I&amp;#8217;d always wondered a little bit how much of a difference deadbolts would make. Turns out, it makes all the difference. The thieves went through our front door in seconds with a crowbar because there was no real reinforcement there that would stand up to that kind of force.&lt;/p&gt;
&lt;p&gt;The seeds of theft, both digital and physical, are usually the identification of weak points. At work, I&amp;#8217;ll call it low hanging fruit. Unless there&amp;#8217;s strong motivation to target a specific someone, thieves don&amp;#8217;t want to have to work hard. If a target is difficult to rob, &lt;em&gt;they won&amp;#8217;t&lt;/em&gt;.&lt;/p&gt;
&lt;p&gt;Having a deadbolt in each of your entryways make your house a high-hanging fruit.&lt;/p&gt;</description><link>http://erickolb.me/post/48003602733</link><guid>http://erickolb.me/post/48003602733</guid><pubDate>Sun, 14 Apr 2013 20:58:05 -0400</pubDate><category>burglary</category><category>security</category><category>home security</category><category>simplisafe</category><category>theft</category><category>locks</category><category>deadbolt</category></item><item><title>gearpatrol:

The Balvenie 50 Year Old. So exclusive that even...</title><description>&lt;img src="http://24.media.tumblr.com/61a473f145dea050b427d4b9a0c0541a/tumblr_mhtjdbeiE21qzxsmpo1_500.jpg"/&gt;&lt;br/&gt;&lt;br/&gt;&lt;p&gt;&lt;a href="http://gearpatrol.tumblr.com/post/42452852040/the-balvenie-50-year-old-so-exclusive-that-even" class="tumblr_blog"&gt;gearpatrol&lt;/a&gt;:&lt;/p&gt;

&lt;blockquote&gt;&lt;p&gt;&lt;a href="http://gear.gp/14EE275"&gt;The Balvenie 50 Year Old&lt;/a&gt;. So exclusive that even the master brewer it’s in honor of doesn’t get a bottle.&lt;/p&gt;&lt;/blockquote&gt;

&lt;p&gt;I can’t even fathom the attrition from the angel’s share on a 50 year whiskey!&lt;/p&gt;</description><link>http://erickolb.me/post/42460565238</link><guid>http://erickolb.me/post/42460565238</guid><pubDate>Wed, 06 Feb 2013 18:30:39 -0500</pubDate></item><item><title>kickstarter:

Lonesome highway.Great news from the gaming world...</title><description>&lt;img src="http://24.media.tumblr.com/eb187db0d6efaeccaac5a5f443b9b9db/tumblr_mg9ivqSAFV1qzbiclo1_500.png"/&gt;&lt;br/&gt;&lt;br/&gt;&lt;p&gt;&lt;a class="tumblr_blog" href="http://kickstarter.tumblr.com/post/39942165474/lonesome-highway-great-news-from-the-gaming-world"&gt;kickstarter&lt;/a&gt;:&lt;/p&gt;
&lt;blockquote&gt;
&lt;div&gt;&lt;strong&gt;Lonesome highway&lt;/strong&gt;.&lt;br/&gt;&lt;p&gt;Great news from the gaming world this morning: &lt;em&gt;&lt;a href="http://www.kickstarter.com/projects/149077132/kentucky-route-zero-a-magic-realist-adventure-game?ref=live"&gt;Kentucky Route Zero&lt;/a&gt;&lt;/em&gt;, our favorite magical-realist adventure game about a secret highway in Kentucky and its mysterious travelers, is finally available to play. Check out &lt;a href="http://kentuckyroutezero.com/"&gt;Act 1 here&lt;/a&gt;.&lt;/p&gt;
&lt;/div&gt;
&lt;/blockquote&gt;
&lt;p&gt;Act 1 of 5 is now out for Windows and Mac. I’m intrigued by this, but I’ll be holding out for the Linux version (promised “soon”) before I move on this. If you’re bold enough to give this point-and-click a spin, be sure to share your impressions with me!&lt;/p&gt;</description><link>http://erickolb.me/post/39963404399</link><guid>http://erickolb.me/post/39963404399</guid><pubDate>Mon, 07 Jan 2013 18:26:37 -0500</pubDate><category>video games</category><category>kickstarter</category><category>point and click</category></item><item><title>Skyfall - Think On Your (Technology) Sins</title><description>&lt;p&gt;&lt;em&gt;Notice: This post contains mild spoilers, but it&amp;#8217;s nothing you can&amp;#8217;t gather from the trailer.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;The fact that Skyfall is in theatres right now is pretty impressive, considering that MGM died and came back to life just to bring us more Craig-Bond. Still, it&amp;#8217;s a pretty good movie. Except for how it deals with technology.&lt;/p&gt;
&lt;p&gt;Given the day and age we live in, it&amp;#8217;s hard to ignore technology in modern movie plots. This makes it all the more bewildering that so few writers manage to do it well. Much, much more commonly they do a terrible job with it. Skyfall is a perfect example.&lt;/p&gt;
&lt;p&gt;Here&amp;#8217;s a rundown of the top ten things that went wrong with technology in Skyfall&amp;#8217;s script.&lt;/p&gt;
&lt;p&gt;&lt;img alt="THINK ON YOUR SINS" src="https://s3.amazonaws.com/tumblr.erickolb.me/thinkonyoursins.png" width="500"/&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;1.) IP Tracing Backwards&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;At one point early on, the folks at MI6 have the opportunity to trace a computer attack in progress. They run through it like a phone trace. The attack is coming from the UK, specifically London. Gasp! The attack is coming from &lt;em&gt;inside MI6&lt;/em&gt;!&lt;/p&gt;
&lt;p&gt;Here&amp;#8217;s the problem: that fact would have been immediately obvious. There are only three ranges of IP space reserved for private networks, whether it&amp;#8217;s your home wifi or a first-world intelligence agency. If the attack had originated from inside the private network, they would be able to identify the asset it came from instantly.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Egregiousness factor:&lt;/em&gt; Minimal. They arrived at the same conclusion with a bit more pizzaz. Something happens that precludes the next phase of the investigation (who&amp;#8217;s connected to that asset as a relay point?) on-screen, but in the real world this investigation would have continued into containment and then prevention.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2.) Don&amp;#8217;t Click Shit!&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Later, M receives another fun little message from the hacker-sauce villain. The theme of the message follows on one that punctuates the scene I described above, which was a personalized multimedia presentation designed to her to incite a response. This time, the message includes a link.&lt;/p&gt;
