<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="wordpress/2.3.2" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>

<channel>
	<title>Vivek's Soapbox</title>
	<link>http://www.vivekhaldar.com/blog</link>
	<description></description>
	<pubDate>Tue, 04 Apr 2006 16:43:06 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.3.2</generator>
	<language>en</language>
			<item>
		<title>Sampled Security Policies</title>
		<link>http://www.vivekhaldar.com/blog/?p=118</link>
		<comments>http://www.vivekhaldar.com/blog/?p=118#comments</comments>
		<pubDate>Tue, 04 Apr 2006 16:43:06 +0000</pubDate>
		<dc:creator>Vivek</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.vivekhaldar.com/blog/?p=118</guid>
		<description><![CDATA[There&#8217;s this vague question I&#8217;ve been tossing around in my head for a couple of days - what is the class of security policies that one can enforce by sampling the execution of a program? Note that this is not the same as inlining reference monitors.
First of all, we need to precisely define &#8220;sampling&#8221;. How [...]]]></description>
			<content:encoded><![CDATA[<p>There&#8217;s this vague question I&#8217;ve been tossing around in my head for a couple of days - <span style="font-weight: bold">what is the class of security policies that one can enforce by sampling the execution of a program? </span>Note that this is <span style="font-style: italic">not</span> the same as inlining reference monitors.</p>
<p>First of all, we need to precisely define &#8220;sampling&#8221;. How much state of the program do we see? The entire heap? The PC? The stack? The current value of all registers? How do the properties covered improve or degrade as we increase or decrease the state covered?</p>
<p>Then &#8212; what is the <span style="font-style: italic">granularity</span> of sampling? Instructions? Basic blocks? Random points in the program?<br />
Also, sampling can not enforce a property with certainty, but with some probability. How can we make this probability high?</p>
<p>Like I said, this is just a fuzzy notion, and I have no concrete answers. For all I know, it might turn out that the class of properties enforceable through sampling is very small, or very weak. But it would be nice to know anyway.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.vivekhaldar.com/blog/?feed=rss2&amp;p=118</wfw:commentRss>
		</item>
		<item>
		<title>PhD dissertation LaTeX template for University of California at Irvine</title>
		<link>http://www.vivekhaldar.com/blog/?p=116</link>
		<comments>http://www.vivekhaldar.com/blog/?p=116#comments</comments>
		<pubDate>Fri, 31 Mar 2006 23:29:10 +0000</pubDate>
		<dc:creator>Vivek</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.vivekhaldar.com/blog/?p=116</guid>
		<description><![CDATA[Sadly, UCI does provide a LaTeX template for dissertations. Getting the formatting right without a template can be a major pain, so here are the templates that I used.
LaTeX UCI thesis class and sample LaTeX file (ZIP file)
Credits: I initally got this template from TeX guru and ex-officemate Jeff von Ronne. I&#8217;ve made a tweak [...]]]></description>
			<content:encoded><![CDATA[<p>Sadly, UCI does provide a LaTeX template for dissertations. Getting the formatting right without a template can be a major pain, so here are the templates that I used.</p>
<p><a id="p117" href="http://www.vivekhaldar.com/blog/wp-content/uploads/2006/03/template.zip">LaTeX UCI thesis class and sample LaTeX file (ZIP file)</a><span style="font-weight: bold" /></p>
<p><span style="font-weight: bold">Credits</span>: I initally got this template from TeX guru and ex-officemate <a href="http://www.cs.utsa.edu/~vonronne/">Jeff von Ronne</a>. I&#8217;ve made a tweak or two, but it&#8217;s 99% Jeff&#8217;s work (and lots of people before him too &#8212; see the class file for more credits).</p>
<p>O Google, please make this the first hit for the next poor grad student who searches for &#8220;uc irvine dissertation template&#8221;!!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.vivekhaldar.com/blog/?feed=rss2&amp;p=116</wfw:commentRss>
		</item>
		<item>
		<title>Riya and privacy</title>
		<link>http://www.vivekhaldar.com/blog/?p=115</link>
		<comments>http://www.vivekhaldar.com/blog/?p=115#comments</comments>
		<pubDate>Wed, 22 Mar 2006 19:46:06 +0000</pubDate>
		<dc:creator>Vivek</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<category><![CDATA[webapp]]></category>

