<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Techdulla</title>
	<atom:link href="http://techdulla.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://techdulla.wordpress.com</link>
	<description>Ramblings of yet another IT guy</description>
	<lastBuildDate>Tue, 06 Mar 2012 13:08:42 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='techdulla.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>Techdulla</title>
		<link>http://techdulla.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://techdulla.wordpress.com/osd.xml" title="Techdulla" />
	<atom:link rel='hub' href='http://techdulla.wordpress.com/?pushpress=hub'/>
		<item>
		<title>Offshoring and education gap</title>
		<link>http://techdulla.wordpress.com/2012/03/02/offshoring-and-education-gap/</link>
		<comments>http://techdulla.wordpress.com/2012/03/02/offshoring-and-education-gap/#comments</comments>
		<pubDate>Fri, 02 Mar 2012 20:05:48 +0000</pubDate>
		<dc:creator>Dan</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[computer science]]></category>
		<category><![CDATA[developers]]></category>
		<category><![CDATA[graduates]]></category>
		<category><![CDATA[offshoring]]></category>
		<category><![CDATA[outsourcing]]></category>
		<category><![CDATA[software engineer]]></category>
		<category><![CDATA[software-development]]></category>
		<category><![CDATA[technology]]></category>

		<guid isPermaLink="false">http://techdulla.wordpress.com/?p=383</guid>
		<description><![CDATA[I missed the RSA Conference this week for various reasons but I did get to spend the better part of two days out of the office hanging with a group of CTO&#8217;s.  The group was a mix of early stage and later stage companies from various industries, which made for some interesting conversation.  One of [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=techdulla.wordpress.com&#038;blog=2345490&#038;post=383&#038;subd=techdulla&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>I missed the RSA Conference this week for various reasons but I did get to spend the better part of two days out of the office hanging with a group of CTO&#8217;s.  The group was a mix of early stage and later stage companies from various industries, which made for some interesting conversation.  One of the sessions I enjoyed being part of was focused around <a title="Wikipedia -- Offshoring" href="http://en.wikipedia.org/wiki/Offshoring" target="_blank">Offshoring</a>.  I had very little to add in this session since we don&#8217;t have to deal with this at my company, directly anyway, but I was all ears.</p>
<p>Most of the folks in the room were offshoring at least some of their development work.  Here were some of the key takeaways that everyone seemed to be in agreement on:</p>
<ul>
<li>The quality in India has gone down dramatically over the past 10 years.  Good for fixing small bugs but not for innovative ideas or dealing with big issues.  Most of this is attributed to how competitive the market is in India for good people.  The talented engineers typically jump from place to place for the $$$.</li>
<li>Vietnam seems to be ramping up as the new India.  One CTO described it as India 16 years ago with very eager and talented individuals.  The downfall there is language barrier is still high.</li>
<li>Greece, Russia, and Bulgaria also got high marks on the technical aptitude and ability to tackle the tougher projects.</li>
<li>For the most part, people are not offshoring to save money they are primarily doing it to <a href="http://en.wikipedia.org/wiki/Follow-the-sun" target="_blank">follow-the-sun</a>.</li>
<li>One company (who shall remain nameless) pays the same regardless of where the work is being done.  So if they would hire you to work from India, Russia, or Vietnam you would get paid the same as the engineer in Silicon Valley.</li>
<li>They recommend you keep the senior folks who are driving the architecture of the apps and systems local and supplement the lower level with offshoring.</li>
<li>Security of the code is not a big concern for most of the companies.  Recommend you work with reputable groups that have good references as opposed to just the lowest bidder.</li>
<li>Tight integration with your offshore teams is critical for retention.  Meet with these teams regularly either via video or by getting on a plane.</li>
<li>Communication is KING.</li>
</ul>
<p>I thought there were some interesting points in there.  One of them that was most surprising to me was the &#8220;We don&#8217;t save money by doing this&#8221; comment.  So if you don&#8217;t save money, and you just want to follow-the-sun, why not hire some 2nd and 3rd shift developers local to do the job.  The problem there appears to be an educational issue.  Common theme among the CTO&#8217;s was that, similar to my <a href="http://techdulla.wordpress.com/2012/02/15/hiring-is-hard/" target="_blank">last post</a>, hiring is hard.  Kids are coming out of school with CS degrees wanting $100k+ salaries yet they can&#8217;t actually write useful code.  They also come out cocky as I heard multiple stores of interviews where recent graduates are basically demanding things of the companies prior to even getting a job offer.  I&#8217;m not saying CS grads are useless, there are obviously some talented people coming out of colleges and universities, but the bottom line is that they are having trouble finding talented and motivated individuals.  Often times when they compare the resume from someone local with someone in, lets say Russia, it is an easy decision because the person in Russia has more experience, more advanced degrees and more desire to work.  Too much theoretical teaching going on in the US schools seemed to be a common thread.</p>
<p>So if you are a software engineer, what do you do?  For one, I think you have to realize that you can&#8217;t expect to get oodles and oodles of money because you can write &#8220;Hello World&#8221;.  This is a much different world today than it was 20, 15, 10, hell even 5 years ago.  If I look back to when I graduated from college a few moons ago, if you could write code you could write yourself a paycheck.  I had friends coming out of CS who hated it but knew they would get paid.  I&#8217;m not sure that will work today.  It is an industry where you need to have a passion for what you do and how you do it.  From what I hear, too many people are still just looking to get paid.</p>
