Physically Unfit 15 July, 2008 at 2:16 pm

OK, so, I never made it past the first week of that 100-pushups thing. Not because I can’t do it (although, i’m not sure I’d've made it, anyway), but because I can’t DO it. With DK’s stuff everywhere, it’s hard to find a space large enough to stretch prone to DO a push up. Then when DK is awake, he wants to come see what I’m doing and climb on me. And when K’s around, he wants to come stand RIGHT UNDER ME. Makes it hard to do the ‘down’ so I CAN push ‘up’.

So, I’m kindof abandoning that I guess.

Then we got a workout video thing for exercising with the baby. Except (a) the person talking is really insipidly annoying (?), which is really to be expected. They want perky cheerful people. But then the exercises, half of them I can’t (who has enough room in their house, with a baby, to act like a sumo-wrestler?) or won’t do (I refuse to believe there is an actual benefit to making stupid noises at DK). YOU may be doing these in an empty studio that has 3 adults, 3 yoga mats, 3 babies/toddlers, and 3 tiny-ass baskets of toys, but *I’m* doing it at home with the baby’s stuff. Lemme tell you. Not the same :o

Still, it was a damn good workout the two days I did it. Just hard to find a time when I want to spend 45 minutes of me & des to workout. Although it is a nice break from days on end playing xbox with him, I s’pose.

Started working on Weight Watchers(tm) again this week. The chart stuff indicates 24-30 points a week for me. Yesterday was 50. Today is looking to be 40+. My piece of pumpkin bread in the morning is 8. Actually, it was 12, but I cut it smaller yesterday. I started saying something about it “did you see this morning I took …” and Kiir filled in for me “waaaaaay way way too much?” … so maybe not as better as I thought :/ So today I took a SMALLER slice. Next time I make bread I need to make the three smaller loave the recipe calls for. Because cutting soft crumbly bread to a quarter inch thickness is hard. And not very filling.

But my healthy cheese sammich for lunch? Two slices of wheat bread, and two slices of munster cheese? 8 points again! WTF! *sigh* I should drop it to 1 slice of cheese (cheese = 3 pts, bread = 1pt). But I don’t know if that’s enough flavour. Milk? 2-3 pts depending on which glass (well, the really small glass would be 1 and the really big one is 4, but I’m assuming I’m usually using one of the 3 middle sizes, since I only have 2 of the small small and the big big i usually don’t fill all the way).

Still. Some pumpkin bread, two glasses of milk, and a sandwich, and I’m up 15 points, nearly 20 if I keep the second slice of cheese or take the bigger slice of pumpkin :/

OI!

100 Pushups Challenge 28 June, 2008 at 11:12 pm

So, some folks on the forums my old everquest guild come gaming collective use …

uh …

some folks on a forum I read were talking about the “100 pushup challenge” and talking about trying it. We have some stuff dedicated to quarterly weight stuff and diet etc, so I figured I’d join in on this. Doesn’t look like we’re getting WiiFit anytime soon, what with the high demand and low production, so why not. and, c’mon, doing 100 pushups? gonna need some muscle or toning for that! and the 6-week training? gonna build some muscle during that, I imagine. so, it could well be good for my weight.

Or at least turn some of my excess weight into functional muscle mass instead.

Did the “initial test” a few minutes ago, and hit 15. With K assisting. By standing under me when I pushed up, to make sure I went all the way up I guess. Just wish he’d moved out for down rather than me using my head to nudge him around an’ stuff! Nothing I read, quickly, suggests that there’s any difference in structure once I’ve passed 10 to begin with, and since I just hit the “rank 3″ listing at the bottom edge, I figure “15-20″ is a good initial measure. So. Let’s see how THIS goes ;)

Back from Vacation at 9:34 pm

Left for vacation last friday. Left the house at 10:30, arrived in NC at 11:30. AM and PM respectively …

To be fair, however, we left at 10:30, went to gymboree, picked up a few things at target, did lunch, hit the grocery for my happy pills so they wouldn’t run out thursday evening. Got “on the road” around 1:30. Stopped at kiir’s grandmother ~4:30? her aunt was there visiting on HER way to vacation too! then another aunt stopped by with her two kids, 5 and 8?, and we ended up just staying for dinner rather than leaving and then stopping in 20 miles :o Boy likes to eat at 6. 6:30 at the outside, if you give him a snack to keep the starvation at bay. Left there around 7:30 again, so I was really only driving 7 hours. But since I got up at 8:30, it was a long damned day :o