&lt;p&gt;Naturally, M clicks it.&lt;/p&gt;
&lt;p&gt;Oh, it&amp;#8217;s only a link to an online video; that&amp;#8217;s lucky! Granted, the attacker already has enough control over M&amp;#8217;s system to steal focus on an active console session. It&amp;#8217;s unlikely he would actually &lt;em&gt;need&lt;/em&gt; human interaction to do further harm on that system (or, following on the previous scene, that network). Still&amp;#8230;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Egregiousness factor:&lt;/em&gt; Irritating, but plausible. As the head of an organization that certainly traffics independently in information and security, this kind of thick-headed ignorance to information security is shocking. Has she neither the training nor the sense that clicking on an obvious hacker payload is a terrible idea? Why was the IT department not her first phone call after clicking it?&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;3.) Let&amp;#8217;s Plug It In, I&amp;#8217;m Sure It&amp;#8217;s Safe!&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;At one point, the villain is captured and brought to MI6&amp;#8217;s headquarters. They do the sensible thing with his meatworks &amp;#8212; they put him into a holding cell where his captors have access to him to interrogate, but he does not access to anything outside of the cell. That&amp;#8217;s how holding cells work, generally.&lt;/p&gt;
&lt;p&gt;Meanwhile, they are far less sensible about his laptop. They plug it into the network to explore its contents. Not an isolated DMZ for untrusted or possibly malicious assets. A trusted network! With access to important subsystems, like the controls to the physical holding cell.&lt;/p&gt;
&lt;p&gt;Predictably, things do not go well for MI6.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Egregiousness factor:&lt;/em&gt; Idiotic. Q is not a genius.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;4.) It Takes Two&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;The aforementioned laptop has not one, but two ethernet interfaces. It&amp;#8217;s a really, really beefy machine. I bet one is for all the packets in and the other is for the packets out. Computers work like that, right?&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Egregiousness factor:&lt;/em&gt; No. Computers do not work like that. Not without unnecessarily a very convoluted environment-specific configuration, but this does not and should not convey that the machine is any more super. It just makes #3 twice as dumb.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;5.) Jargonizing&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;On the heels of the scene I described in #3, there&amp;#8217;s a frantic hacking scene. The good guys are trying to unravel the loot from the villain&amp;#8217;s laptop. Technical terms are flying back and forth, regardless of whether it fits or not. The screen is a mess of nonsense visualization, mostly just to try (and mostly fail) to represent how hard this is.&lt;/p&gt;
&lt;p&gt;I&amp;#8217;ll dig into some of the finer points of awfulness, but this scene is a classic example of throwing as much jargon as the writers could find at the script and hoping beyond hope that something sticks.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Egregiousness factor:&lt;/em&gt; This is slightly less bad than the horrifying programming/hacking sequence of Swordfish.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;6.) Polymorphic Encryption&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;One of the more irritating examples of nonsense jargon to come out of #5 was the following utterance from Q: &amp;#8220;He&amp;#8217;s using a polymorphic encryption algorithm. It keeps changing!&amp;#8221;&lt;/p&gt;
&lt;p&gt;Let me be clear. This is not a thing. This doesn&amp;#8217;t even make sense.&lt;/p&gt;
&lt;p&gt;Whether you&amp;#8217;re using symmetric or asymmetric encryption, the point is that the key will decrypt the cipher text. That key doesn&amp;#8217;t change. If there&amp;#8217;s an active system re-encrypting the cipher, it&amp;#8217;s still using the same key pair in the end, so you haven&amp;#8217;t changed that the same key unlocks it all in the end. If you&amp;#8217;re worried about the integrity of the cipher text itself without the presence of the key, your algorithm isn&amp;#8217;t very good &amp;#8212; it doesn&amp;#8217;t matter if you keep changing it with a derivative key.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Egregiousness factor:&lt;/em&gt; High. This is entirely unnecessary. If I start talking about ACTUAL ENCRYPTION THAT REALLY EXISTS, I will make most people zone out within minutes. You don&amp;#8217;t have to invent bullshit to tech-impress the audience.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;7.) Gibberish&amp;#160;!= Hexadecimal&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;During the same hacking sequence I described in #5, Bond&amp;#8217;s contribution is to identify non-hexadecimal pairs of characters in a block of what is otherwise clearly a hexadecimal block. This isn&amp;#8217;t a great observation - these couplets are literally in a different color on screen.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Egregiousness factor:&lt;/em&gt; This is utter nonsense. The stuff you&amp;#8217;re putting on screen, it&amp;#8217;s either hexadecimal or it&amp;#8217;s not. Anything that isn&amp;#8217;t 0-9 or A-F is not hexadecimal. Make up your mind. This was not a clue, it was stupid.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;8.) An Ultimately Weak Lock&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Those non-hexadecimal characters I mentioned in #7 quickly anagram out to form a word, a name. &amp;#8220;Try that as a password,&amp;#8221; Bond suggests. It works. The tangled knot of nodes and edges quickly unscrambles into the protected data.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Egregiousness factor:&lt;/em&gt; My brain is exploding because of the bullshit.&lt;/p&gt;