<p>What do you think?</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/techdulla.wordpress.com/383/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/techdulla.wordpress.com/383/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=techdulla.wordpress.com&#038;blog=2345490&#038;post=383&#038;subd=techdulla&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://techdulla.wordpress.com/2012/03/02/offshoring-and-education-gap/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://2.gravatar.com/avatar/84a30a632b634932d0f6dc3a6323033d?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Techdulla</media:title>
		</media:content>
	</item>
		<item>
		<title>Hiring is hard</title>
		<link>http://techdulla.wordpress.com/2012/02/15/hiring-is-hard/</link>
		<comments>http://techdulla.wordpress.com/2012/02/15/hiring-is-hard/#comments</comments>
		<pubDate>Thu, 16 Feb 2012 03:31:11 +0000</pubDate>
		<dc:creator>Dan</dc:creator>
				<category><![CDATA[Lesson Learned]]></category>
		<category><![CDATA[hiring]]></category>
		<category><![CDATA[interviews]]></category>

		<guid isPermaLink="false">http://techdulla.wordpress.com/?p=372</guid>
		<description><![CDATA[When we had an opening on my staff for a system administrator I thought it was going to be a pretty easy hire.  If you watch the news there are lots of people out of work, that should help right?  It is a great company, that should help right?  It isn&#8217;t a super senior level [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=techdulla.wordpress.com&#038;blog=2345490&#038;post=372&#038;subd=techdulla&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>When we had an opening on my staff for a system administrator I thought it was going to be a pretty easy hire.  If you watch the news there are lots of people out of work, that should help right?  It is a great company, that should help right?  It isn&#8217;t a super senior level position so should have a fairly wide audience, that should help right?  Pay is good and benefits are better, that should help right?  They would have an amazing boss, ok maybe not but 4 out of 5 isn&#8217;t bad right?  <img src='http://s1.wp.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p>Boy was I wrong!  I have been working with recruiting firms, placing ads, hitting up my professional and friend network which has resulted in me looking at 98 candidates.  I haven&#8217;t met with all 98 candidates but I have read all the resumes and interviewed about 20.  One guy almost got an offer but with two outs in the bottom of the ninth he got pulled.</p>
<p>I will admit that our interview process isn&#8217;t a walk in the park, but it isn&#8217;t so bad that people cry when finished (well most people anyway&#8230;more on that later).  We have had all kinds of candidates.  Some were smart but couldn&#8217;t make a complete sentence.  Some couldn&#8217;t make eye contact.  Some couldn&#8217;t spell, at all.  Some had NO background in tech!  The list goes on, you get the point but here are some of my favorites:</p>
<p><strong>Candidate 1:  The breakdown</strong></p>
<p>This guy had about 5 years experience in mostly support roles but was in a Junior SysAdmin role.  Resume was good, personality was good, what he wanted to do in the future was good.  I have some basic tech questions I ask all candidates in an interview just to make sure they know their ass from their elbow.  So I ask him to describe to me how DHCP works&#8230;.couldn&#8217;t do it.  I ask him how DNS works&#8230;..couldn&#8217;t do it.  I asked him a simple logic/troubleshooting question&#8230;.couldn&#8217;t do it.  He looked like he was ready to cry, at which point he asked if he should leave the interview.  Awkward!</p>
<p><strong>Candidate 2:  The people person</strong></p>
<p>This guy was doing some sys admin work at a fairly large company but was also the top-level support guy for the C-Level team.  We get near the end of the interview, which was going ok until he said he didn&#8217;t like to do anything that has to do with a computer once he leaves the office. So I ask him a question:  &#8220;If you could have any job in the world, what would it be?&#8221;  His response was: &#8220;Probably something in manual labor because I don&#8217;t have any other skills.&#8221;  So I changed it up a little, &#8220;Assuming you had all the skills, what job would you choose?&#8221;  After about 30 seconds of deep thought he then says, &#8220;Well I would probably still do manual labor, because if I took any other office type job I would likely need to work with people more than I already do in IT, and I don&#8217;t like dealing with people.&#8221;  WHAT!?  I thought I was being punked!</p>
<p>It has been an interesting road and I have learned a lot in the process.  My interviewing skills have improved dramatically which has probably been the best result from this whole thing.  I have also learned that there are a lot of people who are in IT that really should not be in IT.  It amazes me how many people have made a career out of this without really knowing anything.  I want to find someone who is hungry.  Hungry to learn, hungry to grow, hungry to be better.  They should want to know the unknown while being honest with themselves on what that means.  I&#8217;ve got the buffet, but can&#8217;t find anyone who wants to eat.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/techdulla.wordpress.com/372/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/techdulla.wordpress.com/372/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=techdulla.wordpress.com&#038;blog=2345490&#038;post=372&#038;subd=techdulla&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://techdulla.wordpress.com/2012/02/15/hiring-is-hard/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://2.gravatar.com/avatar/84a30a632b634932d0f6dc3a6323033d?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Techdulla</media:title>
		</media:content>
	</item>
		<item>
		<title>STFU about the TSA</title>
		<link>http://techdulla.wordpress.com/2010/11/24/stfu-about-the-tsa/</link>
		<comments>http://techdulla.wordpress.com/2010/11/24/stfu-about-the-tsa/#comments</comments>
		<pubDate>Wed, 24 Nov 2010 14:28:25 +0000</pubDate>
		<dc:creator>Dan</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[TSA]]></category>

		<guid isPermaLink="false">http://techdulla.wordpress.com/?p=369</guid>