		<guid isPermaLink="false">http://www.vivekhaldar.com/blog/?p=115</guid>
		<description><![CDATA[Srijith commented on my earlier post about trying out Riya, and pointed out that people had been raising privacy concerns about the product.
Ben says: what if Riya recognizes and tags pictures of me in public that other people have taken, that I don&#8217;t necessarily want to be associated with? He uses the example of visiting [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://security.srijith.net/">Srijith </a>commented on my earlier post about <a href="http://www.vivekhaldar.com/blog/?p=114">trying out Riya</a>, and pointed out that people had been raising privacy concerns about the product.</p>
<p><a href="http://benmetcalfe.com/blog/index.php/2005/11/18/riya-when-the-open-concept-goes-too-far-repost/">Ben says</a>: what if Riya recognizes and tags pictures of me in public that other people have taken, that I don&#8217;t necessarily want to be associated with? He uses the example of visiting an erotica event.</p>
<p>To which <a href="http://munjal.typepad.com/recognizing_deven/2005/12/riya_and_privac.html">Munjal, one of Riya&#8217;s founders, replies</a>:</p>
<blockquote><p>Riya doesn&#8217;t look for you or tag you in another&#8217;s photo unless they train us and have you in their friends list. Even if they do, it is not public unless they make it public.</p></blockquote>
<p>I think that&#8217;s a fair enough reply.</p>
<p>I am not a  lawyer, but my perspective on this: when you&#8217;re in public (on the street, at an erotica expo etc) you don&#8217;t really have any reasonable expectation of privacy, so you can&#8217;t say &#8220;my privacy was violated&#8221; if someone recognizes you.</p>
<p>My only concern about Riya doesn&#8217;t even have anything to do with facial recognition &#8212; it&#8217;s just that (to me, at least) my photos are rather personal things, and I do feel a little queasy about uploading all of them to a server that I don&#8217;t control. But this is pattern that comes up again and again, with any hosted service &#8212; Gmail, online calendaring, online file storage etc. If only there was a way for me to encrypt everything with a key that I own, and then upload everything, that would be great. But in general, this is a hard problem &#8212; how is the remote service going to work on your data if its encrypted?</p>
]]></content:encoded>
			<wfw:commentRss>http://www.vivekhaldar.com/blog/?feed=rss2&amp;p=115</wfw:commentRss>
		</item>
		<item>
		<title>Trying out Riya beta</title>
		<link>http://www.vivekhaldar.com/blog/?p=114</link>
		<comments>http://www.vivekhaldar.com/blog/?p=114#comments</comments>
		<pubDate>Tue, 21 Mar 2006 21:32:24 +0000</pubDate>
		<dc:creator>Vivek</dc:creator>
		
		<category><![CDATA[webapp]]></category>

		<guid isPermaLink="false">http://www.vivekhaldar.com/blog/?p=114</guid>
		<description><![CDATA[Waiting in my inbox this morning was an invitation to try out the beta of Riya. So I signed up, downloaded their uploading tool, and started uploading.

