Friday, July 14, 2006

Try Adobe LiveCycle Policy Server online.

I guess this is a great follow up to my last post pondering whether or not the theft of Coca Cola recipes was preventable. Adobe has now offered the Adobe LiveCycle Policy Server as a service. Aside from trendsetting by offering software as a service (SAAS), this provides an excellent opportunity for anyone to test drive the functionality without having to download, install and configure the Policy Server.

The service is easy to use and can be used with Acrobat 6 or 7 although 7 offers higher security by utilizing the AES encryption standard in 128 bit cyher strength.

The Protected PDF service is now available as a public beta (users need to create a free trial account). You can access it either via the Create Adobe PDF Online service https://createpdf.adobe.com or directly via https://policy.adobe.com/spdf/login.do

Policy Server protects PDF documents and will not allow them to be rendered unless the policies declared by the document owners have been satisfied. Even then, APS might not allow certain types of interactions with the documents such a printing or copying parts of the document.

What I like doing is also using it as a tool to see how many people actually read the stuff they ask you for. Any PDF document can be audited to see who actually read it, for how long and what other actions they took.

Wouldn't it be fun to ask someone to summarize a document you sent them when you know for a fact they haven't read it? Oops - now my prankster side is emerging.

Wednesday, July 12, 2006

Another preventable theft of IPR? Maybe.

In my position as a technical evangelist, I often get opinions flying at me left, right and centre (note "correct" spelling of "centre") of issues. One recent issue that blew me away was in response to a news bit about how the FBI allegedly stopped an espionage ring from stealing a secret Coca-Cola recipe and selling it to rival Pepsi.

Given I usually talk about how using Adobe LiveCycle Policy Server could have prevented such things, many people were eager to come up to me and express that I should write about this. I am hesitant to make any such claims for a number of reasons. First - if you are dealing with people who have access to information and they are really intent on betraying your organization and leaking the information outside, there is little you can do to stop them. Employing some advanced information assurance technology like Adobe Policy Server or Microsoft’s Rights Management Server will do little to thwart someone with a pen, paper and access to the recipe or a digital camera. Secondly, if you can render something once, you can capture it and re-serialize it to distribute electronically later. The side channel art of deception is also commonly referred to as "Social Engineering".

People looking at Policy Server need to be very clear on their expectations. Policy server can do a number of very important things to protect digital property. Looking at the scenario at Coca-Cola, I would have recommended the following:

  1. Any recipe document should have been policy protected and available only to a very small list of people who were supposed to have access to it. I would also place a large watermark on the document so each of them know that if they release the document it can be traced back to them.

  2. I would audit the list of people who have access rights and immediately suspend rights to anyone who no longer needs to have the information.

  3. When the document is stored, it would always be encrypted using the AES 128 bit cipher.

  4. I would regularly audit the trail of document interactions to see if there are any patterns that would indicate a problem such as an employee repeatedly rendering it and trying things like Printing, Control-Printscreen, Cutting and Pasting etc. If these patterns persevere, it could be indicative of a problem.

  5. In the event that the recipe did leak out, I would immediately make that document non-render able.

  6. Each document involved in the process would have it's entire process model documented and would be immediately deprecated and non-render able once it is no longer required.

In short, no matter what security system you put in effect, someone can and will find a way around. What Applications like Policy Server do is make it more difficult for people to do front channel attacks, often drawing more attention to themselves as they have to develop side channel tactics.

On a side note, no one has yet claimed the $500.00 I offered if this Adobe Policy Server protected document could be rendered. It is still up for grabs if anyone thinks they can defeat Policy Server. The cash is sitting here – waiting for you.

Monday, July 10, 2006

Johnny Rotten, Artificial Intelligence and LiveCycle

My new photo, taken by Matt Mackenzie, has caused a stir in the tech community, but in my own true fashion, I really don’t care. So What!! The concern seems to be that I have a striking similarity to Johnny Lydon a.k.a. Johnny Rotten of Sex Pistols and P.I.L. fame. Of course - as a punk musician, the Pistols were one of my all time favorite bands and a major influence. In fact, my new band, F.L.U., is heavily influenced by a sound created by the Pistols. I also find that P.I.L was imenseley more musically interesting than the Pistols. Therefore, I find any comparison to Johnny a major compliment and there are some similarities:

1. Neither of us is complacent. If something is broken - do something about it.
2. Both of us are musicians who write and perform politically driven music.
3. We both push the boundaries. No society advances without someone constantly provoking it. People hate it but it needs to be done.
4. I guess there may be a slight resemblance between my picture and some from his site but you judge. I personally thought I was more like Billy Idol from Gen-X. Met the guy once - we do look alike.