		<description><![CDATA[Thanksgiving is upon us and as I reflect upon all of the things in my life I have to be thankful for one thing is certain, Life is Good.  Sure, there are things that could be better, but when put into perspective I really don&#8217;t have much to complain about.  There are people out there [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=techdulla.wordpress.com&#038;blog=2345490&#038;post=369&#038;subd=techdulla&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>Thanksgiving is upon us and as I reflect upon all of the things in my life I have to be thankful for one thing is certain, Life is Good.  Sure, there are things that could be better, but when put into perspective I really don&#8217;t have much to complain about.  There are people out there with no jobs this holiday season, trying to provide for their families.  There are people who don&#8217;t know where their next meal will come from.  There are people, brave men and women, who are over seas fighting for our country who will not see their families and are just trying to make it home in one piece.  I could go on and on with the examples of people who have hardships, more hardships than myself, but lets stop there.  So where am I going this this feel good story?  I am going to the topic that no one can seem to avoid right now, the TSA.</p>
<p>Whether I am on Facebook, Twitter, blogs, around the water cooler, listening to the radio or watching the nightly news I can not seem to escape people bitching about the TSA.  I know this is not going to be a popular sentiment with the readers of my blog, or most of my friends: <strong>STFU about the TSA</strong> and in particular the <strong>TSA Agents</strong>.  I get that people don&#8217;t like being touched.  I get that people don&#8217;t like being seen &#8220;naked&#8221;.  You have options though, drive or take the train.  Do I think the TSA has gone too far?  To some extent yes, but on the other hand, whether you agree or disagree the goal is to keep us safe.  I&#8217;m not going to make this post about whether or not the new procedures are actually helping to keep us safe.  That is a battle for another day.  What I am going to make this post about is how all your bitching, whining, and harassment toward the TSA agents is misdirected.</p>
<p>If you didn&#8217;t like a movie that was playing at theaters across the country, would you harass the person selling tickets to the movie?  You know, the kid behind the counter who sells the actual tickets for 8 hours per day, do you harass him?  I hope not.  He is just doing his job.  Whether he agrees with the theater&#8217;s choice of showing the movie or not he is trained to stand there and collect money for tickets.  He does it or he loses his job.  I look at TSA Agents the same way, they are doing their jobs.  Don&#8217;t like that comparison, ok here is another one.</p>
<p>Do you agree with the war in Iraq?  If the answer is no, do you then harass soldiers when you see them?  What about veterans, do you harass them?  If you do, then you deserve a punch in the face&#8230;twice.  You should be thanking them for their service.  You should be picking up their tab at the bar.  You should be glad they are out there doing what we can&#8217;t or won&#8217;t.  At the end of the day though, these men and women are out there doing their jobs (though a very dangerous one).  Whether or not you agree with the policy that puts them there doesn&#8217;t change the fact that they are serving our country and doing what is asked of them.  While I do not put TSA Agents on par with soldiers, I think their goals are the same, to keep people safe.  They are being asked to keep the skies safe by screening thousands of people per day who pass by them.  For the most part, they encounter normal people just trying to get from point A to point B.  Now what about that one passenger who isn&#8217;t trying to get from point A to point B?  Would you want the pressure of finding that one in 10 million passenger who&#8217;s agenda is to hijack the plan, or worse&#8230;blow it up?  I wouldn&#8217;t.  There is a lot of pressure that goes along with that job, so for travelers to say TSA agents &#8220;take their job too seriously&#8221; I&#8217;m not sure they understand what it is they are actually tasked with doing.</p>
<p>Lets say the TSA agent doesn&#8217;t do his job and lets say he lets someone through who later blows up a plane.  Imagine the backlash from the American public.  Because one guy was not screened thoroughly enough things can be turned upside down.  One could argue that is how we got to where we are today.  What about the agent?  His life will be turned upside down as well, as will every TSA agent currently employed.  It is a thankless job, and it just got a lot harder because now you are harassing these guys and gals.  You refuse to get scanned, then you threaten them about giving you a pat down, then you video tape it, post it on YouTube, and post to Facebook or Twitter for all the world to see.  Thankless doesn&#8217;t even describe the position.  For the record, yes there are some TSA Agents who step over their boundaries, but that is true in every profession from cops, to firefighters, to IT folks.  There are always going to be some bad apples.</p>
<p>So I leave you with this:  If you don&#8217;t like the policies and want to see them changed, write to your representatives and offer up suggestions on making the policies better but let the TSA Agents do their job and while you are at it thank them for putting up with us.  They want to get in their hours, get home to their families, and collect a pay check like the rest of us.</p>
<p>Hope everyone have a save and happy Thanksgiving.</p>
<p>&#8211;DanO</p>
<p>&nbsp;</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/techdulla.wordpress.com/369/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/techdulla.wordpress.com/369/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=techdulla.wordpress.com&#038;blog=2345490&#038;post=369&#038;subd=techdulla&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://techdulla.wordpress.com/2010/11/24/stfu-about-the-tsa/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://2.gravatar.com/avatar/84a30a632b634932d0f6dc3a6323033d?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Techdulla</media:title>
		</media:content>
	</item>
		<item>
		<title>Back from Vegas and feeling good</title>
		<link>http://techdulla.wordpress.com/2010/08/11/back-from-vegas/</link>
