Google


WWW kriha

 

Systems and Technologies

Blog | Sitemap | Text Version | [Atom Feed]
datenschutzzentrum deutschlandstoppt-softwarepatente.deforum informatiker fuer frieden
Security Architecture in Browsers and Operating Systems, more...

A collection of interesting papers on Chromium, Vista, tainting, non-determinism by concurrency, Sel4 and anonymity in P2P systems. And about the bad effects of compatibility.

5th GamesDay at HDM, more...

The computer games industry is growing like never before. The development of computer games and extensions has become a billion dollar business. If you want to get an overview of the latest developments, the technologies and strategies behind, then the GamesDay is your event. Companies will demonstrate game development and products and you can get your hands dirty in workshops.

The topics covered include artificial intelligence, simulation of business processes, building extensions to well-known games, the development of mobile games and game engines and many more.

[Note]Note

13.6.2008, 9.00, room 011 (audimax), GamesDay at HDM Nobelstrasse 10. Open to the public and free of charge. You can find directions to HDM at the HDM homepage . Agenda and url for live stream, chat and blog can be found at the GamesDay Page.

Web Developer Day at HDM, more...

On our third web day we have a focus on the latest development technologies on the web. We will show data mining technologies, usability approaches and especially various client facing technologies. Microsoft will present Silverlight and Adobe will do the same with Flex and Air. Last but not least deployement and maintenance of web apps will be discussed. Colleagues from the faculty for audio-visual technology will present a collaborative 3D site based on Adobe Air.

[Note]Note

30.5.2008, 9.00, room 011 (audimax), WebDeveloper Day at HDM Nobelstrasse 10. Open to the public and free of charge. You can find directions to HDM at the HDM homepage . Agenda and url for live stream and chat can be found at the WebDeveloper Day Page.

API is UI or "why API matters", more...

Few programmers are aware that API design really is user interface design. And few know some basic rules on API design like minimal interfaces etc. Here is some information extracted from an excellent article in QUEUE (the ACM magazine).

Risk processing with our stone-age brain, more...

After the freeway killing: are you scared about driving below highway bridges? Do you think about the incident while driving? How rational is this behavior? How natural? Read about surprising ways our stone-age brain does risk assessment and take a look at some real risks.

OpenID and Cross-Site Access Control Specification, more..

I have read those specs recently and I do not really understand them well. Read my objections and tell me where I am wrong. I will discuss both later in detail..

Morphware and Configware - a new computing paradigm, more..

This is a discussion of a very interesting paper by Reiner Hartenstein, TU Kaiserslautern, on the success of FPGAs and the problems of programming configurable hardware. He describes the benefits of configuration (improvement of the von Neumann Architecture) and we software people understand the problems of it by now as well (;-). At least in software there is a trend back from configuration to more flexible programming languages.

I found the article in the book "nature based computing" which I had ordered for distibuted systems in the winter term. There are quite a number of nice papers, e.g. on hardware architecture, statistical methods and swarm computing.

The current banking crisis, more..

Thanks to input from Roger Stampfli I was able to assemble a nice collection of papers and videos on the current crisis. It is actually quite frightening to realize how badly the bankers and brokers have been gambling and how badly the national banks are now reacting by printing ever more money. Being a fan of cybernetics it looks to me as if the abuse of the financial systems is now threatening the whole. This crisis could start the end of capitalism. But will it change back to a state-run bureaucracy that has already once shown that it does not work? Or will it change to something better?

Trends in the internet of the world, more..

The fallout of an interview for the SWR. Tackles the physical structure, connectedness and bottlenecks (which could be control points as well), countries and people falling into the digital divide, the access problem and the danger of google dominating the world. And some austrian whining on plagiarism in the humanities being supported by google. The diagrams created from the netdimes project are really nice..

Service Level Agreements - or how to turn friends into enemies.

Some things just never cease to surprise me - especially all things business. SLAs are one of them. Does anybody REALLY believe in those instruments? Is it REALLY better to turn the relation between business and IT within a company into a legal minefield? Read about some fundamental doubts on this vision.

Social Intelligence and Social Computers - the future of Computer Science, more...

Inspired by swarm intelligence, human centric computing and the general fear of all things social a short piece on why intelligence is socially based, what kind of role the Internet plays in fostering this type of intelligence and who the enemies are. Includes a discussion of Shirky's "here comes everybody".

