Showing posts with label Half-baked Idea. Show all posts
Showing posts with label Half-baked Idea. Show all posts

Monday, 30 September 2013

Physical Books are the best technology for reading, and bookstores should 'give' an eBook with every physical book published

I just bought 5 books at a really nice book store in central London and it is amazing how:
  1. these bookstores are still afraid of the digital world 
  2. don't have the confidence to say: 
      "... If you buy a physical copy, we will give you (or sell for 10%) the eBook version. 

       ... the reason we 'give' you the eBook, is because the 'real' book is much better, but there are places were you might want to use the eBook.."
This is something that I already talked about it in my Why doesn't Waterstones (UK BookStore) also upsell kindle books? post (which has more ideas on what bookstores should do to provide a better service to readers).

Wednesday, 25 September 2013

Should developers code naked once a week? (or in a mankini?)

That way developers (or managers) would have more 'empathy' with the 'naked' state of the applications they are developing and publishing :)

I got this idea, following from this comment/suggestion on Guidelines of OWASP:

Wednesday, 31 July 2013

Email (outlook.com, gmail) should be stored on a git repository, with hashes used to detect account hijack

On the topic of being secure (and minimising account compromise) while using hostile networks (see Day 1 - made it to Vegas, start of ASP.NET MVC research  and Trying to keep secure while at BlackHat and DefCon 2013) I started using outlook.com, and was wondering how can I detect if that account is hijacked (for example by somebody who has a root SSL cert and is sitting on the same wireless network that I'm in (currently at Starbucks using the Mirage WIFI))

So what happens if somebody sends an email from this account:



How could I detect it?

Monday, 10 June 2013

'Open Library' for my RaspberryPi, Arduino, BeagleBone, Pyhton, CodeClub books and materials on the Chiswick High Road

Yesterday I 'dropped' 10 Python books to a friend's kid house with a 'take a look at these books and pick one that make sense to you' workflow (they are trying to use a RaspeberryPI and learn how to code in Python)

Later that day one of the kids asked me '... can we keep two?..' , which is always a good sign :)

This got me thinking that that some of my books (I have lot of them) deserve to be shared with more kids :)

Maybe I could have them 'somewhere' on the local Chiswick High Road (West London) as a kind of 'Public Geek Library' for kids (and adults).

This could also be a great location to put information about CodeClub and examples of what I'm creating with the kids that I am teaching every Wednesday.

Sunday, 28 April 2013

The RaspberryPi index (similar to the Big Mac Index)

The other day I was thinking about the loss of local industry that has happened in Europe (and lots of other countries) and I realised that what we need is the RaspberryPI Index which would work in a similar way to the Big Mac Index

The RaspberryPI Index  would be the "cost of producing a RaspberryPI compatible device in a particular country or region".

This would be a great measure of how much technological industry would exist in a particular country (and help to find the gaps in the market/production-chain).

Saturday, 16 March 2013

Feature request: Tweet backups to Git/GitHub

Here is a feature that would help to make the most of the amazing knowledge that is daily shared on twitter.

The idea is to have tweet data stored in a git repository which would contain:
  • Tweets (all available info for each tweet, which is a LOT more than what is currently exposed on the multiple tweet client apps)
  • Followers
  • Following
  • Connects (when others reference the account)
Ideally there should be a commit for each item , but a daily commit should also work.

Thursday, 3 January 2013

I think the time as come for OWASP to have its own secure browser(s)

The idea is to create a customised version of a popular browser (like Chrome or Firefox) that has been customised to be secure out-of-the-box.

It could even be something like http://www.srware.net/ but I want to leverage the trust-network that OWASP has (and its potential to peer-review) to create a piece of software that I actually trust (or that it can earn my trust with time)

Friday, 14 December 2012

CI is the Key for Application Security SDL integration

The more time I spent with CI (namely with TeamCity) the more my instinct is saying ‘this is how we should be delivering and automating security knowledge!'.

