Sunday, March 26, 2023
Shirts for Skittles!
Tuesday, May 17, 2022
Dr. Strange and the movie leaving madness
My daughter summed up my feelings about Dr. Strange and the Multiverse of Madness when the credits rolled and she proclaimed "that was dumb." I felt let down and betrayed. For the past month we had overloaded on Marvel movies getting my younger two kids caught up so this could be their first MCU movie to watch in a theater. The trailers looked good, Spider Man No Way Home exceeded expectations, and I walked into the theater expecting to share something special with my children. I got this instead:
The @DrStrange movie is what you get when you mix half an Evil Dead homage, half a cameo clip show, and half a marvel movie together in a blender, take out the best parts, and hit puree!
— Nathan Cooprider (@ncooprider) May 13, 2022
I have learned a bit of context in the week and a half since watching the film. My position has softened a bit. Elizabeth Olsen felt like the MCU had cost her too many opportunities and wanted out. The Scarlet Witch from the comics actually goes full crazy. The Darkhold has a rich history of corrupting users. Fans eager to see a "Marvel horror movie" looked to see Sam Raimi unleashed on the screen. If I had thought through it a bit more maybe I could have seen this coming, but I did not.
My biggest complaint came from the treatment of Wanda. Instead of building off what she "learned" in WandaVision, this movie picks up like that series did not even happen (other than her two kids being the impetus for the entire plot). With little or no transition, she goes from triumphant and repentant hero to villain worse than Thanos. It felt a little tone deaf to take one of the few female Avengers still alive and make her the antagonist. Not just tone deaf: it sounded like a dog whistle to incels.
I had other qualms besides Wanda's arc. The Illuminati seemed superfluously stupid. This group supposedly defeated Thanos, but then couldn't even go a few rounds with the Scarlet Witch? Reed Richards is the smartest man alive, but he doesn't realize he's hopelessly outgunned? Wanda goes insane using the Darkhold and becomes the bad guy, but Dr. Strange suffers only a weird growth in his forehead and no other consequences? The Wanda variant is not able to fight back and just lets her body get used? For that matter, Wanda and Xavier can't overcome the Darkhold together?
I think a better exposition and maybe a clearer redemption may have helped with Wanda's story, but the movie would still be a mess. This is easily my least favorite Marvel show or movie so far. I'm saying this is even worse that Fantastic 4. I left wishing I had saved my "first Marvel movie with all my kids" token for Thor.
Tuesday, April 30, 2019
Fundraising ideas for Destination Imagination Global Finals

- Year-round fundraising. Ideally, fundraising occurs all year round and not just during the month or so between states and globals. The problem with this is what to do with the funds if you don't actually make it to globals? Our town has a non-profit that supports the DI program. Money accumulates with that organization so that it's there when a team does make it to globals. That's the theory, although I realize there's a lot of details in the implementation which I do not know.
- GoFundMe. We got tipped off to this during our first trip to globals and we're using it again. The site does take a fee off the top, but it's worth the cost in the ease of use. A lot of successful fundraising has to do with reducing friction for those who want to donate, and GoFundMe does a great job of that.
- Business sponsorships. Our town has a culture of working with local businesses to provide support for various things. It really does take a village. I realize that demographics and culture might make this a less viable option. Remember that it's a culture that has to start sometime and somewhere, so why not with supporting DI? You can even sweeten the deal by mentioning how you will display your gratitude for the fundraising.
- Business fundraisers. This is another side of the previous item, but maybe more palatable for businesses. We have a number of restaurants in the area that will do proceed sharing nights. For example, 20% of the proceeds from orders at Ginger during April 23rd were donated to our town teams heading to Global Finals. I admit that the owners of the restaurant have a daughter on one of the teams, but I've seen other organizations do similar things with a local pizza place. It makes sense: you drive traffic to their restaurant and so everybody wins.
- Bonfire. We did a t-shirt fundraiser for the first time this year and it took off like gangbusters. Part of that came from a particularly popular design by the older sister of one of the team members, but even our less popular shirts did well. Obviously you want some kind of original design that will sell well, but that's a little like saying "buy low, sell high" on the stock market.
- Cookies. A different organization we participate in uses selling cookie mixes and doughs to fundraise. We are dipping our toes into that a little right now, although I cannot report on the results for us yet. We have noticed success elsewhere with selling cookie doughs or mixes. It takes some time to create and deliver the goods, but the supplies are actually pretty cheap and yield a good return for what you sell. I've seen a similar approach done with pizzas.
- Share. Share on every social media platform you have, and then do it again. Specifically, I am thinking of Facebook and Instagram. If you use Twitter, tweet early and often. Same with Pinterest. Even go for Reddit, if it fits. I am not sure about LinkedIn as a platform for this, but I tried it. I am not a Snapchat user so I did not use that myself, and the same goes for Whatsapp. I probably should have. Once you have the GoFundMe or Bonfire or whatever set up, market it on social media over and over and over again.
