Pages

Wednesday, January 12

H.264 is being dropped from Chrome

Chromium Blog: HTML Video Codec Support in Chrome.

Key sentence from above article:

"Though H.264 plays an important role in video, as our goal is to enable open innovation, support for the codec will be removed and our resources directed towards completely open codec technologies."

Key comment from Slashdot on above article:

"This serves two strategic purposes for Google. First, it advances a codec that’s de facto controlled by Google at the expense of a codec that is a legitimate open standard controlled by a multi-vendor governance process managed by reputable international standards bodies. (“Open source” != “open standard”.) And second, it will slow the transition to HTML5 and away from Flash by creating more confusion about which codec to use for HTML5 video, which benefits Google by hurting Apple (since Apple doesn’t want to support Flash), but also sucks for users."

Google, just when I started to like you again.  I turned away from you for about a year and a half because you pissed me off with the Buzz thing.  Now you go and do this.

One step forward, two steps back.

Tuesday, January 11

iPhone 4 goes to Verizon too.

Finally, after long last, the iPhone is coming to Verizon.

I probably could go on Ad nausem about the new iPhone, but I'll just cover the bullet points

  • The antenna is redesigned, and as a result the buttons are moved slightly down on the left, so some cases may not fit.

  • CDMA, not LTE.  Which means you can't talk and surf at the same time. (Feature that I use a lot)

  • You can use the iPhone as a wifi hotspot (so like a mifi) for up to 5 devices.  Nice.

  • Coming February 10th for GA.  Advanced ordering for Verizon Customers on Feb 3.

  • Otherwise, it's the iPhone 4.


This will be nice.

Seven Cool Open Source Projects for Defenders

TaoSecurity: Seven Cool Open Source Projects for Defenders.

Richard Bejtlich wrote this good post over on his blog, a few good OpenSource tools to defend your networks with.  He talks about the newest updates with:

  • Rumainte IDS

  • Security Onion

  • Bro IDS

  • Suricata IDS

  • Snorby

  • OpenFPC

  • Polman

  • Snort

  • ClamAV

  • Razorback


Richard does pay me a kind compliment, so thank you Richard.  Take a look at his post and try some of the tools out.

Tuesday, January 4

A Year in Reflection

I am reading all these posts on reflection on 2010 and accomplishments for this year.

Yes, I accomplished a lot for this year.  Lots and Lots of work stuff.  But I accomplished one thing that eclipses all else.

I have a beautiful family with an awesome wife and two beautiful kids.

Happy New Year everyone.  Well wishes for 2011.

Tuesday, December 21

Macworlds 2010 App Gems Awards

Macworlds 2010 App Gems Awards | Mobile | Macworld.

p.p1 {margin: 0.0px 0.0px 12.0px 0.0px; font: 12.0px 'Lucida Grande'}

Macworld’s list of the best iOS apps from 2010.  Some really nice stuff here, good to see that I have most of them and use them quite often.


If you are an iOS user, check it out.

Tuesday, December 14

Whew, what a whirlwind

Talk about a busy end of the year, so on top of going my actual consulting gigs for customers, I am also doing the other full time job I have of the Snort Community Manager. If you read my blog, you've known this.

So, what have I worked on so far.

  • Snort Twitter account. Not really a lot of work here, other than getting Twitter to remove it from the parker's clutches and give it to us.

  • Snort Blog. Getting this set up, with the DNS entries, blog posts, editing, writing, design, and even the banner image (thanks CC for that!) was about 3 weeks worth of work.  Check it out http://blog.snort.org

  • Snort Mailing list/Forum Consolidation. I thought it best to let the Community decide, so I made a non-scientific poll to choose between the forums, the mailing lists, or the penultimate solution, to merge the two. Thought of Google Groups for this. Google Groups allows you to post like a forum, and post like a mailing lists, and Google Groups takes care of the arrangement, merging, and threading. Very nice. I had this all set up, and was preparing for everyone to start making the move over to Google Groups, and we came up with another idea. So we're working that angle right now (stay tuned).

  • Snort Subscriptions. Been doing a bit of backend work on Snort subscriptions, trying to figure out how to work this out to be a more streamlined process and eliminate a lot of the headache and purchasing obstacles for our users. Concept work mostly.  Also talking about VRT Subscriptions with various members of the legal team and VRT.

  • ClamAV subscriptions. Working on what we are doing and going to do for certified ClamAV code.

  • Code licensing. Meetings with our legal team!

  • Writing articles for magazines and getting ready for speaking engagements in 2011. Pretty much what it says.

