Interview With Microsoft's Chief of Security
Paul Coe Clark III writes: "I interviewed Howard Schmidt, Microsoft's head of security, questioning him about, among other things, cyberterrorism and Redmond's responsibility for insecure features in the wake of many virus attacks.
/. readers might find it interesting. They can find it here."
first post, bizhos!
+ Donald Gunth
+ Email: dgunth@quicktek.net
"Caffeine is the greatest lubricant ever created." -ESR
Isn't that an oxymoron?
Is that like asking a blind man to describe the color green?
3
2
6
2
3
3
6
6
2
5
8
4
6
5
6
2
2
8
6
3
7
1
9
4
1
6
7
4
4
5
1
9
6
7
6
5
1
6
2
9
5
8
3
3
6
9
2
7
3
3
3
8
6
9
5
3
5
4
7
5
8
6
7
5
8
6
8
4
6
1
3
4
9
9
5
2
8
5
5
1
2
2
6
8
9
9
3
2
9
4
3
7
5
9
5
7
9
7
7
5
1
4
5
7
5
3
8
5
2
2
1
1
1
9
8
2
3
7
4
1
2
2
2
9
1
7
5
5
3
5
7
4
1
9
1
6
1
6
9
6
8
8
9
9
3
8
2
4
7
8
9
9
2
8
4
3
8
4
9
1
1
8
2
5
6
3
5
1
3
9
4
7
3
2
7
9
6
1
3
8
6
8
2
5
9
4
7
1
3
2
2
5
3
6
3
3
4
3
8
7
9
6
2
8
5
5
8
9
6
8
6
2
5
3
5
4
5
9
5
5
2
3
7
3
8
5
9
4
9
5
1
4
9
8
6
1
6
3
3
1
6
1
8
3
1
8
3
5
3
1
2
1
5
9
6
4
8
2
6
8
5
6
5
2
6
5
7
9
5
4
1
5
8
7
4
2
1
9
8
3
6
2
1
8
4
9
6
4
6
4
9
9
5
4
4
2
4
7
9
4
6
3
6
2
7
1
6
1
2
9
3
2
7
1
2
5
5
5
4
6
9
9
9
4
8
9
9
6
9
6
2
1
4
4
7
4
3
1
8
4
6
4
8
2
5
4
5
3
5
9
8
3
7
7
7
6
4
9
3
6
4
9
1
3
9
7
3
9
2
4
5
8
8
4
3
4
7
5
4
6
4
2
3
1
5
3
4
4
4
6
7
9
7
7
3
2
6
3
5
2
5
5
1
8
5
8
3
3
4
4
7
8
2
4
9
4
4
3
4
8
5
9
8
2
7
1
6
5
7
1
8
4
1
8
7
7
8
5
5
9
2
1
9
9
5
1
7
2
1
7
1
6
3
3
2
2
8
2
1
6
9
1
9
7
7
2
7
4
4
3
8
5
9
4
6
9
7
9
6
2
7
3
7
5
3
9
2
7
9
5
8
9
1
5
1
5
5
8
8
2
8
5
7
8
2
9
6
4
3
4
1
4
1
5
2
9
4
5
9
3
7
1
4
2
5
8
1
4
7
9
7
8
4
3
1
4
3
6
3
9
3
7
5
1
1
2
6
6
3
8
2
1
5
6
7
7
7
1
3
3
7
5
9
6
1
1
2
4
8
4
8
4
5
2
1
3
8
1
5
9
9
7
9
9
6
5
1
4
2
3
9
5
9
5
9
7
6
6
7
8
1
2
9
4
3
9
3
2
6
6
5
5
1
6
7
8
7
1
1
9
1
6
3
2
2
5
1
3
7
3
6
1
3
6
9
5
8
8
1
5
7
4
6
6
5
5
7
7
5
1
3
3
4
1
1
7
1
3
5
1
2
4
6
9
4
8
7
9
9
8
6
3
3
2
7
9
4
9
5
9
3
8
6
1
8
5
3
1
4
7
3
6
9
7
2
2
3
5
8
2
4
8
2
5
9
9
2
9
6
3
1
7
6
3
4
1
5
4
3
9
3
3
7
2
5
7
5
6
1
5
5
4
7
3
5
1
9
7
8
4
8
3
8
9
3
1
9
9
7
1
3
7
1
1
2
3
8
3
9
7
1
2
5
7
7
2
9
6
5
5
7
2
3
9
8
1
8
8
8
9
6
7
6
7
1
5
4
2
3
7
7
9
2
2
6
4
2
1
7
6
8
1
6
4
5
4
1
7
4
2
6
2
8
7
1
4
2
5
2
1
9
3
5
6
6
5
7
8
3
4
3
5
9
5
2
5
7
8
8
2
3
4
4
1
1
8
2
4
3
5
3
2
3
7
1
2
9
6
8
5
8
9
2
1
3
6
8
9
5
3
6
3
8
3
2
8
3
4
5
3
3
2
3
4
9
9
3
1
8
7
8
6
9
4
7
8
5
5
1
4
5
6
3
1
1
1
7
4
3
9
5
6
7
5
6
3
8
3
1
9
2
7
5
3
9
2
9
6
9
6
8
5
7
4
1
2
4
7
5
1
5
6
2
3
3
9
3
2
4
6
2
4
8
9
7
4
3
8
3
7
8
9
1
9
4
9
6
7
1
3
7
7
8
9
3
2
8
5
5
3
4
9
8
8
4
5
6
6
5
1
3
2
1
3
4
2
9
7
5
5
7
8
1
2
6
8
1
7
7
2
2
3
8
5
7
7
6
2
9
9
2
6
8
7
7
7
6
5
1
7
8
4
1
9
4
9
4
6
5
4
9
2
2
2
4
4
8
8
2
6
7
4
7
6
7
5
5
7
7
2
5
6
5
2
1
6
1
8
6
4
9
7
5
6
3
4
8
6
2
5
5
1
1
3
8
7
3
3
2
3
3
4
3
8
9
6
8
7
6
7
4
4
2
5
3
7
8
5
3
2
2
5
2
8
8
8
2
8
3
1
3
4
1
5
4
9
7
5
3
5
3
9
2
8
2
9
5
8
1
5
6
5
4
5
2
9
2
1
9
3
8
3
4
7
5
5
2
3
7
4
5
1
5
5
2
6
1
3
4
9
8
8
3
8
6
6
2
2
6
7
1
1
2
2
1
5
1
7
9
6
3
6
8
9
4
3
8
6
7
7
2
4
2
2
2
3
5
3
2
6
1
5
3
5
3
5
7
9
4
5
2
3
8
7
3
3
9
1
5
7
7
2
1
4
9
7
5
9
9
7
6
3
8
7
9
8
7
2
5
6
3
7
1
6
2
7
9
3
3
1
7
1
1
9
1
9
6
9
3
5
4
1
9
1
5
9
1
7
1
2
7
3
3
7
3
5
9
1
6
3
7
9
1
6
7
3
3
6
6
8
2
5
1
5
6
8
9
3
5
9
5
6
3
9
6
5
9
9
3
8
7
7
2
1
1
7
1
6
9
6
8
9
1
5
9
4
1
2
7
3
8
1
4
8
3
9
6
8
3
1
9
3
2
4
8
9
7
4
2
5
5
1
4
4
8
3
3
3
4
6
4
2
2
3
2
4
7
4
7
8
3
4
4
1
3
6
1
4
3
5
5
7
2
2
4
5
7
7
1
3
4
4
5
5
7
7
9
4
1
2
2
5
8
4
5
8
1
9
4
3
1
3
3
1
9
9
8
6
3
4
9
2
4
1
7
4
7
7
7
7
1
9
2
6
7
5
7
4
1
5
2
9
6
2
3
3
4
5
7
1
3
3
8
6
9
7
9
9
9
7
2
1
7
3
6
2
7
9
7
1
5
7
7
6
1
9
5
5
9
7
4
5
9
9
8
8
1
5
2
7
9
4
3
1
5
8
9
4
2
2
2
1
9
7
7
3
4
6
6
5
7
6
2
1
8
8
1
5
6
2
7
6
6
6
4
4
4
4
2
5
4
2
6
8
7
2
5
1
9
2
5
1
1
1
6
6
2
2
6
9
8
4
9
7
8
2
2
1
3
5
7
4
2
6
1
6
4
7
2
9
7
9
1
4
4
8
1
9
1
2
8
7
7
4
7
1
9
3
3
6
4
6
9
6
8
6
8
5
2
2
2
5
8
8
3
1
8
1
5
4
8
2
2
2
7
8
2
3
7
1
1
5
9
7
2
4
9
2
9
3
9
9
6
9
8
5
1
3
4
6
8
9
9
3
8
9
8
2
2
4
6
4
7
9
4
7
7
8
3
1
5
5
9
8
4
9
3
6
2
1
7
3
9
5
2
6
6
2
7
8
3
9
7
4
5
3
4
9
3
6
6
9
2
9
9
6
4
6
2
7
8
4
2
7
2
1
3
8
4
1
3
4
4
3
7
1
2
8
3
4
8
9
1
8
2
3
3
2
6
3
3
2
9
8
2
7
1
3
5
5
3
4
3
1
5
6
2
7
8
8
2
4
4
7
6
3
4
1
8
9
1
6
1
7
4
7
3
7
7
7
8
5
9
2
4
4
2
6
9
8
6
7
8
5
8
2
5
8
8
1
2
3
9
3
8
4
3
1
3
9
5
5
5
1
9
2
2
5
9
8
8
8
2
4
1
1
3
1
9
4
9
5
1
2
4
2
4
8
9
4
8
4
2
7
5
5
2
6
5
5
1
1
4
1
4
7
3
7
3
1
5
1
8
8
1
3
7
1
7
2
3
5
6
2
5
3
6
1
4
7
1
4
5
9
3
9
7
6
4
7
3
4
7
5
8
6
3
3
3
9
8
9
6
2
3
9
8
6
1
5
6
4
6
1
7
3
6
4
5
7
7
5
8
9
7
2
4
7
5
4
5
7
5
5
2
4
1
6
7
4
1
3
1
4
5
2
1
7
4
5
