<?xml version="1.0" encoding="UTF-8" ?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:base="http://everything2.com/">
    <title>cordelia's New Writeups</title>
    <link rel="alternate" type="text/html" href="http://everything2.com/index.pl?node=Everything%20User%20Search&amp;usersearch=cordelia" />
    <link rel="self" type="application/atom+xml" href="?node=New%20Writeups%20Atom%20Feed&amp;type=ticker&amp;foruser=cordelia" />
    <id>http://everything2.com/?node=New%20Writeups%20Atom%20Feed&amp;foruser=cordelia</id>
    <updated>2002-12-21T16:45:47Z</updated>
<entry><title>Incentivizing antisocial behavior (idea)</title><link rel="alternate" type="text/html" href="http://everything2.com/user/cordelia/writeups/Incentivizing+antisocial+behavior"/><id>http://everything2.com/user/cordelia/writeups/Incentivizing+antisocial+behavior</id><author><name>cordelia</name><uri>http://everything2.com/user/cordelia</uri></author><published>2002-12-21T16:45:47Z</published><updated>2002-12-21T16:45:47Z</updated>
<content type="html">A community exists as a &lt;a href=&quot;/title/social+fiction&quot;&gt;social fiction&lt;/a&gt; between a group of individuals who find themselves drawn together by something common - &lt;a href=&quot;/title/location%252C+location%252C+location&quot;&gt;locality&lt;/a&gt;, &lt;a href=&quot;/title/religion&quot;&gt;religion&lt;/a&gt;, or &lt;a href=&quot;/title/common+interest&quot;&gt;common interest&lt;/a&gt;.  A community is a &lt;a href=&quot;/title/microcosm&quot;&gt;microcosm&lt;/a&gt; of &lt;a href=&quot;/title/society&quot;&gt;society&lt;/a&gt;, and &lt;a href=&quot;/title/the+ties+that+bind&quot;&gt;the ties that bind&lt;/a&gt; people together can be ever so &lt;a href=&quot;/title/fragile&quot;&gt;fragile&lt;/a&gt;.
&lt;p&gt;
Oddly, one often finds that as a society grows, it can create rewards for some form of &lt;a href=&quot;/title/antisocial+behavior&quot;&gt;antisocial behavior&lt;/a&gt;.   Take a look at any &lt;a href=&quot;/title/depression&quot;&gt;depression&lt;/a&gt; era.  Some would act out - throwing a rock through a store window - for the privilege of spending a warm night in jail, and getting a hot square meal at the same time.   Inadvertent rewards are but a small step - it's when the reward becomes institutionalized that the community must beware.
&lt;p&gt;
&lt;h4&gt;Example: Curve-based grading&lt;/h4&gt;
When my mother was getting her &lt;a href=&quot;/title/degree&quot;&gt;degree&lt;/a&gt;, she recalls a professor with a strict curving system: 3 people would get an A on each exam from each class; 8 a B, etc.   Now my mother was a straight A student, and, halfway&amp;hellip;</content>
</entry><entry><title>CISSP (person)</title><link rel="alternate" type="text/html" href="http://everything2.com/user/cordelia/writeups/CISSP"/><id>http://everything2.com/user/cordelia/writeups/CISSP</id><author><name>cordelia</name><uri>http://everything2.com/user/cordelia</uri></author><published>2002-10-06T21:55:03Z</published><updated>2002-10-06T21:55:03Z</updated>