  • Laying the groundwork for webcasts and Snort User Group Meetings. Going to fire these up in 2011 again. Several Snort User Group meetings are wanting to start back up. Great to see that there is a lot of interest for our community.

  • Bug filing and progress. What I've started doing is, if bug reports come in via various methods of bug reports, I take them in, triage them, put them into bugzilla, and provide feedback to the people that filed the bugs. This seems to be working quite well right now.

  • Working with our Web-team on any Snort.org issues. Pretty much what it sounds like.

  • Fixing Snort.org. For instance, I rearranged the http://www.snort.org/docs link. To bring the content that people are looking for the most to the front page. Also it was brought to my attention that we had a bunch of W3C html coding errors. I went through and fixed about 40+ of these.  Along with about 100 other barely seen or noticed changes to Snort.org in order to bring the good content to the front, and the content that is barely used to the back (or done away with).

  • Internal VRT Subscriptions. It was brought to my attention that several people that work at Sourcefire apparently didn't have access to the VRT rules (like they should have).  Had to fix that!


Had an email that today that asked me about all these new "news" dissemination  methods that we are standing up and is it going to create confusion.  That's probably a blog post left for the Snort.org blog.

Wednesday, December 8

Snort has a Twitter account

Another post for my Snort/IDS audience that read my blog.

We managed to get a hold of the "Snort" account on Twitter.  Someone was simply squatting on the name, not using it, so Twitter has a way of petitioning to get a hold of a name for a bunch of different reasons.  So we got with Twitter and they freed up the @Snort Twitter name for us.

Using the @Snort Twitter account we'll post new news, upcoming items, blog posts, news about Snort and interesting other tidbits that may or may not be found anywhere else on Snort.org

Check it out, follow us:  http://twitter.com/Snort.  Thanks!

Wednesday, December 1

Snort 2.9.0.2 Released!

To let my Snort audience know, if you don't know already by the mailing list, we just released Snort v2.9.0.2, a bug fix release.  Enjoy!

Snort :: Snort 2.9.0.2 Released!.

Tuesday, November 30

Sorry for the lack of posts, I've been particularly busy.

Been pretty busy lately with my two full-time day jobs at Sourcefire.  The good news is, if you are a Snort user, that I am working on a lot of things that will not only make our community better, but improve how Sourcefire interacts with that community and allow us to move forward in a more progressive manner.

Aside from Sourcefire/Snort stuff, the shop that is restoring my Mustang is almost done (should get it back this week, and when I do, I'll post pics), I'm working on the shops website too (as the old one needed some TLC).  I got with the owner and we decided to redo the whole thing, so I am doing that in my spare time as well.

Thank you Squarespace!

Also working on another website that I tighten up a bit (aside from tightening up Snort.org a bit as well) for another company (Car alarm company) that I do a bit of consulting/marketing for.  So, it feels like I am buried in html lately.

On top of all of that, my son is doing well, my daughter is awesome and my wife's Grandmother died this past week, so we are all dealing with that as well.

Busy Busy Busy.  Stay tuned.  I've got a few posts lined up for the pipeline for not only this blog but for another blog I am starting, so when that all comes together, stay tuned!

Sunday, November 28

Tuesday, November 23

"So I have this IDS now what?" presentation at BSidesDE

Joel Esler, so I have this IDS now what BSidesDE1 on USTREAM. Conference.

Above is a link to my presentation from BSidesDelaware a couple weeks ago.  For some reason the audio and video are like 5 minutes off, but the presentation (for the most part) is intact.

Monday, November 22

Monday, November 15

New Role at Sourcefire

This is just an announcement to let the users of our OpenSource products know that we have a new community manager here at Sourcefire.

Over the past year or so, Mike Guiterman, our former Community Manager has taken on a different role within Sourcefire.  In the meantime, I've been filling some of the void.

For those of you that weren't able to make the Snort Rally/Pig Roast this past Friday at Sourcefire HQ, I have been officially assigned the role of Sourcefire's OpenSource Community Manager.

I know many of you, but for those who I don't, I came from the OpenSource community, working for the government using Snort in actual deployments.  I submit rules to VRT, and was one of the original submitters to BleedingSnort (Now Emerging Threats).  I've worked with both the OpenSource community and with our Corporate customers since I came to Sourcefire giving me first hand knowledge at how the community plays a vital role in the direction, development, and QA of our products.

I'll be focusing on product innovation in our OpenSource projects, as well as:

  • Communicating with the communities.

  • Being available to answer questions and receive comments.

  • Coordinating the release of OpenSource project software.

  • Providing whitepapers and instructional materials on our software.