Do we look alike? !!! Or do I look more like this:



So what the hell does this have to do with artificial intelligence and Adobe LiveCycle. Artificial Intelligence is a huge waste of time and will never work. What is promising is the concept of Computational Intelligence or getting computers to aspects of mimic intelligence based on our expectations. There are two very important and almost always neglected aspects of CI. One is the lack of context. Context is everything, especially for inference. Look at the Sex Pistols putting out Never Mind the Bullocks made a lot of people at the time very upset for a number of reasons. It was insulting to the queen of England and talked about real things we all think. Keep in mind this perspective, the Queen of England once hated Rock and Roll, but has since knighted several rock musicians. In the context of rock’s invention, it was not accepted however over time, it became an acceptable art form (WFT that really means). Looking back now, the Pistols got an entire generation to sit up and say "something’s not working here and were pissed". In the right context, I would nominate Johnny and the boys for giving an entire generation the message that they better think for themselves and things can be changed. It changed my life. When I had the chance to work for the United Nations and be disruptive and tell people who were full of crap that they were full of crap. I did it and I am proud of that.

The point is that Context is everything and most approaches to artificial intelligence seem to be rather static than dynamic. Most of the AI research to date in the field of Ontologies and semantics seems to take a hard coded approach. This is not how humans think.

To add to the problem, there is one other important thing that humans do well that computers cannot do as well. This is excellently summed up in David Luckham who I consider a genius in every sense of the word. Definitely on par with Johnny. Simply stated, it is the ability to detect two events, recognize the context in which they occur and understand the causality relationship between them For example, if you came home and saw that your spouses car was gone, that is one event. If you then saw a guy carrying a TV around the corner, that in itself is another event. Now put the two events together and the causality may point to a situation where they are stealing your TV because the house is empty and they helped themselves. Easy for a human, not so easy for a programmer to capture this model in a generalized sense so it can be reused over multiple examples.

To make Computational Intelligence work, one would require a model for Complex Event Programing, an inference engine using something like the Blackboard patterns with a hypothesis limiter on it to negate the exponential hypothesis problem, a context ontology to layer over top of whatever semantic reasoning one might employ, and a large enough source of events that be used to feed it all. The latter is very important since event isolation would lead to an incomplete set of events to mine for the inference component and probably miss key things.

This is where Adobe LiveCycle enters. LiveCycle, as a platform, has several key places where events are captured and stored in a manner that they can be audited later. The next generation of the LiveCycle platform and the blades that plug into it carry a much more complex series of audit trails than the last version.

Here is a hypothetical situation where a phishing attack is starting. A mass email goes out and tells customers of a bank to use their forms to change their password because of a security breach. If you use LiveCycle Forms, served from a LiveCycle Form Manager, you will generate an auditable event each time one of your customers grabs the form. If your customers account is then accesses and a transfer form is filled out, that will also generate a second event. You now have two events that have a relationship to one thing - the unique account. This should be a relatively easy pattern to catch if you are using LiveCycle as a platform over your IT infrastructure. If you were to use multiple disparate technologies, it could also be caught however this may take more hard work to account for different Document models and mine the events at the same level of granularity.

LiveCycle Policy Server will be able to make events accessible in the LC 8 release and via the SDK, some events are available now. This should be useful to companies who are serious about thwarting criminal behaviour linked to people using their IT infrastructure.

Back to Johnny Rotten now. Things have to change in the world. The pistols and PIL changed me and now I am feeding back change into the world. People need to start thinking about this stuff and start finding ways to fix it. Come to think of it, I guess I am not too changed from my previous punk days. The picture on the left was taken in July of 2006 ;-)

Adobe LiveCycle: why is it so boring?

So you might think that is a funny title for a blog entry made by a guy who is supposed to be the evangelist for Adobe LiveCycle. I mulled it over for quite a while before deciding that it really is accurate and portrays what I want to say.

For those of you who do not know what LiveCycle is, it is a core part of Adobe’s engagement platform. Essentially, it is a platform plus a series of servers that provide core functionality to act as a bridge to allow an enterprise to engage the far edges of the internet in a variety of ways. The marketing spiele states:

The Adobe® LiveCycle® family of J2EE-based enterprise software enables organizations to create, deploy, and optimize solutions to more efficiently capture, process, and archive information. It combines robust process management with electronic forms, document security, and document generation in an integrated and cohesive set of products that work inside and outside the firewall, for users in online and offline environments.

LiveCycle solutions leverage the universal client Adobe Reader® software and Intelligent Documents based on PDF and XML to capture information from users and automatically process it to the back-end or transaction systems that need it.”

For more about what it is, just visit http://www.adobe.com/products/livecycle/

The top four reasons why I think some find it boring?