Monday, 10 December 2012

Windows Azure is what IIS 7.5 should be

The more I look at Windows Azure (while dealing with IIS deployment automation issues in TeamMentor) the more I fell that Windows Azure is what IIS 7.5 (or 8) should be.

What is really good about Windows Azure is its deployment and versioning capabilities (you can even deploy via git pushes these days). And apart from the webserver bit, most of IIS' Gui is focused on website deployment (which is what Azure does really well).

Monday, 29 October 2012

Handling code samples on translation of technical content


Here an interesting problem, how to deal with code-samples when doing translations?

We are in the process of translating TeamMentor into a couple languages and the issue come up on how to identify the Code Samples for the translators (which at the moment should all be wrapped using <pre> tags (since that is how the Javascript-based-code-formatting works)).

Here is my first raw idea:
  1. create a fork (of the target library) for a particular translation
  2. run a script on all articles that remotes ALL code samples and replaces it with a unique ID (the extracted code snipptets would be stored separately)
  3. the translators work on the articles (which now have no code samples)
  4. the translators commit their change into their fork (we can help them if they want)
  5. we re-apply the code samples
What I like about this idea is: 

1) we remove 'areas for translators to make mistakes' (i.e. there are no code samples in their content)
2) we are able to visualize all code samples in one place
3) we can make a pontual decision on the cases where it makes sense to do some translation on the code samples (cases where there is a lot important code comments)

Since the translation house(s) have its own tools (and parsers), the final solution is probably going to be a mix of this idea and what they already do with their technology (no need to solve problems that already have solutions :)  )

Any good solutions out there that work well for Html content with code samples?

Sunday, 28 October 2012

SecDDev - Security Driven Development

I was thinking today about the areas where security (and secure development) can add value to the SDL and hit on the concept of Security-Driven-Development (SecDDev)

SecDDev is security coding activities driven by security focused developers (which is much more productive than the current security as TAX model we have today)

The way I got into this idea was that I was thinking about one of the TeamMentor (TM) refactorings that I would like to see happening, namely the need to create a 'read-only' version of TeamMentor for sites like TeamMentor.net

This would be a version of TM that has no ability to change the Libraries and Article's content, which is a great way to achieve security, since it is harder to exploit a feature when the code is not there :)

What is interesting on this scenario ('Read-Only TM') is that the business requirement ('have a rock-solid version of TM hosted in TeamMentor.net that can be sold to customers') doesn't NEED this isolation! It possible (and easier) to deploy a version that has the full (very powerful) TM editing capabilities and hope that those features are not exploited, or that none of the editors and admin users delete anything (see missing iOS Library incident). This lack of business requirement,  means that unless there is an additional driver to create this 'read-only' version, it won't happen (which explains why we end-up with the bloated 'security-vulns-rich' applications we have today).

Now there is a good business case for 'application isolation and robustness' but those tend to be fuzzy concepts which are hard to measure. For example, in this kind of activities, there is a massive lack of external recognisable metrics, where the site looks and behaves the same before and after the refactoring (until it is able to sustain an exploit/mistake or massive traffic spike). In fact these changes tend to introduce massive side effects (see 'About' page broken due to ClickJacking protection)

And this is where the idea of SecDDev occurred to me where I was thinking 'if only I had a security focused development guy/team that would help me in doing this refactoring'.

Since that person (the Security-Driven-Developer) would have has as part of his job spec the "improvement of TM's security" (where that is just one of the (many) roles and responsibilities that I have in TM's SDL) he/she would be much more focused into making it happen.

Creating a read-only version of TM, which in practice means the isolation of the read-code and the edit-code into separate sites/areas which can be easily removed, is a good example of an important-but-not-urgent activity that would make a massive difference in TM's overal security architecture.