		<comments>http://techdulla.wordpress.com/2010/08/11/back-from-vegas/#comments</comments>
		<pubDate>Wed, 11 Aug 2010 15:37:04 +0000</pubDate>
		<dc:creator>Dan</dc:creator>
				<category><![CDATA[Android]]></category>
		<category><![CDATA[Conference]]></category>
		<category><![CDATA[Mobile Phone]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://techdulla.wordpress.com/?p=358</guid>
		<description><![CDATA[Once again I made the annual pilgrimage to Las Vegas for BlackHat and Decfon.  As expected it was another great week spent attending interesting talks and hanging out with some of my favorite people&#8230;doesn&#8217;t get much better than that.  My last day in Vegas somehow got me roped into a fitness challenge, sadly I can&#8217;t [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=techdulla.wordpress.com&#038;blog=2345490&#038;post=358&#038;subd=techdulla&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>Once again I made the annual pilgrimage to Las Vegas for BlackHat and Decfon.  As expected it was another great week spent attending interesting talks and hanging out with some of my favorite people&#8230;doesn&#8217;t get much better than that.  My last day in Vegas somehow got me roped into a fitness challenge, sadly I can&#8217;t use alcohol as an excuse.  My buddy Ward decided we should have a little competition to see who can get in better shape for BlackHat 2011.  I&#8217;m not one to back away from a challenge so it&#8217;s on!  This is going to spread into more of an open challenge for all, but my goal is really just to beat Ward.  Good luck buddy, you are going to need it.</p>
<p>I really wanted to get this post out last night but for various reasons it didn&#8217;t happen.  Since a day late is better than nothing, here it goes.  Yesterday Kaspersky <strong><a href="http://www.kaspersky.com/news?id=207576152" target="_blank">announced</a></strong> that the First SMS Trojan for Android has been found in the wild.  Usually this is not something that I would blog about, sms for profit on a mobile device is nothing new.  What I think stands out though is how much easier Android makes this type of attack.  There are very little controls in place to prevent users from installing anything they want, good or bad.  This is kind of the point of Android but I see it as a flaw in the current implementation.  I decided to re-tweet this announcement from Kaspersky and it raised some questions over why I and the security industry make a big deal out of these things.  I get where that attitude comes from, really I do.  From a technical standpoint it isn&#8217;t impressive, new, or surprising.  In  Vegas, between BlackHat and Defcon, there were a lot of   sessions  related to Android, so it is expected that there would be malware out  there.  However; from a general awareness standpoint, I think it is a valid story.  So why do I think it is valid from an  awareness  standpoint if it is expected?  Expected by a security or tech guy is different than expected by the masses.  My non techie friends have no idea this kind of stuff is possible unless I tell them or they see it on the news.  Taking that up a notch, I often have discussions about  security  risks with CxO folks who after the explanation ask <strong>&#8220;Has it happened?&#8221;</strong> They  want real  life examples.  I can talk until I am blue in the face about  something  that was demonstrated onstage at Defcon or in my lab, but until it happens  to someone  in the real world and it gets press, it is as if it can&#8217;t/won&#8217;t happen.  Mobile devices are still looked at simply as cell phones by many, but they are much more.</p>
<p>Now, I&#8217;ll admit that this is not something people should freak out about and vendors are going to milk this to try and profit (what else is new).  As I mentioned before, malware for a phone that allows someone to initiate SMS messages and profit from it isn&#8217;t new.  As an individual the worst that can happen is you get a big bill and then have the hassle of disputing the charges.  You would probably call Verizon and tell them you didn&#8217;t send those text messages they would work something out and you would not pay the full amount.  Now if the malware was smart, it would only initiate a few messages per month and hide on the phone, therefore not raising the eyebrows of most users.  Would you notice a few extra dollars on your personal mobile account or family plan?  What about companies that have corporate plans for employee phones?  They have hundreds if not thousands of phones.  The likelihood of a few premium text messages being caught is low.  I know that at our small company with less than 100 mobile lines that are paid for by the company the finance department would never notice an extra $5-$10 per line each month. It was pointed out that premium SMS isn&#8217;t really bad like giving away company secrets, so why are we talking so much about it.</p>
<p>My argument to that is the SMS vector is the quick hit for profit and just the tip of the iceberg.  It takes much less effort by an attacker to write code that will send a text and instantly make money than to invest the time to write much more complicated spy software, grab the data, look for company secrets, and then try to profit from it (more risk too).  That doesn&#8217;t mean it can&#8217;t be done right, it just isn&#8217;t being done yet.  There are a few companies selling this type of spy software today (Flexispy, MobiStealth, and Mobile-Spy to name a few), so it exists.  It requires you to have access to the phone as after installing the application you need to activate and configure it but it will log location data, sms messages, email messages, call logs (some record actual calls).  Sure, turning that into a piece of malware that self activates and configures is more work but I don&#8217;t think it is far off.</p>
<p>Make no mistake, I do not think installing an agent from Kaspersky, McAfee, Sophos, Symantec etc. is the answer.  It isn&#8217;t the answer on desktops and it will not be the answer on Android and other mobile devices.  We need to treat these mobile devices more like a computer and less like a phone.  A lot of the same protections we use on the laptop/desktop side should carry over, for example:</p>
<p>1.  Better protection for users.  That may take away some of the functionality but have a user mode and admin mode.  Just as you don&#8217;t need to run everything as root, users don&#8217;t need complete admin access to their mobile device at all times.<br />