&lt;p&gt;Given how they pointed out in #6 that the bad guy is using mythical encryption functions to protect his data, you would expect the key to rival the effort he&amp;#8217;s put into protecting his data.&lt;/p&gt;
&lt;p&gt;No, that might make sense. Instead he&amp;#8217;s using a password. A case-insensitive password of a single character class and about 10 characters. A password that is barely better than &amp;#8220;password&amp;#8221;. A password he left lying around in his data on the device.&lt;/p&gt;
&lt;p&gt;The more believable setup to this whole moronic scenario would be if he&amp;#8217;d written the password on a post-it on the bottom of the laptop. Oh, I forgot; he&amp;#8217;s a spy. Maybe put the post-it in a secret compartment.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;9.) Radio is Awesome Technology&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Skyfall has no hesitation expressing its love for radio. This might be touching, if they spent any amount of time thinking about how radio works (or at least how it doesn&amp;#8217;t work).&lt;/p&gt;
&lt;p&gt;First is the tracking transmitter Bond if given by Q early on in the film. It&amp;#8217;s one of the only two &amp;#8220;gadgets,&amp;#8221; if you can indeed call them that, that he&amp;#8217;s given. It&amp;#8217;s not a GPS tracker &amp;#8212; that point is made amply clear through dialog from multiple characters.&lt;/p&gt;
&lt;p&gt;The thing is the size of a keychain, which means it&amp;#8217;s powered by a watch battery. Let&amp;#8217;s go nuts and assume it&amp;#8217;s powered by &lt;em&gt;two&lt;/em&gt; watch batteries. That&amp;#8217;s not enough power to transmit a signal from a remote area of China to one listening stations where MI6 could receive it, let alone the three it would take to triangulate a signal.&lt;/p&gt;
&lt;p&gt;Later on, Bond finds himself chasing our super villain through Underground tunnels. Meanwhile, back at MI6, a little icon labeled &amp;#8220;Bond&amp;#8221; zips through a 3D map of the tunnels. How is he being tracked? Presumably it&amp;#8217;s the same radio transmitter. But it turns out radio waves don&amp;#8217;t travel all that effectively through rock &amp;#8212; there are physical limits to how radio travels through dense material like rock and concrete. So, apparently I was wrong before: that transmitter is powered by &lt;em&gt;magic&lt;/em&gt;.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Egregiousness factor:&lt;/em&gt; Forgivable. If this were the worst of the movie&amp;#8217;s offenses against science, it would hardly be worth mentioning. I bring it up largely because the script goes out of its way to applaud low tech, even while abusing it as thoroughly as it does high tech.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;10.) &amp;#8220;There&amp;#8217;s only 6 people in the world who could code this.&amp;#8221;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;No. You&amp;#8217;re wrong, Q. This statement is foolish and you&amp;#8217;re an egotistical ass.&lt;/p&gt;
&lt;p&gt;It might be true (though a stretch) that only a handful of people in the world could originally come up with a programming trick, but once it&amp;#8217;s been done it can be replicated. Despite everything Hollywood has tried to convince you of, the world has no shortage of very smart people who are very good at expanding good ideas if not cooking them up on their own. In fact, there&amp;#8217;s entire sub-industries within IT of them.&lt;/p&gt;
&lt;p&gt;Pro tip: almost none of the aforementioned very smart people work for governments during peace time because the pay is dirt.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Round up&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Skyfall may be the least Bond-like Bond film I&amp;#8217;ve seen. With Daniel Craig in the suit, MGM has been reaching for a grittier Bond. They&amp;#8217;ve added a few dashes of John McClaine in the mix. I would say this experiment has been a mixed bag but is mostly successful. It&amp;#8217;s with disappointment (and a fair amount of catharsis) that I write this post because I want to see Hollywood do tech well and even when it&amp;#8217;s doing other things right, so much goes awry with the wrong consultants on the job. So, Hollywood! &lt;em&gt;Bubbe&lt;/em&gt;! Give me a call next time, alright?&lt;/p&gt;</description><link>http://erickolb.me/post/36695497447</link><guid>http://erickolb.me/post/36695497447</guid><pubDate>Tue, 27 Nov 2012 18:24:31 -0500</pubDate><category>bond</category><category>hacking</category><category>james bond</category><category>movies</category><category>radio</category><category>skyfall</category><category>technology</category><category>programming</category><category>encryption</category><category>passwords</category><category>private networks</category><category>networking</category><category>daniel craig</category><category>MGM</category><category>M</category><category>Q</category><category>MI6</category><category>information security</category><category>infosec</category></item><item><title>surplus-mag:

Target Joffrey Poster