  • Providing the go-between for the OpenSource communities and Sourcefire software developers, including receiving OSS feature requests and bugs.  Entering these into our internal bug tracking system, and following up with the submitters.

  • Snort-Groups.  Standing these back up, both virtually and in person.

  • Speaking about our software at events and shows.


I have several projects in mind alerady, but the first thing is I want to hear from you.  Suggestions, ideas, complaints, and compliments.

  • How we can make things better.

  • Problems with Snort, ClamAV, DaemonLogger, or Razorback

  • Features you'd like to see with these projects

  • What isn't working now?

  • What is working now!

  • How can we make bug tracking more efficient?

  • How can we make False positive submissions better?

  • What can we put out (in terms of training and whitepapers) for better understanding and results?

  • ???


Let me hear it.  Email me directly at jesler@sourcefire.com.  I want to be able to track your ideas so I can write you back when we make movement.

I'll summarize your submissions in a blog post in the future and let everyone know where we are at with the progress of these great ideas.

I'd like to thank people both internally at Sourcefire and the community for building the community into what it is today, and I look forward to a great future!  Also thanks to Mike Guiterman for his years of hard service working with our OpenSource communities.

For Razorback(tm) please continue to submit feature requests and any
other Razorback items to the Razorback Trac at:

http://sourceforge.net/apps/trac/razorbacktm/

And for Nugget related items please use:

http://sourceforge.net/apps/trac/nuggetfarm/

You can of course, also use the mailing lists for Razorback and the
Nugget Farm.

Tuesday, November 2

Security B-sides Delaware tickets are almost gone!

If you are in the area (or even if you aren't, I know of people traveling a pretty good distance to get here) and you haven't got your ticket for Bsides DE yet, you may want to get on it.

The first round of tickets are all gone, and there are only 40 left of the extension tickets.

<plug>

I'm speaking at 1:00, right after lunch.  See the speaker's schedule here.  But anyway, if you haven't got your tickets yet, you might want to hurry up and grab them from here.  Cost?  Free.

Archiving Emails in Mail.app, there's an app for that.

If you are using Mail.app on OSX, this post is for you.

It's been well known to people that read my blog that I am an Inbox-Zero ninja, and generally pride myself on my ability to get through vast amounts of email quickly because of the system that I have refined over the past several years of experimenting.

Techniques in Archiving


One of the things about Inbox Zero is the ability to quickly move an email out of your "Inbox" and into another folder.  If you sort your emails that come into your Inbox by topic or subject or whatever, different folders may do good things for you.  For instance I have a folder where all Snort related email goes.  The three Snort mailing lists go straight to my inbox where I read most of them and then file them away using a keyboard shortcut.  Other Snort related mailing lists just go straight to this box, leaving me with only the important ones in my inbox.

Most listserver traffic of the 40 or so listservers that I belong to go straight to a "listserver" folder, where I can deal with it later.  You get my point.

But everything that I don't filter, is in my inbox, which usually nets me about 200~ emails a day that I need to deal with.  When I read an email I have possible outcomes.

  • Delete it

  • Archive it (if I need it later)

  • Respond to it (if it takes shorter than 2 minutes to accomplish this task)

  • Delegate it (if I am not the appropriate person to deal with "x" email)

  • Make a todo to deal with it later.


Delete it


Duh.  I don't do enough of this.

Archive it.


This is the meat of the post, and kind of the point of writing this article.  I am a firm believer in leaving your hands on the keyboard if possible.  Learning the keyboard shortcuts in your favorite app will not only save time, but it also keeps your hands where you need to be doing work.  On the keyboard (instead of continually reaching for your mouse).  There are keyboard shortcuts for almost anything in OSX, and if you can't find it, or the menu command doesn't have a keyboard shortcut, you can make a keyboard shortcut to do what you want in Snow Leopard.  Heck, there are keyboard shortcuts in Gmail (learn em!)

Now, how do you do this in Mail.app, well there is a little app called "Archive" that will allow you to do this.

Archive.  Archive allows you to do exactly that.  Archive the email that you are presently on.  It creates a folder in your email accounts named "Archive", and when you mash the shortcut in your inbox, it puts the email that you have lighted in the appropriate Archive folder.  Simple, clean, done.

There is also Mail Act-On, which I've talked about before here, is a nice little app if you need to do more advanced things than Archive, but for 99% of you, check out Archive, it does what you need.

Respond to it


If I think it'll take less than 2 minutes to respond to the email that I am currently reading, I'll bang out a response.  I try to not bang out a "quick" response "just to keep the ball moving" as Kevin Rose says.  I try to write out a through response.  My point in doing this is to eliminate further email by providing any answers I can, by asking the appropriate question so that the response to my email is full of exactly what I need it to be, and so that people don't waste more time by me not wasting theirs with a "short terse banged-out email".

