<?xml version="1.0" encoding="iso-8859-1"?>
<rss version="2.0">
  <channel>
    <title>Erick Rudiak.  Songwriter.  Singer.  Human.</title>
    <link>http://erick.rudiak.com/weblog/</link>
    <description>From Erick&#039;s brain to the Internet&#039;s prying little ears.</description>
    <language>en-us</language>           
    <generator>Nucleus CMS v3.32</generator>
    <copyright>©</copyright>             
    <category>Weblog</category>
    <docs>http://backend.userland.com/rss</docs>
    <image>
      <url>http://erick.rudiak.com/weblog//nucleus/nucleus2.gif</url>
      <title>Erick Rudiak.  Songwriter.  Singer.  Human.</title>
      <link>http://erick.rudiak.com/weblog/</link>
    </image>
    <item>
 <title>On lightning strikes.</title>
 <link>http://erick.rudiak.com/weblog/index.php?itemid=90</link>
<description><![CDATA[Last week, Microsoft announced <a href="http://www.microsoft.com/presspass/press/2008/aug08/05-08BlackHat08PR.mspx">some changes </a>to its monthly patch notification mechanism.  What caught my eye the most was this:<br />
<blockquote><br />
In addition, as part of the company's ongoing effort to improve its guidance for customers, Microsoft announced its new Exploitability Index. Developed based on customer feedback, the Exploitability Index will provide customers with guidance on the likelihood of functional exploits being developed for vulnerabilities addressed by Microsoft security updates. This additional information helps customers better assess their unique risks and better prioritize deployment of the monthly security update.<br />
</blockquote><br />
I certainly commend Microsoft (and Oracle) for taking the bull by the horns with their approach to vulnerability patching.  It's a difficult problem to tackle and the element of predictability they have brought to the table helps their customers.  Delivering an "exploitability index" is another story, on the other hand.  <br />
<br />
It's attempting to answer an interesting and difficult question: "will this happen to me?"  To make the example more real, let's ask "will lightning strike me?"  To answer this question, we can look at some data that can shed real light on the question.  The National Weather Service <a href="http://www.lightningsafety.noaa.gov/lightning_map.htm">tracks lightning strikes</a>.  You can look at a map of the US and immediately tell what the likelihood of being struck by lightning is for your location; if you dig deeper, you can figure it out for time of year, trends in strike density, etc.  <br />
<br />
<a href="http://www.lightningsafety.noaa.gov/lightning_map.htm"><img src="/img/nws-lightning-density.png"></a><br />
<h5><a href="http://www.lightningsafety.noaa.gov/lightning_map.htm">map from lightningsafety.noaa.gov</a></h5><br />
<br />
This data is considered reliable because it uses verifiable historical and geological information about the threat (lightning).  Information security, unfortunately, does not conform to the same rules.  While Microsoft certainly can make predictions about exploitability of an issue based on their undisputed expert knowledge on the subject, we simply don't have the luxury of looking back on years (or centuries) of data to support those assertions.  This is not to knock Microsoft; it's simply that the threat changes so rapidly:<br />
<br />
<ul><br />
<li>It's not the same threat every time: buffer overflows in Windows Metafile Format this month, insufficient randomness in DNS query sequence numbers the next, etc.;<br />
<li><a href="http://www.slate.com/id/2081042/">"Unknown unknowns"</a>: the customer wants to know "will lightning strike <i>me, here and now</i> ?" and to answer that, Microsoft has to understand a staggering number of combinations of software (always), hardware (sometimes), and other mitigating controls (occasionally firewalls, device configurations, etc.); just recently, <a href="http://www.microsoft.com/technet/security/bulletin/ms08-037.mspx">MS08-037</a> was revised several times after its initial publication in early July as more details about the interaction of the exploit and the fix itself became known; (<i>updated 12 Sep 2008</i>) the <a href="http://www.microsoft.com/technet/security/bulletin/MS08-sep.mspx">September 2008</a> bulletin was updated four days after release "to add Microsoft Office Project 2002 Service Pack 2, all Office Viewer software for Microsoft Office 2003, and all Office Viewer software for 2007 Microsoft Office System as Affected Software."<br />