1
4
9
5
4
7
1
8
5
9
2
1
8
2
5
7
6
4
3
8
3
1
2
9
9
9
1
1
9
9
7
9
1
8
9
5
5
9
9
6
6
7
5
2
8
5
7
1
6
9
5
6
5
4
3
9
3
6
1
4
3
4
2
4
5
2
1
8
8
8
3
6
5
9
4
6
8
6
5
7
9
3
6
2
2
6
1
5
4
8
4
7
9
9
3
6
3
3
6
6
9
3
2
1
3
3
9
5
4
1
9
8
6
4
7
6
2
3
2
9
7
5
7
6
8
2
3
9
5
8
4
1
4
5
1
1
8
4
2
1
5
8
4
4
6
6
7
5
8
3
4
4
5
5
3
5
4
8
4
4
3
5
8
1
6
5
3
4
2
4
3
2
4
1
9
1
6
5
7
9
1
8
3
7
8
3
2
1
2
3
4
5
2
7
1
4
5
2
1
6
1
8
1
2
7
2
4
7
5
7
3
2
9
8
8
1
3
5
9
4
9
9
1
3
4
5
1
8
4
1
9
8
8
4
1
5
7
6
7
8
1
4
1
9
7
3
4
9
6
8
9
1
2
5
3
9
8
4
1
3
5
7
7
9
7
2
6
8
2
8
9
8
9
2
5
1
2
6
2
3
7
4
7
3
1
7
1
3
3
8
3
7
6
4
2
6
9
4
7
3
2
5
3
3
3
6
2
8
9
1
9
5
6
2
4
1
9
5
2
8
8
8
8
7
8
3
8
5
5
2
9
4
9
8
8
6
1
5
2
2
4
3
9
7
6
3
8
2
7
7
6
2
1
4
4
8
9
6
7
4
2
4
9
6
6
1
3
5
4
1
5
9
4
9
7
6
3
6
4
7
9
2
5
5
9
4
3
7
7
1
1
5
9
7
8
9
1
8
5
2
6
6
6
9
4
8
2
2
2
4
2
3
6
6
3
3
7
9
1
1
9
2
1
4
3
1
9
5
8
1
4
5
2
2
8
8
7
9
8
1
2
7
8
5
7
6
2
3
3
6
7
7
8
5
3
1
6
6
2
9
4
5
6
8
7
8
4
8
3
6
5
7
3
9
3
5
8
6
2
6
9
8
5
4
1
3
3
2
9
5
6
4
2
4
4
5
1
6
4
2
2
2
5
2
2
7
8
9
6
4
5
9
6
3
7
2
7
4
8
2
8
8
4
9
5
4
5
9
3
8
7
1
5
6
1
4
6
7
3
4
2
6
4
1
9
5
2
4
6
6
2
5
3
2
5
3
1
4
2
3
9
2
4
9
4
8
6
8
7
6
2
7
6
3
4
1
4
3
3
8
9
6
8
3
3
5
5
8
7
5
1
8
9
3
2
6
8
3
8
9
1
4
2
1
6
2
3
4
3
8
4
4
3
3
7
6
3
7
9
8
7
5
4
6
4
5
2
5
5
2
5
6
9
3
7
9
4
5
5
2
3
9
8
3
6
9
4
9
1
6
2
8
3
6
7
8
6
9
1
8
2
5
2
3
9
1
2
2
4
5
8
2
8
5
5
5
8
1
3
9
9
6
1
2
4
4
1
7
5
4
5
9
3
7
9
4
8
3
3
2
3
2
2
7
8
3
4
5
6
5
7
6
4
2
6
7
6
2
9
8
7
7
3
9
9
7
9
9
4
8
4
1
1
1
9
9
9
7
9
6
6
5
9
4
9
6
1
4
3
5
4
3
7
9
7
5
2
3
1
2
7
9
9
5
3
8
8
9
2
6
7
7
4
6
5
4
8
3
1
8
3
6
6
9
2
9
6
1
3
1
6
7
8
1
9
1
7
3
3
8
6
6
9
7
4
5
7
5
2
3
8
4
4
8
2
9
4
5
1
8
9
5
4
7
2
8
3
4
4
2
5
1
5
1
7
5
6
9
4
2
7
7
9
5
9
7
8
4
6
3
9
8
8
8
8
9
4
4
2
5
1
1
5
4
4
9
6
7
8
4
4
9
9
6
8
6
7
5
4
7
3
5
4
5
5
3
4
5
9
1
3
4
6
8
2
7
4
7
9
2
3
6
3
6
6
7
8
8
3
5
9
2
1
1
9
5
2
1
5
2
3
8
6
7
6
6
6
9
1
3
4
5
5
8
7
8
4
9
8
1
7
8
4
6
7
3
5
1
8
2
9
1
5
1
7
2
6
4
5
3
6
9
4
5
3
5
4
3
1
8
6
1
5
1
6
5
9
5
1
1
8
9
2
1
8
3
9
8
3
9
9
9
7
6
4
8
1
1
5
7
4
9
4
4
2
6
4
9
1
7
5
7
9
4
7
4
3
1
6
9
8
7
5
2
7
5
4
3
8
7
4
6
6
2
3
1
6
3
3
6
2
6
7
1
9
9
5
3
9
7
1
6
8
3
9
7
4
3
3
3
7
4
7
9
5
2
6
7
3
2
6
9
4
9
7
5
5
1
7
9
2
2
2
7
6
2
2
7
9
6
5
3
1
1
6
4
1
9
7
5
2
7
4
1
2
3
7
4
7
4
9
2
4
9
2
6
3
6
2
8
8
6
5
7
2
9
5
4
5
3
8
1
8
6
7
6
4
2
7
9
2
7
7
4
4
4
7
6
3
3
8
1
5
6
4
5
9
5
2
4
7
2
1
3
5
6
7
2
3
9
2
6
3
1
8
8
9
7
3
2
8
6
6
9
9
3
7
6
9
4
6
9
6
5
5
2
7
1
6
5
2
8
5
9
5
2
1
3
3
3
4
6
8
2
5
8
8
2
5
4
2
9
7
4
8
7
3
9
7
3
7
5
2
8
3
9
3
2
9
4
1
3
2
5
2
2
1
9
4
7
4
6
9
5
9
9
5
8
3
4
6
4
7
7
5
7
6
2
8
1
4
8
3
6
3
7
6
2
4
5
9
4
4
2
7
1
8
1
4
4
2
4
7
4
4
3
5
2
4
1
3
9
4
8
3
2
2
1
2
1
6
2
9
1
6
7
6
7
2
1
5
5
4
5
9
6
2
8
9
3
7
1
3
2
1
9
6
8
6
2
3
7
8
9
1
9
3
7
3
8
7
2
4
5
5
2
4
9
6
8
5
3
7
1
5
1
8
9
5
6
1
3
1
7
6
7
4
8
7
2
2
8
5
4
9
3
2
6
2
8
4
4
7
6
9
4
4
3
5
2
4
4
7
6
4
6
1
1
5
6
1
5
3
2
5
1
1
1
5
8
2
9
6
3
7
4
4
1
7
1
8
9
1
9
6
1
6
2
6
5
1
6
3
7
8
4
7
4
6
5
8
2
6
2
5
3
5
3
2
9
8
3
9
4
1
1
7
1
8
3
5
8
7
6
3
5
9
1
2
2
7
2
3
5
5
7
3
4
8
8
6
4
8
2
7
5
1
2
2
9
9
3
1
5
7
9
9
2
7
9
2
5
9
3
7
6
8
7
4
6
1
4
6
3
8
7
8
9
4
5
9
6
7
4
5
8
9
7
7
7
1
4
7
6
5
6
9
4
1
3
6
1
9
8
1
6
9
6
9
8
7
8
4
2
2
5
3
8
7
7
2
8
5
1
9
8
5
4
9
4
8
5
5
9
5
1
7
2
7
2
3
2
5
9
8
6
4
8
3
6
5
3
8
2
1
7
2
9
5
6
2
1
8
6
1
2
2
3
8
4
4
2
5
5
8
2
6
8
2
8
6
1
2
5
8
3
3
9
8
9
2
1
1
6
8
1
8
8
8
2
7
2
9
9
9
6
8
8
5
8
9
4
4
9
5
5
1
6
4
6
7
6
2
6
7
6
6
5
2
6
6
5
1
3
1
1
4
6
1
6
6
4
7
5
5
2
3
5
4
2
9
1
7
2
9
9
1
9
4
5
3
1
5
5
4
2
4
9
4
9
7
8
8
5
5
6
2
6
8
4
6
8
4
6
6
8
8
4
3
1
1
1
7
3
8
9
8
3
5
6
3
4
4
3
9
9
2
8
2
1
7
9
5
6
6
9
1
7
3
3
5
7
3
1
7
9
2
6
6
3
3
3
2
2
6
1
5
7
7
9
6
1
5
7
7
1
1
9
3
4
7
1
3
8
9
5
2
5
6
4
2
9
4
9
7
5
6
4
1
9
3
1
7
7
1
2
2
7
1
5
6
7
7
9
5
4
6
8
4
3
8
6
3
3
3
1
1
1
4
9
6
9
5
9
7
2
7
2
9
6
8
1
7
5
1
3
5
1
3
9
6
2
8
9
1
9
9
7
4
5
6
9
6
2
5
3
9
8
7
6
4
5
6
8
3
8
8
2
1
1
2
3
4
6
5
8
3
7
2
7
3
4
6
1
4
2
7
7
7
1
5
1
8
9
3
7
5
7
2
3
3
5
4
5
8
1
1
7
9
8
9
3
1
4
1
4
5
7
3
8
4
5
2
9
2
5
9
8
6
3
7
7
8
4
8
3
6
7
2
8
1
5
7
5
3
9
8
7
4
4
7
5
4
7
4
8
5
4
6
6
2
8
6
3
6
6
5
5
1
3
1
2
1
5
3
9
2
2
2
2
3
2
7
5
1
8
4
9
3
8
9
5
7
9
8
8
7
3
2
2
3
5
3
9
1
5
2
3
3
8
2
7
5
3
5
7
2
4
6
1
8
3
4
9
3
2
5
9
4
3
4
5
6
5
6
1
7
8
9
3
9
1
2
6
7
5
4
9
7
1
2
6
1
6
2
3
5
8
4
4
8
6
9
6
8
4
5
3
8
1
7
1
3
6
2
9
6
4
1
5
3
1
9
6
4
7
8
5
6
8
4
3
8
9
4
3
2
9
4
9
9
5
4
2
1
6
5
3
6
8
2
6
8
7
9
6
9
9
7
1
8
9
4
4
8
4
5
9
9
9
7
5
9
6
4
3
9
4
3
1
3
3
7
6
8
8
2
6
8
4
5
5
8
4
8
3
3
6
6
5
6
4
7
6
2
5
3
8
8
2
2
2
9
4
9
2
5
8
8
6
9
8
1
7
3
4
8
4
4
5
7
6
4