Test and Quality, Security, Web Development and Games - four new Days in the summer term

We will have four days in the (short) summer term. Testing of web applications, of open source programs, test methodology, risk assessment and psychology, forensics and industrial espionage, the latest in web development frameworks and tools and last but not least the development of games and the communities supporting them. These are all topics in the upcoming Days.

[Note]Note

If you are working on something in those areas, perhaps just about ready to finish your thesis, or you are an industry-specialist in those areas. Please get in touch with me if you would like to participate.

The future of computer science - 10 years CS&M, more..

The computer science and media faculty at HDM proudly celebrates its 10th anniversary. If you want to know what CS&M graduates do, just join us on Thursday for presentations by our alumni. If you have questions about the future of computer science and its general course - say you don't believe that IT's job is to create Orwells 1984, spam and malware, then you should attend our sessions on the future perspectives of computer science. Ambient intelligence, mobile networks and a social, utilitarian future based on computer science paradigms are our topics.

And enjoy the HDM Media Night right after our event. Besides state-of-the-art IT technology like multi-touch screens etc. you will be able to watch all HDM projects of this term. Movies, computer animations etc. give you an idea of the creative potential of HDM Stuttgart.

[Note]Note

24. January 2008, HDM Stuttgart, Nobelstrasse 10. 9.00 - 16.30. Free of charge and open to the interested public.Live stream and chat available, see agenda .

Intelligent Web Day at HDM - semantics, search and interaction , more..

The web is an incredible source of information - if it can be tapped. Google is doing it rather successfully. But how can you tap into this well? Machine learning is getting really important in the context of collaborative sites on the web. How can you extract information from web and wikis? How do semantics and search work? How do you use meta-data as annotations to drive new and better GUIs? The answers:

[Note]Note

14. December 2007, HDM Stuttgart, Nobelstrasse 10. 9.00 - 16.45. Free of charge and open to the interested public.Live stream and chat available, see agenda .

4th Games Day at HDM, designing virtual worlds , more..

Desing and content, not raw technology are key in our 4th games day. Learn how to create virtual worlds. See live game demonstrations and discuss current and future trends in gaming and game industry. Beginners welcome!

[Note]Note

7. December 2007, HDM Stuttgart, Nobelstrasse 10. 9.00 - 17.30. Free of charge and open to the interested public.Live stream and chat available, see agenda .

Are security laws "immutable"?

and why would somebody say so? A short bit on so called "immutable laws" of security proposed by Microsoft guys. I've used structural text analysis methods to uncover the assumptions behind. It's the typical MS argumentation: the operating system is OK. Systems can't be safe against malware. It has nothing to do with architecture. And it's the users fault anyway.

The things that make computer games playable, more..

No, it is not the latest in computer graphics that makes games successful - at least not the animation alone. Good games offer good game play mechanics - in other words good ways to interact with the game (and perhaps other players as well). But the mechanics are not enough by far. On top of this good balancing is required to make a game fun to play. Read the thesis by Thomas Fuchsmann to understand how games tick.(BTW: we call the person who has fun with a software game "player" - and we call the person who runs office software "user" - ever thought about this?)

Virtual Worlds - Party or Content, more..

The presentation of the HDM media jungle raised some heated discussions on design, goals and content (or its lack of). But do we know the language and rules of virtual worlds yet? On growing pains of technologies and media channels.

Failed PCs and failed objects, more..

A paper from Alan Kay et.al. on how to design a PC that enables the user (everything an object, scriptable, self-explaining, tractable, minimal and compact etc.). I did not understand everything (take a look at the bootstrapping section) but it sounds fascinating. Aand Richard Gabriel on reasons why the object approach failed in many cases. Gabriel argues for a multi-paradigm approach to software and I think he is right.

So you are famous now, more..

Security warnings from Heise made you and your application famous! And in times of viral and guerillia marketing we all know that bad publicity is better than no publicity. But there are cases when you might not really like the publicity. Read on how the talks from our Security Day might save your butt one day!

Quality Software needs Time, correct? - more...

Timesheets are important for software management - a myth according to some studies. How much do software developers differ with respect to productivity and quality? Read on.

Internet-Security: Grundlagen, now in print, more..

Looks like it is finally done. The first volume is in print, the second one on "Sichere Systeme" needs to be proofed and will follow shortly.

Additional information, bug-fixes and the slides will be privided here, as well as Q&A stuff. The authors welcome comments and suggestions for improvement.

Mashups, Gears, Scalability and so on - Google Tech Talks, more...

Use tech talks to learn more on scalability, mashups, model-based-testing etc.

5seats and more, intersting software projects at CS&M .