<li>Exploitability inevitably changes over time.  It only takes <a href="http://en.wikipedia.org/wiki/Brighton_hotel_bombing#IRA_responsibility">one lucky attacker</a> to take a vulnerability from theoretical exploit to weaponized worm.  ASLR protection in Windows Vista has been considered a great mitigating control against a variety of overflow attacks, yet at Blackhat 2008, <a href="http://searchsecurity.techtarget.com/news/article/0,289142,sid14_gci1324395,00.html">a paper was presented showing how ASLR can be bypassed</a> -- this fundamentally changes the "likelihood of exploitation" equation for an entire class of vulnerabilities, both past and future;<br />
<li>For most vulnerabilities, the fact that there's a patch pretty much guarantees that someone has (or is working on) an exploit.  Microsoft says it themselves:<br />
<blockquote><br />
Along with the predictability of Microsoft's monthly security update process is the emergence of an undesirable cycle: the release of exploit code, related to those updates, sometimes within hours of release.<br />
</blockquote><br />
<br />
</ul><br />
As a customer trying to decide whether or not to patch every month, I continue to applaud Microsoft's efforts to give me decision-enabling information.  Alas, the Exploitability Index is a piece of trivia isn't tipping the scales on the decision for me.  If I'm at the ol' swimming hole and I see a thunderstorm approaching, I'm going to get out of the water -- not so much because I've been reading the lightning strike density maps for my neck of the woods, but because I know that -if- I get struck, it's going to <i>hurt</i>.  Similarly, as I decide whether or not to patch a given vulnerability immediately, I'm going to make that decision on the same factor: <strike>if</strike> <i>when</i> an exploit for that vulnerability is released, I want to know which data it's going to hit and how hard.  I want to know how much it's going to hurt.<br />
<br />
Stay tuned next week when I wax rhapsodic on "The Firestone tire recall of 2000 and why I don't care how <i>long</i> that SQL injection issue has been around."<br />
]]></description>
 <category>tech</category>
<comments>http://erick.rudiak.com/weblog/index.php?itemid=90</comments>
 <pubDate>Sat, 13 Sep 2008 07:09:00 -0400</pubDate>
</item><item>
 <title>A birth this week.</title>
 <link>http://erick.rudiak.com/weblog/index.php?itemid=76</link>
<description><![CDATA[For the first time in <a href="http://erick.rudiak.com/symg2006.php">three</a> <a href="http://erick.rudiak.com/weblog/?itemid=39">years</a>, I was unable to attend the <a href="http://www.symg.com/trips/adventures/guitar_workshop.php">SYMG High Sierra Singer Songwriter Adventure</a>.  I made many great friends on those trips, and it was a gut-wrenching decision not to go this time around.  Every year, each member of the gang would write a song with a common title.  In 2006, it was "Collapsible Plans"; last year, it was <a href="http://erick.rudiak.com/songs/raininggravel.php">"Raining Gravel"</a>.  This year, it was <a href="http://www.poltz.com/blognews/archives/2008_08.html">"Paradise Pie"</a>, and though I wasn't able to join the trip, I did birth a song with the same name, just to make myself feel a little bit better.  I even got to stamp another location on my <a href="http://erick.rudiak.com/songmap.php">songwriter passport</a> with this one (hint: look around Cuba).<br />
<br />
Listen here: <br />
<a href="http://erick.rudiak.com/songs/stream/paradisepie.mp3">Paradise Pie MP3</a> (click <a href="http://erick.rudiak.com/songs/paradisepie.php">here</a> to read along with the lyrics).<br />
]]></description>
 <category>music</category>
<comments>http://erick.rudiak.com/weblog/index.php?itemid=76</comments>
 <pubDate>Tue, 12 Aug 2008 08:09:00 -0400</pubDate>
</item><item>
 <title>Nowhere to hide.</title>
 <link>http://erick.rudiak.com/weblog/index.php?itemid=50</link>
<description><![CDATA[<script type="text/javascript" src="/flowplayer/examples/js/flashembed.min.js"></script><script type="text/javascript" src="/flowplayer.js"></script><br />
<div id="videoplayer"></div><br />
It was nice to have fans recording the Brothers K show last month, though it does imply a much lower margin for error than usual.  I finished the show with <i><a href="/songs/reputoprovestri.php">Creator</a></i> (a.k.a. "Reputo Pro Vestri").  <br />
<br />
My next, and probably last, tour date for the summer is the <a href="http://ulchicago.com">Underground Lounge</a> showcase on Wednesday, June 25th at 9:00 PM.<br />