1
5
8
7
6
4
3
1
5
3
1
1
9
8
7
4
4
9
3
2
3
7
5
9
4
9
7
7
6
9
9
1
8
8
3
9
8
1
2
4
8
4
4
7
4
4
1
2
2
4
7
6
6
6
8
7
8
2
3
3
6
5
8
8
1
5
2
9
8
6
3
4
6
9
5
1
1
4
7
6
3
1
9
4
5
1
2
9
5
7
7
3
5
1
5
8
7
3
6
2
2
2
3
2
5
7
7
3
3
8
5
6
1
2
7
2
8
1
9
4
7
3
2
3
7
4
5
6
8
4
3
6
7
4
6
1
1
9
5
4
9
5
1
6
4
4
8
7
5
8
1
4
5
7
5
9
7
3
3
8
7
3
5
7
3
7
4
6
2
9
3
4
7
4
1
9
2
9
9
8
1
7
1
4
8
2
8
8
3
9
2
2
3
5
5
9
1
5
6
2
4
8
5
6
8
7
5
8
2
6
5
9
5
5
2
6
2
5
7
4
7
2
2
5
1
8
2
3
2
6
5
3
1
3
2
1
7
5
9
8
7
7
1
5
4
1
3
1
5
1
3
7
3
1
4
1
1
5
6
6
5
2
6
2
2
5
1
6
8
5
2
9
3
2
7
5
7
9
7
3
8
9
8
1
7
6
6
1
5
1
4
1
6
9
3
2
1
1
8
8
1
8
4
7
7
7
4
9
5
2
6
3
1
4
4
4
4
9
4
2
1
9
7
7
9
7
3
3
5
7
5
8
2
4
7
6
7
6
2
1
2
9
8
1
2
1
3
6
2
9
4
2
5
2
5
9
9
9
2
1
1
6
4
1
5
4
3
9
8
8
5
9
1
1
9
8
5
8
6
1
2
6
6
3
5
5
7
6
1
9
7
8
4
2
5
4
5
5
8
3
4
1
6
1
5
4
1
6
2
5
5
2
3
9
8
4
5
6
3
8
7
8
6
3
4
6
5
2
2
6
6
7
8
4
2
7
2
8
7
9
7
1
9
7
6
6
3
4
4
4
1
3
9
4
4
2
8
7
1
6
9
8
7
8
7
3
7
5
6
7
8
9
5
4
7
4
4
8
8
2
2
2
4
8
5
8
6
2
4
5
4
4
6
1
8
4
7
3
7
9
3
8
2
3
3
3
9
8
8
5
1
1
9
7
7
5
5
1
8
9
1
6
4
8
2
3
1
8
6
1
6
9
5
2
1
7
7
6
9
3
4
8
4
9
2
5
2
4
9
8
2
1
8
6
6
7
1
9
3
9
5
5
3
6
6
1
7
7
6
3
8
1
8
8
1
7
6
2
1
2
6
5
5
1
5
7
3
3
8
1
8
4
4
6
8
5
2
9
4
1
8
2
2
5
1
1
3
3
1
2
6
3
5
5
1
4
2
7
7
9
6
9
4
8
7
5
4
2
5
2
5
8
7
1
9
2
8
8
9
8
4
1
4
6
2
1
7
8
7
8
4
6
5
6
7
2
7
8
4
4
2
7
6
5
9
5
4
9
7
7
7
4
8
1
9
3
5
3
4
6
5
2
1
6
3
1
1
4
8
1
2
7
2
9
9
6
1
1
7
9
9
9
8
4
3
5
7
6
6
5
5
5
2
6
1
2
1
6
7
2
4
3
6
4
8
7
4
2
7
3
4
4
9
3
1
8
6
2
2
6
4
1
5
9
5
7
3
9
4
7
6
8
8
2
5
7
7
3
3
5
2
6
6
3
2
2
9
5
1
5
9
6
2
9
9
5
1
4
9
3
4
2
1
5
2
9
2
8
2
8
1
4
4
6
7
7
8
9
1
4
8
6
9
4
1
9
7
1
2
7
8
3
6
7
2
5
1
2
6
1
2
7
5
2
4
1
3
1
7
1
4
9
5
2
3
4
6
2
6
5
9
7
7
9
9
3
4
3
8
6
4
2
3
1
9
1
3
9
4
4
8
1
3
5
2
1
6
1
4
6
4
6
7
2
1
1
8
5
8
4
4
9
2
7
3
2
6
5
5
1
5
3
1
5
3
3
5
1
2
2
8
3
8
8
6
3
4
3
1
3
2
6
7
4
9
8
6
4
8
3
1
1
6
3
7
2
6
8
6
8
5
4
2
6
8
9
9
1
3
7
4
6
6
5
8
8
5
6
9
4
2
3
9
3
4
5
2
3
3
1
8
6
6
1
8
6
3
9
9
5
4
2
5
5
7
6
5
9
5
5
4
5
7
5
7
9
5
4
5
5
9
3
1
7
5
6
8
1
7
5
9
9
5
6
3
1
2
9
3
4
5
9
2
2
2
8
8
3
4
2
4
3
9
1
6
5
6
1
1
5
6
3
1
5
3
3
4
6
7
5
4
6
8
8
9
1
8
9
3
2
5
4
4
6
2
3
5
3
9
2
6
8
8
1
2
8
5
1
6
7
8
3
6
7
5
5
1
2
7
5
3
4
7
2
8
1
8
2
1
8
1
9
4
9
2
3
3
6
5
4
8
8
3
4
8
5
5
2
4
9
7
7
9
8
1
1
4
7
3
9
6
3
9
7
6
5
2
5
5
9
8
7
7
5
7
2
4
5
1
9
5
8
6
5
8
2
9
2
4
1
6
9
9
6
7
6
8
8
3
4
3
8
1
3
2
7
5
4
9
8
9
2
9
8
4
1
4
6
2
4
6
3
6
2
3
3
6
7
7
7
4
3
5
6
4
3
8
7
2
1
5
1
7
2
9
7
2
7
3
7
7
5
7
7
8
6
1
7
5
8
4
6
5
9
4
5
1
6
6
5
1
4
9
7
8
6
9
8
5
6
4
9
8
4
2
5
8
4
6
6
6
5
5
6
5
6
7
6
5
4
9
8
3
6
1
8
5
3
8
2
5
7
1
4
8
3
2
8
2
8
2
9
9
5
3
9
7
5
3
4
5
9
2
6
3
6
4
7
5
7
6
2
5
5
8
7
9
1
2
4
7
9
3
8
5
7
1
4
7
1
8
1
1
8
9
5
4
7
7
7
5
7
1
4
9
1
7
7
1
6
2
2
8
6
8
7
1
4
4
1
9
8
2
8
1
8
3
3
5
4
6
6
5
3
1
5
5
9
6
4
7
1
2
5
6
2
5
7
8
3
6
2
1
3
7
5
4
6
3
5
3
4
8
5
4
8
2
5
2
1
5
1
6
3
9
3
6
7
3
1
5
2
3
9
8
4
6
1
4
3
6
7
9
8
8
2
7
7
5
1
2
1
1
7
4
3
7
8
6
2
8
3
7
5
5
5
5
1
5
3
2
6
5
7
5
1
2
3
6
2
2
1
2
4
6
8
6
9
7
1
3
9
8
8
7
5
4
5
4
3
1
3
1
1
6
2
7
7
6
8
7
7
4
1
2
5
4
5
4
9
1
7
6
9
1
7
7
3
5
6
2
7
3
5
5
8
5
5
9
4
9
8
2
7
3
4
9
1
9
9
2
4
5
2
3
7
7
8
2
6
1
8
7
1
9
3
2
1
4
8
1
3
4
2
2
5
8
4
6
7
3
7
1
1
1
9
5
5
7
2
3
7
4
7
3
8
7
4
6
6
2
6
7
9
5
8
9
2
1
3
2
7
8
8
7
6
1
1
5
6
8
3
2
4
1
8
5
8
2
9
7
3
6
9
9
3
5
5
9
7
2
7
2
9
8
1
3
1
5
1
7
8
3
1
1
8
6
2
8
4
4
7
1
1
4
8
3
9
5
3
6
3
5
9
9
5
7
7
4
6
3
6
6
9
5
5
4
8
4
6
8
9
3
1
5
4
8
5
2
3
8
1
6
9
7
6
6
7
9
3
7
6
3
7
3
7
9
9
2
2
4
9
3
1
2
2
4
5
5
6
2
7
5
3
8
1
6
7
8
4
3
5
3
4
5
3
7
6
1
6
8
8
9
2
5
7
1
6
2
8
8
7
6
9
2
3
9
3
8
4
4
3
1
3
7
8
4
1
7
1
7
7
5
2
6
4
5
2
9
3
6
6
4
8
9
2
6
3
7
8
9
5
4
5
8
6
4
3
4
9
9
3
2
7
8
7
5
8
8
7
1
1
9
2
2
1
5
5
6
7
6
6
7
2
3
7
9
8
6
4
7
3
1
8
9
3
8
7
3
7
2
7
2
3
4
3
9
3
7
9
8
4
3
1
1
1
9
9
2
1
1
9
5
1
7
2
1
5
8
9
1
9
5
6
5
1
2
3
4
8
1
1
4
2
9
5
4
3
6
2
8
7
1
3
9
4
7
5
8
4
1
2
9
9
7
6
5
7
3
8
7
9
1
7
5
1
3
6
9
2
6
7
4
4
8
5
2
4
4
8
4
8
6
8
2
6
3
5
8
5
2
4
8
2
2
7
7
9
5
8
7
8
4
2
1
5
4
9
7
9
6
2
8
6
6
1
5
3
5
5
7
2
9
1
5
2
1
9
8
9
3
4
4
6
5
7
1
5
8
5
6
6
5
2
6
5
3
8
2
3
3
8
3
5
4
4
4
7
2
8
2
2
8
4
2
5
8
3
2
2
7
2
4
6
7
8
3
7
6
5
2
8
6
9
2
6
1
3
4
8
8
4
4
4
2
2
4
9
6
3
3
2
6
3
7
9
8
8
3
8
8
3
8
8
2
8
3
6
1
3
9
5
7
6
6
7
4
4
4
3
8
7
3
4
4
5
2
8
9
3
9
4
2
4
9
9
4
7
7
8
7
5
9
4
3
4
1
9
2
7
5
7
7
9
6
9
2
7
5
3
7
1
8
8
9
6
8
8
3
3
6
8
9
7
7
8
4
7
3
5
2
2
6
3
7
4
7
9
8
6
1
6
3
8
1
9
9
5
9
6
8
3
7
8
1
8
4
2
6
6
4
8
6
1
8
9
1
1
8
5
1
1
2
1
1
2
3
4
4
1
8
1
8
4
2
1
5
6
9
7
8
2
3
4
5
1
2
8
6
9
7
2
7
5
6
9
5
3
3
8
7
7
2
5
8
8
1
2
6
1
8
4