- Individual emails. Email your family. Email your friends. Email everybody you know. Probably don't email your coworkers, but if they have an off-topic channel or list or forum, put it there. Don't spam people (email them repeatedly), but a single reach out shouldn't bother anybody. Ask for donations, but also ask for them to share with THEIR networks.
Tuesday, June 2, 2015
Goodbye, TWiT!
Last weekend I unsubscribed from all my TWiT podcasts. The hypocrisy and lack of professionalism finally became too much. I post this on a blog because I have recommended the podcasts to others. While I cannot find every person and rescind my endorsement, I can post my decision here. I will also note that I do not judge anybody who does not make the same decision I made. I may be misinformed or ignorant of key pieces of information, but I do not trust Leo Laporte or his TWiT network anymore
I finally had to confront the duplicity of TWiT when, at the end of Security Now from May 26th, Leo announced that they would not be airing the taping of that show live anymore. Steve Gibson got confused, but Leo explained they would still tape it at the same time, but that they would only air the produced copy later and not the live show. I knew that Leo has often expressed the immense value he gets from the chatroom and doing live shows, so I knew something must have happened. I also knew that since this wasn't the first time, it must have been something bad. It was.
Even so, I might have overlooked it in isolation. I might have at least waited for the dust to settle. My problem is that the list of offenses has grown too long and too pervasive:
- Leo's affair with his CEO
- Erik Lanigan's dismissal and eventual death
- Petty banning of Jason Calacanis
- Leo accidentally showing sexts on shows
- Departure of many hosts
- General misogyny during shows
- Recent emphasis on virtualized porn
- Most recent issue
Thursday, June 5, 2014
One year later: Snowden & the NSA leaks
Working for a company that produces an information security product, I always assumed the United States conducted some level of surveillance and spying going on the internet. Nevertheless, PRISM still felt like a slap in the face. Assuming the government has betrayed you is one thing, seeing documents showing how they're doing it is something else. My previous office worked on information fusion, and the state-of-the-art there pretty much stunk. I naively hoped that applied universally, but that appears incorrect. I understand why the NSA wants to collect all this information, but I also understand the Fourth Amendment.Writing this post has been on my todo list for a few months now, the anniversary of the leaks being a convenient forcing function. In another month comes another significant anniversary: the 4th of July. Have you considered what sort of effect NSA-like surveillance would have had on the American Revolution? We now put the Founding Fathers on pedestals and consider them inspired men, but at the time they were traitors to England. Although we may romanticize the origins of our nation to some extent, I feel it reasonable to assume that a surveillance state would have squashed it. Look at how China has handled Tiananmen Square, and that was 25 years ago.
These leaks will forever be associated with Edward Snowden, so a discussion of one must involve the other. He accurately predicted the government's attempt at character assassination in his initial interview. At least one of my coworkers instantly condemned Snowden's leak and called him "a tool." I regularly listen to TWiT, and Leo Laporte almost as quickly labeled Snowden as a hero. At his talk at RSA earlier this year, Richard Clarke labeled Snowden as a traitor and said the United States should prosecute him as such. My opinion of Snowden trended toward positive, although it swayed significantly depending on with whom I had most recently spoke.
What would you do in Snowden's shoes? In his recent NBC interview he claims to have raised the issues internally, although the NSA denies this. Have you ever worked anywhere that your ideas would get patiently listened to and then the only response would be a nice pat on the head? Can you see that being the case at the NSA, a government organization? If he tried to raise the issue internally (like I suspect many have), he obviously did not get enough response. If he did not raise the issue internally, perhaps he though he might get "disappeared" to Gitmo. Maybe he thought he might get droned. The post-9/11 rules for how the government treats those it does not like seem very undefined. The Patriot Act, Obama's inaction, and his own experience as a government contractor had cost him his faith in the system.
One objection to Snowden's behavior during the first couple of weeks consisted of his somewhat strange escape route. To complain about NSA surveillance and then go to a country that obviously had it significantly worse seemed hypocritical. To go from there to KGB-led Russia made little sense as well. His interview throwing softball questions to Putin did not help. I do not have all the answers here, but I know that if I really wanted and expected change, I needed to stay in a place where I could act. That meant Snowden had to stay out of range of United States authorities. A safe bet that our two biggest frenemies could keep him out of jail, provided he applied a little leverage. Maybe that leverage consisted of not airing their dirty laundry, or sharing one or two country-specific NSA secrets. I admit the evasion route still has questionable parts, but it at least seems feasible.