]]></description>
 <category>music</category>
<comments>http://erick.rudiak.com/weblog/index.php?itemid=50</comments>
 <pubDate>Mon, 16 Jun 2008 01:04:10 -0400</pubDate>
</item><item>
 <title>Some follow-ups</title>
 <link>http://erick.rudiak.com/weblog/index.php?itemid=49</link>
<description><![CDATA[First, a follow-up to <a href="http://erick.rudiak.com/weblog/?itemid=42">A Tale Of Two Stories</a>.  That's the one where I suggest that my songs might have commercial value.  I'm not quitting my day job, but I do want to make an open and unabashed call out to the folks at <a href="http://www.uglydolls.com/#/meet-the-uglies/cinko/">Uglydoll</a>: if Cinko ever gets his own TV show or maybe even a commercial, this should be the theme song/jingle:<br />
<br />
<a href="http://erick.rudiak.com/songs/stream/cinko.mp3">Cinko.mp3</a><div class="rightbox"><img src="/img/cinko.jpg"></div><br />
<br />
Second, a follow-up to <a href="http://erick.rudiak.com/weblog/index.php?itemid=30">My Very Own OINY Moment</a>.  <br />
I was going to be really excited about the <a href="https://www.thepoint.com/campaigns/stop-the-event-promoters-ordinance">Event Promoters Ordinance</a> passing in Chicago, because that would have meant that cool acts like Mozart and U2 and Elton John would've had to play tiny venues in Oak Park and Evanston.  But then the whole thing got tabled (to thunderous applause from the local music community, natch) AND I found out that <a href="http://poltz.com">Steve Poltz</a> is touring the midwest and had a night available to play in Evanston.  <br />
<br />
Steve and I will be playing songs and spinning yarns of <a href="http://www.poltz.com/blognews/archives/2007_08.html#000793">epic ant battles</a> on Wednesday, May 28th, starting at 7:00 PM.  All this will happen right here in Evanston at the inimitable and unsurpassed <a href="http://local.google.com/local?f=q&amp;sll=37.0625,-95.677068&amp;sspn=63.472213,79.277344&amp;hl=en&amp;q=cafe+express+in+evanston+il&amp;latlng=42041111,-87690000,7994233020260369496">Brothers K Coffee</a>.  Donations (<a href="http://www.x-rates.com/d/USD/EUR/graph120.html">preferably in Euros</a>, but we'll take what we can get) are encouraged - baristas have needs too, you know!<br />
<br />
<div class="leftbox"><img src="/img/poltz-symg2007.jpg"></div>  ]]></description>
 <category>music</category>
<comments>http://erick.rudiak.com/weblog/index.php?itemid=49</comments>
 <pubDate>Wed, 14 May 2008 23:26:14 -0400</pubDate>
</item><item>
 <title>Hotti show Friday</title>
 <link>http://erick.rudiak.com/weblog/index.php?itemid=48</link>
<description><![CDATA[My next attempt at "<a href="http://erick.rudiak.com/weblog/index.php?itemid=36">playing for a hostile crowd</a>" will be at <a href="http://maps.google.com/maps?ie=UTF-8&oe=utf-8&client=firefox-a&dq=hotti+biscotti+loc:+Chicago,+IL&daddr=3545+W+Fullerton+Ave,+Chicago,+IL+60647&geocode=4186120623785703541,41.924612,-87.715395&ll=41.924612,-87.715395&iwstate1=dir:to&iwloc=A&f=d&z=13" class=external>Hotti Biscotti</a>, opening for blues rockers <a href="http://www.myspace.com/mikemichalakband" class=external>Mike & The Michalaks</a>.  OK, it's actually The Mike Michalak Band, but I'm going to be up front requesting <i>The Living Years</i> anyway.  Mike's cool that way.  Showtime is 9:00 PM Friday, May 2nd.<br />
]]></description>
 <category>music</category>
<comments>http://erick.rudiak.com/weblog/index.php?itemid=48</comments>
 <pubDate>Fri, 25 Apr 2008 21:28:33 -0400</pubDate>
</item><item>
 <title>Once.</title>
 <link>http://erick.rudiak.com/weblog/index.php?itemid=47</link>
<description><![CDATA[Over the past few weeks, a lot of people have been telling me that I need to see <i><a href="http://en.wikipedia.org/wiki/Once_%28film%29">Once</a></i> because, you see, I'm a singer-songwriter and it's about singer-songwriters.  I couldn't figure out why they did not also tell me to see <i><a href="http://www.imdb.com/title/tt0057076/">From Russia With Love</a></i> on similar grounds, but I trust my friends and I tend to agree with <a href="http://www.93xrt.com/episode_download.php?contentType=36&amp;contentId=1283864">The Regular Guy</a> and <a href="http://www.avclub.com/content/cinema/once">The A.V. Club</a>, so I rented <i>Once</i> this weekend.<br />
<br />