Delegate It.


Otherwise known as the "Forward" button.  I get a ton of email, not all appropriate for me to handle, some need to go to our web team, some need to go to our research team, but it comes to me, because I "handle" the email, as opposed to ignore it.  I don't mind being the conduit to which people communicate, at least I know things are getting done, and I have a pulse on what is going on.

Todo It.


If the email contains an action that I need to perform, but I can't do it right now, I have a keyboard shortcut that allows me to highlight a section of text, mash a keyboard shortcut, and Omnifocus will grab the hightlight-ed input that I selected and makes a Todo out of it, along with a link in Omnifocus back to the email that generated it.  (This is called "Clipping" for you Omnifocus nerds, get ON IT.)  I quickly set a context (email) and a due date.  Then I go onto the next email.  Everyday, I get to the bottom of the "Todo"s that are due that day, and that includes the thoughtful emails.

Matter of fact, writing this post about "Archive" was a Todo.

Let me go mark it done.

BTW -- Inbox Zero comes from Merlin Mann.  I'm not stealing his work.  It's insightful.  He rocks.  MerlinMann.com and InboxZero.com

Tuesday, October 26

Snort Community Pig Roast

(If you read this on Twitter, please RT!)

Sourcefire is going to throw a community pig roast at our World Wide Headquarters on November 12, 2010.  We'll have some talks by Marty Roesch (our fearless leader) and Matt Watchinski (or VRT fearless leader).

Date: Friday, November 12, 2010
Time: 12:00PM


Where: Sourcefire HQ
9770 Patuxent Woods Dr.
Columbia, MD 21046


The event is open to our community, and we'd like you to come on over and hang out!

Please RSVP at: http://now.sourcefire.com/?elqPURLPage=2?elqformname=101112_snort_bbq&URL=

Notes syncing between Mail.app and iPhone, finally

I've written several times over the years about the need for Notes to sync automatically between the iPhone and the Mac Mail.app Desktop application.  Well, unbeknownst to me (because I stopped using Notes in Mail.app because of the lack of this feature), in iOS 4.0 Apple has built this in.

I didn't test it right away when the release came out, and just now that I haven't written about it either since they built this in.  But it works.

If you have an IMAP account, you can go into your account settings on your iPhone and turn on "Notes" in that account's preferences.  Mail will create a folder called "Notes" on the IMAP server, and your "Notes" on Mail.app will be sync'ed Over-the-Air with your iPhone.

I have my Mail.app set up like this:



So that all my notes and to-do's stay intact in one account, and not spread apart different accounts.  But there is more than one advantage to MobileMe for this particular feature.  If you set it to MobileMe, Notes are pushed.  (As opposed to pull, as they would be with other IMAP accounts.)

In short, Apple enabled Notes syncing in iOS 4.0.  It works.  Give it a shot.

Facetime

Facetime, Apple’s new iPhone 4 to iPhone 4 video chat application got a bit of an update on Tuesday of this week.

Jobs said it himself, the biggest thing that people wanted when facetime was shown on the iPhone for the first time was the integration of the system into the Mac desktop.  I talked about this back on this original post when the iPhone 4 came out.  Finally, at Tuesday’s speech Jobs and Apple rolled out the Facetime client for the desktop.

It works.

You can call Mac to Mac using Facetime, you can also call Mac to iPhone or iPhone to Mac, likewise with the iPod Touch. The resolution is good (it’s scaled down a bit if you are used to iChat’s resolution), audio is excellent, and it works flawlessly. In fact, when it came out, I was on a hotel network. I tried to initiate an iChat connection to my Dad, and we couldn’t do it for lack of bandwidth, however, Facetime connected right away without a problem.

The only thing that I thought was a bit strange, and I know I'm not the only one, was that Apple released it as a separate application for the Mac.

However, after I thought about it for a bit, I came back to my original conclusion that this is a temporary step. The application is simple and easy to write, so that’s what Apple did. I imagine in order to build the feature into iChat, they'd have to rewrite the whole application, and while they didn’t at all indicate that this was going to happen in 10.7 Lion (which they also started talking about on Tuesday), it makes a lot of sense to have it built into the OS.

One of the other things that i noticed about facetime is that it doesn’t really give you any kind of “presence” notification. For instance, it would make sense that since Apple knows you are connected to the internet via $device, they would be able to provide some type of presence notification along with it, I assume this is going to come with 10.7 too.