2.  Better controls for corporate IT departments.  Allow them to push policies for what can be installed and what can be accessed on the device.<br />
3.  More user awareness is needed.  Many Android users do not understand that the device is really a mini computer that allows them to text and place calls.  They look at it like a cell phone with cool features.  They need to change how they think of the device.</p>
<p>Interested to hear what others think.</p>
<p>&#8211;DanO</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/techdulla.wordpress.com/358/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/techdulla.wordpress.com/358/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=techdulla.wordpress.com&#038;blog=2345490&#038;post=358&#038;subd=techdulla&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://techdulla.wordpress.com/2010/08/11/back-from-vegas/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://2.gravatar.com/avatar/84a30a632b634932d0f6dc3a6323033d?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Techdulla</media:title>
		</media:content>
	</item>
		<item>
		<title>Support just keeps getting worse.</title>
		<link>http://techdulla.wordpress.com/2010/07/23/support-just-keeps-getting-worse/</link>
		<comments>http://techdulla.wordpress.com/2010/07/23/support-just-keeps-getting-worse/#comments</comments>
		<pubDate>Fri, 23 Jul 2010 13:10:47 +0000</pubDate>
		<dc:creator>Dan</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://techdulla.wordpress.com/?p=351</guid>
		<description><![CDATA[Do you remember the days when you would call technical support and actually get someone knowledgeable on the phone who could help you resolve a problem?  I remember a time when this was true, or maybe I just want to remember it that way&#8230;kind of like remembering how I used to walk to school, uphill, [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=techdulla.wordpress.com&#038;blog=2345490&#038;post=351&#038;subd=techdulla&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>Do you remember the days when you would call technical support and actually get someone knowledgeable on the phone who could help you resolve a problem?  I remember a time when this was true, or maybe I just want to remember it that way&#8230;kind of like remembering how I used to walk to school, uphill, both ways, in the snow&#8230;..barefoot.  My latest support nightmare revolved around trying to get an IP security camera configured.  I took it out of the box, followed the directions&#8230;.nothing.  I then verified via the DHCP server that it was grabbing an address and it was&#8230;good news.   Tried using the software that came with the camera to access it once again&#8230;.nothing.  Tried accessing the web interface&#8230;nothing.  Port scanned the device&#8230;nothing.  Power cycle and repeat&#8230;nothing.  Break out the paper clip and reset the device&#8230;nothing.</p>
<p>Seems like the web server built into the camera is defective, but maybe, just maybe there is some secret piece I am missing.  The call to tech support begins.</p>
<p>Starts out simple enough, give out my name, email address, camera model, and serial number.  The woman, who has a heavy accent (India if I had to guess) is having a hard time understanding me as I spell out the information.  I explain the problem and what steps I have taken to troubleshoot the problem.</p>
<p>Her:  Did you install the software?<br />
Me:  Yes<br />
Her:  Did you search for the camera?<br />
Me: Yes<br />
Her:  Did it find the camera?<br />
Me:  No, that is why I am calling you.<br />
Her:  Is the camera powered on?<br />
Me: Umm&#8230;yes it is powered on.<br />
Her: Is it connected to your network?<br />
Me:  Yes<br />
Her:  With a cable?<br />
Me:  Yes with a cable&#8230;it is blue in case that matters.<br />
Her:  Lets uninstall and reinstall the software.<br />
Me:  I already did that.  It didn&#8217;t make a difference.<br />
Her:  Let me know when the software is uninstalled.<br />
Me:  I already uninstalled and reinstalled, it didn&#8217;t make a difference.</p>
<p>Silence for about a minute.</p>
<p>Me:  Hello<br />
Her:  Is the software uninstalled yet?<br />
Me: ummm&#8230;sure&#8230;I mean yes, yes it is.<br />
Her:  Ok please put the CD in and install the software again.<br />
Me:  Reinstalled&#8230;.same problem.<br />
Her:  That was fast, what software did you install?<br />
Me:  My computer is super fast.  I installed the config software.</p>
<p>At this point she has me repeat the search process using the software.  Still no dice.  I explain that I know it has an IP address on the network.</p>
<p>Me:  Is there a way to configure this camera without using the software?<br />
Her:  Lets reinstall the software again.<br />
Me:  Do we have to use this software for the initial config or is there a special admin page we can connect to on the device?<br />
Her:  Lets do a reset of the device while you reinstall the software.<br />
Me:  DO I NEED TO USE THIS SHITTY SOFTWARE TO CONFIGURE THIS DEVICE?<br />
Her:  Yes, the software is required for initial setup.</p>
<p>30 minutes later after rebooting, resetting, changing cables</p>
<p>Her:  Ok, the software is not working.  Lets configure this manually.<br />
Me:  You mean configure without using the shitty software?<br />
Her:  Yes, please open Internet Explorer and type&#8230;<br />
Me:  Grrrr&#8230;..</p>
<p>That didn&#8217;t work either.</p>
<p>Her:  What do you see for lights on the device?<br />
Me:  I see a solid orange light.<br />
Her:  Do you see a green light?<br />
Me:  No, I see an orange light.<br />
Her:  Is there a green flashing light?<br />
Me:  All I see is a single light.  It is ORANGE, not GREEN, and it is not flashing it is solid.<br />
Her:  Please unplug the power to the device, I will tell you when to plug it back in.<br />
Me:  Ok<br />
Her:  Did you unplug it?<br />
Me:  Yes<br />
Her:  Did you plug it back in?<br />
Me:  No, I was waiting for you to tell me when to plug it back in.<br />
Her:  Good<br />
(wait 20 seconds)<br />
Her:  Did you plug it back in yet?<br />
Me:  Still waiting for you to tell me.<br />
Her: Good<br />
(wait 30 seconds)<br />
Me:  Do you want me to plug this in yet?<br />
Her:  Oh yes, please plug it in now.</p>
<p>The device goes through it&#8217;s boot process and when it settles down.</p>