To complicate matter worse, it is hard to make this type of code changes. Even after all my efforts to develop TM in a modular architecture, the technologies and frameworks used (Html, Javascript, jquery, .Net) promote/reward tight integration and inter-dependencies (for example it would be 'security by obscurity' to remove the edit-code from the front-end, but leave it all on the webservices back-end).

This is why when you look at most apps, the code is always in 'development activities blocks' instead of 'security focused blocks'

Another area that SecDDev would have to focus a lot is on UnitTests, since they would struggle to make/propose any meaningful change without the support and cushion of a solid Unit/Integration test suite.  And anybody that gives me a working UnitTest for TM, is somebody that is adding value to me as a developer! (in fact, SI will even pay for those Unit Test :) )

Another interesting 'political' problem happens when the product managers/owners have a lot of power and want to 'lock-in the customer' into a product's technology. For example, a real secure way to create a 'read-only' version of TeamMentor, would be to remove 99% of its code (on both client and server sides) and built a flat-file version (i.e. pure HTML) protected by a simple OAuth-based authentication/authorisation layer (which could even be done as an external service). But this would mean that the 'TeamMentor' product would 'disappear' and all that would be left would be the Content. The good news (for TeamMentor) is that since SI's center of gravity is on the 'Content + Services side' there are no problems in following what is the best engineering route, but when you look at why some applications/websites are so bloated (and don't like to allow the exporting of its data), you will usually find that it happens due to political/strategic decisions instead of engineering ones)

Finally, where are we going to get those SecDDevs from? Well Mark has a good idea for that, see: Let's make this happen: "Investing in Developing Software Security Talent"

Monday, 8 October 2012

Creating an TeamMentor Security Bounty Program

Following the unofficial success of the Test and Hack TeamMentor server with 3.2 RC5 code and SI library request (with already a couple vulnerabilities disclosed), I'm very happy to say that SI is going to make it official.

We will be creating an TeamMentor Security Bounty Program for this week, which is when we are doing a Security Push for TeamMentor (before it is released officially next week).

There still needs to be a bit of thinking on this, with the rules-of-engagement defined, but here is the thinking so far:

Idea: Sync Blogger Posts with a GitHub repository

From the end of the So if my blog account is compromised can I sue Google? post comes an interesting WebService idea:

Sync Blogger posts with a GitHub repository 

Idea: dynamically fetching content from GitHub to show as website

I was thinking of a way to create a very simple way to package and consume an TeamMentor website, and NuGet come to mind (note that you can already consume TM's engine from NuGet via the TeamMentor.CoreLib package, which is the compilation of this VS project)

The problem is that on the WebSite layer (see code here) there are lots of files in there (namely the Html, Image, CSS and JS files) which we need to use.

Now we could create a NuGet package with these files, but that would still mean that the VS project would still have ALL of those files in there.

What I really want is to have access to all those files without actually seeing them (i.e only the custom changes should exist in the VS project file).

At the moment I can see two (kinda crazy ways) to do this:

  1. Package all files into a dll's resources section (like I did with O2's dll dependencies) - using an extra HttpHandler that  would try to match an HttpRequest to an file available (and serve it)
  2. Use the HttpHandler described above to get the files directly from GitHub  (i.e. http request to GitGub to the the files)
The 2nd option would be really cool, but quite a crazy one :)

You basically would have an AppHarbor hosted website whose content where being dynamically fetched (server-side) from GitHub :)

Now if only Asp.NET supported the packing of websites as a one file package

Sunday, 7 October 2012

Idea for improving blog creation productivity (post by screenshot)

Here is an idea for how to improve the quality and creation-speed the technical articles that I write regularly.

I have quite a lot of information to share and publish, and making that process as smooth and simple as possible is very important, since not only will that allow for better articles to be published, it will also increase their quantity.

My requirements are: Write Text with Images and Source code embed in them

Ironically none of the two Blogging engines (Wordpress and Blogger) that I currently use give me an easy environment to do that.