  1. Most successful technologies are very simple and do something so well that they are often forgotten. Think about HTTP – you don’t see analysts and press talking about how radical and exciting it is. HTTP simply is a workhorse that does something extremely useful to the benefit of everyone. Once it is up and running, you tend to forget about it unless you have a problem. Adobe LiveCycle is a workhorse – most people are more interested in what it has done rather than how it has done it. Once it is deployed it sits there quietly in the background just performing its tasks. Not really that exciting…
  1. Another trait that well designed and well thought out technologies have is that they solve a problem and do it well. Once the problem is solved, the IT group moves on to the next problem and unless something breaks, tend to somewhat forget about the problem they just solved over time. Once you deploy LiveCycle to do something, you should hopefully be able to move on to other problems and more or less forget about it.
  1. LiveCycle does the middle tier connecting. Simply, with all the buzz about Application Servers and Rich Internet Applications (RIA’s), the workhorse (the middle tier) is often neglected. Although absolutely essential, most people will never see it directly, only interact with it other that the results. Look at components like LiveCycle Assembler. It gathers data from various other sources and serves it up as a PDF document then hands it off. The end user only sees the PDF document and should not really care how it got created. In fact, if you started telling them about Assembler, most would probably go to sleep since they do not need to care how.
  1. LiveCycle is complex. In fact, there are so many libraries providing the functionality behind the scenes, that most people would (and should) get bored if they tried to read through and understand all of it. If someone is really excited about LiveCycle and talks about it with a passion, they need another hobby.
Of course, if you are excited about LiveCycle, that doesn't imply a social adjustment is in order. The people who make, design and promote LiveCycle have to be somewhat fanatical about the platform itself and we are.

In following weeks, I will post some more advanced subjects converning LiveCycle. Stay tuned.

Microsoft and ODF: Yeah, what he said.

I cannot over emphasize the importance of accurate journalism in my blog. Rather than repeat this, please just read the ZDnet blog on the subject:

http://blogs.zdnet.com/BTL/?p=3300&tag=nl.e622

Thursday, July 06, 2006

Adobe LiveCycle Assembler - what is it?

Adobe LiveCycle Assembler is a cool new technology for those of you working with aggregating data from multiple sources to bind into a PDF document as output. It embraces a simple pattern of Whole-part using a template model to declare the construction of a final PDF document. This is done using an XML template called a "Document Description XML (DDX)" that defines the single output file and the content and data used to create it.

LiveCycle Assembler is a server based solutions that uses the DDX templates and the specified source documents, manipulates the data in the source documents according to the specifications of the DDX, and places the resulting documents in the specified output location.

Why I like this?

Simple - it is starting the road to declarative PDF expressed in XML and DDX document sare relatively easy to
author. The namespace of the DDX language is http://ns.adobe.com/DDX/DocText/1.0/, and the root element is
DocText. A simple example of
how the root might look?

















The DDX format allows for rich declarative expressions for all elements of a PDF document, ranging from Metadata to control over text of artwork. The data model for the XML is well thought out. Describing simple items like bookmarks is easy and you can also express actions:




Most documents formats appear to be moving towards a full XML expression with some form of packaging. Open Document Format (ODF), the OASIS open standard for XML declared documents, spreadsheets and presentations, uses XML as the standard for syntax. Norm Walsh was a pioneer in using DocBook which used stylesheets to display XML and even the next version of Microsoft Office is purported to be in XML format. In general, it seems to be a relatively popular activity nowadays.

Wednesday, June 28, 2006

Flash Player on Linux by year end

Having run a Linux Laptop and desktop for a while, I sympathize with those of you waiting to get Flash 9 for Linux. I have made good on my promise from JavaOne to follow up internally. The latest public news I have found is that we will have updated the Flash player for Linux by the end of this year. Read near the bottom. If you have comments on this subject, please feel free to leave them here. Although I do not speak for Adobe on this blog, I do perceive that there is a sense of urgency on this issue that seems to increase in the last two months.

Flex, that "Web 2.0 thingy" and today as a significant event in history

So today, Flex 2.0 was officially released. Hurray! What? Exactly! So why is the arrival of Flex so important and if it truly is, why is this event not larger?

First - for those of you who do not know what Flex is, Flex is an offering from Adobe that allows you to create Rich Internet Applications (RIA's) that display using Flash by using a declarative markup langauge (MXML). Furthermore, unlike Flash Director, Flex Builder caters specifically to developer who like to think in terms of Objects, Event Models, Event Handlers, MVC and other commonly accepted programming methodoligies and techniques, rather than the timeline based world of Flash Director. Flex has two important components - the Flex Builder, an Exclipse based development tool that comes with a wide range of prebuilt widgets and components, and Flex Data Services, a server that can allow the heavy lifting to be done away from the client.

A major point of clarity - to use Flex, you do not need to buy anything. There is a free Compiler available and you can write your own server and bind to it however you want. Adobe sells it tools based solely on the value they present. Most people will want to do a few common tasks and these are packages in our tools to make it much easier and quicker for you to get your next generation RIA up and running. This model was triumphed by Macromedia - think of why people bought Dreamweaver instead of hand coding HTML and JavaScript. Still - please feel free to use the free stuff.

Flex arroving in its' current iteration is a major milestone on the road to the next generation of the internet or what some are calling "Web 2.0". Flash has been for a long time the preferred technology for most rich internet applications and Flex bridges the gaps between web developers and application developers. It briges the gaps between enterprise architecture and the edge. There is even a bridge between AJAX and Flex.

In short, this toolset, the common programming model and forced MVC architectural constraints are moving the internet along to whatever it will be. Want to make a rich HTML text editor for your site? It used to take several days or weeks to do. Today, using Flex Builder 2, you can make the front end in minutes (I actually timed myself and my fastest time was 42 seconds).