<p>Her:  What do you see for lights?<br />
Me:  I still only see an orange light.<br />
Her:  Do you see a green light?<br />
Me:  I only see an orange light.<br />
Her:  Is the green light solid or flashing?<br />
Me:  OMG</p>
<p>In the end I just told her to give me the case number and I would get a new camera because as much fun as this phone call has been I can&#8217;t take it anymore.</p>
<p>New camera arrived yesterday and appears to be working just fine&#8230;.for now.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/techdulla.wordpress.com/351/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/techdulla.wordpress.com/351/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=techdulla.wordpress.com&#038;blog=2345490&#038;post=351&#038;subd=techdulla&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://techdulla.wordpress.com/2010/07/23/support-just-keeps-getting-worse/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://2.gravatar.com/avatar/84a30a632b634932d0f6dc3a6323033d?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Techdulla</media:title>
		</media:content>
	</item>
		<item>
		<title>Apple does it again</title>
		<link>http://techdulla.wordpress.com/2010/07/01/apple-does-it-again/</link>
		<comments>http://techdulla.wordpress.com/2010/07/01/apple-does-it-again/#comments</comments>
		<pubDate>Thu, 01 Jul 2010 12:13:35 +0000</pubDate>
		<dc:creator>Dan</dc:creator>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[activesync]]></category>
		<category><![CDATA[iOS 4]]></category>
		<category><![CDATA[iPhone]]></category>
		<category><![CDATA[MAPI]]></category>

		<guid isPermaLink="false">http://techdulla.wordpress.com/?p=344</guid>
		<description><![CDATA[How a company can release a product as high profile as the iPhone and not realize there is a major flaw with the antenna design is beyond me.  But I received word today that there is another flaw, not just with the new iPhone, but with iOS4 that can wreak havoc on Exchange servers. Apparently [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=techdulla.wordpress.com&#038;blog=2345490&#038;post=344&#038;subd=techdulla&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>How a company can release a product as high profile as the iPhone and not realize there is a major flaw with the antenna design is beyond me.  But I received word today that there is another flaw, not just with the new iPhone, but with iOS4 that can wreak havoc on Exchange servers.</p>
<p>Apparently iOS4 can somehow make your Exchange server stop accepting MAPI sessions from Outlook clients.  Apple is aware of the problem and has released a <a href="http://support.apple.com/kb/TS3398" target="_blank"><strong>configuration profile</strong></a> that you need to install on the iPhone.  This is sure to be a pain in the ass for Exchange Admins as employees buy their own iPhones or update their 3G(s) iPhones with the new OS.  Way to go Apple!</p>
<p>Note:  If your Exchange server stops accepting MAPI sessions and you can not get the problem iPhone updated, disabling ActiveSync for the user at the Exchange level should open up MAPI again.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/techdulla.wordpress.com/344/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/techdulla.wordpress.com/344/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=techdulla.wordpress.com&#038;blog=2345490&#038;post=344&#038;subd=techdulla&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://techdulla.wordpress.com/2010/07/01/apple-does-it-again/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://2.gravatar.com/avatar/84a30a632b634932d0f6dc3a6323033d?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Techdulla</media:title>
		</media:content>
	</item>
		<item>
		<title>Here comes the bus</title>
		<link>http://techdulla.wordpress.com/2010/05/19/here-comes-the-bus/</link>
		<comments>http://techdulla.wordpress.com/2010/05/19/here-comes-the-bus/#comments</comments>
		<pubDate>Wed, 19 May 2010 15:55:23 +0000</pubDate>
		<dc:creator>Dan</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://techdulla.wordpress.com/?p=338</guid>
		<description><![CDATA[I want to get feedback from folks on this, so comment away.  Over the past six months I have been working with companies going over pro&#8217;s and con&#8217;s of moving their most critical service(s) off to the &#8220;cloud&#8221;.  I&#8217;m not going to get into the upside and downside here, because it is different for every [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=techdulla.wordpress.com&#038;blog=2345490&#038;post=338&#038;subd=techdulla&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>I want to get feedback from folks on this, so comment away.  Over the past six months I have been working with companies going over pro&#8217;s and con&#8217;s of moving their most critical service(s) off to the &#8220;cloud&#8221;.  I&#8217;m not going to get into the upside and downside here, because it is different for every service and every company.  A concern that has come up with the security folks involved is focused around their reputation and credibility.</p>
<p>One side of the argument is that their reputation is on the line regardless of where the data lives.  They are responsible whether it lives in-house or not.  With that line of thinking they are much more comfortable keeping the data in-house where they can monitor and manage it and everything around it.  Moving their data off to a Google Apps account for example, where they are limited in what they can implement for security policy and monitoring is next to nothing makes them very anxious.  They do not want their credibility as a security professional riding on Google.</p>
<p>The alternate argument is that by having the data in-house there are unrealistic expectations put on their ability to keep the data safe.  Nothing is 100% secure and therefore it is just a matter of time until it gets breached at which point they will lose a lot of credibility.  Moving it offsite, lets pick on Google again, seems like a great idea because if there is a breach they can stand back and say &#8220;Not my fault&#8221; because securing that data is no longer their responsibility.  The obvious thought there is that they can not be blamed for someone else&#8217;s mistake or lack of control.</p>
<p>Camp1 thinks that they are getting thrown under the bus the first time Google has a breach.  Camp2 thinks they will be driving the bus over Google when the SHTF.</p>