At the end of the term our computer science projects are presented to the public. And as always this has been a demonstration of ideas and know-how. Need to find out what makes a Web2.0 application? Take a look at 5seats - a smart application that avoids empty cars being driven around. Built by Benjamin Kenner, Matthias Hahn, Marc Böhret with Ruby on Rails/REST etc. it is a wonderful showcase for Web2.0. But there is much more so take a look at the list of projects . And last but not least a wonderful computer animation about our future according to Orwell. Watch Benjamin Zeiser's Panopticum .

An integrated view on web application security, testing and Web Application Firewalls (WAF), more...

Application Architecture needs to drive application security internally, external security components like WAFs and the whole testing process. Read more about some ideas to leverage application models. Application security is going to be a core topic for our next Security Day. And read more about current security related work at HDM.

5. IBM Day - Data Warehousing, Data Mining etc., more...

Christian Brabandt and Otto Görlich from IBM GBS will talk about on demand information and how it is created, how it works in large data-warehouses and the latest changes in technology and business.

[Note]Note

Friday 22.06.07 at HDM Nobelstrasse 10. Room 148. 9.30 - 12.15. The talks are open to the public and free of charge. See HDM Homepage for directions, agenda and streaming information.

CS&M at the BSI conference, more

A few words on the 10th BSI conference at Bonn-Bad Godesberg.

Nerds and geeks in lack und leder - Beyond Fear Tour II

The story of our second motorbike excursion and some pics..

The people problem, more...

Computer science discovers humans..

MI-Stammtisch Zürich Section, more...

hard working MI specialists in Zürich...

Secondlife - making the virtual life work like real life

Secondlife is just like Digital Restriction Management - a backward view on the possibilities of "being digital". It is important to separate the centralized business model from the the technical and social opportunities of virtual worlds. Are there distributed alternatives? SeeOpenCroquet Article from Heise News.

On PCs as appliances and the merits of security testing, more...

Just some reflections on our - very successful - first Security Day at HDM.

The problem of many speakers, more...

Events from our computer science and media faculty are frequently streamed into the internet. We have built a nice, mobile streaming solution. The only problem left is how to capture voices from the audience without having to run around with a microphone and yelling "stop, wait for the mic." at the speaker. I've got two ideas on how to solve this problem: balloon-microphones and the throwable multi-party microphone.

2nd Games Day at HDM - play a game and go to jail, more...

The second Games Day will put the focus on "positive" aspects of computer games, with the help of Dr. Reinhard-Hauck from PH Ludwigsburg.

Presentations will cover technology, arts and economics behind games development: cell chip internals, audio and sound in games, game economics and a large game project. Louis Natanson from our partner university Abertay will present studies in games development and creativity.

[Note]Note

15.12.2006, 9.00 at HDM Nobelstrasse 10, room 056, open to the public and free of charge. See HDM Homepage for directions and program

Finally - the second volume "Sichere Systeme" is done!

And just at the right time: system security is slowly getting more attention with google and microsoft trying new browser architectures. The book covers a lot of critical areas: usability, attacks, platform security and frameworks, browser archtictectures etc. I will also post links to papers and thesis work from HDM people. We had some good work recently on concurrency, anonymity, tainting and Sel4. And we managed to get a guest author: Fred Spiessens wrote a chapter on a langauage and model checker for capability systems. Scoll and Scollar are now an open source projects.

Infoq.com - the new portal site, more...

Take a look at an amazing new portal site for IT-interested people. Excellent articles and videos from on of the makers of theserverside.com.

Security Day on Risks and Security, more...

Lidl and Co. - is security making our life better or worse? Who wins, who loses? And how do we deal with risk in general. If you want to learn more about the psychology, sociology and technology of risk and security, this is your day. An excellent panel of speakers will take you on a tour around all aspects of security and risk. From the underground economy and abuse of systems to the dangers of total control, mixed with concepts and tools for anonymity or safer e-commerce. And at the beginning we will take a view on the history and social evolution of risk and its assessment.

[Note]Note

25.4.2008, 9.00, room 011 (audimax), Security Day at HDM Nobelstrasse 10. Open to the public and free of charge. You can find directions to HDM at the HDM homepage . Agenda, url for live stream and chat can be found at the Security Day Page.

Test and Quality Day at HDM, more...

There is a clear pressure on the software industry towards better quality software. Testing is becoming a core competence for developers too who need to learn a test-driven software production process. And architects need to understand what applications have to provide to make testing easier. Model-driven development and testing are core technologies here.