People who don’t watch Game...</title><description>&lt;img src="http://24.media.tumblr.com/tumblr_mby6anriIR1r10ux5o1_500.jpg"/&gt;&lt;br/&gt;&lt;br/&gt;&lt;p&gt;&lt;a class="tumblr_blog" href="http://surplusmag.com/post/33651772568/target-joffrey-poster-people-who-dont-watch-game"&gt;surplus-mag&lt;/a&gt;:&lt;/p&gt;
&lt;blockquote&gt;
&lt;h2&gt;Target Joffrey Poster&lt;/h2&gt;
&lt;p&gt;People who don’t watch &lt;em&gt;Game of Thrones … &lt;/em&gt;you’re probably confused and please excuse us for a second as we nerd out about HBO’s hit show.  People who do watch… &lt;a href="http://www.redbubble.com/people/bamboota/works/8877280-the-perfect-target?p=poster"&gt;target practice&lt;/a&gt;.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Drop the price to $2 per target (same as other novelty targets) and I’ll take a dozen.&lt;/p&gt;</description><link>http://erickolb.me/post/33670365010</link><guid>http://erickolb.me/post/33670365010</guid><pubDate>Mon, 15 Oct 2012 19:14:38 -0400</pubDate><category>game of thrones</category><category>firearms</category><category>target practice</category></item><item><title>I decided to give lock picking a spin at DerbyCon. I bought a...</title><description>&lt;iframe src="//www.tumblr.com/video/erickolb/33105828454/400" id="tumblr_video_iframe_33105828454" class="tumblr_video_iframe" width="400" height="225" style="display:block;background-color:transparent;overflow:hidden;" allowTransparency="true" frameborder="0" scrolling="no" webkitAllowFullScreen mozallowfullscreen allowFullScreen&gt;&lt;/iframe&gt;&lt;br/&gt;&lt;br/&gt;&lt;p&gt;I decided to give lock picking a spin at DerbyCon. I bought a basic set of picks from the &lt;a href="http://bloomingtonfools.org/" target="_blank"&gt;Fraternal Order of Locksport (FOOLS)&lt;/a&gt; crew and sat down to begin my first attempts at picking a padlock.&lt;/p&gt;
&lt;p&gt;It turns out the &lt;a href="http://www.masterlock.com/products/product_details/4" target="_blank"&gt;Master Lock No. 4 laminated locks&lt;/a&gt; are ridiculously easy to pick — I was able to tackle those as a complete novice in a matter of minutes. The &lt;a href="http://www.masterlock.com/products/product_details/3D" target="_blank"&gt;Master Lock No. 3&lt;/a&gt; proved more of a challenge. I was able to defeat the lock just once before the end of the conference, and only then after a half hour of trying and some pointers from a more experienced lock picker. When I got home, I bought a No. 3 to continue practicing.&lt;/p&gt;
&lt;p&gt;As you can see from the video here, I’ve gotten pretty handy with it. I can pretty reliably pop this padlock in a matter of seconds anymore. I’m looking to progress onto some more difficult locks; perhaps a 5- or 6-pin cylinder before attempting something with security pins? Any suggestions on what locks to look for next?&lt;/p&gt;</description><link>http://erickolb.me/post/33105828454</link><guid>http://erickolb.me/post/33105828454</guid><pubDate>Sun, 07 Oct 2012 15:59:00 -0400</pubDate><category>lock picking</category><category>derbycon</category><category>master lock</category><category>locksport</category></item><item><title>NIST Gives Keccak Function SHA-3 Designation</title><description>&lt;p&gt;Last night, &lt;a href="http://www.nist.gov/itl/csd/sha-100212.cfm" target="_blank"&gt;NIST announced the winner of the SHA-3 competition&lt;/a&gt; that began back in 2007. The algorithm being standardized is the &lt;a href="http://en.wikipedia.org/wiki/SHA-3" target="_blank"&gt;Keccak (pronounced &amp;#8220;catch-ack&amp;#8221;)&lt;/a&gt;. The function was designed by programmers from Belgium and Italy, most notably Joan Daemen who co-designed the Rijndael cipher we&amp;#8217;ve come to know as AES. Keccak is not derrived from SHA-2. The advantage here is that any future attack on SHA-2 does not extend into an attack - hypothetical or manifested - on SHA-3.&lt;/p&gt;
&lt;p&gt;The thing to keep in mind when considering this news is that SHA-3 is neither replacing a broken algorithm nor providing a one-stop-shop for protecting sensitive data. If we&amp;#8217;ve learned just one thing since the advent of the GPU, it should be that hashing functions are deterministic unidirectional compression functions and not what we should think of as encryption. These things are so fast that use of a hashing function to protect your data is undone simply by exhaustively compressing comparison messages until we&amp;#8217;ve found a matching hash.&lt;/p&gt;
&lt;p&gt;Why am I on a soap box about it? Two reasons.&lt;/p&gt;
&lt;p&gt;First, I&amp;#8217;m already seeing people eager about &amp;#8220;upgrading&amp;#8221; existing security functions that currently employ SHA-2 to SHA-3. This is nonsense; SHA-3 is not quantifiably more secure than SHA-2. Please don&amp;#8217;t do this. It&amp;#8217;s a waste of your time and your employer&amp;#8217;s money.&lt;/p&gt;
&lt;p&gt;Second - and more troubling - I&amp;#8217;ve seen some folks excited about &amp;#8220;upgrading&amp;#8221; from bcrypt to SHA-3. This isn&amp;#8217;t nonsense, it&amp;#8217;s absurd. An algorithm like bcrypt is valueable and useful for applications like salted password storage because it is a memory-hard key derivation function. It is slow and when it comes to storing passwords, slow is secure. To the person who already knows the password, an evaluation of a few thousand milliseconds is less than a hiccup. But it renders that mode of attack wildly impractical for someone who wants to brute force your stolen password hash. The Keccak function does not compare to this; if you eschew something int he bcrypt/scrypt/PBKDF2 family for simple SHA-3, you&amp;#8217;re &lt;a href="https://twitter.com/hashcat/status/253462812620361728" target="_blank"&gt;regressing back into GPU-assailable territory&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;The round-about point I&amp;#8217;m making here is that the NIST announcement does not radically change the landscape. If this news has you thinking about radical change in your software already, you&amp;#8217;ve probably not got your feet planted firmly on the ground. Best to consider SHA-3 an option to, but not a replacement for SHA-2.&lt;/p&gt;