Kiir’s parents arrived saturday, we hit the pool. Went to New Bern, the Birthplace of Pepsi Cola!, but the town was basically closed when we went on Sunday. Monday was more pool and playing at the timeshare b/c mom had to work most of the day. Tuesday we (kiir, dk, me, and dad) went to the beach (mom had to work all day (this is a repeating theme)). DK LOOOVED the sand and the surf and the ocean and everything. Unless you took away his plastic shovel. Then the universe sucked and was trying to eat his favourite toy and and and ooh shovel! yay. :) (I had to run into the water a few times when he dropped it whilst playing in the tide, oi)

Tuesday night mom and dad watched DK so Kiir and I could go out for dinner , just the two of us. I was afraid all the good restaurants were an hour away at the beach area, but Kiir had found a few in New Bern that sounded decent. We actually went to a japanese steakhouse, was pretty good.Wednesday we did the pool again, mom played with DK for a bit between calls. Thursday they left and we went to the pool and started packing things up

Friday, checkout was at 10AM. I had called and gotten permission to leave at noon instead, since we didn’t really think the 15mo old was going to be conducive to packign quickly, nor amenable to getting up early enough to be out and on the road at 10 :o Kiir took him to the pool around 10ish, and I spent until 11:30-11:45 packing the car. They finally came back to see why I hadn’t come over to pick them up after finishing. On the road around noon, yay. Stopped in like 20 minutes for lunch at IHOP, picked up blueberries for the boy wonder, and off we went!

Stopped at Kiir’s grandmothers again and had dinner with them. Dinner was nice, but the important part of this stop was giving desmond some time OUT of his carseat to run around. Because he woke up when I stopped for gas an hour outside of Richmond. And he was PISSED. Because he was DONE with his car seat :o

Got home last night ~10ish, yay.

NTS: Strawberry Picking is NOT a White Shirt Affair 16 June, 2008 at 8:40 pm

So, Sunday for Father’s day, we (Kiir, DK and me) went out to pick strawberries at Larriland again :)

Which is humourous, since I don’t actually much like strawberries, although I’m told that as a child I did. Certainly explains why I remember going strawberry picking with my mom. Had wondered why I did that when I didn’t like them

Anyway. Sunday morning, DK woke up at about 7AM. I was really planning to sleep another hour or two, personally, but up we got and played some Lost Odyssey and waited for mommy. At some point, I grabbed a random shirt from the living room for DK so that K could go for a walk (since it was just us three, we all went, or no one went). Afterwards, when Kiir got up, I grabbed two shirts and two shorts and let DK pick out his clothes. It wasn’t until we were out to pick that I realized that perhaps the white shirt wasn’t the best of all possible choices. (I just checked the pics from Kiir’s blog, and no. It’s not the same white shirt. Entirely different stupid idea :o)

Afterwards we went up to the farm to get some whole milk for DK on vacation next week, then home and bathtime (did I mention he had strawberries? hello?) before my parents came up.

And then there were three … 14 June, 2008 at 9:44 pm

So ….

Yeah. Today, amongst various other tasks and errands, we stopped at Dream Wizards. Dream Wizards was where I used to buy Magic: The Gathering, Illuminati: New World Order, and Jyhad cards. Back in high school ;) We’d play in the back rooms on Friday evenings, and pick it all up and drive to the other end of the lot to the Roy Roger’s that was open until midnight.

Ten years ago, give or take, the place moved to a new location. I actually kindof preferred the old one, because it had the dark dungeon feel to it being in teh back corner of a somewhat unused area of stores. I think technically it’s old location is the basement of an REI now :o I understand the move, though. Better location, better business. Bigger location, so they can hold tournaments and play nights and such, which probably brings in mad cash when 50 kids come in to play Pokemon cards every week (kids … adults … whatever ;o)

ANYWAY! I decided to stop there and look for something in particular. Found it, too. DK now has his own, personal, private, set of DICE! It’s the full case, d4 through d20, everything you’d need for playing D&D now :) I’d put up a pic, but lets face it, they’re dice. And I’d have to get the camera, upload on kiir’s box, blah blah blah, and I am WAY too lazy.