Meet industry specialists and learn about test methodologies, procedures and real world tools to test web-based and other software.

[Note]Note

Test and Quality Day at HDM, 11.04.2008, 9.00 room 56 at Nobelstrasse 10, Stuttgart. Live stream and chat channel are provided. Please see the HDM homepage for agenda and travel info.

IBMs new Unified Method Framework Methodology, more...

The Computer Science and Media faculty at HDM is one of the few universities in the world that has IBMs blessing to teach this special methodology. It has its roots in the Global Services Method and the Rational Unified Process Methodology. In its fifth installment Bernard Clark, Senior IT Architect and Managing Consultant at IBM GBS and University Ambassador for HDM will cover new channels and media in the financial industry. Governance, service-orientation etc. will be big topics of the workshop as well. Particpants will learn the continuous refinement of visions to tractable models and methods.

[Note]Note

Starting Friday 28.4.08, 9.00 at HDM Nobelstrasse 10, room 041. Contact me if you want to attend.

Thou shallst not write parsers by hand, more..

Only a short reminder that parser generation toolkits exist (like Antlr) and that they should be used for reasons of quality and maintenance. And a mentioning of the second edition of Wirths book on compiler construction which is just unbelievably well written - in case you need to stock up on compiler technology and are too shy for the 1000+ pages of the dragon book. Go get Wirths book! At 24 Euro this is a bargain!.

Cold Reading Patterns - when profiling meets the astro channel, more..

I had lots of fun lately with an issue of cryptogramm. Schneier mentioned an article that described the patterns of explanation used by criminal profilers as cold reading patterns. In other words: language pattens destined to create vagueness and to avoid being caught with a wrong statement? Who would have thought that profilers use those?

Security as an eduction problem??, more..

A few comments on a CCCS talk on web application security and a rant against the "security is an eduction problem" for both users and developers. There are too many counter-examples. Security needs to be built in. Otherwise we should tell the car makers to finally get rid of all airbags and safety belts: its all a matter of disciplined driving.

Sex, Lies and Appliances - how to tame the anonymizer, more..

I read a disgusting piece of advertisement by a security company who offers a filtering appliance against the threat of anonymizers. Typical US lingo, full of rightousness, scares of legal repercussions and turning everybody into a little "sheriff". Not to forget the lack of technical information or its weaknesses. Trying to detect the use of an anonymizer through URL filtering and rules is rather hard with an SSL tunnel!.

Joe Weizenbaum or the hunt for natural intelligence

A short obituary on Joe Weizenbaum. I used it to paint a picture of computer science that ranges from the happy days of naive adoption to the current time of total control. Who would have thought that things could ever get this bad?See how far human reason has lost against the power of control through computers.

Multi-faceted client identity or the misconfigured SCIP problem, more...

An addendum to the first security book on the problem of badly configured SCIP proxies which map serveral different client IDs onto one SSL-SessionID. When client identity becomes a heuristic outcome. (Thanks to Matze Schmidt and Thomas Huber).

Free your phone - Iphone, OpenMoko etc, more..

An apple video, a thesis on OpenMoko and some thoughts on openness and smartphones with almost desktop power.

Linux Day at HDM - the revolution OS in action , more..

Learn more about using Linux on mobile systems, for high-availability applications or for the building of secure systems. Meet Linux afficionados or simply interested users and discuss the future of this extremely successful project. And meet the new KDE4.0 desktop environment and celebrate with us its release at our release party (starting at 18.00 at our S-bar).

And use our blog at linux-day.de . You can find there also the map of the KDE release parties all over the world.

[Note]Note

18. January 2008, HDM Stuttgart, Nobelstrasse 10. 9.00 - 16.45. Free of charge and open to the interested public.Live stream and chat available, see agenda .

Security in Online Worlds , more..

An excellent thesis by Martin Scheffler on the use of capability-secure languages in scene graphs. Shows the lambda based capability patterns like facet, forwarder and sealer/unsealer at work to allow anonymous, distributed and context dependent access control.

What agile people need , more..

Our development day showed why agile people need agile methods and languages. There is a tight connection between agility and tools. Read on why I think we lost the agility and what can be done about it.

What makes good software development , more..

Our first developers day has its focus on agile development. Read on why this is not a new fad but has always existed. Still, it is getting more popular nowadays, perhaps due to the ever increasing weight of .NET and J2EE, Java and C++ etc. Learn alternative ways to program fast, agile solutions and have fun doing so. But perhaps you are a manager? Learn how agile methods might save your project. You don't have to be an expert developer to profit from this day.