The story is certainly engaging and resonant, the songs are strong and the depiction of the songwriting and recording process (yes, there is definitely a "car test") was refreshing, if a bit treacly.  But I couldn't help wondering how much having heard an hour of <a href="http://soundopinions.org/shownotes/2008/011108/shownotes.html">Glen Hansard on Sound Opinions</a> helped me along while watching the movie.  Knowing what I did about the <a href="http://en.wikipedia.org/wiki/Once_%28film%29#Production">history of the movie</a> made it easier to get into the music and the story and not be distracted by the question of whether these were actors playing musicians or musicians playing actor (if you haven't seen the movie and it matters, try not following the link, OK?).  It also helped knowing just enough about slavic languages to have a good guess at the key phrase in the second act, although I have to agree with the director's decision not to subtitle the Czech.<br />
<br />
All of which, ultimately, tells me that <i>Once</i> is a good movie but an even better DVD - the extra features and commentary help the movie make an intimate connection which is so critical to the songwriting and performing process.  It is, in effect, the all-important <a href="http://erick.rudiak.com/songs/reputoprovestri.php">banter</a> inbetween songs that brings audience and artist together.  Certainly, there are plenty of artists who can walk on stage, say nothing at all, and perform for 90 minutes and make it worth the price of admission.  Elvis Costello comes immediately to mind, though the last time I saw him at the Chicago Theater, he did take time between songs to respond to someone in the crowd by announcing "I will <i>not</i> play [expletive] <i>Veronica</i>."  It was still a great show with great artistry and I'm glad I saw it.  For my money, though, there's something about a show with a <a href="http://www.avclub.com/content/feature/more_talk_less_rock_15_masters">storyteller</a> that takes artistry to a new level.  Some shows don't need it, and I don't think I'm going to start watching movies exclusively with the DVD commentary on from now on.  But I will continue to hope that, if I've discovered a new musician whose songs I like on the radio or online, they'll tell stories about them when I go to see the show.  <i>Once</i> was helped by it quite a bit.<br />
<br />
P.S.  <i><a href="http://www.shotgunstories.com/">Shotgun Stories</a></i> was the best movie I saw in 2007 (that was released in 2007).  The intensity of the third act was impressive, given the understated tones of the entire movie throughout.  ]]></description>
 <category>music</category>
<comments>http://erick.rudiak.com/weblog/index.php?itemid=47</comments>
 <pubDate>Mon, 28 Jan 2008 00:32:38 -0500</pubDate>
</item><item>
 <title>Lilly&apos;s show: Jan 11 @ 8PM</title>
 <link>http://erick.rudiak.com/weblog/index.php?itemid=46</link>
<description><![CDATA[Hey, gang.  Hope you're having a great new year.  I've created a slew of songs<br />
that have led a truly sheltered life here in the little hamlet of Evan's Town -<br />
they lie on the couch drinking homemade izzes, or maybe they go hiking and<br />
munch roasted marshmallows by the fire.  It's about time they saw the harsh,<br />
real world out there, so I'm taking them out to <a href="http://www.myspace.com/lillysbar">Lilly's</a> <a href="http://maps.google.com/maps?q=2513+N+Lincoln+Ave,+Chicago,+IL+60614,+USA&amp;ie=UTF8&amp;ll=41.930012,-87.651629&amp;spn=0.011893,0.020771&amp;z=16&amp;om=1&amp;layer=c&amp;cbll=41.927442,-87.651589&amp;cbp=1,609.5313427801628,,0,-0.99178338934604">in Chicago</a> on Friday,<br />
January 11th.  They'll face the harsh reality of an unfamiliar public, a dark<br />
room, and the threat of merely-conditional love.  Won't you join me and help<br />
them feel a little bit at home?  I knew you would :-)  $6 gets you into the<br />
song-desheltering party at 8pm-9pm, with nu-jazz outfit <a href="http://myspace.com/projectninetynine">Project 99</a><br />
following.]]></description>
 <category>music</category>
<comments>http://erick.rudiak.com/weblog/index.php?itemid=46</comments>
 <pubDate>Sat, 5 Jan 2008 10:47:01 -0500</pubDate>
</item><item>
 <title>Changing meter</title>
 <link>http://erick.rudiak.com/weblog/index.php?itemid=45</link>