Thank you for reading through my thoughts on Snowden & the NSA leaks. I still do not obsess about it, but felt the anniversary deserved more than a passing note. I think Snowden did something incredibly brave and that history books will describe him as a hero. In our fear after 9/11, the pendulum of freedom vs. security swung dramatically toward security. It's time it swung back to freedom.
DISCLAIMER: This post reflects my views and opinions only. Any comments made on this website, by myself or by third parties, do not necessarily reflect views or opinions of my employer, religion, family, or any other organization to which I belong.
Thursday, September 5, 2013
Widening the bell curve
That brings us back to “widening the bell curve.” A normal distribution follows a bell curve: extremes happen much less often than the average. Something not following that probability, such as “magically” finding every Nazi transport, would appear as an extraneous bump on the bell curve. The information theory solution of widening the bell curve ahead of time tries to avoid exposing that bump. Widening occurs by adding additional data points to smooth out the distribution, and must be added in many places to ensure a smooth and symmetrical bell shape. Figuring out just what to do to maintain the normal bell curve became the job of one protagonist in Cryptonomicon.
Tuesday, July 23, 2013
Person of Interest: Now a documentary!
I wrote a blog posts at the ends of season one and two talking about how the show's world melded with our current reality and what we could learn from that.
Thursday, July 11, 2013
Managing Security Tradeoffs between Private and Public Information
New Bit9 blog post: Managing Security Tradeoffs between Private and Public Information.
It talks about this graph I've been thinking about:
You can read all my Bit9 blog posts here.
Saturday, June 15, 2013
Wednesday, June 12, 2013
CS Reading List
|
This textbook changed my life, or at least the course associated with it did. I thought I wanted to do computer graphics up until taking CS 324 at BYU. The labs which come with this book introduced me to an abstraction level of computing that I loved: looking at the hardware side while staying barely on the software side. I still regularly use this book for a reference.
| |
|
Anyone serious about software development will at least have some familiarity with design patterns. Of course, knowing design patterns no more makes you a software designer than knowing the contents of a Lego store makes you a Lego sculptor. Still, the Gang of Four’s canonical introduction to this topic helps us all have a foundational vocabulary upon which to build.
| |
|
A paradigm shift in the construction and motivation of complex systems. The open source software movement continues forward. Whether or not you subscribe to the philosophy to any degree, you will interact with people who do. This book can help Cathedral types understand, appreciate, and maybe become more like Bazaar types. It does not include free beer.
| |
|
My graduate school advisor recommended that all incoming computer science students read this book. Although it centers on Licklider, it provides an amazing background on the advent of modern computing up to the start of the century. It blew my mind to realize how early the visionaries imagined the world at which we eventually arrived.
| |
|
I admit that this one is old. Fred Brooks experience managing the development of IBM’s System/360 took place in the mid-60s, and the essays center on that experience. Later editions have added chapters looking back on the earlier suppositions, and they appear to hold up well. Wading into software engineering management really does mean walking through tar pits.
| |
|
Technology in the information age has rapidly outpaced legislation and societal norms. This creates significant problems as old laws and ways of thinking about things can artificially cripple and hamper technology enabled progress. Typically, those that understand the societal norms and legislation are not the ones who understand the technology, and vice versa. Lessig grasps both sides and, more importantly, proffers solutions.
| |
|
I admit this may be more of a fanboy addition and that a similar list to this one in 20 years probably will not include this book. However, I like the perspective Jeff Jarvis brings to the discussion about privacy. I’m not saying he’s 100% correct, just that we need to see things from this point of view as well. We are social beings ready to reap the benefits to be gained through sharing.
|
|
I almost put this book in the non-fiction section as it’s semi-autobiographical, but in the end it’s a novel. The protagonist of the story investigates the meaning of quality, conveying his thoughts through conversations with others and flashbacks. The thought required to read this book may exercise mental muscles not normally used, but we can all benefit from understanding quality and how to pursue it.
| |
|
Author Mark Russinovich draws from years of experience architecting software for the Windows operating system to write a compelling, modern-day, thriller. The two biggest weaknesses of the book include a zealous following of stereotypes and more adult content than seems necessary for the story. One thing the book does exceptionally well is get into the nitty-gritty of exploits in an engaging way.
| |
|
This story moved me to tears, which says something (either about me or about the story). A lot of bad things happen to innocent people in this technological thriller, but in the end the author paints a world-wide networked society in which I want to participate.
| |
|
The upcoming movie has increased interest in this work, but I first read it as a kid. Probably my favorite book of all time, it presents a number of philosophical and technological issues that still face us today. The movie cannot possibly do this book justice, so I suggest you read it and the other seven books in the series (I know there’s more but I can only vouch for the original eight).