[Note]Note

23. November 2007, HDM Stuttgart, Nobelstrasse 10. 9.00 - 17.00. Free of charge and open to the interested public.

Web Application Firewalls to the rescue, more..

Want to know what a WAF can do for your health? Don't wait till you get an honorable mention in newspapers for your security leaks. Learn how to profit from a WAF both in case of an emergency and as a long term defense in depth strategy. Learn what they can do and how. Read the thesis by Sebastian Roth..

Findability and Collective Intelligence, more..

Two rather new books on social and psychological aspects in search and web applications. The "soft" sciences are really getting into our turf...

Modeling Distributed Systems, more..

Even small solutions consisting of few components and processes show a surprising level of complexity once errors, life-cycle phases and special qualities are introducted. Mostly it is the experience of the developers (that's why older seems better here) that controls the chaos - somehow. An example case and some ideas on what we would need to create practical models of distributed systems and what we would like to express.

2. Security Day at HDM, more..

Our second security day at HDM has a focus on application security. Web applications firewalls, strong authentication, mainframe security and penetration testing help developers create and run secure applications. The development process of secure applications is also presented. A live-hacking demonstration gives a clear of vulnerabilities. The management of vulnerabilities will also be discussed.

[Note]Note

19.10.2007 at HDM Nobelstrasse 10, Stuttgart. See www.hdm-stuttgart.de for further information. A live stream will be provided as well. The event is free of charge and open to the interested public.

A how-to of organizing events, more..

A little write-up (with the help of Mareike Lattermann) to help students in organizing our days.

The thing from the internet - a good way to create awareness?

How to scare people for all the wrong reasons. Some funny "fifties" posters on security topics. But are they really teaching the right ideas or are they just documenting and re-inforcing what is wrong in our software? The "duck and cover" approach to bad security design?

Usability and Security, more...

The KES article that Roland Schmitz and myself wrote is now available online. Core topic: usability chances in a world of reduced authority.

Ideas for a Web3.0 day, more...

Semantics, searching based on different approaches, data-mining and meta-data used by ever more Javascript on the client side. Read more about current projects with UIMA etc.

IT and the law - results from the Digital Rights Day™, more...

Does IT change the law? Does the law cover virtual worlds? Have we lost the war on civil rights? Read more on the results of our Digital Rights Day and get an idea what is coming up next.

1. Digital Rights Day at HDM - the digital assault on civil rights

the first digital rights day covers important topics from internet right, open source, patent right and last but not least civil rights. Not to forget the legal aspects of virtual worlds. Well known lawyers and members of the Chaos Computer Club will guarantee lively sessions. Kurt Jaeger as a representative of the "Freiheitsredner" and head of a local ISP will talk about the various aspects of freedom.

[Note]Note

Friday 15.6.07 at HDM Nobelstrasse. 9.00 in room 56 (aquarium). Open to the interested public and free of charge. Agenda, directions, streaming etc. at: HDM Homepage

3rd Games Day at HDM - game engines and virtual worlds

Just a few comments on our most successful games day ever.

Computer Science and Media

Julia Duwe wrote a very nice article on the why and how to study computer science and media. She took our faculty as a role model. Her article has been printed in unicum magazine

The security-industrial complex (SIC), more...

Is there already a SIC in place - just like the well-known military industrial complex? Is there still an interest in systems that are more secure - or is this considered damaging to a thriving business?

Authority reduction in Vista, more...

Does it really improve end-user security? Or does it only help Microsoft? A short discussion of an article by Joanna Rutko.

Political Patterns, more

Looks like the "soft" sciences are getting more and more important in computer science. Usability needs a lot of psychology. Security needs a lot of psychology as well. As IT is becoming truly ubiquitous knowledge of the patterns of political manipulation is becoming more and more important.

First Security Day at HDM, more...

The CS&M faculty is pleased to announce the first Security Day at HDM.

Presentations will cover various aspects of current security research and development. Specialists from the industry as well as CS&M members will demonstrate platform security, infrastructure solutions, application security and last but not least current crypto applications. E.g. learn how to approach a security concept for mobile devices or how mobile DRM works.

[Note]Note

12.1.2007, 9.00 at HDM Nobelstrasse 10, room 056, open to the public and free of charge. See HDM Homepage for directions and program

Games Day Results, more...

There where quite some things to learn from our Games Day. E.g. how distributed the reality of games development already is, how audio and sound work in games, how to program the cell chip and finally how to organize a huge game project at HDM.