I thought I was the only programmer/knitter in the world, but no, like rocker/hacker ch1Xors, there is an active group of my odd demographic on the internet!
First of all, the awesome folks at KnitML have created a standard content model for knitting patterns, along with a pattern renderer, so you can get an idea of what your knitted object will look like from its pattern. I always thought that knitting patterns were computer program-like in style. And of course they should be: knitting machines need deterministic, procedural instructions. I always thought it was interesting how crafty folks, many of whom would probably claim they know nothing about writing computer programs, comfortably use control structures in knitting patterns.
Here is a great talk on the history of knitting in relation to computing/hacker culture, including open source patterns, knitting in public spaces, and how technology and the internet is shaping the state of the art.
Also, here is a roundup of geek craft from 2007, including knitting a space invaders scarf. Pixelated old video game images make good quilts and knits.
Monday, December 31, 2007
RFID tags in new $20 bills
Apparently this is not new, though it's new to me: new $20 bills have RFID tags in them, and when you microwave them, they explode! That's way more fun than microwaving AOL CDs. Link
So now a thief can not only determine remotely if you are carrying your US passport, he can also determine if you're carrying large bills. Awesome.
So now a thief can not only determine remotely if you are carrying your US passport, he can also determine if you're carrying large bills. Awesome.
Thursday, December 20, 2007
MSI Script vs Windows Security
I have recently been working on fixing bugs in my company's software installer (using Wise, hacking msi script), and have discovered some frightening things about how easy it is to do silent, invasive things during an install that Windows really shouldn't allow you to do.
1. Change the value of windows system registry values:
If you try to do this explicitly as a regular user (or without elevated privs on Vista), Windows will politely tell you that you can't. But if you execute the following MSI script during an installation (running the installation as a regular user), msiexec gets elevated priviledges, and can do whatever you want. Here's an example silently disabling UAC during an installation by launching regedit from cmd. (This is run in Wise via 'Execute Program from Destination', Working directory: SystemFolder):
"[SystemFolder]\cmd.exe" /c "[SystemFolder]\reg.exe" ADD HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v EnableLUA /t REG_DWORD /d 0 /f
2. Run a low-level system tool:
Similar idea, you can basically run anything you want from cmd. This example gives everyone full access rights recursively to a directory, not necessarily one that you own or have permissions to change. As long as it's run within msi, Windows lets you do it:
"[SystemFolder]\cmd.exe" /c echo y| "[SystemFolder]\cacls.exe" "[ProgramFiles]\DirectoryYouWantToMessWith" /T /G everyone:F
Yikes. I'm going to programmer hell for exploiting things like this as quick workarounds. The moral of this story is: be very careful about the random executables and installers you download from the internet. There's nothing preventing malicious users from using techniques like this to do arbitrary bad things to your computer.
1. Change the value of windows system registry values:
If you try to do this explicitly as a regular user (or without elevated privs on Vista), Windows will politely tell you that you can't. But if you execute the following MSI script during an installation (running the installation as a regular user), msiexec gets elevated priviledges, and can do whatever you want. Here's an example silently disabling UAC during an installation by launching regedit from cmd. (This is run in Wise via 'Execute Program from Destination', Working directory: SystemFolder):
"[SystemFolder]\cmd.exe" /c "[SystemFolder]\reg.exe" ADD HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v EnableLUA /t REG_DWORD /d 0 /f
2. Run a low-level system tool:
Similar idea, you can basically run anything you want from cmd. This example gives everyone full access rights recursively to a directory, not necessarily one that you own or have permissions to change. As long as it's run within msi, Windows lets you do it:
"[SystemFolder]\cmd.exe" /c echo y| "[SystemFolder]\cacls.exe" "[ProgramFiles]\DirectoryYouWantToMessWith" /T /G everyone:F
Yikes. I'm going to programmer hell for exploiting things like this as quick workarounds. The moral of this story is: be very careful about the random executables and installers you download from the internet. There's nothing preventing malicious users from using techniques like this to do arbitrary bad things to your computer.
Wednesday, December 12, 2007
Pennsylvania: still the land of pie
Wednesday, December 5, 2007
Sunday, December 2, 2007
The Karl Denson Trio
Sacramento is not a hip place. It's a nice place- it has big trees, fancy houses, wide streets. The Governator keeps it safe and clean. But it's not generally the place to find cool new music. So I was pleasantly surprised last Wednesday when I went to see The Karl Denson Trio at Harlow's in Sacramento. It's been a long time since I've seen good jazz live.
The trio was made up of a drummer, sax/flute player, and keyboard player. They produced a huge sound for only three people. The keyboard player played two keyboards at once: he played the bass melodies on a Nord with his left hand, and funky gospel-y organ with his right. The driving melodies and harmonies were super tight, and the sax player and keyboard player had perfected a mysterious system for building up melodies while improvising over the course of the song. Sometimes the sax player would play the flute, and I've never seen flute played in such a bad-ass way. He literally had to wipe his face with a towel in between flute solos. Jason (the bass player in our band) said that he hoped one day to achieve the musical level of the keyboard player's left hand.
The Karl Denson trio had the whole crowd dancing on the floor. And these were mostly middle aged white guys in their "going out" tech teeshirts.
I think my favorite song was Lunar Orbit (it had a killer face-mopping flute solo), which is also the title track of their new album.
The trio was made up of a drummer, sax/flute player, and keyboard player. They produced a huge sound for only three people. The keyboard player played two keyboards at once: he played the bass melodies on a Nord with his left hand, and funky gospel-y organ with his right. The driving melodies and harmonies were super tight, and the sax player and keyboard player had perfected a mysterious system for building up melodies while improvising over the course of the song. Sometimes the sax player would play the flute, and I've never seen flute played in such a bad-ass way. He literally had to wipe his face with a towel in between flute solos. Jason (the bass player in our band) said that he hoped one day to achieve the musical level of the keyboard player's left hand.
The Karl Denson trio had the whole crowd dancing on the floor. And these were mostly middle aged white guys in their "going out" tech teeshirts.
I think my favorite song was Lunar Orbit (it had a killer face-mopping flute solo), which is also the title track of their new album.
Grant got the memo
How many engineers does it take to arrange a group photo? All of them. First everyone suggests all possible ideas for lighting, arrangement of people, location. Then everyone argues about the order in which to try all specified permutations, then the camera is accidentally set on 'auto' and takes 40 pictures of everyone arguing. 45 minutes later we had 100 photos of the team, the probability of having taken a good photo finally approaching 1.
Subscribe to:
Posts (Atom)