As with everything I post on this blog thought, don't just take my word for it or believe me. Try it out for yourself.

Thursday, June 15, 2006

Interview on Web 2.0

I am really grateful to the Syscon folks for creating this interview:
http://tv.sys-con.com/read/235922.htm

The gist is about the Web 2.0 but with some actual depth added to the concept. The ideas started during a blog exchange with Tim Oreilly. Despite the fact that the name "Web 2.0" is perhaps suboptimal, the "thing" that people have come to link to the term does exist. Problem is (of course) that the "thing" is undefined. Accordingly, everybody thinks it is something a little bit different.

The interview discusses some possibilities for creating a set of reusable architectural patterns using the Mackenzie-Nickull Architectural Patterns Metamodel to distill out the differences in Tim Oreilly's examples of Web 1.0 and Web 2.0. This would by far be the most concrete definition.

Dion Hinchliffe recently published an example of some of the Web 2.0 Patterns I have been working on. Matt Mackenzie, who is always thinking beyond the edge, also has some interesting thoughts on the subject of Web 2.0.

Wednesday, May 24, 2006

SOA 2.0 makes people finally speak out!

I have observed a really cool phenomena in the last week. Normally, when someone comes out with a new buzzword that doesn't really have any substance, most people merely complain quietly and go about their business. With Gartner and Oracle now having gone public with their term "SOA 2.0", the collective disgust seems to have finally reached the tipping point where people can no longer keep quiet. I am a bit surprised for two reasons. One is that I have talked to Yefim Natis and actually found him highly intelligent. It doesn't seem characteristic of him to back a buzzword like SOA 2.0.

The second surprise is the wave of attacks coming at the use of the term. This is good to see that folks are finally starting to yell "where's the beef" and "the emperor has no clothes". Some recurring thoughts on SOA 2.0 are spot on. This is a compilation of my favorites so far.

http://markclittle.blogspot.com/2006/05/soa-20-ignorance.html

http://www.mac-kenzie.net/blog/2006/05/24/soa-20-what-are-they-smoking/

http://www.mwdadvisors.com/blog/2006/05/soa-20-stop-madness.html

http://jroller.com/page/dancres?entry=oh_no_soa_2_0

http://sw.deri.org/~juan/weblog/?p=242

http://mult.ifario.us/articles/2006/05/24/soa-2-0-mud-in-the-mud-puddle

http://www.thedatafarm.com/blog/PermaLink.aspx?guid=cfb38e60-5c9c-4670-8c36-ae36f114e075

http://voelterblog.blogspot.com/2006/05/it-folks-out-of-control.html

http://data-entry-business.blograzor.com/52352/


You'll notice a pattern here. There are about 3 or 4 people who like the term and several of the entries in Google's blog search simply syndicate the same content. The above links are unique comments written by people who I consider pragmatic and smart, not based on this but on previous blog entries they have written.

Monday, May 22, 2006

The Fan just got smothered!!!!

The fan just got hit big time!

I cannot believe this is happening. I met up with Mark Little at Java One and he told me some people are actually starting to talk about “SOA 2.0”. The German language has the only words for this – “einfach unglaublich”. Roughly translated it means “utterly unbelievable”.

Now Mark is a very smart guy – I work with him on many Web Services standards bodies where he provides great value. I have never seen him get really upset about anything before I saw this blog entry. This should be a testament to how absurd the concept of SOA 2.0 is.

As Mark correctly points out, you cannot take some half baked marketing term and milk it for another few miles by sticking a version number at the end of it. This appears to be nothing more than a scam to keep people coming back for more information. People – they are making it up!!! You are being lead down the wrong path. I can see it in my head:

Analyst: “SOA is the answer to anything. Even if you don’t know the question. Too bad I can’t tell you what it is exactly but if you listen to me, maybe you can do it someday.”

Customer: “Actually, I think I figured it out. It is a model for software architecture.”

Analyst: (Thinks silently – “Oh no – they’re on to me. What should I do??”)

Analyst: ” Very well, I think now you are ready for SOA 2.0”.



Please note I am not just picking on analysts - they are just the easiest target in this case ;-)

On Mark’s blog, he notes that Steve says Web 2.0 it is a mix of EDA and SOA. Bullocks! All SOA is event driven. How can you have a service that does something if there is no notion of an event (trigger) in the architecture? I suppose if you just built it and it sat there doing absolutely nothing but even then it would be event driven since doing nothing is what it should do in the absence of any events. Can anyone provide an example of SOA that is NOT event driven?

A group of people (over 200 members and observers to be precise) got together out of disgust for lack of clarity around SOA and put together a Reference Model to clarify what is meant by the term. Being largely end users, they asked all the right questions. If SOA is architecture, as the name implies, how do we express it as architecture or some architectural artifact? How is it different from other interface based designs? Does it have a right to exist as a term (*read – does it have any substance or is it pure marketing hype)?