<content type="html">&lt;h3&gt;Certified Information Systems Security Professional&lt;/h3&gt;&lt;br&gt;The CISSP certification is maintained by the &lt;a href=&quot;/title/International+Information+Systems+Security+Certification+Consortium&quot;&gt;International Information Systems Security Certification Consortium&lt;/a&gt; (&lt;a href=&quot;/title/ISC%253Csup%253E2%253C%252Fsup%253E&quot;&gt;2&lt;/sup&gt;&quot; class='populated' &gt;ISC2&lt;/a&gt;).   Mastery of a  common body of knowledge, encompassing ten &lt;a href=&quot;/title/domains&quot;&gt;domains&lt;/a&gt;, as well as three years of experience in the field are required for certification.  The ten domains are:&lt;br&gt;&lt;ul&gt;&lt;li&gt;&lt;a href=&quot;/title/Security+Management+Practices&quot;&gt;Security Management Practices&lt;/a&gt;
    &lt;li&gt;&lt;a href=&quot;/title/Access+Control+Systems&quot;&gt;Access Control Systems&lt;/a&gt;
    &lt;li&gt;&lt;a href=&quot;/title/Telecommunications+and+Network+Security&quot;&gt;Telecommunications and Network Security&lt;/a&gt;
    &lt;li&gt;&lt;a href=&quot;/title/Cryptography&quot;&gt;Cryptography&lt;/a&gt;
    &lt;li&gt;&lt;a href=&quot;/title/Security+Architecture+and+Models&quot;&gt;Security Architecture and Models&lt;/a&gt;
    &lt;li&gt;&lt;a href=&quot;/title/Operations+Security&quot;&gt;Operations Security&lt;/a&gt;
    &lt;li&gt;&lt;a href=&quot;/title/Applications+and+Systems+Development&quot;&gt;Applications and Systems Development&lt;/a&gt;
    &lt;li&gt;&lt;a href=&quot;/title/Business+Continuity+Planning+and+Disaster+Recovery+Planning&quot;&gt;Business Continuity Planning and Disaster Recovery Planning&lt;/a&gt;
    &lt;li&gt;&lt;a href=&quot;/title/Law%252C+Investigation%252C+and+Ethics&quot;&gt;Law, Investigation, and Ethics&lt;/a&gt;
    &lt;li&gt;&lt;a href=&quot;/title/Physical+Security&quot;&gt;Physical Security&lt;/a&gt;
&lt;/li&gt;&lt;/li&gt;&lt;/li&gt;&lt;/li&gt;&lt;/li&gt;&lt;/li&gt;&lt;/li&gt;&lt;/li&gt;&lt;/li&gt;&lt;/li&gt;&lt;/ul&gt;</content>
</entry><entry><title>Detecting an attacker's IP address hidden by backscatter (idea)</title><link rel="alternate" type="text/html" href="http://everything2.com/user/cordelia/writeups/Detecting+an+attacker%2527s+IP+address+hidden+by+backscatter"/><id>http://everything2.com/user/cordelia/writeups/Detecting+an+attacker%2527s+IP+address+hidden+by+backscatter</id><author><name>cordelia</name><uri>http://everything2.com/user/cordelia</uri></author><published>2002-10-06T13:55:01Z</published><updated>2002-10-06T13:55:01Z</updated>
<content type="html">It is a commonly held belief in the &lt;a href=&quot;/title/Information+Security&quot;&gt;Information Security&lt;/a&gt; community that an attacker, performing &lt;a href=&quot;/title/reconnaissance&quot;&gt;reconnaissance&lt;/a&gt; against a set of computers, will hide their own &lt;a href=&quot;/title/identity&quot;&gt;identity&lt;/a&gt; and location by including a &lt;a href=&quot;/title/backscatter&quot;&gt;large number&lt;/a&gt; of &lt;a href=&quot;/title/forged+source&quot;&gt;forged source&lt;/a&gt; packets.   Most Information Security professionals don't have a strong enough math background to realize that this technique, used simply, is flawed, and thus, &lt;a href=&quot;/title/defeatable&quot;&gt;defeatable&lt;/a&gt;.
&lt;p&gt;
Posit an attacker that generates a stream of traffic, with their own &lt;a href=&quot;/title/source+IP&quot;&gt;source IP&lt;/a&gt;.   To cover their tracks, for each packet in this stream, they generate a large number of similar or identical packets, with a randomly chosen IP address.
&lt;p&gt;
Here's where the math comes in.  Using the &lt;a href=&quot;/title/expectation+is+linear&quot;&gt;linearity of expectations&lt;/a&gt;, we can calculate how many unique source IPs we expect to see from a given amount of traffic.
