<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Kindloaf's Blog</title>
	<atom:link href="http://kindloaf.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://kindloaf.wordpress.com</link>
	<description>Just another WordPress.com weblog</description>
	<lastBuildDate>Sun, 14 Dec 2008 17:39:38 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<cloud domain='kindloaf.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://www.gravatar.com/blavatar/464a1a25ccf04c68a00d44c9cfd8d245?s=96&#038;d=http://s.wordpress.com/i/buttonw-com.png</url>
		<title>Kindloaf's Blog</title>
		<link>http://kindloaf.wordpress.com</link>
	</image>
			<item>
		<title>[article note] beating the average</title>
		<link>http://kindloaf.wordpress.com/2008/12/14/article-note-beeting-the-average/</link>
		<comments>http://kindloaf.wordpress.com/2008/12/14/article-note-beeting-the-average/#comments</comments>
		<pubDate>Sun, 14 Dec 2008 17:31:41 +0000</pubDate>
		<dc:creator>kindloaf</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[computer science]]></category>
		<category><![CDATA[programming]]></category>
		<category><![CDATA[technology]]></category>

		<guid isPermaLink="false">http://kindloaf.wordpress.com/?p=15</guid>
		<description><![CDATA[I just finished reading the article &#8220;Beating the Average&#8221; by Paul Graham.  The author argues that LISP is the most powerful languages.  He explains how that helps his startup company Viaweb to beat their competitors.  In the author&#8217;s view, program languages fall in an abstractness continuum and vary in power.  A higher-level language programmer, if [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=kindloaf.wordpress.com&blog=5329993&post=15&subd=kindloaf&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>I just finished reading the article &#8220;<a href="http://www.paulgraham.com/avg.html">Beating the Average</a>&#8221; by Paul Graham.  The author argues that LISP is the most powerful languages.  He explains how that helps his startup company Viaweb to beat their competitors.  In the author&#8217;s view, program languages fall in an abstractness continuum and vary in power.  A higher-level language programmer, if look downwards, will find the lower-level language not acceptable.  However, if he looks upwards, he would think the languages are all the same.</p>
<p>The author makes the point that programming language is a habit.  People are used to their favorite language and are reluctant to change.  Therefore a lot of ordinary programmers code in &#8220;median&#8221; languages and never change.</p>
<p>I like the article and the way the points are made. However, I suspect that their technologies are better than the competitors because they are smart people. If they use another language, probably they are still at a better position.</p>
<p>Following are some quotes from the article:</p>
<ul>
<li>Programming languages are not merely technologies, but habits of mind as well, and nothing changes slower.</li>
<li>This idea is rarely followed to its conclusion, though. After a certain age, programmers rarely switch languages voluntarily. Whatever language people happen to be used to, they tend to consider just good enough.</li>
<li>We weren&#8217;t writing this code for our own amusement. We were a tiny startup, programming as hard as we could in order to put technical barriers between us and our competitors.</li>
<li>But I don&#8217;t expect to convince anyone (over 25) to go out and learn Lisp.</li>
<li>Ordinarily technology changes fast. But programming languages are different: programming languages are not just technology, but what programmers think in.  They&#8217;re half technology and half religion.</li>
</ul>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/kindloaf.wordpress.com/15/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/kindloaf.wordpress.com/15/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/kindloaf.wordpress.com/15/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/kindloaf.wordpress.com/15/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/kindloaf.wordpress.com/15/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/kindloaf.wordpress.com/15/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/kindloaf.wordpress.com/15/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/kindloaf.wordpress.com/15/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/kindloaf.wordpress.com/15/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/kindloaf.wordpress.com/15/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=kindloaf.wordpress.com&blog=5329993&post=15&subd=kindloaf&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://kindloaf.wordpress.com/2008/12/14/article-note-beeting-the-average/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8b01b42d2f0f8c681c6ad1333db4d0c4?s=96&#38;d=identicon" medium="image">
			<media:title type="html">kindloaf</media:title>
		</media:content>
	</item>
		<item>
		<title>ISP gone wild</title>
		<link>http://kindloaf.wordpress.com/2008/11/13/isp-gone-wild/</link>
		<comments>http://kindloaf.wordpress.com/2008/11/13/isp-gone-wild/#comments</comments>
		<pubDate>Thu, 13 Nov 2008 04:16:11 +0000</pubDate>
		<dc:creator>kindloaf</dc:creator>
				<category><![CDATA[security]]></category>
		<category><![CDATA[computer]]></category>
		<category><![CDATA[computer science]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[technology]]></category>