These people wrote a Reference Model which defines an architectural paradigm for organizing and using resources under different domains. The Reference Model is not architecture per se, it merely notes the main concepts, at a completely abstract level, for the entities which consistently appear within service oriented domains.

SOA Definitions – There’s enough for one per person.

Given the current Wikipedia definition and the OASIS Reference Model for SOA, it appears that SOA is something we all have probably been doing for a long time. Even Starbucks implements the OASIS Model. Service provides for their Services (they provide caffienated beverages to customers) use visibility (signs, advertising) to let others know the services are available. There is an interaction model (money for coffee) that uses a behavior model (pay first, coffee later) to provide the service. There is a service description (like WSDL for customers) and a fabric they attach to to allow service consumers to interact with the service. WS-* is the same. This really makes me wonder when I see quotes stating things like “over 60% of all companies hope to be doing SOA by 2007”. Even some smart IBM'ers have been skeptical of peoples claims to be “doing SOA”. Given they also have at least established a metric for SOA, they are IMO entitled to talk about it. For someone who starts this sort of a conversation without using a *useful and measure-able” definition of SOA is, cannot be held in high esteem.

The OASIS Reference Model for SOA does not purport to be the one and only true definition of SOA. It is simply a model that is a stick in the mud (or FUD in this case). Even if you do not agree with it, it represents a non-proprietary definition which you can use as a point of reference to state where your definition differs. Someone can easily state “When I say SOA, I differ from the OASIS Reference Model in the following ways….. [insert your POV here]”.

Summary

Mark is a smart guy, beware of people selling anything undefined with a 2.0 extension and if your “doing SOA”, be careful and don't forget to use Starbucks products .

Adobe Developer Week Registration Live

Registration for Adobe Developer week is now live. The week long event is completely virtual. It is sort of an "anti-conference" of sorts.

URL: http://www.adobe.com/cfusion/event/index.cfm?event=detail&id=452429&loc=en_us


Developer Week is a week of free, online technical seminars on Adobe technologies, scheduled for June 12-16. I will be presenting on Friday.

Friday, May 19, 2006

The coolest thing at Java One 2006


Okay - so Java One is in its' final day. Yes - tons of really cool technology here but three things really caught my eye and stood out from the others. I guess the gist is that software itself is no longer enough to be really cool because all three picks are both hardware and software based.

Number three was the computer controlled train set using Java to control all aspects of two HO scale engines interactions with the track. Yes- its' been done before but I have to tip my hat to those who can take the imagination to do this and somehow find the time too. I gave him a Flex 2 beta 3 CD and explained how it would be possible to make a flash webpage to allow people to log in remotely and control the train set. You could play with it from your desktop. Flex and trains - stoke!!

Number two was the java powered robot car. Sun's pavilion featured a home built, mad scientist designed computer controlled car that really blew me away. Just imagining the interfaces to connect all the controls of a car to a program, being able to read live input data and account for all variances to be able to drive a car is staggering to think about.


By far my favorite is the java controlled lego robots. Bruce Boyes of Systronix one upped everyone else by developing java controllers for robots. The system works well with Lego (tm), one of my all time favorite toys.
There is just something cool about putting java into toys.

so why is this my tops pick? The Java/lego robots were built using JVEX. JVEX-robotics is a project to interface the VEX Robotics System controller to Java single board computers. The goal is to free the Java host from low level device management responsibilities by delegating these tasks to the VEX hardware. The result is that Java can easily be used with the VEX kit, which is a great prototyping environment. You can come up with an idea during morning coffee and make a prototype using Lego and talk to it via JVEX all before lunch.

I'm going to order some of this - just think of the cool uses.

1. I could install these controllers inside the street lights in Vancouver and build a remote control and transmitter in my car so the lights are always turning green for me when I drive. Very cool. Still - others may get pissed if they found out.

2. I could sneak into the railways yard and implant the system into life sized trains then sit in Dick Hardt's balcony overlooking the waterfront and plays trains - with real trains! Rad!

3. I could build tiny legs for my cell phone and install the system with controls for the legs. The next time I lose my cell phone, I'll just jump on a terminal, log in and tell it to walk home by itself (serves it right for losing itself in the first place).

4. I'm going to place tiny switches in the elevators at all the tall buildings then randomly pick floors for people to go to. This would be too funny. I will then build a web enabled application to allow others to remotely control the elevators speed, destination and behavior with cameras to observe the resulting mayhem on CCTV over the internet. Better yet, you could bid on eBay to control your co-workers experiences in elevators. Too much fun!!!

I don't think I can play with just plain old lego anymore. What blows me away is that this stuff was so cutting edge 15 years ago that it would have been locked into a military basement somewhere. Now - you can buy kits from Lego and Systronix. You can use Flex to code front ends in Flash to allow distributed control over these robots and the whole thing is here today.

If you see a Sony Ericson cell phone with tiny robotic legs stumbling around looking lost, you know who's it is. Please kindly remind it that it shouldn't have got lost in the first place and point it towards Vancouver.

Time to go speak at Java One.

Ciao!