But DK now has his own dice :)

Mailing List Woes 13 June, 2008 at 8:51 pm

So, DK is upstairs trying to fall asleep. Kiir was up all night reading, so she’ll likely fall asleep with him, although she did have a nap after I got home (and probably during his afternoon nap, but I don’t know for sure)

I’m going through my feeds (busy lately ; I’ve managed to keep up with the small ones, but the big ones? the ones that get 50+ a day? and tend to have things I actually click through to more often? yeah, a little behind on those … only ~500 right now.) anyway, looking at them, and deciding I’m not sure I really feel like reading them right now, I remember that my email has the SANS NewsBites, twice weekly digests with various security bits.

I have today’s. And the one from Tuesday.
And last week’s.
And the previous week’s. and back probably two months since I last managed to get the time to clear them.

I remember setting up the feed from SANS last year into google reader. Except instead of an item for each bit, there’s an item for each category. And the title is the cat title, and the body? the cat title. not even a headline listing :/

Now I’m contemplating the feasibility of setting somethign up to receive the messages, auto parse, and then produce an rss feed that i can then subscribe to (wow, that doesn’t sound complicated, does it?) since if it’s in my feeder I think I’d actually keep up on it. Because the feeder is somewhat easier to “glance at”

Ya, I start off commenting on how I don’t have time to read the stuff I’m already subscribed to, then move on to thinking about a way to make more to read … go me :)

How DO You Secure a Password on a Web App? at 12:46 pm

So … One of the tasks I’ve been looking at is a password server at the office. The major driving goal is that, after 5 years or so of succesfully NOT changing the password every 90-days, someone at the top of the Oracle group got a bug up their ass (actually, I think it’s a new head guy) and they’re declaring that they WILL change them now.

They’ve also said that they can’t be bothered to figure out who uses what accounts or to tell them that the passwords are changing. So one solution being tossed around is some dual account strategy where everything has two complete access points on offset cycles and some kind of SSL authenticated session managing so that we don’t have to worry about the passwords anymore because they won’t be used we’ll have the SSL certs. Without passwords? NOOO! There’ll still be passwords, we just won’t be using them, so it won’t matter if they change. But the certs, will they have passwords? NO!!! that’s the whole point! that way it’s secure! because now the connection is encrypted!

But … uh … if I can just swipe the cert, now, instead of the password … what has this gained us? other than that now we can eliminate that pesky security precaution of changing the password, because presumably we’re not talking about cycling the certs every whenever … “Well, if it’s compromised, we can just change the SSL cert and it won’t matter!” … uh, we can do that now. It’s called changing the PASSWORD. And it’s about 90x simpler than creating a cert. Oh, and self-signed non-authenticated certs area PITA, and I wouldn’t garauntee Oracle would even accept them for connections, lets be honest. OH! AND the guy proposing it has no idea if it’s even feasible! functional! possible!

My idea was to set up a database that has all the user/server/password combos that are used and the apps that use them. then a web service. and then App A connects to SERVICE, says “I am A, tell me what I need to know” and gets back all the relevant password/connection information. The passwords can be stored encrypted (I’m looking at mysql’s builtin AES, since I need to get it back out). The service can be HTTPS, so it’s not listenable. Then the service gets the password out, and passes it to the app that asked. If I look up client certs (same problems as their plan, but I’m not trying to use them to avoid the password, see?) and set it up, now I can use the cert to authenticate the app (I can also use the request IP for furtherance probably). We can set up however many accounts for any system. We can set up multiple different types of accounts. One app can have 3 databases to talk to on 3 different types of database and 2 or 3 account logins apiece

And the biggest danger? Well, the app can get it’s data. See, technically, if the SSL Cert is swiped and used in a forged request, well, then that forged request would get the credentials for use that app had. But you know what? If they’re swiping the cert, they could just swipe the password file, Because if the system can use it, the system can access it. And if the system can access it, then a sufficiently wide hole will allow the attacker to access it. And if they’re in for a penny, they’re in for a pound.