&lt;p&gt;
Assume the attacker sends 10,000 random packets per second, and 1 true packet.   Sampling across 30 seconds, we see 300,030 different packets.  The expectation&amp;hellip;</content>
</entry><entry><title>Humour: D&amp;D Third Edition (idea)</title><link rel="alternate" type="text/html" href="http://everything2.com/user/cordelia/writeups/Humour%253A+D%2526D+Third+Edition"/><id>http://everything2.com/user/cordelia/writeups/Humour%253A+D%2526D+Third+Edition</id><author><name>cordelia</name><uri>http://everything2.com/user/cordelia</uri></author><published>2002-06-03T22:58:13Z</published><updated>2002-06-03T22:58:13Z</updated>
<content type="html">&lt;p&gt;An &lt;a href=&quot;/title/interesting&quot;&gt;interesting&lt;/a&gt; collection of &lt;a href=&quot;/title/e-mail+humor&quot;&gt;e-mail humor&lt;/a&gt;, that points out some inconsistencies in a ruleset.  But then, it also makes fun of itself, by laughing at the wrong things.   Some of these catches are definite issues, but that's why the book is called the &lt;a href=&quot;/title/Dungeon+Master%2527s+Guide&quot;&gt;Dungeon Master's&lt;/a&gt; &lt;i&gt;&lt;a href=&quot;/title/Dungeon+Master%2527s+Guide&quot;&gt;Guide&lt;/a&gt;&lt;/i&gt;.  DMs are supposed to make rulings up as they go to maintain consistency.  But to address some of the comments that seemed most bogus:&lt;/p&gt;

&lt;dl&gt;
&lt;dt&gt;&lt;b&gt;The extreme heat/extreme cold rules render much of the real world uninhabitable as everyone in Fairbanks in winter or Phoenix in summer takes enough subdual damage to render them unconscious in just a few hours.&lt;/b&gt;&lt;/dt&gt;
&lt;dd&gt;Yup.  I've been in Phoenix in the summer.  And, if it weren't for &lt;a href=&quot;/title/air+conditioning&quot;&gt;air conditioning&lt;/a&gt; and drinking lots of water, odds are, I would've passed out had I tried to adventure around in that weather.&lt;/dd&gt;

&lt;dt&gt;&lt;b&gt;Simulacrum produces a creature that has among other traits 51-60% of the &quot;speech&quot; of the&lt;/b&gt;&lt;/dt&gt;&lt;/dl&gt;&amp;hellip;</content>
</entry><entry><title>Bordeaux (place)</title><link rel="alternate" type="text/html" href="http://everything2.com/user/cordelia/writeups/Bordeaux"/><id>http://everything2.com/user/cordelia/writeups/Bordeaux</id><author><name>cordelia</name><uri>http://everything2.com/user/cordelia</uri></author><published>2002-02-16T03:25:57Z</published><updated>2002-02-16T03:25:57Z</updated>
<content type="html">Both a &lt;a href=&quot;/title/city&quot;&gt;city&lt;/a&gt; and a &lt;a href=&quot;/title/region&quot;&gt;region&lt;/a&gt; in Southern &lt;a href=&quot;/title/France&quot;&gt;France&lt;/a&gt;.  The city straddles the banks of the &lt;a href=&quot;/title/Garonne&quot;&gt;Garonne&lt;/a&gt; River, making it an &lt;a href=&quot;/title/inland&quot;&gt;inland&lt;/a&gt; &lt;a href=&quot;/title/port+city&quot;&gt;port city&lt;/a&gt; (in fact, &lt;a href=&quot;/title/Fort+Medoc&quot;&gt;Fort Medoc&lt;/a&gt; defends access from its island location downstream on the &lt;a href=&quot;/title/Gironde&quot;&gt;Gironde&lt;/a&gt;).  A relatively small city, &lt;a href=&quot;/title/Bordeaux&quot;&gt;Bordeaux&lt;/a&gt; is quite pleasant even for the non-&lt;a href=&quot;/title/Francophone&quot;&gt;Francophone&lt;/a&gt;&lt;a href=&quot;/title/s&quot;&gt;s&lt;/a&gt; (if you speak &lt;a href=&quot;/title/English&quot;&gt;English&lt;/a&gt;), as a multi-century vacation spot for the &lt;a href=&quot;/title/British&quot;&gt;British&lt;/a&gt;.  In addition to having an airport just outside the city, access to the city via the &lt;a href=&quot;/title/TGV&quot;&gt;TGV&lt;/a&gt; is convenient from &lt;a href=&quot;/title/Paris&quot;&gt;Paris&lt;/a&gt; - a 3 hour &lt;a href=&quot;/title/express+train&quot;&gt;express train&lt;/a&gt;, or a 4 hour &lt;a href=&quot;/title/local+train&quot;&gt;local train&lt;/a&gt;.