D

Wednesday, May 17, 2006

Java One

Java One is really busy this year. Really cool too. Yeah - there is the usual plock about "enterprise java services" and "robust scalable architectures" as the new "paradigm". Buzzword bingo anyone?

Anyways, if you read this and are at Java One, drop by the booth and say hi. I'll be there all day every day.

Monday, May 01, 2006

More on AES encryption

Okay - some people have been making some rather brazen claims about the ability to crack a PDF document which uses the AES 128 bit key to encrypt the content. I am not sure if they are truly psychic (one plausible way to crack AES), but doing such using a brute force attack is probably not going to work without a bit of luck. To understand how complex AES is, let's explore how the key is derived and what it means to "break" or "crack" encryption.

The AES standard has a fixed block size of 128 bits and a key size of either 128, 192 or 256 bits. The key is expanded using Rijndael's key schedule in which most of AES calculations are done in a special finite field. Operates on a 4 x —4 array of bytes (the State) and uses four distinct steps to encrypt.

1. AddRoundKey - each byte of the state is combined with the round key; each round key is derived from the cipher key using a key schedule (simple).

2. SubBytes - SubBytes is a non-linear substitution step where each byte is replaced with another according to a lookup table. In order to add non-linearity to the key, the Galois Field (GF) is used to derive the inverse function of 2 to the power of 8. This has been credited with keeping things unlinear.

3. ShiftRows - a transposition step where each row of the state is shifted cyclically a certain number of steps.

4. MixColumns - a mixing operation which operates on the columns of the state, combining the four bytes in each column using a linear transformation. This provides diffusion in the final cipher in conjunction with ShiftRows. Each column is treated as a polynomial over GF(28) and is then multiplied modulo x4 + 1 with a fixed polynomial c(x) = 3x3 + x2 + x + 2.

The final round replaces the MixColumns stage with another instance of AddRoundKey.

To give you an idea of the complexity of the resulting decryption process, to crack a 128 bit key would take approximately 3.4 x 10^38 guesses assuming the correct key was the last one you tried. To place this in perspective, is estimated that if a DES key generator were able to discover 1 DES key per second, it would take 149 thousand-billion (149 trillion) years to crack a single 128 bit AES key. As a side note, most physicists accept that the universe is approximately 20 billion years old.

As Homer Simpson would say - "D'oh!!!".

What people who are claiming to "break" AES have to use as a metric is a methodology which is anything faster than an exhaustive search for all the keys, also referred to as a "brute force" attack. There is another type of attack methodology called a "side channel attack which does not operate on the actual cipher but on mechanisms around it. There have been two claims of success in breaking AES using side channel attacks. You should note that both of these required access to an application running on the same machine.

Anyone still feel they can get the $500 I offered for cracking the document?

Friday, April 28, 2006

Working with XML data in Flex and Flash

I have been playing around with a new feature of Flex 2.0 (actually it is a new part of ActionScript 3.0). It is called E4X or ECMAScript for XML. It allows Flex developers to very simply and quickly write down and dirty bindings from XML data to Flex objects.

I will be teaching a 4 hour tutorial at the upcoming Geoweb in Vancouver July 24-28 2006. My good friends at Galdos host this conference and do a great job every year. This year the course will be a hands on developer course with Flex 2.0 and a ton of ActionScripting and even a finale of using the Flex API to Yahoo maps.

Okay – so I am not going to repeat the entire tutorial module here (it is not even complete), but I will share the *.mxml file with you. It is commented to be relatively clear what is going on. For clarity, I put the GML XML sample inline. To work with XML in ActionScript, you simply declare the XML data as an object, then you can use the various XPath like filters and queries against it. While it is not as robust as the full blown JAXB, it is very effective. Here is the sample file – just cut and paste it into your Flex 2.0 project and start playing around by un-commenting the various lines that demonstrate the functionality. The actual file can be downloaded from http://www.nickull.net/blogimages/GML.mxml to avoid retyping.

Enjoy!

Friday, April 21, 2006

AJAX hammers servers?

I read a question posed by James Governor's blog and Tim Bray's always insightful response to it yet was left feeling unfulfilled. It lead me to this blog which provided some further information. Perhaps it is the jetlag or I just haven't abused enough caffeine today but I feel compelled to write more.

The author does not define several things which make his statements relatively un-confirmable. First of all, there is no such thing as a spec for the Web 2.0 so his claim that RIA's are a crucial aspect is a flawed assumption from a pragmatic standpoint, although somewhat orthogonal to the question asked.

So let's look at what AJAX does and why it is favored. In the past, if you wanted to make a webpage that displayed up to date information, you may have to force the page to refresh itself every few minutes or prompt the user to do this. Since HTTP is stateless, that means firing off an HTTP get() request every few minutes to retrieve the entire page. The easiest way to do this was to use the meta-refresh element of HTML 4.0 transitional. Since HTTP server are idempotent, they respond each time they get the request. Tim and I had a conversation about this back in 1999-2000 when he called it TAXI (the father of AJAX). The question posed was "wouldn't it be much more efficient to only refresh parts of a page rather than the whole page). Out of that necessity, AJAX was born. It was actually Microsoft that cemented it by putting the XMLHTTPRequest() object into IE.