8
9
8
1
2
3
1
5
9
6
3
2
8
9
5
1
6
6
6
9
8
2
3
9
3
6
6
6
9
2
1
8
6
3
8
9
5
9
7
3
3
5
9
2
8
4
7
3
5
1
3
3
9
8
8
4
8
9
4
8
5
8
4
6
8
1
3
4
4
6
2
2
7
5
3
7
9
8
4
8
5
8
5
3
8
6
9
5
5
5
6
6
6
1
3
3
4
9
1
1
1
2
9
7
9
1
1
3
7
1
9
2
2
4
2
5
1
1
1
5
3
5
3
9
5
8
9
1
5
1
4
1
8
4
2
9
2
2
6
6
4
5
5
6
5
6
6
8
4
8
5
3
5
6
2
4
9
2
2
3
6
5
4
7
2
1
8
6
7
5
5
7
9
2
3
2
6
4
4
1
4
5
6
1
1
8
5
6
3
6
1
6
3
8
2
1
9
2
6
3
3
2
2
4
9
7
6
4
5
8
1
1
5
2
1
4
1
3
6
8
4
4
4
5
5
7
3
8
9
5
5
7
7
2
2
3
4
9
3
4
7
4
9
1
1
4
4
9
4
7
7
4
2
1
2
2
8
1
6
4
8
2
4
4
5
8
2
1
6
8
9
2
7
9
4
4
4
2
5
2
3
8
2
1
6
3
4
6
3
5
6
5
2
7
6
7
5
3
5
9
2
9
4
9
2
8
4
4
5
1
5
8
5
2
7
8
7
8
1
5
1
4
6
1
9
9
9
2
9
9
8
4
2
9
4
3
2
7
1
7
8
6
6
4
4
1
3
3
5
2
9
7
7
2
4
2
1
7
5
4
6
8
2
9
8
6
6
1
7
5
9
4
3
5
5
4
4
5
1
9
4
7
1
9
1
2
3
5
1
2
4
8
3
7
4
2
9
8
2
1
7
1
2
5
1
3
8
9
3
1
9
6
3
1
8
2
4
7
9
4
1
4
1
2
8
1
1
1
4
5
5
6
6
4
5
9
2
4
8
7
9
7
3
8
6
1
3
8
2
8
8
7
8
6
5
7
2
9
8
5
6
4
7
6
1
2
6
8
6
9
5
8
6
1
9
5
1
5
3
2
1
2
8
7
5
2
6
5
3
5
2
7
9
5
7
9
7
6
8
1
1
4
5
8
3
5
9
9
9
1
6
4
2
3
4
7
9
1
3
8
8
6
1
6
9
2
1
4
5
7
3
3
7
4
7
1
8
8
8
1
2
2
7
4
4
8
6
3
2
8
4
6
8
2
4
2
6
5
4
5
7
5
6
3
4
6
7
9
3
3
1
4
6
1
5
1
6
4
9
6
2
8
8
6
7
9
6
2
9
3
1
6
7
1
3
9
2
2
8
8
1
6
2
1
3
7
5
4
6
6
1
9
9
9
8
5
7
3
9
8
1
8
8
6
5
1
8
8
5
4
4
8
1
5
3
3
7
6
5
4
6
3
5
1
6
5
5
3
2
9
1
8
2
4
5
6
5
3
7
6
5
5
9
3
7
7
2
8
5
8
6
8
5
4
6
3
2
7
1
1
8
5
6
3
6
3
5
4
6
5
1
4
1
7
4
3
3
3
1
2
2
8
6
3
5
1
7
1
8
3
6
4
9
5
1
2
2
3
3
2
3
1
8
9
2
9
9
8
1
5
6
4
6
1
6
2
9
5
5
9
3
8
7
2
7
2
2
8
2
6
7
9
3
8
2
2
7
8
1
6
2
3
2
3
8
8
4
8
5
8
5
4
4
8
6
3
7
2
4
5
9
2
4
5
6
2
7
8
1
4
4
5
8
6
3
3
3
1
7
6
4
2
9
4
4
4
2
4
3
9
7
1
7
7
9
5
1
9
7
7
9
3
6
7
3
3
3
5
4
6
3
1
7
4
6
7
6
1
6
2
7
7
8
5
4
8
5
2
2
4
5
4
4
4
4
5
8
4
2
7
6
3
8
8
8
6
7
3
1
3
3
3
5
2
1
1
5
8
6
3
3
5
2
1
6
4
1
7
9
4
5
3
2
7
2
9
7
9
4
5
8
8
2
2
2
8
8
2
6
5
9
8
8
9
7
2
9
2
8
3
4
8
6
7
1
9
6
5
5
6
4
9
4
1
1
4
4
3
7
9
1
6
9
5
3
2
7
4
9
9
6
1
6
2
5
1
2
8
2
1
9
1
9
6
7
1
5
6
2
6
1
5
8
8
8
3
2
2
7
4
7
1
6
1
7
2
9
1
2
2
3
5
6
2
2
3
3
7
2
5
8
4
2
6
4
6
2
1
8
1
7
9
4
9
1
6
4
9
6
2
9
5
8
1
4
6
1
5
2
3
1
1
1
6
2
1
4
7
2
1
4
2
2
2
2
6
2
2
2
9
1
5
4
4
9
9
7
3
2
1
2
1
7
9
5
1
5
3
1
6
6
1
8
4
1
9
5
6
7
6
7
4
8
2
6
1
3
1
2
6
5
6
6
8
1
1
2
6
6
7
1
2
7
8
4
7
5
8
7
1
5
3
9
1
7
5
9
5
8
6
7
6
6
9
2
9
5
6
9
7
9
3
4
2
9
5
3
4
6
6
3
4
7
6
4
9
6
3
8
9
4
1
4
3
6
5
7
4
4
3
6
7
8
9
6
6
7
6
7
9
1
7
8
7
9
7
3
9
4
6
7
2
2
2
5
3
2
4
3
5
6
5
3
8
4
9
5
7
1
1
3
1
7
2
6
4
9
3
9
6
3
7
7
5
6
1
3
8
5
8
7
6
2
2
6
3
9
3
2
2
7
1
7
1
3
2
9
2
7
3
3
2
2
6
7
4
4
4
9
6
7
7
2
6
8
7
9
9
6
2
2
3
1
2
3
7
8
5
8
3
1
6
9
8
5
9
1
3
6
8
6
3
3
7
9
8
4
9
6
1
5
7
7
6
1
1
4
1
5
5
9
2
5
6
2
5
1
5
5
1
4
1
4
4
8
8
6
5
4
6
4
3
6
8
4
6
5
3
5
8
8
2
2
7
1
5
6
1
3
1
4
6
4
1
4
7
9
3
9
3
6
9
7
6
5
4
3
9
4
4
4
2
1
9
5
3
7
3
7
7
7
6
5
3
5
8
3
2
4
7
1
3
6
7
5
6
3
4
4
3
2
9
2
8
2
9
8
3
9
6
5
9
4
4
7
9
2
7
3
4
4
2
5
3
6
1
5
9
1
7
2
2
7
4
1
9
2
9
9
8
4
2
2
9
2
6
8
8
1
2
3
6
5
6
7
9
1
2
1
6
3
9
7
6
8
7
6
3
3
1
9
6
6
6
8
4
3
4
3
4
5
6
8
5
6
7
3
5
3
9
9
1
3
4
9
3
9
1
1
7
2
7
3
5
4
2
5
5
3
5
1
6
1
2
1
8
2
3
3
6
9
2
8
1
3
4
4
2
5
1
6
3
3
1
9
9
2
5
6
7
6
8
1
3
8
5
2
3
7
7
9
1
1
8
3
1
1
5
6
6
3
1
4
2
4
7
5
9
2
6
1
6
5
1
4
2
6
1
3
3
5
7
6
2
6
3
7
2
1
2
1
3
3
2
5
2
6
3
4
2
3
9
4
5
7
4
2
1
6
4
9
6
5
3
5
1
5
9
2
1
5
7
8
1
6
6
4
2
6
4
9
6
5
7
7
5
9
7
2
3
6
3
2
7
8
6
8
6
5
7
7
9
7
2
2
6
3
6
4
4
9
4
9
3
8
6
9
7
6
6
6
8
4
1
5
7
9
8
3
7
6
4
6
8
7
2
9
8
1
7
2
8
4
4
8
6
2
7
5
5
9
3
7
4
3
7
2
7
7
9
3
6
5
5
5
9
3
8
6
4
2
4
1
4
1
8
4
6
2
4
9
8
2
3
7
3
7
3
6
5
6
5
2
2
4
8
8
9
4
5
9
6
1
2
9
1
3
6
5
3
3
2
8
8
2
9
5
6
8
1
7
7
9
3
7
4
5
3
1
6
1
2
3
7
7
4
3
3
9
5
2
3
8
7
5
7
4
6
6
8
1
8
7
4
6
4
7
2
2
7
8
8
9
4
5
1
1
3
5
9
5
7
5
8
1
4
6
1
4
8
6
3
9
2
6
9
4
1
5
6
9
5
8
9
8
5
3
3
5
5
3
9
9
6
7
3
9
4
4
8
8
2
9
9
5
1
2
8
8
1
9
3
7
4
8
7
1
4
4
5
7
9
1
1
3
4
4
3
2
7
7
7
8
9
3
8
6
4
8
4
3
6
5
6
8
5
5
8
4
9
1
8
3
5
9
8
6
3
9
7
8
6
8
6
8
7
1
4
4
4
6
3
9
9
3
7
4
7
3
3
1
6
4
2
9
6
5
2
7
4
2
7
8
7
5
7
8
9
7
1
4
5
7
9
7
8
4
6
3
1
7
2
9
7
4
2
5
7
9
6
9
5
7
4
9
7
4
5
5
9
8
2
5
5
7
3
6
1
7
8
4
7
2
3
4
2
1
8
8
4
6
6
1
3
2
8
4
6
4
7
1
2
4
8
4
9
9
4
7
8
1
7
6
7
5
2
8
4
1
6
1
4
5
8
8
1
8
7
4
6
5
7
9
5
7
5
4
1
9
6
9
5
6
9
1
2
9
1
8
1
1
9
1
6
1
3
2
8
8
4
4
5
9
1
9
2
3
5
3
9
8
4
4
6
7
9
8
8
7
8
7
7
2
4
9
5
3
4
4
9
1
3
9
9
2
7
2
7
5
4
3
7
6
6
2
8
4
9
2
6
5
4
3
9
8
9
4
2
1
2
6
3
8
7
1
2
7
3
5
2
2
9
1
9
2
2
3
4
4
1
8
3
8
8
2
9
5
5
1
4
7
2
1
7
9
8
3
9
6
2
3
8
2
6
3
5
9
8
2
7
9
3
9
7
6
6
7
9
6
9
8
7
9
6
7
8
7
2
7
4
6
3
3
1
8
8
9
8
9
9
2
4
8
8
8
1
8
3
6
9
9
2