&lt;p&gt;Postscript: Please tell me you&amp;#8217;re not still using SHA-1. Please, &lt;em&gt;please&lt;/em&gt; tell me you&amp;#8217;re not still using SHA-0 or MD5.&lt;/p&gt;</description><link>http://erickolb.me/post/32806097252</link><guid>http://erickolb.me/post/32806097252</guid><pubDate>Wed, 03 Oct 2012 11:11:51 -0400</pubDate><category>information security</category><category>infosec</category><category>security</category><category>hashing functions</category><category>SHA-3</category><category>SHA-2</category><category>SHA-1</category><category>AES</category><category>NIST</category><category>MD5</category><category>passwords</category><category>bcrypt</category><category>scrypt</category><category>PBKDF2</category><category>Rijndael</category><category>Keccak</category></item><item><title>DerbyCon Take-Aways: CookieCadger</title><description>&lt;p&gt;A security conference is usually a pretty good time and place to drop some new software (or the occasional 0-day) on the world and this year&amp;#8217;s DerbyCon in Louisville, KY was no disappointment. Over the next few days, I&amp;#8217;ll cover some of the new shinies that saw their first dawn at the conference as well as some of my general take-aways and talking points.&lt;/p&gt;
&lt;p&gt;First up is a nifty piece of software called &lt;a href="https://www.cookiecadger.com/" target="_blank"&gt;CookieCadger&lt;/a&gt;. Drawing its name from the verb &lt;em&gt;to cadge&lt;/em&gt; - meaning to obtain by imposing on another&amp;#8217;s generosity - CookieCadger is a spiritual successor to &lt;a href="http://en.wikipedia.org/wiki/Firesheep%20" target="_blank"&gt;FireSheep&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;FireSheep is a security toy released as a Firefox extension back in 2010 to demonstrate the need for SSL channels at the social networking sites that have become the backbone of our daily web consumption. It implemented a session impersonation attack by lifting session identifiers from cookies being transmitted over unencrypted web traffic. The project caught the attention of the intended parties, HTTPS traffic was enabled for the big players, and FireSheep drifted into the obscurity of vaporware.&lt;/p&gt;
&lt;p&gt;Two years later, enter CookieCadger. Started by as a Iowa State graduate project by &lt;a href="https://www.mattslifebytes.com/" target="_blank"&gt;Matthew Sullivan&lt;/a&gt;, CookieCadger expands on the legacy of FireSheep and builds a considerably more robust toolkit from the same concept.&lt;/p&gt;
&lt;p&gt;An attacker runs the software (written in Java, so it&amp;#8217;s cross-platform from day one) on one or more network interfaces, presumably on older wireless or unswitched wired networks. For instance let&amp;#8217;s say he&amp;#8217;s in the corner of Joe&amp;#8217;s Coffee Shack, a local draw known for its free wifi and open mic nights. All around him people are conducting web traffic happily over port 80, blissfully unaware or unconcerned with the truth that their data is literally flying through the air. The attacker&amp;#8217;s machine is sniffing this traffic and extracting vulnerable session data from a packet capture. He doesn&amp;#8217;t even need to be sniffing traffic live &amp;#8212; he can load in a pcap file to do it, so don&amp;#8217;t think you&amp;#8217;re safe just because your traffic&amp;#8217;s running through switched hardware.&lt;/p&gt;
&lt;p&gt;&lt;img alt="CookieCadger - Collecting The Data" src="https://s3.amazonaws.com/tumblr.erickolb.me/security/Cookie+Cadger_2012-10-02_14-19-13.png" width="500"/&gt;&lt;/p&gt;
&lt;p&gt;CookieCadger comes with a few pre-built modules for convenience. If you&amp;#8217;re foolish enough not to be using Facebook over HTTPS, he&amp;#8217;ll see that pop up in a convenient frame of identified sessions. With a quick double-click, CookieCadger launches your Facebook session in his browser window. Total access. There&amp;#8217;s a WordPress adapter as well; log into any WP install on an unsecured channel, he&amp;#8217;ll see that session. Maybe he&amp;#8217;ll use your privileged account to create another for himself to come back to later. It&amp;#8217;s easy to build your own adapters for session identification, extraction, and impersonation; just write three methods in JavaScript to tailor it to the target of your choosing and you&amp;#8217;re done.&lt;/p&gt;
&lt;p&gt;&lt;img alt="CookieCadger - Launching The Session" src="https://s3.amazonaws.com/tumblr.erickolb.me/security/Cookie+Cadger_2012-10-02_14-27-06.png" width="500"/&gt;&lt;/p&gt;
&lt;p&gt;As a blue team member, I&amp;#8217;ve already started to come up with some practical applications for this application. The most obvious is to use it for your company&amp;#8217;s web applications to verify whether you&amp;#8217;re leaving yourselves vulnerable to this exact method of exploitation. I can also see this being used in layperson presentations to demonstrate what SSL encryption is, why it&amp;#8217;s important, and what can happen if you believe it doesn&amp;#8217;t matter to you.&lt;/p&gt;
&lt;p&gt;CookieCadger is not free, but it&amp;#8217;s a very modest $10 and that money goes direct to Hackers for Charity. I&amp;#8217;ve already got my copy and I&amp;#8217;ve been tinkering around with this at home. I recommend checking it out. The source code will be released in the near future (supposedly mid-October) after undergoing a post-hackfest code cleanup.&lt;/p&gt;