Now let's separate business needs from technology. If you have a business requirement to provide current, up to date information to your end users via the internet, you are going to do it, regardless of the underlying technology and the costs on servers. From a pure pragmatic standpoint, one should want to do this in the most efficient manner possible. There are several models available to use.

One is that the server "pushes" information to clients when some event happens (perhaps a stock price changes). The problem with this is that it often means the server has to dispatch a large number of concurrent messages when that event occurs, even if the clients themselves are not requesting it. Suboptimal - this can cause server overload, scare small children and bruise fruit.

Second model is the client side pull. This usually makes more sense given the client controls the nature of the request frequency, although the services architects determine the content size and policies for requests. This makes it much easier on the server to balance its outward messages given not all clients are likely to request at the exact same time.

Reloading only part of a page or even just the data for that part of the page is much more efficient that having to load an entire page or the data and presentation aspects of a component of the page, therefore, I would state that AJAX (or other AJAXian type methodologies) are probably the most efficient way to handle the business requirements that are placed on the web today.

If you were to ban AJAX from the web, we would have to revert to full page reloads which would certainly be more bandwidth and processor intensive than AJAX enables.

My opinion - those who are online gamers, porn surfers, MP3 downloaders are all more likely to cause the scalability problems that AJAX developers. Carefully thought out architecture should be used where possible. AJAX solves more problems that it creates.

Duane

Wednesday, April 19, 2006

Circumventing PDF with gmail? Not!!

I was recently amused by reading a blog of a group who apparently
defeated PDF's DRM system by using GMail's "convert to HTML" option. I nearly fell off my chair when I read the claim " (it) works regardless of the files; usage restrictions..". Yes - under certain circumstances you can gain access to text or other components of a PDF document that has policy protection on it, but *only* if the person applying the policies set the policies to allow this type of access AND does not encrypt the PDF. Keep in mind that PDF is a completely free, open and available standard that anyone can implement. There are several third party SDK's to manipulate PDF documents. Before you read the blog above, it is extremely helpful to understand how the encryption and DRM mechanisms work.

In general, if you do not want someone other than the intended recipient to
view a PDF, you should encrypt it. By default, the encryption level for compatibility with Acrobat 5.0 and later is 128bit RC4. Encrypting the contents of a PDF with a strong key results in a situation where there is no way gmail or any other
application can crack it open by brute force. The PDF is turned into cipher text that is completely incomprehensible to anyone without the key to open it. I am so certain of this that I will provide $500 USD to the first person who can open this document within one year.

A person encrypting a PDF document has several options. First, you can determine the compatibility for earlier versions of Acrobat (5 , 6) or jump straight to Acrobat 7.0 and higher. If you select to encrypt it for Acrobat 7, the default level encryption method is AES, much harder (read = impossible) to crack using brute force.



You can also opt to encrypt all the document contents, or leave the metadata unencrypted. This is useful should you want to be able to have the document searchable in real time based on the metadata. Note the lower section of the screenshot above - by default, the box is checked to allow text access to the document. If you leave this selected, some PDF applications can access the text. If you don't want this, please de-select this option. After setting all of the options and pressing next, you will still be given a generic warning that certain non-Adobe products might not enforce this document's policies. Note that if you do not select "require a password to open the document", the usefulness of encrypting it is moot. Others will still not be able to copy the document by using the text copy tool or Control-C, but other means can be employed.

To summarize so far, Acrobat has DRM capabilities to limit the following interactions with documents

1. ability to disable printing
2. ability to disable cut and paste
3. ability to disable control printscreen
4. ability to disable local file saving
5. ability to disable local file saving
6. ability to disable accessibility
7. ability to make a document no longer exist

A person must comprehend the frame and scope of the intended use of each of
these and their built in restrictions. PDF's are like music - if you can
render it once, it is possible to capture it and render it again. Even if
we figured out a way to prevent all third party screen scraping software
from capturing what you see on a computer screen, someone who both has
access to the document for a single view AND intent to distribute it further can simply take adigital photo of their computer screen to circumvent all of these. There is simply no way to stop someone who is intent on doing this using 1-6 above.

Another methodology is available to place a dynamic watermark on the page, perhaps stating the users name and address in bold gray text across the document. This too can be defeated if one took a screen shot of the document and used a great tool like ... err "Adobe Photoshop" to take care of that nasty watermark. I am guessing the magic wand tool is your best friend here ;-)

So how can you protect a PDF? If you really want to make it secure and also
track the users interaction with it, you would be wise to use Adobe Policy
Server
. The policy server uses a model of persistent DRM that follows the
document everywhere it goes. If you feel the document is out of control and
you want to stop it, you can simply "destroy" the document which will cause
it to fail to un-encrypt itself when someone opens it. Is there a way
around that? Sure - sneak into the office of the person who made the
policy, install a tiny pinhole camera near their desk and capture their
authentication.