9
7
8
7
6
7
6
9
8
7
6
7
8
5
4
3
2
5
6
1
4
9
8
6
3
4
1
4
7
3
1
9
6
2
6
5
8
7
4
2
7
3
5
5
8
1
2
3
8
7
8
8
4
6
1
2
8
4
4
2
2
9
6
7
9
4
6
8
1
3
2
8
4
1
9
8
9
3
1
9
8
4
1
2
5
1
3
6
3
5
4
1
1
3
1
4
6
1
6
9
8
2
1
1
6
4
2
6
2
3
9
3
5
5
2
8
6
8
6
4
7
5
7
2
6
3
1
7
6
3
7
6
6
3
8
4
1
3
9
2
5
7
4
8
2
6
4
2
6
3
3
9
8
9
5
7
5
1
2
7
7
5
2
3
2
4
6
7
7
6
3
1
8
4
8
2
2
8
1
5
6
3
4
8
7
8
5
1
7
3
8
8
6
8
2
4
1
2
2
2
3
2
6
8
5
2
7
9
4
3
6
1
3
9
2
2
4
9
4
1
7
6
3
9
7
5
3
8
6
6
3
9
4
7
5
9
7
1
7
2
2
2
5
4
3
6
7
4
1
1
9
3
4
1
9
9
4
2
6
3
2
1
6
5
9
8
1
5
1
2
7
8
4
6
4
8
4
5
3
1
8
9
7
1
7
3
3
6
7
1
8
3
5
5
6
2
1
3
3
7
6
3
9
5
6
3
8
4
7
6
5
2
5
3
1
9
9
1
4
3
3
9
4
8
3
3
2
7
3
8
4
5
1
4
9
5
6
9
8
7
6
1
2
8
4
9
4
6
8
8
3
6
8
9
6
3
5
8
8
1
3
3
7
3
4
4
1
4
5
9
7
8
4
5
2
8
1
6
5
2
3
4
8
5
7
9
5
3
8
3
2
5
8
1
6
4
5
5
5
5
6
9
3
1
1
9
2
2
1
3
5
7
5
4
2
4
1
6
1
2
2
4
5
9
4
5
4
4
9
3
1
7
1
9
2
7
1
6
2
5
7
5
2
9
6
6
8
5
9
9
3
9
6
9
5
4
8
5
7
1
3
5
5
6
3
2
3
6
9
5
4
2
5
9
4
2
4
8
5
9
9
1
8
2
2
8
3
2
4
3
4
7
9
8
4
6
4
9
6
7
3
5
4
1
3
7
8
4
4
8
4
6
4
8
1
7
1
3
6
6
1
1
2
4
9
2
3
4
9
7
2
9
2
7
9
7
1
5
7
7
6
2
7
5
7
2
7
7
2
8
5
9
3
4
3
1
3
9
4
8
7
6
6
7
1
7
1
9
1
3
5
3
8
9
9
1
4
8
6
9
2
2
1
7
6
8
6
1
7
3
5
1
8
8
9
2
3
3
6
1
1
7
7
5
8
2
8
4
3
4
2
5
5
5
7
7
9
7
2
2
6
2
5
5
4
8
2
5
5
6
5
7
8
1
3
1
7
6
7
1
7
4
4
4
1
8
8
6
3
6
7
1
8
9
2
7
2
4
3
5
6
3
2
5
5
4
7
7
3
5
8
4
4
3
5
5
9
5
8
1
2
3
5
8
5
8
2
1
9
1
7
7
1
1
1
2
1
3
2
4
9
6
9
5
1
2
6
8
2
1
2
1
8
5
1
6
9
7
7
2
3
9
5
2
4
5
6
7
2
3
2
3
2
8
9
6
6
1
1
2
3
5
7
3
8
1
4
7
1
1
3
5
6
9
2
3
3
8
4
8
1
4
8
5
7
3
6
8
6
4
5
2
1
3
2
5
4
3
3
5
9
1
7
2
6
6
7
7
6
2
3
4
1
2
1
8
2
6
2
5
2
2
4
8
6
5
9
6
8
1
4
8
5
6
9
8
8
5
6
8
8
6
5
7
4
1
5
1
6
2
1
5
5
1
2
3
8
9
7
1
1
2
7
7
4
8
6
1
9
9
5
6
4
9
4
1
9
9
3
5
2
7
6
3
7
1
8
9
5
2
6
3
5
2
1
6
6
4
3
8
9
9
9
5
5
8
7
6
7
3
9
2
3
6
3
8
9
4
4
1
8
4
7
2
7
6
8
4
6
7
1
3
5
1
2
4
1
3
3
4
6
3
9
1
1
4
4
3
6
9
7
4
3
8
8
8
9
4
3
1
7
1
6
3
1
7
5
3
6
1
9
6
3
4
4
5
7
3
6
1
7
8
3
5
1
4
7
2
5
3
4
3
8
7
3
9
7
4
6
2
2
3
7
2
1
7
1
8
6
1
6
1
7
2
5
6
4
4
1
2
7
8
4
2
3
5
1
8
8
3
6
8
8
1
8
3
1
5
9
7
9
3
7
9
4
6
6
2
2
3
3
8
9
6
5
8
7
9
2
5
3
3
1
1
5
9
9
1
8
5
8
1
6
4
2
3
2
7
3
7
7
8
4
1
1
5
5
6
5
6
7
4
7
5
5
7
4
6
4
3
1
4
5
7
8
2
4
3
3
1
2
8
5
7
4
8
8
8
3
2
9
3
9
5
2
8
5
6
8
1
1
1
2
4
4
8
1
3
5
6
5
9
2
4
2
2
8
9
8
9
3
2
2
7
8
6
8
8
2
9
2
3
9
6
8
8
1
2
3
7
2
6
5
6
5
7
1
5
9
6
3
4
3
1
9
2
3
3
8
1
2
1
1
9
9
6
5
5
5
3
4
5
7
6
9
2
1
1
3
9
4
7
5
4
6
4
3
4
8
4
1
1
7
8
3
8
3
5
3
5
7
7
9
6
9
7
4
9
1
6
7
7
8
5
9
9
4
5
7
3
7
2
7
4
2
4
4
5
7
6
8
4
1
6
6
4
9
6
5
2
9
8
2
8
6
7
7
4
5
6
8
8
5
5
3
9
9
2
5
6
3
4
5
9
6
1
6
7
8
9
3
4
7
7
6
2
4
1
1
4
2
6
9
5
1
8
6
3
3
7
2
3
6
9
2
9
4
5
4
4
2
5
9
4
6
5
9
8
2
6
2
4
1
8
4
7
2
7
6
2
2
9
2
5
7
9
8
3
3
2
9
2
4
5
1
1
7
5
9
7
2
5
5
4
6
8
5
9
1
7
3
2
3
9
4
3
8
7
6
8
7
1
6
5
8
5
1
1
6
1
8
1
1
that at the time this is posted, Hotmail / Msn websites are down ©©
3
2
6
2
3
3
6
6
2
5
8
4
6
5
6
2
2
8
6
3
7
1
9
4
1
6
7
4
4
5
1
9
6
7
6
5
1
6
2
9
5
8
3
3
6
9
2
7
3
3
3
8
6
9
5
3
5
4
7
5
8
6
7
5
8
6
8
4
6
1
3
4
9
9
5
2
8
5
5
1
2
2
6
8
9
9
3
2
9
4
3
7
5
9
5
7
9
7
7
5
1
4
5
7
5
3
8
5
2
2
1
1
1
9
8
2
3
7
4
1
2
2
2
9
1
7
5
5
3
5
7
4
1
9
1
6
1
6
9
6
8
8
9
9
3
8
2
4
7
8
9
9
2
8
4
3
8
4
9
1
1
8
2
5
6
3
5
1
3
9
4
7
3
2
7
9
6
1
3
8
6
8
2
5
9
4
7
1
3
2
2
5
3
6
3
3
4
3
8
7
9
6
2
8
5
5
8
9
6
8
6
2
5
3
5
4
5
9
5
5
2
3
7
3
8
5
9
4
9
5
1
4
9
8
6
1
6
3
3
1
6
1
8
3
1
8
3
5
3
1
2
1
5
9
6
4
8
2
6
8
5
6
5
2
6
5
7
9
5
4
1
5
8
7
4
2
1
9
8
3
6
2
1
8
4
9
6
4
6
4
9
9
5
4
4
2
4
7
9
4
6
3
6
2
7
1
6
1
2
9
3
2
7
1
2
5
5
5
4
6
9
9
9
4
8
9
9
6
9
6
2
1
4
4
7
4
3
1
8
4
6
4
8
2
5
4
5
3
5
9
8
3
7
7
7
6
4
9
3
6
4
9
1
3
9
7
3
9
2
4
5
8
8
4
3
4
7
5
4
6
4
2
3
1
5
3
4
4
4
6
7
9
7
7
3
2
6
3
5
2
5
5
1
8
5
8
3
3
4
4
7
8
2
4
9
4
4
3
4
8
5
9
8
2
7
1
6
5
7
1
8
4
1
8
7
7
8
5
5
9
2
1
9
9
5
1
7
2
1
7
1
6
3
3
2
2
8
2
1
6
9
1
9
7
7
2
7
4
4
3
8
5
9
4
6
9
7
9
6
2
7
3
7
5
3
9
2
7
9
5
8
9
1
5
1
5
5
8
8
2
8
5
7
8
2
9
6
4
3
4
1
4
1
5
2
9
4
5
9
3
7
1
4
2
5
8
1
4
7
9
7
8
4
3
1
4
3
6
3
9
3
7
5
1
1
2
6
6
3
8
2
1
5
6
7
7
7
1
3
3
7
5
9
6
1
1
2
4
8
4
8
4
5
2
1
3
8
1
5
9
9
7
9
9
6
5
1
4
2
3
9
5
9
5
9
7
6
6
7
8
1
2
9
4
3
9
3
2
6
6
5
5
1
6
7
8
7
1
1
9
1
6
3
2
2
5
1
3
7
3
6
1
3
6
9
5
8
8
1
5
7
4
6
6
5
5
7
7
5
1
3
3
4
1
1
7
1
3
5
1
2
4
6
9
4
8
7
9
9
8
6
3
3
2
7
9
4
9
5
9
3
8
6
1
8
5
3
1
4
7
3
6
9
7
2
2
3
5
8
2
4
8
2
5
9
9
2
9
6
3
1
7
6
3
4
1
5
4
3
9
3
3
7
2
5
7
5
6
1
5
5
4
7
3
5
1
9
7
8
4
8
3
8
9
3
1
9
9
7
1
3
7
1
1
2
3
8
3
9
7
1
2
5
7
7
2
9
6
5
5
7
2
3
9
8
1
8
8
8
9
6
7
6
7
1
5
4
2
3
7
7
9
2
2
6
4
2
1
7
6
8
1
6
4
5
4