I use Wordpress for the https://o2platform.wordpress.com blog and 159 articles later (with tons and tons of source-code examples) I have given up using it (which is why you will noticed that my recent O2 technical posts where written on this blog). The three key problems I had with Wordpress where:

  • massive bloat of their interface,
  • hard to upload images, 
  • spending tons of time (after writing the article) fixing its html formating.


I use Blogger for this blog and 405 posts later I also had enough with its:

  • html formatting,
  • image Upload workflow, 
  • no support for Code Samples/Formatting, 
  • convoluted preview mode (which also affects the stats), 
  • no support for Markdown/WikiText , 
  • lack of proper/consistent support for HTTPS/SSL , 
  • poor mapping/exposure of related content (all we have at the moment are 'Labels') , 
  • not very nice Design. I'm still using the 'Simple' mode since I really didn't liked the 'Dynamic Views' they added recently (and by the number of Blogger blogs that don't use 'Dynamic Views', I guess I'm not the only one)

Now for Blogger's credit, I do prefer its GUI (which I'm using now) and for text-only blog posts it's good.

My key problem with images and code samples is that its creation needs to be instant (namely from copy and paste). When telling a story I like to use images and code samples intermixed with text, since they not provide powerful visual clues on that is happening, they also shorten the amount of text that needs to be written.

The problem with HTML formatting, which is something that I also had to deal with TeamMentor, is that HTML is a horrible way to store visual metadata. There are so many variations and ways to format the code, that HTML editors have an impossible job in trying to make sense of it (and add to that the XSS vectors).

Bottom Line:  if Google/Blogger, Wordpress, a bunch of WYSIWYG web editors, can't get it right, ,my instinct is pointing me to the conclusion that there is NO SOLUTION. 

Which means that the solution is NOT to improve HTML parsing, but to replace it with something better, like for example WikiText or MarkDown.

These days I'm a massive fan of this idea. I added WikiText support to TeamMentor as a experiment (and non-documented feature), and it just took off. WikiText is now the preferred way to create content (all new articles in the new 3.2 release where written using it) AND on the next version of TeamMentor we are going to move ALL our content into (most likely ) Markdown.

To wrap up the description of the problem, although I could move to a complete new blogging/publishing platform (and I have looked at what is available), what is currently out there doesn't give me a clean solution for my needs, which is to 'Write Text with Images and Source code embed in them'.

I'm also a bit stuck with Blogger because:

  • I already have a decent number of readers (not a lot, but significant)
  • It has a nice 'Create post from email' which I tend to use (and saves time to re-post emails I write)
  • I like its stats (and I have good historical data)
  • It has a number of features to allow blog consumption (RSS, subscribe by email, post to twitter)
  • It has a decent search (both on blog and on admin panel)
  • It supports plain pages (like the ones linked from the top menu)
  • Adding YouTube videos to pages is quite easy
  • It supports direct HTML manipulation (i.e. XSS by design) which allows me to embed GISTs, PDF viewers and YouTube videos
  • Decent amount of 'Google Search Driven' traffic
  • The 'Latest blog post(s)' email that is sent out (for the email subscribers) is quite nice, effective and includes the posted images (but not the embedded gists)


So what is a solution?

Here is my current half-baked idea:

  • Use a TeamMentor 3.2 based website to write the posts (since I will have Markdown, code and image support there)
  • Either: 
    • option A:) Repost the article's HTML as a blog post
    • option B) Repost the article as an screenshot (of the original article)

Option B is quite interesting since it would (if it works) give me the best of both words:

  • A place to write articles that is fast while keeping the post content in a consumable format (namely the code samples)
  • An easy to consume and distribute blog post (which would be basically a repost blog entry with: a title, link and image)
  • The content created stored in Git (since that is what TeamMentor uses)
Since O2 and TeamMentor already have the technology required to do it, the next steps are to write the O2 scripts required to make this happen :)