See what I am getting at, no matter what you do, there is a way around it if
someone is really intent. The easier method is "social engineering" rather than brute force.

So here is a challenge. Take this document here (link to APS protected
document) and try to render it with gmail (or any other method). I will pay
$500 USD to the first person who can show me the un-encrypted content of this document within one year of this.

How I would do it? I would probably try to lure myself into providing a password to a site that offered me some form of membership and hope that I was rather lazy and used the same password for this document. D'oh!! Not gonna work - I typed a random phrase of about 13 characters to encrypt this using AES.

Good luck!

Tuesday, April 18, 2006

The Web 2.0

I now feel compelled to write in this subject after holding my breath and counting to 10 several times. I recently read YABA* about building a "Web 2.0 Meter". A not bad idea *if* you had some sort of defined criteria that those being judged could adhere to. Another site claims it is a Web 2.0 validator
Web 2.0 Validator.

Enough! I can even hear Homer Simpson saying “D’oh!!” when he thinks about this. Time to rant a bit from Logic 101. You cannot measure something by two independent “meters” without some distinct set of metrics around the subject. Sorry folks, it is that simple. I would like to point out that the Web 2.0 validator site had the sense to state the rules they use and that the gist of the article at Oreilly was not about the web 2.0 meter. It was a realization that the concepts we have come to “associate” with the Web 2.0 were really the Web 1.0’s original goals. GAH!!! I just had an unpleasant realization that now I am trying to quantify the Web 2.0. To solve this problem, I think we have to look to the past as well as the future (yeah yeah – so what does that rule out? Thinking about the exact present moment?). The Oreilly folks are pretty smart IMO so please don't take this as some petty stab - more of a friendly prod :-)

If “Web 2.0” is to be used as a catch all term for where we are going, let's put some substance behind it. If not, it will suffer the same symptoms as SOA and Web Services - both very meaningful to most people, just with differing semantics. In fact, the lack of clarity around SOA lead a group of almost 200 people to get together and write a formal Reference Model for SOA under the auspices of OASIS. Similarly, a group got together within W3C and worked on a Reference Architecture for Web Services. I am proud to state that I worked on both projects.

So what can be done to put substance in the Web 2.0?

1. Write an abstract reference model to show the components of the Web 2.0 (abstract); and
2. Create sets of high level abstract patterns, mid level patterns and low level idioms to illustrate what is really meant by the web 2.0; and
3. Create reference architecture (in plural and somewhat generic) for all components of the Web 2.0, describing their externally visible properties and relationships with other components.

An example would be to illustrate the syndication-subscription pattern using some architectural patterns template. The abstract notion is that subscribers notify a syndication component of their wish to receive content. When the syndication component has content it is ready to push out, it configures a list of recipients based on some criteria then proceeds to push the content out. A lower level idiom could show this implemented using Apache components, perhaps even with options for content formatting based on device, reliable messaging protocols, security and end user authentication with a persistent security model for the content itself.

The cool thing about this approach is that it still gives each and every implementer the freedom to make their own black box components whilst preserving a common layer of understanding. It also provides documentation about what is really meant, granted, those who cannot distinguish abstract from concrete may still be confused.

Of course to do this, you would require an architectural patterns meta model and template that allowed you to go from the very abstract to the very concrete, but I think I know where one is that can be donated to some organization.

Why should this be done? Simple – without this, “Web 2.0” is nothing more that a marketing term. Sure – several people will say “no – it means X and exactly X”, but the chances of Boolean Y = eval(personA.X == personB.X) evaluating to “1” in every instance is very low IMHO.

The Web 1.0, aka the “internet”, has achieved a common definition though. Even though it is not concisely written, there is general consensus on what a web server does, what the layered wire protocols do, how security works and how people interact with websites (via browsers). If someone says “this server is internet enabled”, people imply that it means it can take HTTP requests and return text in compliance with the requesters requirements.

Sorry – folks. I just don’t believe that the Web 2.0 will inherit an implied reference model the way the Web 1.0 did. The culprit for this is the Web 1.0 as it exists – it allows anyone, almost anywhere, to write what they think the Web 2.0 is and share it with others. Also, unlike the Web 1.0, the Web 2.0 is not mandatory. The basic components of the Web 1.0 such as HTTP, TCP/IP, SMTP, MIME, HTML etc all were mandatory, therefore it was fairly easy to draw a box and state – this is the Web 1.0. One could even through in some common non-mandatory components and still make a solid statement (example – scripting languages (ASP, VBScript, JavaScript, ActionScript plus CSS, XML et al).

A Reference Model for the Web 2.0 might want to declare some form of compliancy and conformancy statements. Such might be a weighted test of it could be a bar that you must pass. Regardless, before this exists, what is the point of building “validators” and “meters”. Harrumph – end of rant. Take it all with a grain of salt – the Oreilly folks are smart and I’m sure we’ll see something soon ;-)

If not – does anyone feel compelled to take a stab at a formal definition? I will gladly jump in the fray and donate my time to help.

*Yet Another Blog Article – in case you didn’t figure it out ;-)