1
7
4
2
6
2
8
7
1
4
2
5
2
1
9
3
5
6
6
5
7
8
3
4
3
5
9
5
2
5
7
8
8
2
3
4
4
1
1
8
2
4
3
5
3
2
3
7
1
2
9
6
8
5
8
9
2
1
3
6
8
9
5
3
6
3
8
3
2
8
3
4
5
3
3
2
3
4
9
9
3
1
8
7
8
6
9
4
7
8
5
5
1
4
5
6
3
1
1
1
7
4
3
9
5
6
7
5
6
3
8
3
1
9
2
7
5
3
9
2
9
6
9
6
8
5
7
4
1
2
4
7
5
1
5
6
2
3
3
9
3
2
4
6
2
4
8
9
7
4
3
8
3
7
8
9
1
9
4
9
6
7
1
3
7
7
8
9
3
2
8
5
5
3
4
9
8
8
4
5
6
6
5
1
3
2
1
3
4
2
9
7
5
5
7
8
1
2
6
8
1
7
7
2
2
3
8
5
7
7
6
2
9
9
2
6
8
7
7
7
6
5
1
7
8
4
1
9
4
9
4
6
5
4
9
2
2
2
4
4
8
8
2
6
7
4
7
6
7
5
5
7
7
2
5
6
5
2
1
6
1
8
6
4
9
7
5
6
3
4
8
6
2
5
5
1
1
3
8
7
3
3
2
3
3
4
3
8
9
6
8
7
6
7
4
4
2
5
3
7
8
5
3
2
2
5
2
8
8
8
2
8
3
1
3
4
1
5
4
9
7
5
3
5
3
9
2
8
2
9
5
8
1
5
6
5
4
5
2
9
2
1
9
3
8
3
4
7
5
5
2
3
7
4
5
1
5
5
2
6
1
3
4
9
8
8
3
8
6
6
2
2
6
7
1
1
2
2
1
5
1
7
9
6
3
6
8
9
4
3
8
6
7
7
2
4
2
2
2
3
5
3
2
6
1
5
3
5
3
5
7
9
4
5
2
3
8
7
3
3
9
1
5
7
7
2
1
4
9
7
5
9
9
7
6
3
8
7
9
8
7
2
5
6
3
7
1
6
2
7
9
3
3
1
7
1
1
9
1
9
6
9
3
5
4
1
9
1
5
9
1
7
1
2
7
3
3
7
3
5
9
1
6
3
7
9
1
6
7
3
3
6
6
8
2
5
1
5
6
8
9
3
5
9
5
6
3
9
6
5
9
9
3
8
7
7
2
1
1
7
1
6
9
6
8
9
1
5
9
4
1
2
7
3
8
1
4
8
3
9
6
8
3
1
9
3
2
4
8
9
7
4
2
5
5
1
4
4
8
3
3
3
4
6
4
2
2
3
2
4
7
4
7
8
3
4
4
1
3
6
1
4
3
5
5
7
2
2
4
5
7
7
1
3
4
4
5
5
7
7
9
4
1
2
2
5
8
4
5
8
1
9
4
3
1
3
3
1
9
9
8
6
3
4
9
2
4
1
7
4
7
7
7
7
1
9
2
6
7
5
7
4
1
5
2
9
6
2
3
3
4
5
7
1
3
3
8
6
9
7
9
9
9
7
2
1
7
3
6
2
7
9
7
1
5
7
7
6
1
9
5
5
9
7
4
5
9
9
8
8
1
5
2
7
9
4
3
1
5
8
9
4
2
2
2
1
9
7
7
3
4
6
6
5
7
6
2
1
8
8
1
5
6
2
7
6
6
6
4
4
4
4
2
5
4
2
6
8
7
2
5
1
9
2
5
1
1
1
6
6
2
2
6
9
8
4
9
7
8
2
2
1
3
5
7
4
2
6
1
6
4
7
2
9
7
9
1
4
4
8
1
9
1
2
8
7
7
4
7
1
9
3
3
6
4
6
9
6
8
6
8
5
2
2
2
5
8
8
3
1
8
1
5
4
8
2
2
2
7
8
2
3
7
1
1
5
9
7
2
4
9
2
9
3
9
9
6
9
8
5
1
3
4
6
8
9
9
3
8
9
8
2
2
4
6
4
7
9
4
7
7
8
3
1
5
5
9
8
4
9
3
6
2
1
7
3
9
5
2
6
6
2
7
8
3
9
7
4
5
3
4
9
3
6
6
9
2
9
9
6
4
6
2
7
8
4
2
7
2
1
3
8
4
1
3
4
4
3
7
1
2
8
3
4
8
9
1
8
2
3
3
2
6
3
3
2
9
8
2
7
1
3
5
5
3
4
3
1
5
6
2
7
8
8
2
4
4
7
6
3
4
1
8
9
1
6
1
7
4
7
3
7
7
7
8
5
9
2
4
4
2
6
9
8
6
7
8
5
8
2
5
8
8
1
2
3
9
3
8
4
3
1
3
9
5
5
5
1
9
2
2
5
9
8
8
8
2
4
1
1
3
1
9
4
9
5
1
2
4
2
4
8
9
4
8
4
2
7
5
5
2
6
5
5
1
1
4
1
4
7
3
7
3
1
5
1
8
8
1
3
7
1
7
2
3
5
6
2
5
3
6
1
4
7
1
4
5
9
3
9
7
6
4
7
3
4
7
5
8
6
3
3
3
9
8
9
6
2
3
9
8
6
1
5
6
4
6
1
7
3
6
4
5
7
7
5
8
9
7
2
4
7
5
4
5
7
5
5
2
4
1
6
7
4
1
3
1
4
5
2
1
7
4
5
1
4
9
5
4
7
1
8
5
9
2
1
8
2
5
7
6
4
3
8
3
1
2
9
9
9
1
1
9
9
7
9
1
8
9
5
5
9
9
6
6
7
5
2
8
5
7
1
6
9
5
6
5
4
3
9
3
6
1
4
3
4
2
4
5
2
1
8
8
8
3
6
5
9
4
6
8
6
5
7
9
3
6
2
2
6
1
5
4
8
4
7
9
9
3
6
3
3
6
6
9
3
2
1
3
3
9
5
4
1
9
8
6
4
7
6
2
3
2
9
7
5
7
6
8
2
3
9
5
8
4
1
4
5
1
1
8
4
2
1
5
8
4
4
6
6
7
5
8
3
4
4
5
5
3
5
4
8
4
4
3
5
8
1
6
5
3
4
2
4
3
2
4
1
9
1
6
5
7
9
1
8
3
7
8
3
2
1
2
3
4
5
2
7
1
4
5
2
1
6
1
8
1
2
7
2
4
7
5
7
3
2
9
8
8
1
3
5
9
4
9
9
1
3
4
5
1
8
4
1
9
8
8
4
1
5
7
6
7
8
1
4
1
9
7
3
4
9
6
8
9
1
2
5
3
9
8
4
1
3
5
7
7
9
7
2
6
8
2
8
9
8
9
2
5
1
2
6
2
3
7
4
7
3
1
7
1
3
3
8
3
7
6
4
2
6
9
4
7
3
2
5
3
3
3
6
2
8
9
1
9
5
6
2
4
1
9
5
2
8
8
8
8
7
8
3
8
5
5
2
9
4
9
8
8
6
1
5
2
2
4
3
9
7
6
3
8
2
7
7
6
2
1
4
4
8
9
6
7
4
2
4
9
6
6
1
3
5
4
1
5
9
4
9
7
6
3
6
4
7
9
2
5
5
9
4
3
7
7
1
1
5
9
7
8
9
1
8
5
2
6
6
6
9
4
8
2
2
2
4
2
3
6
6
3
3
7
9
1
1
9
2
1
4
3
1
9
5
8
1
4
5
2
2
8
8
7
9
8
1
2
7
8
5
7
6
2
3
3
6
7
7
8
5
3
1
6
6
2
9
4
5
6
8
7
8
4
8
3
6
5
7
3
9
3
5
8
6
2
6
9
8
5
4
1
3
3
2
9
5
6
4
2
4
4
5
1
6
4
2
2
2
5
2
2
7
8
9
6
4
5
9
6
3
7
2
7
4
8
2
8
8
4
9
5
4
5
9
3
8
7
1
5
6
1
4
6
7
3
4
2
6
4
1
9
5
2
4
6
6
2
5
3
2
5
3
1
4
2
3
9
2
4
9
4
8
6
8
7
6
2
7
6
3
4
1
4
3
3
8
9
6
8
3
3
5
5
8
7
5
1
8
9
3
2
6
8
3
8
9
1
4
2
1
6
2
3
4
3
8
4
4
3
3
7
6
3
7
9
8
7
5
4
6
4
5
2
5
5
2
5
6
9
3
7
9
4
5
5
2
3
9
8
3
6
9
4
9
1
6
2
8
3
6
7
8
6
9
1
8
2
5
2
3
9
1
2
2
4
5
8
2
8
5
5
5
8
1
3
9
9
6
1
2
4
4
1
7
5
4
5
9
3
7
9
4
8
3
3
2
3
2
2
7
8
3
4
5
6
5
7
6
4
2
6
7
6
2
9
8
7
7
3
9
9
7
9
9
4
8
4
1
1
1
9
9
9
7
9
6
6
5
9
4
9
6
1
4
3
5
4
3
7
9
7
5
2
3
1
2
7
9
9
5
3
8
8
9
2
6
7
7
4
6
5
4
8
3
1
8
3
6
6
9
2
9
6
1
3
1
6
7
8
1
9
1
7
3
3
8
6
6
9
7
4
5
7
5
2
3
8
4
4
8
2
9
4
5
1
8
9
5
4
7
2
8
3
4
4
2
5
1
5
1
7
5
6
9
4
2
7
7
9
5
9
7
8
4
6
3
9
8
8
8
8
9
4
4
2
5
1
1
5
4
4
9
6
7
8
4
4
9
9
6
8
6
7
5
4
7
3
5
4
5
5
3
4
5
9
1
3
4
6
8
2
7
4
7
9
2
3
6
3
6
6
7
8
8
3
5
9
2
1
1
9
5
2
1
5
2
3
8
6
7
6
6
6
9
1
3
4
5
5
8
7
8
4
9
8
1
7
8
4
6
7
3
5
1
8
2
9
1
5
1
7
2
6
4
5
3
6
9
4
5
3
5
4
3
1
8
6
1
5
1
6
5
9
5
1
1
8
9
2
1
8
3
9
8
3
9
9
9
7
6
4
8
1
1
5
7
4
9
4
4
2
6
4
9
1
7
5
7
9
4
7
4
3
1
6
9
8
7
5
2
7
5
4
3
8
7
4
6
6
2
3
1
6
3
3
6
2
6
7
1
9
9
5
3
9
7
1
6
8
3
9
7
4
3
3
3
7
4
7
9
5
2
6
7
3
2
6
9
4
9
7
5
5
1