So, thus, the question. How do you secure it? Because, really, you need to secure the password(s) in such a way that the app can’t access them. That way it can’t divulge them. But, obviously, it then also can’t USE them. Catch-22!

Of course, the other thing to do would be to set up a series of READ ONLY accounts for the query systems (ie — apps), and then SEPARATE accounts that have privs (for the administrative features, etc). But THAT would require giving someone who knew what they were doing control. and that can’t be allowed to happen. We won’t discuss why, because that’d be wrong ;)

This Post Intentionally Left Blank 12 June, 2008 at 10:46 pm

I don’t have a lot to say right now. I’m a little behind on my crypto posts, so I should probably head there next.

DK didn’t want to go to bed at 9, so he came downstairs and fussed about for ~30 miinutes, then fell asleep on my legs for two hours. pins and needles pins and needles!!

Started playing CoH again last week, when he goes to bed early. Tonight we were doing Lost Odyssey again. Spent that two hours wandering around a cave and not finding the danged exit to lead to the next area. Once he went up, I looked at a walkthrough. It’s not the right cave, there IS NO next area from here. And apparently I missed the trigger, before, that would put something in here to find. But I’m thinking of running around for nother couple hours tomorrow, because it’s a great levelling room :)

X Marks The Spot 11 June, 2008 at 8:46 pm

So, after last night’s post …

This morning DK got up at 6:30 while I was in the shower. So instead of leaving early and taking a slightly earlier train to the office, I played Lego Indiana Jones with him for half an hour . At which point he was falling asleep and another ten or twenty minutes would have been a good idea … but I had to catch the train :o

XBox++!

All Available Lines Are Busy 10 June, 2008 at 10:15 pm

A week or so ago, maybe 10 days now?, Kiir sent the XBox back downstairs. I think I was pissing her off to a degree with the comments about it. Wasn’t my intention, as I was kvetching to kvetch. Yeah, I missed being able to play it, but I know she spends a lot of time upstairs with DK when he goes to bed. And he’s been going to bed ~9ish lately, which means that 9-12 she’s up on the bed while he sleeps, and now has nothing to do.

To be fair, we tried hooking her PC up to the TV on it’s VGA-in. It worked. Except she had to rack up the resolutions in everything so far that she was looking at a 800×600 resolution in 720p. With blind-people font sizes so she could READ the chat bubbles. Which meant she couldn’t actually PLAY the game. (Oh, we gave up on browsing as soon as it turned on :o That was RIGHT OUT).

So I felt bad that I harrassed her into giving back the X and being left with jack-all to do while he sleeps. Then this weekend hit.

I think it was Friday I woke up ~5ish. Decided to get up instead of tossing and turning, since every time I rolled over he fussed and roused. About 15 minutes later, he was crawling down the stairs to play with me. So instead of my initial plan of catching an earlier train, I played with him for a while. Like 2 hours. Actually, that might have been before we brought down the X, so that might have been two hours of Mario Kart (I like the game, but I’ve also come to hate it lately ; that’d be a different post I think)

Saturday evening after we went out then N&C (kiir’s brother and his girlfriend) visited, DK was tiiiired. Too tired. He couldn’t fall asleep. So he came down and sat on my lap and ran around the living room. We screamed, we cried. It was very emotional. Eventually I switched from Lego Indiana Jones to Lost Odyssey and we fell asleep after another half hour or so finally.

Sunday we went and visited my parents, his nap was short again, and then he took another short nap on the way home. When we got inside, he was rested enough to not go to bed right away, despite it being 9:30. By 10, he was overtired. And I played some Lego and some Lost Odyssey with him. I think we went to bed between 12 and 1. DK and I finished Lost Odyssey Disc 3 :o

Monday night, he went up around 9, we thought we had managed to slide back to schedule. Then he got up at 9:30. And came downstairs. And around 12 he finally fell asleep. I bought the Penny Arcade game on XBox. I went ahead and bought the Atari Warlords game, since I wanted something simple to play, and LO has some long periods between saves. And he doesn’t seem to sleep well to Legos.

I’m still sorry about possibly annoying Kiir and nagging or harrassing …. but I’m not sorry that I got the X back. Because ~12 more horus of Mario Kart or Pop, and I was going to start KILLING PEOPLE.

It’s been busy :o