&lt;p&gt;Check out Matthew Sullivan&amp;#8217;s slides for the presentation &lt;a href="https://www.cookiecadger.com/wp-content/uploads/Derbycon%202012.pdf%20" target="_blank"&gt;here&lt;/a&gt;.&lt;/p&gt;</description><link>http://erickolb.me/post/32751267460</link><guid>http://erickolb.me/post/32751267460</guid><pubDate>Tue, 02 Oct 2012 15:58:06 -0400</pubDate><category>derbycon</category><category>information security</category><category>encryption</category><category>cookies</category><category>impersonation</category><category>cookiecadger</category><category>firesheep</category><category>louisville</category><category>kentucky</category><category>infosec</category><category>security</category></item><item><title>olympicfashion:

Archery London 1908 - Archery London...</title><description>&lt;img src="http://25.media.tumblr.com/tumblr_macfp0Sv9m1rbw3yio1_500.jpg"/&gt;&lt;br/&gt;&lt;br/&gt;&lt;p&gt;&lt;a class="tumblr_blog" href="http://olympicfashion.tumblr.com/post/31522419034/archery-london-1908-archery-london-2012"&gt;olympicfashion&lt;/a&gt;:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Archery London 1908 - Archery London 2012 &lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Archery makes looking frumpy look cool.&lt;/p&gt;</description><link>http://erickolb.me/post/31810751019</link><guid>http://erickolb.me/post/31810751019</guid><pubDate>Tue, 18 Sep 2012 15:59:38 -0400</pubDate><category>olympics</category><category>archery</category><category>fashion</category></item><item><title>surplus-mag:

Math Club Tee
Nothing goes together quite like a...</title><description>&lt;img src="http://24.media.tumblr.com/tumblr_macgq3VAxR1r10ux5o1_500.jpg"/&gt;&lt;br/&gt;&lt;br/&gt;&lt;p&gt;&lt;a class="tumblr_blog" href="http://surplusmag.com/post/31523143647/math-club-tee-nothing-goes-together-quite-like-a"&gt;surplus-mag&lt;/a&gt;:&lt;/p&gt;
&lt;blockquote&gt;
&lt;h2&gt;Math Club Tee&lt;/h2&gt;
&lt;p&gt;Nothing goes together quite like a dangerous motorcycle club and the quadratic equation. Embrace both with this &lt;a href="http://www.fossil.com/en_US/shop/men/clothing/knits_tees/math_club_tee-mc8472p.html?parent_category_rn=331235&amp;departmentCategoryId=&amp;pn=c&amp;cm_vc=331237&amp;rec=5&amp;imagePath=MC8472001"&gt;tee&lt;/a&gt;.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Surplus Mag tapped into my brain this week. I need this shirt to wear when I’m working on my cryptography homework, because that’s how I feel.&lt;/p&gt;</description><link>http://erickolb.me/post/31745317952</link><guid>http://erickolb.me/post/31745317952</guid><pubDate>Mon, 17 Sep 2012 16:01:09 -0400</pubDate><category>fashion</category><category>tee shirt</category><category>t-shirt</category><category>math</category></item><item><title>surplus-mag:

TAG Heuer Carrera 1887 “SpaceX” Watch
Omega and...</title><description>&lt;img src="http://24.media.tumblr.com/tumblr_machbccCIJ1r10ux5o1_500.jpg"/&gt;&lt;br/&gt;&lt;br/&gt;&lt;p&gt;&lt;a class="tumblr_blog" href="http://surplusmag.com/post/31523563362/tag-heuer-carrera-1887-spacex-watch-omega-and"&gt;surplus-mag&lt;/a&gt;:&lt;/p&gt;
&lt;blockquote&gt;
&lt;h2&gt;TAG Heuer Carrera 1887 “SpaceX” Watch&lt;/h2&gt;
&lt;p&gt;Omega and NASA have always had a long lasting relationship and now another luxury watch manufacturer is getting in the space game. This &lt;a href="http://tagheuer.com"&gt;TAG Heuer&lt;/a&gt; Carrera 1887 features the SpaceX logo and both the &lt;span&gt;Falcon 9 launch rocket and Dragon spacecraft - two of their most notable projects. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;For those unaware of what SpaceX is, it’s a space transportation company founded by Elon Musk - the genius behind PayPal and Tesla Motors. The guy is basically a real life Tony Stark. Don’t be surprised if he starts fighting off super villains in near future.&lt;/span&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;I don’t commonly like chronograph-style watches because they violate every principle of simplicity ever uttered. This watch, however, peaks in epic territory on multiple levels. It’s an incredible stylish, understated chronograph that isn’t brazen with its window dressing. It commemorates one of the more important initiatives in modern space travel as well.&lt;/p&gt;</description><link>http://erickolb.me/post/31679292767</link><guid>http://erickolb.me/post/31679292767</guid><pubDate>Sun, 16 Sep 2012 16:00:06 -0400</pubDate><category>fashion</category><category>watches</category><category>NASA</category><category>SpaceX</category><category>dragon</category><category>TAG Heuer</category><category>chronograph</category></item><item><title>surplus-mag:

Vintage Wooden Arrows
These cool hand painted...</title><description>&lt;img src="http://25.media.tumblr.com/tumblr_macht6eQY51r10ux5o1_500.jpg"/&gt;&lt;br/&gt;&lt;br/&gt;&lt;p&gt;&lt;a class="tumblr_blog" href="http://surplusmag.com/post/31523933207/vintage-wooden-arrows-these-cool-hand-painted"&gt;surplus-mag&lt;/a&gt;:&lt;/p&gt;
&lt;blockquote&gt;
&lt;h2&gt;Vintage Wooden Arrows&lt;/h2&gt;
&lt;p&gt;These cool hand painted &lt;a href="http://www.etsy.com/listing/98880176/new-colors-vintage-wooden-arrow"&gt;arrows&lt;/a&gt; feature real feathers and blunt metal tips. Hawkeye, Robin Hood, Legolas and the editors here at &lt;em&gt;&lt;a href="http://surplusmag.com"&gt;Surplus&lt;/a&gt;&lt;/em&gt; all certify the craftsmanship.&lt;/p&gt;
&lt;/blockquote&gt;</description><link>http://erickolb.me/post/31606389603</link><guid>http://erickolb.me/post/31606389603</guid><pubDate>Sat, 15 Sep 2012 15:58:33 -0400</pubDate><category>archery</category><category>arrows</category><category>craftmanship</category><category>handmade</category></item><item><title>surplus-mag:

Game of Thrones, Rebranded