7
9
2
2
2
7
6
2
2
7
9
6
5
3
1
1
6
4
1
9
7
5
2
7
4
1
2
3
7
4
7
4
9
2
4
9
2
6
3
6
2
8
8
6
5
7
2
9
5
4
5
3
8
1
8
6
7
6
4
2
7
9
2
7
7
4
4
4
7
6
3
3
8
1
5
6
4
5
9
5
2
4
7
2
1
3
5
6
7
2
3
9
2
6
3
1
8
8
9
7
3
2
8
6
6
9
9
3
7
6
9
4
6
9
6
5
5
2
7
1
6
5
2
8
5
9
5
2
1
3
3
3
4
6
8
2
5
8
8
2
5
4
2
9
7
4
8
7
3
9
7
3
7
5
2
8
3
9
3
2
9
4
1
3
2
5
2
2
1
9
4
7
4
6
9
5
9
9
5
8
3
4
6
4
7
7
5
7
6
2
8
1
4
8
3
6
3
7
6
2
4
5
9
4
4
2
7
1
8
1
4
4
2
4
7
4
4
3
5
2
4
1
3
9
4
8
3
2
2
1
2
1
6
2
9
1
6
7
6
7
2
1
5
5
4
5
9
6
2
8
9
3
7
1
3
2
1
9
6
8
6
2
3
7
8
9
1
9
3
7
3
8
7
2
4
5
5
2
4
9
6
8
5
3
7
1
5
1
8
9
5
6
1
3
1
7
6
7
4
8
7
2
2
8
5
4
9
3
2
6
2
8
4
4
7
6
9
4
4
3
5
2
4
4
7
6
4
6
1
1
5
6
1
5
3
2
5
1
1
1
5
8
2
9
6
3
7
4
4
1
7
1
8
9
1
9
6
1
6
2
6
5
1
6
3
7
8
4
7
4
6
5
8
2
6
2
5
3
5
3
2
9
8
3
9
4
1
1
7
1
8
3
5
8
7
6
3
5
9
1
2
2
7
2
3
5
5
7
3
4
8
8
6
4
8
2
7
5
1
2
2
9
9
3
1
5
7
9
9
2
7
9
2
5
9
3
7
6
8
7
4
6
1
4
6
3
8
7
8
9
4
5
9
6
7
4
5
8
9
7
7
7
1
4
7
6
5
6
9
4
1
3
6
1
9
8
1
6
9
6
9
8
7
8
4
2
2
5
3
8
7
7
2
8
5
1
9
8
5
4
9
4
8
5
5
9
5
1
7
2
7
2
3
2
5
9
8
6
4
8
3
6
5
3
8
2
1
7
2
9
5
6
2
1
8
6
1
2
2
3
8
4
4
2
5
5
8
2
6
8
2
8
6
1
2
5
8
3
3
9
8
9
2
1
1
6
8
1
8
8
8
2
7
2
9
9
9
6
8
8
5
8
9
4
4
9
5
5
1
6
4
6
7
6
2
6
7
6
6
5
2
6
6
5
1
3
1
1
4
6
1
6
6
4
7
5
5
2
3
5
4
2
9
1
7
2
9
9
1
9
4
5
3
1
5
5
4
2
4
9
4
9
7
8
8
5
5
6
2
6
8
4
6
8
4
6
6
8
8
4
3
1
1
1
7
3
8
9
8
3
5
6
3
4
4
3
9
9
2
8
2
1
7
9
5
6
6
9
1
7
3
3
5
7
3
1
7
9
2
6
6
3
3
3
2
2
6
1
5
7
7
9
6
1
5
7
7
1
1
9
3
4
7
1
3
8
9
5
2
5
6
4
2
9
4
9
7
5
6
4
1
9
3
1
7
7
1
2
2
7
1
5
6
7
7
9
5
4
6
8
4
3
8
6
3
3
3
1
1
1
4
9
6
9
5
9
7
2
7
2
9
6
8
1
7
5
1
3
5
1
3
9
6
2
8
9
1
9
9
7
4
5
6
9
6
2
5
3
9
8
7
6
4
5
6
8
3
8
8
2
1
1
2
3
4
6
5
8
3
7
2
7
3
4
6
1
4
2
7
7
7
1
5
1
8
9
3
7
5
7
2
3
3
5
4
5
8
1
1
7
9
8
9
3
1
4
1
4
5
7
3
8
4
5
2
9
2
5
9
8
6
3
7
7
8
4
8
3
6
7
2
8
1
5
7
5
3
9
8
7
4
4
7
5
4
7
4
8
5
4
6
6
2
8
6
3
6
6
5
5
1
3
1
2
1
5
3
9
2
2
2
2
3
2
7
5
1
8
4
9
3
8
9
5
7
9
8
8
7
3
2
2
3
5
3
9
1
5
2
3
3
8
2
7
5
3
5
7
2
4
6
1
8
3
4
9
3
2
5
9
4
3
4
5
6
5
6
1
7
8
9
3
9
1
2
6
7
5
4
9
7
1
2
6
1
6
2
3
5
8
4
4
8
6
9
6
8
4
5
3
8
1
7
1
3
6
2
9
6
4
1
5
3
1
9
6
4
7
8
5
6
8
4
3
8
9
4
3
2
9
4
9
9
5
4
2
1
6
5
3
6
8
2
6
8
7
9
6
9
9
7
1
8
9
4
4
8
4
5
9
9
9
7
5
9
6
4
3
9
4
3
1
3
3
7
6
8
8
2
6
8
4
5
5
8
4
8
3
3
6
6
5
6
4
7
6
2
5
3
8
8
2
2
2
9
4
9
2
5
8
8
6
9
8
1
7
3
4
8
4
4
5
7
6
4
1
5
8
7
6
4
3
1
5
3
1
1
9
8
7
4
4
9
3
2
3
7
5
9
4
9
7
7
6
9
9
1
8
8
3
9
8
1
2
4
8
4
4
7
4
4
1
2
2
4
7
6
6
6
8
7
8
2
3
3
6
5
8
8
1
5
2
9
8
6
3
4
6
9
5
1
1
4
7
6
3
1
9
4
5
1
2
9
5
7
7
3
5
1
5
8
7
3
6
2
2
2
3
2
5
7
7
3
3
8
5
6
1
2
7
2
8
1
9
4
7
3
2
3
7
4
5
6
8
4
3
6
7
4
6
1
1
9
5
4
9
5
1
6
4
4
8
7
5
8
1
4
5
7
5
9
7
3
3
8
7
3
5
7
3
7
4
6
2
9
3
4
7
4
1
9
2
9
9
8
1
7
1
4
8
2
8
8
3
9
2
2
3
5
5
9
1
5
6
2
4
8
5
6
8
7
5
8
2
6
5
9
5
5
2
6
2
5
7
4
7
2
2
5
1
8
2
3
2
6
5
3
1
3
2
1
7
5
9
8
7
7
1
5
4
1
3
1
5
1
3
7
3
1
4
1
1
5
6
6
5
2
6
2
2
5
1
6
8
5
2
9
3
2
7
5
7
9
7
3
8
9
8
1
7
6
6
1
5
1
4
1
6
9
3
2
1
1
8
8
1
8
4
7
7
7
4
9
5
2
6
3
1
4
4
4
4
9
4
2
1
9
7
7
9
7
3
3
5
7
5
8
2
4
7
6
7
6
2
1
2
9
8
1
2
1
3
6
2
9
4
2
5
2
5
9
9
9
2
1
1
6
4
1
5
4
3
9
8
8
5
9
1
1
9
8
5
8
6
1
2
6
6
3
5
5
7
6
1
9
7
8
4
2
5
4
5
5
8
3
4
1
6
1
5
4
1
6
2
5
5
2
3
9
8
4
5
6
3
8
7
8
6
3
4
6
5
2
2
6
6
7
8
4
2
7
2
8
7
9
7
1
9
7
6
6
3
4
4
4
1
3
9
4
4
2
8
7
1
6
9
8
7
8
7
3
7
5
6
7
8
9
5
4
7
4
4
8
8
2
2
2
4
8
5
8
6
2
4
5
4
4
6
1
8
4
7
3
7
9
3
8
2
3
3
3
9
8
8
5
1
1
9
7
7
5
5
1
8
9
1
6
4
8
2
3
1
8
6
1
6
9
5
2
1
7
7
6
9
3
4
8
4
9
2
5
2
4
9
8
2
1
8
6
6
7
1
9
3
9
5
5
3
6
6
1
7
7
6
3
8
1
8
8
1
7
6
2
1
2
6
5
5
1
5
7
3
3
8
1
8
4
4
6
8
5
2
9
4
1
8
2
2
5
1
1
3
3
1
2
6
3
5
5
1
4
2
7
7
9
6
9
4
8
7
5
4
2
5
2
5
8
7
1
9
2
8
8
9
8
4
1
4
6
2
1
7
8
7
8
4
6
5
6
7
2
7
8
4
4
2
7
6
5
9
5
4
9
7
7
7
4
8
1
9
3
5
3
4
6
5
2
1
6
3
1
1
4
8
1
2
7
2
9
9
6
1
1
7
9
9
9
8
4
3
5
7
6
6
5
5
5
2
6
1
2
1
6
7
2
4
3
6
4
8
7
4
2
7
3
4
4
9
3
1
8
6
2
2
6
4
1
5
9
5
7
3
9
4
7
6
8
8
2
5
7
7
3
3
5
2
6
6
3
2
2
9
5
1
5
9
6
2
9
9
5
1
4
9
3
4
2
1
5
2
9
2
8
2
8
1
4
4
6
7
7
8
9
1
4
8
6
9
4
1
9
7
1
2
7
8
3
6
7
2
5
1
2
6
1
2
7
5
2
4
1
3
1
7
1
4
9
5
2
3
4
6
2
6
5
9
7
7
9
9
3
4
3
8
6
4
2
3
1
9
1
3
9
4
4
8
1
3
5
2
1
6
1
4
6
4
6
7
2
1
1
8
5
8
4
4
9
2
7
3
2
6
5
5
1
5
3
1
5
3
3
5
1
2
2
8
3
8
8
6
3
4
3
1
3
2
6
7
4
9
8
6
4
8
3
1
1
6
3
7
2
6
8
6
8
5
4
2
6
8
9
9
1
3
7
4
6
6
5
8
8
5
6
9
4
2
3
9
3
4
5
2
3
3
1
8
6
6
1
8
6
3
9
9
5
4
2
5
5
7
6
5
9
5
5
4
5
7
5
7
9
5
4
5
5
9
3
1
7
5
6
8
1
7
5
9
9
5
6
3
1
2
9
3
4
5
9
2
2
2
8
8
3
4
2
4
3
9
1
6
5
6
1
1
5
6
3
1
5
3
3
4
6
7
5
4
6
8
8
9
1
8
9
3
2
5
4
4
6
2
3
5
3
9
2
6
8
8
1
2
8
5
1
6
7
8
3
6
7
5
5
1
2
