Saturday, January 9, 2010
Data vs Life.
Relativity theory of training and travel
Tuesday, January 5, 2010
Considering Privacy and Copyrights
Sunday, January 3, 2010
Taking Tests, Social Engineering and Acting....
Sunday, December 13, 2009
Holiday wishes:
Monday, November 30, 2009
Whitehouse security breaches and Balloon hoaxes
Thursday, November 19, 2009
Should Windows be Free?
There are different meanings of "free" in this conversation. As the phrase goes "Free as in speech, not as in Beer". In one case free refers to open sourcing the code, and in the other, it means being available free of cost or licencing fee.
I suppose my question could be interpreted either way. In the free of cost point of view, they did with IE back in the Netscape era, and giving away Windows would certainly impact competition with Linux and Apple.
Some argue that Microsoft's own practices propagate much of the security issues we have today for example, if Windows was free this wouldn't happen (http://www.pcmag.com/article2/0,2817,2355982,00.asp). We would also not have to worry about Virtual Machines being considered entirely knew instances of the computer. The world would be such a simpler place if there was no need for hacked copies of Windows operating without security updates. How much of the botnet activity on the Internet can be traced to this? Consequently, I would be out of a job, as would entire research companies.
I won't get into the economic dilema's of solving problems entire industries are built around, but the term "disruptive technology" comes to mind. What would be more disruptive than an Open Source Windows OS? If Windows 7 was believed to be secure, and the average price of a laptop or desktop was nearly a factor of 10 less than Macintosh ($300 vs $3000 after hardware upgrades) how would that impact Apple? If the Open Source community were willing to use Windows would Linux be necessary?
Either way, an alternative revenue model would have to be created. Programmers deserved to be paid too. Whether this would be any better or worse than what we currently deal with would remain to be seen.
Monday, November 16, 2009
CEH Review Guide is Released !!

The process of writing was extremely interesting. Being my first one, I learned alot that will make the next one twice as easy so I definitely hope to do this again. Thanks to Larry, Nick and Barry for their help along the way.
Friday, November 13, 2009
A Reminder About Using Wifi On The Road
Thursday, November 12, 2009
Teaching Abroad - Germany
Thursday, October 29, 2009
Intense School featured on "The Today Show"
http://today.msnbc.msn.com/id/26184891#33530153
Thursday, October 22, 2009
Should practices tests be perfect?
Tuesday, October 20, 2009
Two Tenents of Teaching
Monday, September 28, 2009
Hacker Halted Wrap-up
Friday, September 25, 2009
Hacker Journals - Examples fast and noise free
Sunday, August 16, 2009
Series (2 of n): How practice questions work
- What do you want the tester to prove he understands?
- Is this better asked directly or indirectly?
- Should they answer the right answer or illiminate the from the wrong ones?
- Is this a question where distractin noise is appropriate, or should you just keep it short?
- What objective of the final "real exam" goal is this practice preaparing them for?
Thursday, August 13, 2009
Process Oriented Programming
Friday, August 7, 2009
"How to solve it"
These are probably the best four suggestions I can give a student on how to deal with the CEH/ECSA/LPT materials. Remembering first off that perhaps the most fundamental heuristic is "trial and error".
- If you are having difficulty understanding a problem, try drawing a picture.
- If you can't find a solution, try assuming that you have a solution and seeing what you can derive from that ("working backward").
- If the problem is abstract, try examining a concrete example.
- Try solving a more general problem first (the "inventor's paradox": the more ambitious plan may have more chances of success).
Wednesday, August 5, 2009
Series (1 of n): Using practice exams effectively
Part of the current book project I am doing involves writing practice questions. In doing this I have put a lot of thought into the topic and wanted to share some of that here.
First, just to get the controversial part out of the way, I believe in practice questions. They are ethical and it is fair to try to get them as close to the real thing as possible, at least in terms of scope, style, and difficulty level of the real test. That is my opinion and other instructors might disagree.
A risk of providing practice exams is realized if the student can subconsciously understand them to mean "The instructor is essentially taking this test for me, if I do what these questions say and I will pass." I say subconsciously because I have never heard a student actually say this out loud, but I can tell by the way they ask questions about the exam and their general preparation habits when this perception is taking hold. This is the source of the understandable criticism of practice tests, but it can be managed and handled correctly.
As I write the questions for the book, I am placing in some controls. In the interest of security-open-source-minded full disclosure I don't mind explaining them. The best cryptosystems are well known and understood, but are still hard to solve. That is the good model for practice exams as well. Along the way, discussions about real exams are likely to be brought up as well.
To keep the blog postings reasonable in size, I will address specific topics of practice exams, and how to get the most out of them over the course of several postings. In case you are working on some right now start with this thought:
“Practice exams are extensions of lab, lecture and other learning modes. Not replacements for them, and not shortcuts to avoid them.”