		<guid isPermaLink="false">http://kindloaf.wordpress.com/?p=10</guid>
		<description><![CDATA[I just read some news: a &#8220;rogue&#8221; ISP is taken down.
This ISP is McColo.  Looks like it was helping too much spammers, the government and security researchers are so angry that they decide to knock it offline.
In the report there is a chart showing the amount of spam everyday.  One can easily see that when [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=kindloaf.wordpress.com&blog=5329993&post=10&subd=kindloaf&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>I just read some news: <a href="http://arstechnica.com/news.ars/post/20081112-spam-sees-big-nosedive-as-rogue-isp-mccolo-knocked-offline.html">a &#8220;rogue&#8221; ISP is taken down</a>.</p>
<p>This ISP is McColo.  Looks like it was helping too much spammers, the government and security researchers are so angry that they decide to knock it offline.</p>
<p>In the report there is a chart showing the amount of spam everyday.  One can easily see that when the time the ISP was taken down, the amount decreased significantly.</p>
<p>Before I saw this I thought there is not too much incentive for an ISP to help hampering spams.  It requires significant resources and can&#8217;t see immediate return.  Now I see that right things must be done, always.</p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/kindloaf.wordpress.com/10/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/kindloaf.wordpress.com/10/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/kindloaf.wordpress.com/10/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/kindloaf.wordpress.com/10/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/kindloaf.wordpress.com/10/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/kindloaf.wordpress.com/10/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/kindloaf.wordpress.com/10/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/kindloaf.wordpress.com/10/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/kindloaf.wordpress.com/10/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/kindloaf.wordpress.com/10/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=kindloaf.wordpress.com&blog=5329993&post=10&subd=kindloaf&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://kindloaf.wordpress.com/2008/11/13/isp-gone-wild/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8b01b42d2f0f8c681c6ad1333db4d0c4?s=96&#38;d=identicon" medium="image">
			<media:title type="html">kindloaf</media:title>
		</media:content>
	</item>
		<item>
		<title>About Trusting Trust</title>
		<link>http://kindloaf.wordpress.com/2008/11/09/about-trusting-trust/</link>
		<comments>http://kindloaf.wordpress.com/2008/11/09/about-trusting-trust/#comments</comments>
		<pubDate>Sun, 09 Nov 2008 22:01:04 +0000</pubDate>
		<dc:creator>kindloaf</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[computer science]]></category>
		<category><![CDATA[technology]]></category>

		<guid isPermaLink="false">http://kindloaf.wordpress.com/?p=6</guid>
		<description><![CDATA[This paper by David A. Wheeler is quite interesting:
http://www.dwheeler.com/trusting-trust/
It talks a method to counter a possible malicious trojan-horse to be planted in a compiler, which was presented by Ken Thompson in his ACM Turing Award acceptance speech.  This trojan-horse is very special that by examining the source code you find no clue of any malicious [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=kindloaf.wordpress.com&blog=5329993&post=6&subd=kindloaf&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>This paper by David A. Wheeler is quite interesting:</p>
<p><a href="http://www.dwheeler.com/trusting-trust/">http://www.dwheeler.com/trusting-trust/</a></p>
<p>It talks a method to counter a possible malicious trojan-horse to be planted in a compiler, which was presented by Ken Thompson in his ACM Turing Award acceptance speech.  This trojan-horse is very special that by examining the source code you find no clue of any malicious code.</p>
<p>The idea is very cute!</p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/kindloaf.wordpress.com/6/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/kindloaf.wordpress.com/6/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/kindloaf.wordpress.com/6/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/kindloaf.wordpress.com/6/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/kindloaf.wordpress.com/6/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/kindloaf.wordpress.com/6/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/kindloaf.wordpress.com/6/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/kindloaf.wordpress.com/6/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/kindloaf.wordpress.com/6/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/kindloaf.wordpress.com/6/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=kindloaf.wordpress.com&blog=5329993&post=6&subd=kindloaf&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://kindloaf.wordpress.com/2008/11/09/about-trusting-trust/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8b01b42d2f0f8c681c6ad1333db4d0c4?s=96&#38;d=identicon" medium="image">
			<media:title type="html">kindloaf</media:title>
		</media:content>
	</item>
		<item>
		<title>.rhosts Vulnerability &amp; Shatter Attack</title>
		<link>http://kindloaf.wordpress.com/2008/10/28/hello-world/</link>
		<comments>http://kindloaf.wordpress.com/2008/10/28/hello-world/#comments</comments>
		<pubDate>Tue, 28 Oct 2008 19:24:45 +0000</pubDate>
		<dc:creator>kindloaf</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[I read about the famous .rhosts vulnerability from a research paper recently.  The .rhosts vulnerability is due to the interaction between rlogin and ftp.  Some people believed it&#8217;s not a &#8220;bug&#8221;, rather it&#8217;s due to the different assumptions made by rlogin and ftp.
I was shocked by the trust assumptions of rlogin.  It [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=kindloaf.wordpress.com&blog=5329993&post=1&subd=kindloaf&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>I read about the famous .rhosts vulnerability from a research paper recently.  The .rhosts vulnerability is due to the interaction between rlogin and ftp.  Some people believed it&#8217;s not a &#8220;bug&#8221;, rather it&#8217;s due to the different assumptions made by rlogin and ftp.</p>
<p>I was shocked by the trust assumptions of rlogin.  It trusts traffic from an admin port (port number less than 1024) of another host without any authentication.  It shouldn&#8217;t be very surprising though.  The rlogin was designed at a time when functionality is of the paramount concern.  For example, telnet/ftp sends password unencrypted over the network.</p>
<p>As another example of the &#8220;functionality first&#8221; principle, we can have a look at the Shatter Attack.  Similar to the .rhosts vulnerability, Shatter Attacker is due to the lack of authentication of windows message passing system.</p>
<p>The security impacts of the design flaws are serious.  When the systems get popular and the mechanisms mingled with other systems, it&#8217;s difficult to switch.  Operational costs are high since we already have a lot of legacy systems.  That&#8217;s why industry people sometimes prefer a patch to a prevalent flawed design than a secure design built from scratch.</p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/kindloaf.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/kindloaf.wordpress.com/1/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/kindloaf.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/kindloaf.wordpress.com/1/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/kindloaf.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/kindloaf.wordpress.com/1/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/kindloaf.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/kindloaf.wordpress.com/1/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/kindloaf.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/kindloaf.wordpress.com/1/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=kindloaf.wordpress.com&blog=5329993&post=1&subd=kindloaf&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://kindloaf.wordpress.com/2008/10/28/hello-world/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8b01b42d2f0f8c681c6ad1333db4d0c4?s=96&#38;d=identicon" medium="image">
			<media:title type="html">kindloaf</media:title>
		</media:content>
	</item>
	</channel>
</rss>