Cool HQ

Polish radio station. What a cool place to work.

Polish Radio Station

Haggling for Hot Dogs

Esquire: (And other real-life adventures in the neglected art of negotiation.) Everything is open to negotiation. Everything. For three months, the author treated the world that way. This is what ensued.

Halfway through this article I resolved to change how I do business, had a deja-vu moment, and realised I made the same resolution 2.5 years ago when I read it the first time. So I guess I found it on Digg this time then.

I do try to haggle, but I always screw up my starting and ending position, and I always feel like my opponent is laughing his or her ass off at me after I leave. Where’s Tony Robbins when you need him, eh?

“Hey, check this out!”

Bruce Schneier notes a recent study on phishing that found that over 70% of people will click on a link if it looks like it’s coming from someone they know, and jokes about men being suckers for the ladies, what with them being 15% more likely to click if the email comes from the fairer sex. (Although I should also note that, in general, women were 10% more likely to click than men. :)

I think an interesting addition to this research would be an analysis of how the baton is passed between people, and how often it does laps. In this research the names and email addresses probably came from a control set, however in reality phishers get them from address books stolen by a trojans on compromised computers.

Obviously the stolen address book must come from a common contact if both names are in it, but the ruse will be much more successful if the source or target is the owner of the address book, and the opposite number someone in it. And around we go. So what we have here is actually a Six Degrees Of Separation Möbius Strip Of Stupidity.

Another study Bruce notes only serves to highlight the naivety of modern man. Although the response rate isn’t enumerated, a professor at Indiana University has found that people are willing to respond to fraudlent emails if the attacker identifies the first four digits of their credit card number, instead of the usual last four.

You all know why they use the last four, right? If you don’t and the first four digits of your card are 4539, this is Mmbaza from Bank of Ireland and I’d like to talk to you about a trust account in the name of Mrs. Charles J. Haughey and a transaction which will fall in your favour to the tune of 10% of Thirty Million Euros.

Friday

Right, the plan is:

  • 6pm, Cocktails in the Long Island
  • 7pm, Munch in the Flying Enterprise
  • 8pm, Beer in Tom Barrys

Take yer pick to join in.

Security Public Relations Excuse Bingo

Via Bruce, who features himself. :)

I’m going to be naughty and paste all the items, otherwise you’d be there all day hitting refresh.

  • You’re so negative
  • Our proactive technology solutions prevent that
  • Our proprietary encryption algorithms prevent that
  • We have CISSP certified engineers
  • That’s just theoretical mumbo-jumbo
  • You’ll be hearing from our lawyers
  • You’ve got a conflict of interest
  • That’s only there for backward compatibility
  • We meet all government standards
  • We meet all industry standards
  • It doesn’t need to be very secure
  • Nothing is 100% secure
  • We take security very seriously
  • We don’t comment on security matters
  • No comment
  • You are in violation of the DMCA
  • We already knew about it
  • Nobody will ever try to do this
  • What kind of a person looks for flaws?
  • No one would ever think of that
  • Our success speaks for itself
  • You’re paranoid
  • You’re just an academic
  • You’re only helping the bad guys
  • Why do you hate America?
  • You don’t understand the context
  • The product was tested by security experts
  • We employ top security experts
  • Who are you to criticize, anyway?
  • This is probably fixed in the next release
  • No one has complained before
  • No one has ever found any problems
  • It’s a feature our users want
  • Let’s see you design something better
  • You’re just looking for attention
  • You must be being paid by our competition
  • We’ve always done it this way
  • Everybody does it this way
  • We follow industry standard practices
  • We think it is secure enough
  • You’re being irresponsible
  • If you hadn’t told anyone, it would still be secure
  • La, la, la we’re not listening
  • It’s secure enough for our customers
  • We use crypto- graphy
  • We read Schneier’s book
  • What do you have against us?
  • Why are you trying to harm our industry?
  • It would be too expensive to fix that
  • Our customers love our product
  • We’re fully ISO-9001 compliant
  • Nobody’s perfect

My Enormous Erection

Bet that got your attention. The 24m CIX mast was assembled on site last week, and installed in the courtyard inside our services building yesterday.

EDIT: I’ll post a photo of my own tomorrow.

I think I spy our genset up there too, but I could be wrong about that as the infrastructure for it wasn’t in place the last time I visited. (EDIT: That is the genset, and the chillers are on the roof too!)

At this point the major infrastructural action items remaining are:

  • install UPS system
  • install fire suppression bottles
  • install chillers

We still have a lot of smaller jobs to do though, plus the final build out of the network and moving servers from the computer room to the main data floor.

Gimme a bell if you’re interested in the networking stuff, we’re not happy with the offerings we’ve received so far. Talk about overthinking it! (And overpricing it.)

Did you know?

That the phrase “By Hook or by Crook” originated when William the Conqueror swore that he would take Waterford by Hook Head to the east of the harbour, or Crook head to the west. I didn’t (until a few weeks ago).

HTML updates at last!

Although I can understand why the W3C went the XHTML route several years ago, I think it was a distraction from the beautiful simplicity of basic HTML, which essentially made the web what it is today. If it wasn’t for <B> and <I> and their ilk – yes, even <BLINK> – people like me wouldn’t have been interested in playing with HTML, creating the silly little websites we did, and in time moving onto to new toys like Javascript and Perl.

It was those toys – I’m sure the likes of Justin would crucify me for calling Perl a toy, but that’s what it was for me at the outset – that led people like Rasmus Lerdorf to create new toys like PHP, and XMLHttpRequest, and Ruby on Rails. And it was those toys that led to the likes of Digg, and Flickr, and YouTube, and thousands of other sites that you use every day. They’re not basic HTML by any stretch of the imagination, but their foundations are.

Now it looks like we’re going back to our roots, with HTML 5. New elements will be added to the spec, simple and easy-to-understand elements like header and footer, aside and figure, audio and video, details and datagrid. Guess their purposes, you’ll probably be right or not far off.

Hopefully the new generation of web addicts will embrace HTML 5 like we embraced it’s forerunners, breaking away from walled gardens like Facebook and MySpace and building their online presences in their own space, linked together with open standards like SIOC and it’s cousins. It’s not hard. If I can do it…