The super talented Nike...</title><description>&lt;img src="http://25.media.tumblr.com/tumblr_m9n3afDeMn1r10ux5o1_500.jpg"/&gt;&lt;br/&gt; &lt;br/&gt;&lt;img src="http://24.media.tumblr.com/tumblr_m9n3afDeMn1r10ux5o2_500.jpg"/&gt;&lt;br/&gt; &lt;br/&gt;&lt;img src="http://25.media.tumblr.com/tumblr_m9n3afDeMn1r10ux5o3_500.jpg"/&gt;&lt;br/&gt; &lt;br/&gt;&lt;img src="http://24.media.tumblr.com/tumblr_m9n3afDeMn1r10ux5o4_500.jpg"/&gt;&lt;br/&gt; &lt;br/&gt;&lt;p&gt;&lt;a class="tumblr_blog" href="http://surplusmag.com/post/30609005520/game-of-thrones-rebranded-the-super-talented"&gt;surplus-mag&lt;/a&gt;:&lt;/p&gt;
&lt;blockquote&gt;
&lt;h2&gt;&lt;em&gt;Game of Thrones&lt;/em&gt;, Rebranded&lt;/h2&gt;
&lt;p&gt;The super talented Nike designer and &lt;em&gt;Game of Thrones&lt;/em&gt; obsessive Darrin Crescenzi put together this &lt;a href="http://www.fastcodesign.com/1670630/a-top-nike-designer-rebrands-game-of-thrones#4"&gt;rebranding project&lt;/a&gt; and poster for HBO’s latest small screen hit. Something tells us even King Joffrey would approve.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;This poster would be a classy addition to your geek den. I thought about it, but I’m already pretty short on wall space. Do what I could not: put this cool on your wall.&lt;/p&gt;</description><link>http://erickolb.me/post/30651033723</link><guid>http://erickolb.me/post/30651033723</guid><pubDate>Sat, 01 Sep 2012 09:12:15 -0400</pubDate><category>game of thrones</category><category>graphic design</category></item><item><title>"I still have two children. I need to take care of them. To hate [Breivik], it takes all your energy...."</title><description>“I still have two children. I need to take care of them. To hate [Breivik], it takes all your energy. From day one, he’s been a zero to me.”&lt;br/&gt;&lt;br/&gt; - &lt;em&gt;&lt;p&gt;Freddy Lie, father of Elizabeth Lie who was slain in Anders Breivik’s assault on Utøya island. Quote from GQ’s &lt;a href="http://longform.org/2012/07/19/is-he-coming-is-he-oh-god-i-think-he-is/" target="_blank"&gt;&lt;em&gt;“Is He Coming? Is He? Oh God, I Think He Is?”&lt;/em&gt; by Sean Flynn&lt;/a&gt; in the August 2012 issue.&lt;/p&gt;
&lt;p&gt;Breivik was &lt;a href="http://www.bbc.co.uk/news/world-europe-19365616" target="_blank"&gt;recently ruled sane by the Norwegian court and given the maximum sentence of 21 years&lt;/a&gt; for the attack that left 77 dead.&lt;/p&gt;&lt;/em&gt;</description><link>http://erickolb.me/post/30243369140</link><guid>http://erickolb.me/post/30243369140</guid><pubDate>Sun, 26 Aug 2012 10:59:18 -0400</pubDate><category>GQ</category><category>Norway</category><category>Anders Breivik</category><category>terrorism</category><category>news</category></item><item><title>gearpatrol:

Mr. Armstrong (the real Mr. Armstrong). No one will...</title><description>&lt;img src="http://24.media.tumblr.com/tumblr_m9buusm2FJ1qzxsmpo1_500.png"/&gt;&lt;br/&gt;&lt;br/&gt;&lt;p&gt;&lt;a href="http://gearpatrol.tumblr.com/post/30190254441/mr-armstrong-the-real-mr-armstrong-no-one" class="tumblr_blog"&gt;gearpatrol&lt;/a&gt;:&lt;/p&gt;

&lt;blockquote&gt;&lt;p&gt;Mr. Armstrong (the real Mr. Armstrong). No one will ever have a better, more astronomically badass, profile photo. RIP.&lt;/p&gt;&lt;/blockquote&gt;

&lt;p&gt;It is our responsibility to keep the legacy of space travel alive. Curiosity needs to he just the beginning of the journey, not the end.&lt;/p&gt;&lt;p&gt;Rest in peace, Commander Armstrong. We owe you a debt our imaginations might never repay.&lt;/p&gt;</description><link>http://erickolb.me/post/30190934821</link><guid>http://erickolb.me/post/30190934821</guid><pubDate>Sat, 25 Aug 2012 16:25:02 -0400</pubDate></item><item><title>GenCon Replay - Fortune &amp; Glory: The Cliffhanger Game</title><description>&lt;p&gt;A good chunk of my time in the exhibition hall at GenCon was spent at the &lt;a href="http://www.flyingfrog.net/" title="Flying Frog Productions Games" target="_blank"&gt;Flying Frog Productions&lt;/a&gt; booth. I fell in love with their games at GenCon 2011 and wanted to come back and drink deep of their geeky elixir this year.&lt;/p&gt;
&lt;p&gt;&lt;img alt="Fortune and Glory: The Cliffhanger Game" src="https://s3.amazonaws.com/tumblr.erickolb.me/gencon2012/IMG_0852.JPG" width="500"/&gt;&lt;/p&gt;
&lt;p&gt;FFP&amp;#8217;s games seem like they start with a theme and grow from there. Last Night on Earth is the quintessential zombie title (and among the best of them to boot); Invasion from Outer Space hits the classic B-movie martian invasion theme; Touch of Evil covers the colonial supernatural thriller genre; and most recently Fortune &amp;amp; Glory tackles the globe-trotting, Nazi-fighting buried treasure seeker (a la Indiana Jones) trope head on.&lt;/p&gt;
&lt;p&gt;Of all of FFP&amp;#8217;s games, F&amp;amp;G probably has the most pieces. It&amp;#8217;s the most intimidating looking at a distance and certainly has the heftiest price tag ($100 versus $60 for other base games). From the very start, however, you know you&amp;#8217;re getting a lot of game. All of Flying Frog&amp;#8217;s premier titles feature multiple scenarios and/or modes of play. In particular, Fortune and Glory is playable competitively, cooperatively, or even solitaire.&lt;/p&gt;
&lt;p&gt;Full disclosure: &lt;a href="http://siderbox.com/" target="_blank"&gt;Matt&lt;/a&gt; and I really wanted to demo this game at Gen Con last year, but missed the opportunity. We sprang at it this year.&lt;/p&gt;
&lt;p&gt;Sitting down, we chose our characters for the game. I opted for &lt;a href="http://www.flyingfrogwiki.com/ffpwiki/index.php?title=Duke_Dudley" title="Duke Dudley" target="_blank"&gt;Duke Dudley&lt;/a&gt;, a British nobleman whose wealth and patriotism were his unique advantages. (This decision may have been influenced by the fact that the photo model for the Duke was literally standing over my shoulder at the time.) Matt chose &lt;a href="http://siderbox.com/post/29692996732/fortune-and-glory-flyingfroggames-gencon-taken" title="Doctor Zhukov" target="_blank"&gt;Doctor Zhukov&lt;/a&gt;, a mad Russian scientist whose scientific mind gave him other advantages. As with most FFP games, each character gets different dice-related properties as well asspecial abilities.&lt;/p&gt;