<p>I&#8217;ll save my thoughts on this until after people comment.  What do you think?</p>
<p>&#8211;DanO</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/techdulla.wordpress.com/338/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/techdulla.wordpress.com/338/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=techdulla.wordpress.com&#038;blog=2345490&#038;post=338&#038;subd=techdulla&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://techdulla.wordpress.com/2010/05/19/here-comes-the-bus/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
	
		<media:content url="http://2.gravatar.com/avatar/84a30a632b634932d0f6dc3a6323033d?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Techdulla</media:title>
		</media:content>
	</item>
		<item>
		<title>Feeling guilty</title>
		<link>http://techdulla.wordpress.com/2010/05/17/feeling-guilty/</link>
		<comments>http://techdulla.wordpress.com/2010/05/17/feeling-guilty/#comments</comments>
		<pubDate>Tue, 18 May 2010 03:11:31 +0000</pubDate>
		<dc:creator>Dan</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://techdulla.wordpress.com/?p=336</guid>
		<description><![CDATA[After reading Rich Mogull&#8217;s post at Securosis I couldn&#8217;t help but feel guilty for not blogging in AGES.  Rich&#8217;s blog is one of the reasons I got into blogging myself and as he states it allowed me the opportunity to meet people I otherwise wouldn&#8217;t have.  Twitter came along and has taken a big chunk [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=techdulla.wordpress.com&#038;blog=2345490&#038;post=336&#038;subd=techdulla&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>After reading Rich Mogull&#8217;s <a href="http://securosis.com/blog/is-twitter-making-us-dumb-bloggers-please-come-back" target="_blank">post</a> at Securosis I couldn&#8217;t help but feel guilty for not blogging in <strong>AGES</strong>.  Rich&#8217;s blog is one of the reasons I got into blogging myself and as he states it allowed me the opportunity to meet people I otherwise wouldn&#8217;t have.  Twitter came along and has taken a big chunk out of blogging, not only writing, but reading as well.   Is Twitter a replacement for blogging, it shouldn&#8217;t be, but it is a lot easier.  I never had any deep technical posts so can only imagine the work that the smart folks put into their posts.  <img src='http://s1.wp.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p>For the most part I have been staying off the radar lately.  As mom used to say, if you don&#8217;t have anything nice to say&#8230;..</p>
<p>Disenchanted would probably best describe my current feeling toward security.  Dealing with internal policy stuff has been tough, and talking with external companies has been even worse.  I used to think that people made bad decisions focused around security just based on their lack of knowledge surrounding it.  Given the proper information I believed that people would make sound decisions around the security of their information.  I&#8217;m not so sure about that anymore.</p>
<p>Whether it is a start-up or an established company it seems like no one cares about security.  I was talking with a CEO of an established company about their decision to move their messaging and document management to Google Apps.  I asked some questions about how they are dealing with certain security concerns and his response was &#8220;We never really thought about that.&#8221;  So then I described them more in depth to give him the information they didn&#8217;t think about and his response was &#8220;Well we don&#8217;t have anything important in email so if someone gains access it isn&#8217;t a big deal.&#8221;  I don&#8217;t know about you, but I can&#8217;t think of anyone that would be happy to find out their email was breached.  People don&#8217;t realize the amount of confidential information they handle on a regular basis&#8230;until it bites them in the ass.</p>
<p>Unfortunately this is not the only person with this attitude that I have been dealing with.  People, including but not limited to the decision makers, just don&#8217;t seem to care about security.  Make it available, make it easy, hope the odds are in our favor that it won&#8217;t happen to us.</p>
<p>I&#8217;m whining&#8230;I know&#8230;I&#8217;ll stop now.  A more uplifting post will come soon, promise.</p>
<p>&#8211;DanO</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/techdulla.wordpress.com/336/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/techdulla.wordpress.com/336/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=techdulla.wordpress.com&#038;blog=2345490&#038;post=336&#038;subd=techdulla&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://techdulla.wordpress.com/2010/05/17/feeling-guilty/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://2.gravatar.com/avatar/84a30a632b634932d0f6dc3a6323033d?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Techdulla</media:title>
		</media:content>
	</item>
		<item>
		<title>Misleading titles</title>
		<link>http://techdulla.wordpress.com/2009/12/02/misleading-titles/</link>
		<comments>http://techdulla.wordpress.com/2009/12/02/misleading-titles/#comments</comments>
		<pubDate>Thu, 03 Dec 2009 03:00:30 +0000</pubDate>
		<dc:creator>Dan</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[network engineer]]></category>
		<category><![CDATA[networking basics]]></category>
		<category><![CDATA[title]]></category>

		<guid isPermaLink="false">http://techdulla.wordpress.com/?p=331</guid>
		<description><![CDATA[I got roped into helping a company test their video conferencing equipment the other day.  They are in Colorado so this was all over the phone, fun times for sure.  A network engineer from the video company that sells and configures these systems was on the phone with me to do the test.  I figured [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=techdulla.wordpress.com&#038;blog=2345490&#038;post=331&#038;subd=techdulla&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>I got roped into helping a company test their video conferencing equipment the other day.  They are in Colorado so this was all over the phone, fun times for sure.  A <strong>network engineer</strong> from the video company that sells and configures these systems was on the phone with me to do the test.  I figured this should go pretty smooth since I have a <strong>Network Engineer</strong> from the video company in the loop.  Think again.</p>