&lt;p&gt;
While in town, take a stroll down &lt;a href=&quot;/title/Rue+St.+Catherine&quot;&gt;Rue St. Catherine&lt;/a&gt;, a (mostly) &lt;a href=&quot;/title/pedestrian&quot;&gt;pedestrian&lt;/a&gt; street stretching from town center to the &lt;a href=&quot;/title/Place+des+Quinconces&quot;&gt;Place des Quinconces&lt;/a&gt;.  The shops, &lt;a href=&quot;/title/patisseries&quot;&gt;patisseries&lt;/a&gt;, and &lt;i&gt;people&lt;/i&gt; make it quite enjoyable.  If you're an &lt;a href=&quot;/title/American&quot;&gt;American&lt;/a&gt;, you'll probably want to make sure your hotel has at least &lt;a href=&quot;/title/three+stars&quot;&gt;three stars&lt;/a&gt; (there is a nice &lt;a href=&quot;/title/Holiday+Inn&quot;&gt;Holiday Inn&lt;/a&gt; a 5 minute walk from the &lt;a href=&quot;/title/train+station&quot;&gt;train station&lt;/a&gt;).  If you want a guided tour of some wineries, the&amp;hellip;</content>
</entry><entry><title>Big Five (place)</title><link rel="alternate" type="text/html" href="http://everything2.com/user/cordelia/writeups/Big+Five"/><id>http://everything2.com/user/cordelia/writeups/Big+Five</id><author><name>cordelia</name><uri>http://everything2.com/user/cordelia</uri></author><published>2002-01-16T03:52:03Z</published><updated>2002-01-16T03:52:03Z</updated>
<content type="html">&lt;p&gt;The collection of &lt;a href=&quot;/title/large&quot;&gt;large&lt;/a&gt; &lt;a href=&quot;/title/accounting&quot;&gt;accounting&lt;/a&gt; and &lt;a href=&quot;/title/professional+consulting&quot;&gt;professional consulting&lt;/a&gt; firms, used by most corporations to &lt;a href=&quot;/title/audit&quot;&gt;audit&lt;/a&gt; their &lt;a href=&quot;/title/books&quot;&gt;books&lt;/a&gt;, as well as providing other services.  The &lt;a href=&quot;/title/Big+Five&quot;&gt;Big Five&lt;/a&gt; are:&lt;br&gt;&lt;ul&gt;
    &lt;li&gt;&lt;a href=&quot;/title/Ernst+%2526amp%253B+Young&quot;&gt;Ernst &amp;amp; Young&lt;/a&gt;
    &lt;li&gt;&lt;a href=&quot;/title/PriceWaterhouse+Coopers&quot;&gt;PriceWaterhouse Coopers&lt;/a&gt;
    &lt;li&gt;&lt;a href=&quot;/title/KPMG&quot;&gt;KPMG&lt;/a&gt;
    &lt;li&gt;&lt;a href=&quot;/title/Deloitte+%2526amp%253B+Touch&quot;&gt;Deloitte &amp;amp; Touch&lt;/a&gt;
    &lt;li&gt;&lt;a href=&quot;/title/Arthur+Andersen&quot;&gt;Arthur Andersen&lt;/a&gt;
&lt;/li&gt;&lt;/li&gt;&lt;/li&gt;&lt;/li&gt;&lt;/li&gt;&lt;/ul&gt;&lt;br&gt;With the collapse of &lt;a href=&quot;/title/Enron&quot;&gt;Enron&lt;/a&gt;, it seems possible that the Big Five will shrink to the Big Four; these companies are primarily selling &lt;a href=&quot;/title/trust&quot;&gt;trust&lt;/a&gt;, and Andersen's trust has been &lt;a href=&quot;/title/tarnish&quot;&gt;tarnish&lt;/a&gt;&lt;a href=&quot;/title/ed&quot;&gt;ed&lt;/a&gt; by this escapade.&lt;/p&gt;</content>
</entry></feed>