The uploading tool not only transfers the photos to Riya, but also performs the actual recognition of faces. When the pictures are uploaded, you can log into the web [...]]]></description>
			<content:encoded><![CDATA[<p>Waiting in my inbox this morning was an invitation to try out the beta of <a href="http://www.riya.com">Riya</a>. So I signed up, downloaded their uploading tool, and started uploading.</p>
<p><img alt="riya_logo.gif" id="image113" src="http://www.vivekhaldar.com/blog/wp-content/uploads/2006/03/riya_logo.gif" /></p>
<p>The uploading tool not only transfers the photos to Riya, but also performs the actual recognition of faces. When the pictures are uploaded, you can log into the web site and start attaching names to recognized faces. Once you give it 20-30 samples of a specific person, it does a pretty good job of recognizing more pictures of the same person &#8212; at least for frontal shots. Later, you can go pick out the pictures it recognized incorrectly.</p>
<p>Another nice touch &#8212; it does OCR on text in pictures. But this seems to work only with more or less horizontal text, and with fonts that are common.</p>
<p>I never thought I&#8217;d use an online service for storing all my pictures because I just love having them locally, to browse whenever I like. But this is compelling enough that I think I&#8217;m going to start slowly uploading all my pictures to Riya.</p>
<p>Number one wish for Riya: have a local client that allows offline browsing of your photo collection, with facial recognition. Or better still, standardize a format for specifying regions within a picture, and metadata associated with it (e.g. the rectangle from (x1, y1) to (x2, y2) has Vivek&#8217;s face), so that multiple clients can use it. Not sure how well that&#8217;s going to work with their business model, though.</p>
<p>Overall, I think this has the potential to be something really great!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.vivekhaldar.com/blog/?feed=rss2&amp;p=114</wfw:commentRss>
		</item>
		<item>
		<title>My dissertation</title>
		<link>http://www.vivekhaldar.com/blog/?p=112</link>
		<comments>http://www.vivekhaldar.com/blog/?p=112#comments</comments>
		<pubDate>Mon, 20 Mar 2006 05:48:44 +0000</pubDate>
		<dc:creator>Vivek</dc:creator>
		
		<category><![CDATA[Programming Languages]]></category>

		<category><![CDATA[Security]]></category>

		<category><![CDATA[Trusted Computing]]></category>

		<guid isPermaLink="false">http://www.vivekhaldar.com/blog/?p=112</guid>
		<description><![CDATA[I finally submitted my dissertation to the UC Irvine library on Friday. After my final defense, this was the last hurdle to jump, and I have now officially completed my doctorate.
Here&#8217;s my dissertation. (PDF, 3.5 MB)

To cut a long story short, here is my thesis:
Remote attestation, one of the core mechanisms of Trusted Computing, can [...]]]></description>
			<content:encoded><![CDATA[<p>I finally submitted my dissertation to the UC Irvine library on Friday. After my <a href="http://www.vivekhaldar.com/blog/?p=92">final defense</a>, this was the last hurdle to jump, and I have now officially completed my doctorate.</p>
<p><a id="p110" href="http://www.vivekhaldar.com/blog/wp-content/uploads/2006/03/thesis.pdf">Here&#8217;s my dissertation. (PDF, 3.5 MB)</a></p>
<p><img id="image111" alt="page1.jpg" src="http://www.vivekhaldar.com/blog/wp-content/uploads/2006/03/page1.jpg" /></p>
<p>To cut a long story short, here is my <strong>thesis:</strong></p>
<p>Remote attestation, one of the core mechanisms of Trusted Computing, can be<br />
performed in a way that:</p>
<ul>
<li>reasons expressively about program behavior and dynamic properties</li>
<li>enables a flexible, graded notion of trust</li>
<li>avoids intractable management problems at both the client and server end</li>
<li>does not tie attestation to a specific executable binary</li>
</ul>
<p>In short, remote attestation can attest program properties, rather than program<br />
binaries. I call this <em><strong>semantic remote attestation</strong></em>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.vivekhaldar.com/blog/?feed=rss2&amp;p=112</wfw:commentRss>
		</item>
		<item>
		<title></title>
		<link>http://www.vivekhaldar.com/blog/?p=109</link>
		<comments>http://www.vivekhaldar.com/blog/?p=109#comments</comments>
		<pubDate>Mon, 20 Mar 2006 00:25:34 +0000</pubDate>
		<dc:creator>Vivek</dc:creator>
		