<p>The system wasn&#8217;t working, all signs pointed to network issues.  He checked the IP settings and according to him they &#8220;looked right&#8221;, it was a public IP address.  I asked if the unit was actually sitting outside the firewall to which he responded yes.  We troubleshot a few more things before I asked if he was sure it was outside the firewall, again he said yes.  After another 20 minutes of him changing cables and rebooting shit I asked him to humor me and plug his laptop into the wall jack where the video system is connected so I can see what he is getting for an address.  It was a private IP address.  Sigh.</p>
<p>Ok, maybe it wasn&#8217;t his fault, maybe someone switched ports on him or something.  So I tell him that&#8217;s why it isn&#8217;t working.  He tells me it doesn&#8217;t matter.  WHAT!?  He set a static public IP settings on the system and it is sitting on the local LAN and he thinks it doesn&#8217;t matter.  Please explain to me why you think it doesn&#8217;t matter whether or not your system can route to any other networks, this I have got to hear.  He these systems don&#8217;t care if they are behind a firewall or not, they just work.  I had to spend the next 15 minutes explaining to him why that is not going to work.    He still did not agree and told me it doesn&#8217;t matter what he puts in for an IP address, the system will figure it out.  I thought for a moment like the guy was just messing with me, maybe I was being Punk&#8217;d or something&#8230;.but unfortunately he just didn&#8217;t understand networking.  I tried to humor him a little longer but when he started explaining to me that <strong>the Internet is like a cloud and their systems can talk to any other systems in the cloud regardless of where they are</strong> I had to call it quits.</p>
<p>I&#8217;m not sure how this Network Engineer got his title, but he wasn&#8217;t deserving of it.</p>
<p>&#8211;DanO</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/techdulla.wordpress.com/331/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/techdulla.wordpress.com/331/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=techdulla.wordpress.com&#038;blog=2345490&#038;post=331&#038;subd=techdulla&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://techdulla.wordpress.com/2009/12/02/misleading-titles/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://2.gravatar.com/avatar/84a30a632b634932d0f6dc3a6323033d?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Techdulla</media:title>
		</media:content>
	</item>
		<item>
		<title>Me no hungry</title>
		<link>http://techdulla.wordpress.com/2009/12/01/me-no-hungry/</link>
		<comments>http://techdulla.wordpress.com/2009/12/01/me-no-hungry/#comments</comments>
		<pubDate>Wed, 02 Dec 2009 02:28:57 +0000</pubDate>
		<dc:creator>Dan</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[default passwords]]></category>

		<guid isPermaLink="false">http://techdulla.wordpress.com/?p=328</guid>
		<description><![CDATA[I don&#8217;t know how those of you who blog on a regular basis do it. Props to you for the constant effort and dedication, I just can&#8217;t keep up. Things are good with me, been busy with planned projects but even busier with unplanned projects that seem to have appeared from nowhere. Here is a [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=techdulla.wordpress.com&#038;blog=2345490&#038;post=328&#038;subd=techdulla&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>I don&#8217;t know how those of you who blog on a regular basis do it.  Props to you for the constant effort and dedication, I just can&#8217;t keep up.  Things are good with me, been busy with planned projects but even busier with unplanned projects that seem to have appeared from nowhere.</p>
<p>Here is a funny little story I thought I&#8217;d share with you.  I am fortunate to work for a company that provides lunch for the employees every day.  Yes, every day they have lunch brought into the office for us, it is an awesome benefit for sure.  Recently they decided to change things up a bit and give us the option to order our own individual lunch.  Great idea, if you are in the office you can log into a website where you are given a list of local restaurants, choose what you want from any restaurant and it will be delivered with your name on it.  You are allowed a certain dollar amount to spend, and if you go over that you pay the difference.  Can&#8217;t beat that deal right&#8230;.or can you?</p>
<p>I decided to have some fun with the system, with permission of course.  What types of things can I do to this system, let the fun begin!  I was thinking of all the different types of attacks that I could use to beat the system, each one becoming more complicated than the next.  Then I sat back and thought for a minute&#8230;.why over analyze the situation. I decided that before digging in on a technical level lets just try some default passwords.  BINGO!!!</p>
<p>Before you could say enchilada I was able to gain admin access, make myself an admin, give myself a $1000 daily food limit, create new employee accounts, etc.  The next day I ordered food for a bunch of us on my account to see if it raised any red flags&#8230;it didn&#8217;t.  Then I decided to order on behalf of an employee that doesn&#8217;t exist and see if that raised any red flags&#8230;.it didn&#8217;t.  I mean come on, an employee named &#8220;Fat Guy&#8221; ordering family size portions of cannoli&#8217;s and cheesecake should at least draw a little attention.  The fun went on for a few days and needless to say we all ate pretty well that week.  <img src='http://s1.wp.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p>DO NOT USE DEFAULT PASSWORDS!</p>
<p>&#8211;DanO</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/techdulla.wordpress.com/328/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/techdulla.wordpress.com/328/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=techdulla.wordpress.com&#038;blog=2345490&#038;post=328&#038;subd=techdulla&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://techdulla.wordpress.com/2009/12/01/me-no-hungry/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://2.gravatar.com/avatar/84a30a632b634932d0f6dc3a6323033d?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Techdulla</media:title>
		</media:content>
	</item>
	</channel>
</rss>