<description><![CDATA[Unrelated to the <a href="http://www.sciencedaily.com/releases/2007/09/070921110735.htm">changing kilogram</a> (although, frankly, that's a much more interesting story), changing meter is a too-rarely-used songwriter trick: start out as a rock song, finish a waltz.  Of course, it's not a maneuver that's confined to the singer-songwriter genre.  Otherwise, orchestras would have drummers and not conductors.  But it's something that always catches my attention, particularly when it's done well.  I've had mixed success myself: <a href="/songs/reputoprovestri.php">Reputo Pro Vestri</a> is an example of a nice, smooth transition (5/6 in verses, 6/6 in choruses); my <a href="/songs/owlowl.php">collaboration with Luke</a> (3/4 verses, 4/4 coda), not quite as much.  Better examples of this technique, by better songwriters:<br />
<br />
<script type="text/javascript" src="http://images.del.icio.us/static/js/playtagger.js"></script><br />
<br />
<ul><br />
<li>Moxy Fruvous: <a href="/songs/stream/meter_rivervalley.mp3">River Valley</a> (4/4 to 3/4 in bridge)<br />
<li>Beatles: <a href="/songs/stream/meter_hcts.mp3">Here Comes The Sun</a> (4/4 to 3/4 in bridge)<br />
<li>Led Zeppelin: <a href="/songs/stream/meter_foursticks.mp3">Four Sticks</a> (Bonham's actually drumming out sixths but Page is playing measures of 4, 5, 6, and 7)<br />
<li>The Fratellis: <a href="/songs/stream/meter_flath.mp3">Flathead</a> (4/4 verse & chorus to 7/8 ramp)<br />
</ul><br />
<br />
For a much better treatise on time signatures, I recommend <a href="http://blog.pandora.com/archives/podcast/2007/09/meters_time_sig.html">this Pandora blog entry</a>.]]></description>
 <category>music</category>
<comments>http://erick.rudiak.com/weblog/index.php?itemid=45</comments>
 <pubDate>Sun, 23 Dec 2007 15:03:57 -0500</pubDate>
</item><item>
 <title>In America, he&apos;d have been working for Leo Burnett.</title>
 <link>http://erick.rudiak.com/weblog/index.php?itemid=43</link>
<description><![CDATA[<img src="http://erick.rudiak.com/img/boxofkittens.png" alt="All rights reserved, copyright Erick Rudiak 2004.  No, you may NOT lolcat this photo!!!"><br />
The photo above was taken in St. Petersburg in 2004, just outside the Mayakovskaya metro stop.  The sign next to the box of kittens read something to the effect of: "Please help, we need money for our medicine.  Meow."  Why boxes of kittens aren't an Internet meme yet is only a minor mystery to me.  I'm willing to do my part, though.  <br />
<p><br />
World, welcome <a href="http://erick.rudiak.com/songs/boxofkittens.php">Box Of Kittens</a>, the song!]]></description>
 <category>music</category>
<comments>http://erick.rudiak.com/weblog/index.php?itemid=43</comments>
 <pubDate>Sat, 22 Dec 2007 22:32:57 -0500</pubDate>
</item><item>
 <title>Slow news day?</title>
 <link>http://erick.rudiak.com/weblog/index.php?itemid=44</link>
<description><![CDATA[This was the best that my daily vigil of keeping-up-with-the-wacky-world-of-security generated today:<br />
<br />
<UL><br />
<LI>The bad guys are <a href="http://www.eweek.com/article2/0,1759,2230863,00.asp">using clever channels to communicate!</a><br />
<LI><a href="http://www.infoworld.com/article/07/12/11/DNS-attack-could-signal-Phishing-2.0_1.html">If you have unpatched vulnerabilities on your machine</a>, browsing random websites will lead to nothing but trouble!!<br />
<LI>If you're on a shared network and you're not <a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&articleId=9052380&intsrc=hm_list ">encrypting traffic that matters</a>, some nefarious malefactor may already be using your account!!!<br />
</UL><br />
<br />
One thing I've learned over the years is that it helps to know your audience (which is why this blog is 90% songwriting, but I digress...).  Observation #1 about the audiences of the three publications above: odds are, they've been online long enough to know about the perils of patch management, unencrypted data and botnets.  That's been drilled into us from all angles, including the aforementioned trade press.  Observation #2: odds are, that audience is largely corporate in nature (i.e. not a lot of weekend computer enthusiasts working their ranches from sun-up to sun-down are glued to computerworld.com in their leisure time).  Observation #3: the security story that's really going to scare <i>that</i> particular audience straight is that there's an <a href="http://www.infoworld.com/article/07/12/11/Wabisabilabi-selling-remote-exploit-for-SAP_1.html">unpatched SAP vulnerability</a> out there.  Cheers to infoworld.com for reporting it; jeers to all three for offering as news things we already knew back in 1998.]]></description>
 <category>tech</category>
<comments>http://erick.rudiak.com/weblog/index.php?itemid=44</comments>
 <pubDate>Wed, 12 Dec 2007 22:35:20 -0500</pubDate>
</item>
  </channel>
</rss>