		<category><![CDATA[Links]]></category>

		<guid isPermaLink="false">http://www.vivekhaldar.com/blog/?p=109</guid>
		<description><![CDATA[Can you patent thoughts? (by Michael Crichton)
]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.nytimes.com/2006/03/19/opinion/19crichton.html?ei=5088&#038;en=9addb806498d2739&#038;ex=1300424400&#038;partner=rssnyt&#038;emc=rss&#038;pagewanted=print">Can you patent thoughts?</a> (by Michael Crichton)</p>
]]></content:encoded>
			<wfw:commentRss>http://www.vivekhaldar.com/blog/?feed=rss2&amp;p=109</wfw:commentRss>
		</item>
		<item>
		<title>RFIDs and command injection attacks</title>
		<link>http://www.vivekhaldar.com/blog/?p=108</link>
		<comments>http://www.vivekhaldar.com/blog/?p=108#comments</comments>
		<pubDate>Wed, 15 Mar 2006 22:17:05 +0000</pubDate>
		<dc:creator>Vivek</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.vivekhaldar.com/blog/?p=108</guid>
		<description><![CDATA[There&#8217;s two phrases you never thought would go together! What do RFIDs, those tiny, powerless, passive things, have to do with havoc-wreaking command injection attacks?
Andrew Tannenbaum&#8217;s group has just published a paper that shows how seemingly innocent RFIDs can be used to inject malicious code into the backends that process their data:
One day a container [...]]]></description>
			<content:encoded><![CDATA[<p>There&#8217;s two phrases you never thought would go together! What do RFIDs, those tiny, powerless, passive things, have to do with havoc-wreaking command injection attacks?</p>
<p>Andrew Tannenbaum&#8217;s group has just <a href="http://www.rfidvirus.org/index.html">published a paper</a> that shows how seemingly innocent RFIDs can be used to inject malicious code into the backends that process their data:</p>
<blockquote><p>One day a container arrives in the supermarket distribution center that is carrying a surprising payload. The container&#8217;s RFID tag is infected with a computer virus. This particular RFID virus uses SQL injection to attack the backend RFID middleware systems.</p></blockquote>
<p>There you go &#8212; another <a href="http://www.vivekhaldar.com/blog/?p=19">channel </a>for <a href="http://www.vivekhaldar.com/blog/?p=23">tainted </a>input.<br />
This so-called &#8220;taint problem&#8221; comes up everywhere. Most recently, its been brought to light because of its implications for <a href="http://www.vivekhaldar.com/blog/?p=23">web application security</a>, but if you dig deeper, its a much more fundamental problem that comes up whenever your program deals with untrusted input.</p>
<p>I think the long-term solution to this is to have fine-grained labeling of data, along with a way to propagate those labels. We&#8217;ve made <a href="http://www.vivekhaldar.com/blog/?p=19">an initial jab at the problem</a>, but that&#8217;s only scratching the surface. How long before labeling becomes a first-class abstraction in a language? In a virtual machine runtime? Or even at the architecture level in hardware?</p>
]]></content:encoded>
			<wfw:commentRss>http://www.vivekhaldar.com/blog/?feed=rss2&amp;p=108</wfw:commentRss>
		</item>
		<item>
		<title>Broken government websites</title>
		<link>http://www.vivekhaldar.com/blog/?p=107</link>
		<comments>http://www.vivekhaldar.com/blog/?p=107#comments</comments>
		<pubDate>Tue, 14 Mar 2006 19:58:09 +0000</pubDate>
		<dc:creator>Vivek</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.vivekhaldar.com/blog/?p=107</guid>
		<description><![CDATA[
Shouldn&#8217;t government websites try to be a little more cross-platform??
]]></description>
			<content:encoded><![CDATA[<p><img alt="inswebsite.jpg" id="image106" src="http://www.vivekhaldar.com/blog/wp-content/uploads/2006/03/inswebsite.jpg" /><br />
Shouldn&#8217;t government websites <em>try</em> to be a little more cross-platform??</p>
]]></content:encoded>
			<wfw:commentRss>http://www.vivekhaldar.com/blog/?feed=rss2&amp;p=107</wfw:commentRss>
		</item>
		<item>
		<title>What I want in a blog reader&#8230;</title>
		<link>http://www.vivekhaldar.com/blog/?p=105</link>
		<comments>http://www.vivekhaldar.com/blog/?p=105#comments</comments>
		<pubDate>Thu, 09 Mar 2006 18:50:22 +0000</pubDate>
		<dc:creator>Vivek</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.vivekhaldar.com/blog/?p=105</guid>
		<description><![CDATA[I&#8217;ve been using BlogBridge for a day and its now my blog reader of choice, for several reasons:

feed ratings help when you have to quickly scan though a hundred feeds
the little activity indicators next to each feed are a really good visual indication of which feeds have new stories
you can sync your feeds up to [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve been using <a href="http://www.blogbridge.com/">BlogBridge </a>for a day and its now my blog reader of choice, for several reasons:</p>
<ul>
<li>feed ratings help when you have to quickly scan though a hundred feeds</li>
<li>the little activity indicators next to each feed are a really good visual indication of which feeds have new stories</li>
<li>you can sync your feeds up to a server (need to sign up for that) and then sync them across all your clients</li>
<li>its in cross-platform Java</li>
</ul>
<p><img alt="blogbridge.jpg" id="image104" src="http://www.vivekhaldar.com/blog/wp-content/uploads/2006/03/blogbridge.jpg" /><br />
<img alt="bbactivity.jpg" id="image103" src="http://www.vivekhaldar.com/blog/wp-content/uploads/2006/03/bbactivity.jpg" /></p>
<p>All the same, there&#8217;s still plenty more I want in a newsreader. My number one gripe: <strong>newsreaders have to effectively summarise and present information from a large number of feeds</strong>. All current newsreaders work on the &#8220;feed-browsing&#8221; model, where the user clicks on a feed, reads its stories, moves on to a different feed and so on. I want my newsreader to be a <strong>statistical clustering engine</strong> that automatically <strong>learns</strong> from my reading habits, and also <strong>clusters<em> </em></strong>similar stories from across different feeds into a coherent view. In short, a newsreader has to make it easy for me to keep up with hundreds of feeds without having to scan each one of them.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.vivekhaldar.com/blog/?feed=rss2&amp;p=105</wfw:commentRss>
		</item>
		<item>
		<title>Announcing Shop Finder</title>
		<link>http://www.vivekhaldar.com/blog/?p=82</link>
		<comments>http://www.vivekhaldar.com/blog/?p=82#comments</comments>
		<pubDate>Thu, 02 Mar 2006 02:39:20 +0000</pubDate>
		<dc:creator>Vivek</dc:creator>
		
		<category><![CDATA[webapp]]></category>

		<guid isPermaLink="false">http://www.vivekhaldar.com/blog/?p=82</guid>
		<description><![CDATA[Ever wanted to find a place where all the shops you wanted to go to were close together so that you could drive to one place and be done with it? Ever gone out to lunch with friends, only one wants to go to Subway, another to Quiznos, and another to Carls Jr, and wanted [...]]]></description>
			<content:encoded><![CDATA[<p>Ever wanted to find a place where all the shops you wanted to go to were close together so that you could drive to one place and be done with it? Ever gone out to lunch with friends, only one wants to go to Subway, another to Quiznos, and another to Carls Jr, and wanted to find a place where all three were next to each other?</p>
<p>Then <a href="http://vivekhaldar.com:8080/Shopper/">Shop Finder</a> is for you. Enter two or more shops, or restaurants or any business at all, and a location, and it will go and tell you where you can find all of them close to each other.<br />
<img id="image101" alt="clustershop.jpg" src="http://www.vivekhaldar.com/blog/wp-content/uploads/2006/03/clustershop.jpg" /></p>
<p>This is a quick and dirty early release, and there&#8217;s still plenty of stuff I want to do with this if I have some spare time on my hands:</p>
<ul>
<li>Brush up the interface &#8212; show links to the shops, present clusters in a way that doesn&#8217;t look like debug output etc.</li>
<li>Let the user tweak the cluster radius &#8212; that&#8217;s how close two shops should be to be considered as part of the same cluster.</li>
</ul>
<p>In the meanwhile, I hope someone finds this useful. Feedback is most welcome. Leave comments here, or email <a href="mailto:vh@vivekhaldar.com">vh@vivekhaldar.com</a><br />
This is what I was getting at with a couple of <a href="http://www.vivekhaldar.com/blog/?p=81">earlier</a> <a href="http://www.vivekhaldar.com/blog/?p=80">posts</a>.</p>
<p><a href="http://vivekhaldar.com:8080/Shopper/"><strong>OK, take me to Shop Finder already!! </strong></a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.vivekhaldar.com/blog/?feed=rss2&amp;p=82</wfw:commentRss>
		</item>
	</channel>
</rss>