| |
|
Some may argue that Asimov’s I, Robot should take this spot, but I enjoy the scope and vision of the Foundation series. A political treatise wrapped in science fiction, it provides many nuggets of insight for those wishing to live in a modern and civilized society. “Violence is the last refuge of the incompetent.”
| |
|
Where Foundation provides nuggets of insight, The Hitchhiker’s Guide extrapolates technology-enabled life to the absurd. A hilarious romp through the genre, it illustrates the importance of not taking ourselves too seriously since we are always finding out new ways in which the universe is weird. Plus, there’s Marvin.
| |
|
I almost got turned off on this book by the atheist diatribe near the beginning of the book. Luckily I stuck with it and ended up thoroughly enjoying this story. A fun look at MMORPGs and a retrospective of the 80s, the book can introduce that culture for those who missed it. You’ll find it permeates the tech community.
|
Wednesday, May 29, 2013
Wednesday, January 30, 2013
Friday, January 11, 2013
Preaching to the Choir: The Problem with Cybersecurity Education
Posted on the Bit9 blog: Preaching to the Choir: The Problem with Cybersecurity Education
See all my Bit9 blog posts here.
Tuesday, September 18, 2012
Do you accept the Daemon?
Daemon begins with the death of Matthew Sobol, a fictional game designer. Sobol’s massively multiplayer online games brought his company wild success, and apparently left him with too much free time to think about the world order. He decided to change that order post-mortem by leaving behind a powerful internet daemon. The daemon intricates itself with the world’s information technology systems, obtaining immense power. The story follows many characters, some of which fight the daemon and some of which join the daemon. Both approaches provide thought provoking perspectives.
An interesting case study comes from the daemon’s takeover of Leland, a fictional multi-national financial company. Like many large corporations, Leland depends on a complex IT infrastructure. Recent cuts to the IT budget demonstrate the CEO and board view that infrastructure as an unfortunate operating expense rather than a core intellectual property resource. Those cuts produce vulnerable systems and disgruntled employees, which then facilitate the industrial espionage that introduces the daemon to the system. Once inside, the daemon moves laterally and vertically to compromise the entire system. The chiefs and board recognize the stranglehold too late, and the company becomes part of Daemon Inc. Fiction? Yes. Demonstrates real-world issues? Also yes.
Suarez makes several points through the book about technology and our society. Our world consists of largely monolithic monoculture of interconnected systems. We build layer upon layer on top of insecure technologies at the base. As we squeeze out each inefficiency, we make the entire system less flexible and more brittle. A relatively small number of us really know how the digital world works. Powerful people put their power into technology they do not understand or, even worse, misunderstand. Entire fortunes are made virtually and in the blink of an eye, without any produced good or service. All these set up an environment ripe for a cyber-parasite such as Sobol’s daemon.
Unfortunately, no silver bullet exists for dealing with these issues. Carnegie Mellon lead a study on ultra-large-scale (ULS) systems half-a-dozen years ago. Much excitement surrounded the initial release of the study, but it appears that the research area has languished since then. The study identified “security, trust, and resiliency” as a future topic of interest. Indeed. Those three compose a triumvirate for uptime, with each affecting the others. Any solution for one must consider the other two. Does your plan for server resiliency include security and trust? It should.
I really enjoyed Daemon, and highly recommend it. Many others feel the same way. A few complaints come from those who do not realize this first book only contains the the first half of the story. Picture reading Lord of the Rings and stopping midway through The Two Towers. Fortuitously, the rest of the Daemon story already exists in FreedomTM. I suggest getting both and then disappearing for a couple weeks to finish them. You will not regret it.
Need more info about Daniel Suarez and the ideas from his book? Check out these recent interviews for his Kill Decision book tour:
Monday, August 27, 2012
Why it's awesome to work at Bit9
I recently had the pleasure of attending some instruction from retired four-star General Bruce Carlson. The material covered a number of things, including some important life lessons. He emphasized the importance of making sure you love what you do, saying something along the lines of: “my wife tells me I had a job, but I don’t remember doing a single day of work. I got to fly planes for a living.” I suspect some degree of hyperbole, but it still made me think about where I currently choose to earn my living. Not only do I enjoy working at Bit9 (CrunchBase Profile), but I feel others should know that so they will join the company if given the opportunity.Monday, August 20, 2012
Tuesday, July 17, 2012
The Darwin Awards of IT Security: 6 Things to Avoid
Thursday, June 28, 2012
Beyond the Maginot Line: 8 Ways to Improve Your Personal Security Posture
See all my Bit9 blog posts here
Monday, June 11, 2012
Malware Fear: Are Security Companies Manipulating or Highlighting the Truth?
Malware Fear: Are Security Companies Manipulating or Highlighting the Truth?