&lt;p&gt;&lt;img alt="Duke Dudley, British Lord and Treasure Hunter" src="https://s3.amazonaws.com/tumblr.erickolb.me/gencon2012/IMG_0847.JPG" width="500"/&gt;&lt;/p&gt;
&lt;p&gt;With all players&amp;#8217; characters chosen, the treasures of the game were revealed. For each of four colored markers, a treasure (&amp;#8220;The Glove&amp;#8221;) and an adventure (&amp;#8220;Of Zeus&amp;#8221;) are selected from different decks of cards and then combined. A location card places it randomly on the world map. This was a demo of the competitive mode of play, so the goal was the be the first player to amass a fortune of eight gold (foreshortened for brevity) and return to their home city claimed the day.&lt;/p&gt;
&lt;p&gt;When the dice started rolling, the players were off after the titular fortune and glory. The world map is divided up into regional spaces; each space is one movement, as well as each section of ocean or city. Within the first turn, most players had made it to the location of one of the game&amp;#8217;s hidden hidden treasures. Others, like yours truly, got stuck in Wales and ambushed by generic thugs.&lt;/p&gt;
&lt;p&gt;Each adventure specifies a number of dangers. That&amp;#8217;s a measure of the challenges a player must face before they can claim the treasure for their own. A danger card is flipped from a deck. It specifies a type of challenge - such as lore, agility, or cunning - a success threshold, and a required number of successes. Each player&amp;#8217;s character card has a corresponding number of dice. That number of dice are rolled and the rolls that meet or exceed the threshold count towards their passing the challenge. If the challenge is met, the player earns glory points which are used as a secondary currency and may opt to continue towards the treasure or camp until later. If the challenge is failed, a cliffhanger ensues.&lt;/p&gt;
&lt;p&gt;A cliffhanger is the logical escalation of a danger not triumphed. If you fail to meet the agility test of a daring airplane chase, you&amp;#8217;ll flip the card and find yourself trying to escape a flaming wreck on a mountainside, having surrendered all the glory you amassed this turn. Pass this last-ditch effort and you&amp;#8217;ll earn the danger token, get some consolation glory, and get to rest until the next turn. Fail, and you&amp;#8217;ll sustain wounds that move you closer to ultimate defeat.&lt;/p&gt;
&lt;p&gt;If you should succeed in passing all the dangers before the treasure, you take it and need to bring it to a city to fence. Bigger cities mean a bigger take. Drag your feet getting to safety and another adventurer might separate you from your treasure.&lt;/p&gt;
&lt;p&gt;Enter a city, and you&amp;#8217;ll need to flip a city card from another deck. This randomizes your trip into the city and ensures your run to ground might not be so run-of-the-mill. You might score some extra gear to help you out in the field, or you might bump into some Nazis.&lt;/p&gt;
&lt;p&gt;Did I mention the Nazis? I should have. There are Nazis. They have a zeppelin, which is the universal symbol for intrigue, adventure, and Nazi shenanigans. At the end of every turn, a location card is revealed and a movement roll made. The zeppelin moves that many spaces along the shortest path to the indicated locale. If it reaches the location, it drops Nazi tokens on the field that will further complicate your quest. It&amp;#8217;s not all gloom and doom aboard the Nazi airship, however. Each turn, the Third Reich is collecting lost gold of its own on the ship; should you be so daring and lucky as to sneak past the guards while in the same map space, you can steal the Nazi&amp;#8217;s loot!&lt;/p&gt;
&lt;p&gt;F&amp;amp;G is yet another quality product from a fantastic company. One thing I really respect about these guys is that every year, it&amp;#8217;s the guys who are in the photo shoots for the game doing the demos and working the retail counter. They&amp;#8217;re more than happy to sign a photo for you.&lt;/p&gt;
&lt;p&gt;As for my demo, the Duke didn&amp;#8217;t come out on top. A failed race for an artifact in Western Europe kept me busy while a flyboy out of San Francisco got lucky and dug up an artifact worth his requisite 8 gold in his back yard. Maybe next time&amp;#8230;&lt;/p&gt;</description><link>http://erickolb.me/post/30050795064</link><guid>http://erickolb.me/post/30050795064</guid><pubDate>Thu, 23 Aug 2012 15:54:23 -0400</pubDate><category>GenCon</category><category>board games</category><category>tabletop gaming</category><category>Flying Frog Productions</category><category>games</category></item><item><title>Jojo the Bear versus Zard beast. Advantage: Jojo. Invasion from...</title><description>&lt;img src="http://24.media.tumblr.com/tumblr_m8yi2vcqqW1rnlkzoo1_500.jpg"/&gt;&lt;br/&gt;&lt;br/&gt;&lt;p&gt;Jojo the Bear versus Zard beast. Advantage: Jojo. Invasion from Outer Space by @FFPGames. #GenCon (Taken with &lt;a href="http://instagram.com"&gt;Instagram&lt;/a&gt; at GenCon 2012)&lt;/p&gt;</description><link>http://erickolb.me/post/29692314004</link><guid>http://erickolb.me/post/29692314004</guid><pubDate>Sat, 18 Aug 2012 11:08:00 -0400</pubDate><category>GenCon</category><category>Flying Frog Productions</category><category>board games</category><category>tabletop gaming</category><category>Invasion From Outer Space</category><category>circus</category><category>bears</category><category>martians</category></item></channel></rss>