7
5
3
4
7
2
8
1
8
2
1
8
1
9
4
9
2
3
3
6
5
4
8
8
3
4
8
5
5
2
4
9
7
7
9
8
1
1
4
7
3
9
6
3
9
7
6
5
2
5
5
9
8
7
7
5
7
2
4
5
1
9
5
8
6
5
8
2
9
2
4
1
6
9
9
6
7
6
8
8
3
4
3
8
1
3
2
7
5
4
9
8
9
2
9
8
4
1
4
6
2
4
6
3
6
2
3
3
6
7
7
7
4
3
5
6
4
3
8
7
2
1
5
1
7
2
9
7
2
7
3
7
7
5
7
7
8
6
1
7
5
8
4
6
5
9
4
5
1
6
6
5
1
4
9
7
8
6
9
8
5
6
4
9
8
4
2
5
8
4
6
6
6
5
5
6
5
6
7
6
5
4
9
8
3
6
1
8
5
3
8
2
5
7
1
4
8
3
2
8
2
8
2
9
9
5
3
9
7
5
3
4
5
9
2
6
3
6
4
7
5
7
6
2
5
5
8
7
9
1
2
4
7
9
3
8
5
7
1
4
7
1
8
1
1
8
9
5
4
7
7
7
5
7
1
4
9
1
7
7
1
6
2
2
8
6
8
7
1
4
4
1
9
8
2
8
1
8
3
3
5
4
6
6
5
3
1
5
5
9
6
4
7
1
2
5
6
2
5
7
8
3
6
2
1
3
7
5
4
6
3
5
3
4
8
5
4
8
2
5
2
1
5
1
6
3
9
3
6
7
3
1
5
2
3
9
8
4
6
1
4
3
6
7
9
8
8
2
7
7
5
1
2
1
1
7
4
3
7
8
6
2
8
3
7
5
5
5
5
1
5
3
2
6
5
7
5
1
2
3
6
2
2
1
2
4
6
8
6
9
7
1
3
9
8
8
7
5
4
5
4
3
1
3
1
1
6
2
7
7
6
8
7
7
4
1
2
5
4
5
4
9
1
7
6
9
1
7
7
3
5
6
2
7
3
5
5
8
5
5
9
4
9
8
2
7
3
4
9
1
9
9
2
4
5
2
3
7
7
8
2
6
1
8
7
1
9
3
2
1
4
8
1
3
4
2
2
5
8
4
6
7
3
7
1
1
1
9
5
5
7
2
3
7
4
7
3
8
7
4
6
6
2
6
7
9
5
8
9
2
1
3
2
7
8
8
7
6
1
1
5
6
8
3
2
4
1
8
5
8
2
9
7
3
6
9
9
3
5
5
9
7
2
7
2
9
8
1
3
1
5
1
7
8
3
1
1
8
6
2
8
4
4
7
1
1
4
8
3
9
5
3
6
3
5
9
9
5
7
7
4
6
3
6
6
9
5
5
4
8
4
6
8
9
3
1
5
4
8
5
2
3
8
1
6
9
7
6
6
7
9
3
7
6
3
7
3
7
9
9
2
2
4
9
3
1
2
2
4
5
5
6
2
7
5
3
8
1
6
7
8
4
3
5
3
4
5
3
7
6
1
6
8
8
9
2
5
7
1
6
2
8
8
7
6
9
2
3
9
3
8
4
4
3
1
3
7
8
4
1
7
1
7
7
5
2
6
4
5
2
9
3
6
6
4
8
9
2
6
3
7
8
9
5
4
5
8
6
4
3
4
9
9
3
2
7
8
7
5
8
8
7
1
1
9
2
2
1
5
5
6
7
6
6
7
2
3
7
9
8
6
4
7
3
1
8
9
3
8
7
3
7
2
7
2
3
4
3
9
3
7
9
8
4
3
1
1
1
9
9
2
1
1
9
5
1
7
2
1
5
8
9
1
9
5
6
5
1
2
3
4
8
1
1
4
2
9
5
4
3
6
2
8
7
1
3
9
4
7
5
8
4
1
2
9
9
7
6
5
7
3
8
7
9
1
7
5
1
3
6
9
2
6
7
4
4
8
5
2
4
4
8
4
8
6
8
2
6
3
5
8
5
2
4
8
2
2
7
7
9
5
8
7
8
4
2
1
5
4
9
7
9
6
2
8
6
6
1
5
3
5
5
7
2
9
1
5
2
1
9
8
9
3
4
4
6
5
7
1
5
8
5
6
6
5
2
6
5
3
8
2
3
3
8
3
5
4
4
4
7
2
8
2
2
8
4
2
5
8
3
2
2
7
2
4
6
7
8
3
7
6
5
2
8
6
9
2
6
1
3
4
8
8
4
4
4
2
2
4
9
6
3
3
2
6
3
7
9
8
8
3
8
8
3
8
8
2
8
3
6
1
3
9
5
7
6
6
7
4
4
4
3
8
7
3
4
4
5
2
8
9
3
9
4
2
4
9
9
4
7
7
8
7
5
9
4
3
4
1
9
2
7
5
7
7
9
6
9
2
7
5
3
7
1
8
8
9
6
8
8
3
3
6
8
9
7
7
8
4
7
3
5
2
2
6
3
7
4
7
9
8
6
1
6
3
8
1
9
9
5
9
6
8
3
7
8
1
8
4
2
6
6
4
8
6
1
8
9
1
1
8
5
1
1
2
1
1
2
3
4
4
1
8
1
8
4
2
1
5
6
9
7
8
2
3
4
5
1
2
8
6
9
7
2
7
5
6
9
5
3
3
8
7
7
2
5
8
8
1
2
6
1
8
4
8
9
8
1
2
3
1
5
9
6
3
2
8
9
5
1
6
6
6
9
8
2
3
9
3
6
6
6
9
2
1
8
6
3
8
9
5
9
7
3
3
5
9
2
8
4
7
3
5
1
3
3
9
8
8
4
8
9
4
8
5
8
4
6
8
1
3
4
4
6
2
2
7
5
3
7
9
8
4
8
5
8
5
3
8
6
9
5
5
5
6
6
6
1
3
3
4
9
1
1
1
2
9
7
9
1
1
3
7
1
9
2
2
4
2
5
1
1
1
5
3
5
3
9
5
8
9
1
5
1
4
1
8
4
2
9
2
2
6
6
4
5
5
6
5
6
6
8
4
8
5
3
5
6
2
4
9
2
2
3
6
5
4
7
2
1
8
6
7
5
5
7
9
2
3
2
6
4
4
1
4
5
6
1
1
8
5
6
3
6
1
6
3
8
2
1
9
2
6
3
3
2
2
4
9
7
6
4
5
8
1
1
5
2
1
4
1
3
6
8
4
4
4
5
5
7
3
8
9
5
5
7
7
2
2
3
4
9
3
4
7
4
9
1
1
4
4
9
4
7
7
4
2
1
2
2
8
1
6
4
8
2
4
4
5
8
2
1
6
8
9
2
7
9
4
4
4
2
5
2
3
8
2
1
6
3
4
6
3
5
6
5
2
7
6
7
5
3
5
9
2
9
4
9
2
8
4
4
5
1
5
8
5
2
7
8
7
8
1
5
1
4
6
1
9
9
9
2
9
9
8
4
2
9
4
3
2
7
1
7
8
6
6
4
4
1
3
3
5
2
9
7
7
2
4
2
1
7
5
4
6
8
2
9
8
6
6
1
7
5
9
4
3
5
5
4
4
5
1
9
4
7
1
9
1
2
3
5
1
2
4
8
3
7
4
2
9
8
2
1
7
1
2
5
1
3
8
9
3
1
9
6
3
1
8
2
4
7
9
4
1
4
1
2
8
1
1
1
4
5
5
6
6
4
5
9
2
4
8
7
9
7
3
8
6
1
3
8
2
8
8
7
8
6
5
7
2
9
8
5
6
4
7
6
1
2
6
8
6
9
5
8
6
1
9
5
1
5
3
2
1
2
8
7
5
2
6
5
3
5
2
7
9
5
7
9
7
6
8
1
1
4
5
8
3
5
9
9
9
1
6
4
2
3
4
7
9
1
3
8
8
6
1
6
9
2
1
4
5
7
3
3
7
4
7
1
8
8
8
1
2
2
7
4
4
8
6
3
2
8
4
6
8
2
4
2
6
5
4
5
7
5
6
3
4
6
7
9
3
3
1
4
6
1
5
1
6
4
9
6
2
8
8
6
7
9
6
2
9
3
1
6
7
1
3
9
2
2
8
8
1
6
2
1
3
7
5
4
6
6
1
9
9
9
8
5
7
3
9
8
1
8
8
6
5
1
8
8
5
4
4
8
1
5
3
3
7
6
5
4
6
3
5
1
6
5
5
3
2
9
1
8
2
4
5
6
5
3
7
6
5
5
9
3
7
7
2
8
5
8
6
8
5
4
6
3
2
7
1
1
8
5
6
3
6
3
5
4
6
5
1
4
1
7
4
3
3
3
1
2
2
8
6
3
5
1
7
1
8
3
6
4
9
5
1
2
2
3
3
2
3
1
8
9
2
9
9
8
1
5
6
4
6
1
6
2
9
5
5
9
3
8
7
2
7
2
2
8
2
6
7
9
3
8
2
2
7
8
1
6
2
3
2
3
8
8
4
8
5
8
5
4
4
8
6
3
7
2
4
5
9
2
4
5
6
2
7
8
1
4
4
5
8
6
3
3
3
1
7
6
4
2
9
4
4
4
2
4
3
9
7
1
7
7
9
5
1
9
7
7
9
3
6
7
3
3
3
5
4
6
3
1
7
4
6
7
6
1
6
2
7
7
8
5
4
8
5
2
2
4
5
4
4
4
4
5
8
4
2
7
6
3
8
8
8
6
7
3
1
3
3
3
5
2
1
1
5
8
6
3
3
5
2
1
6
4
1
7
9
4
5
3
2
7
2
9
7
9
4
5
8
8
2
2
2
8
8
2
6
5
9
8
8
9
7
2
9
2
8
3
4
8
6
7
1
9
6
5
5
6
4
9
4
1
1
4
4
3
7
9
1
6
9
5
3
2
7
4
9
9
6
1
6
2
5
1
2
8
2
1
9
1
9
6
7
1
5
6
2
6
1
5
8
8
8
3
2
2
7
4
7
1
6
1
7
2
9
1
2
2
3
5
6
2
2
3
3
7
2
5
8
4
2
6
4
6
2
1
8
1
7
9
4
9
1
6
4
9
6
2
9
5
8
1
4
6
1
5
2
3
1
1
1
6
2
1
4
7
2
1
4
2
2
2
2
6
2
2
2
9
1
5
4
4
9
9
7
3
2
1
2
1
7
9
5
1
5
3
1
6
6
1
8
4
1
9
5
6
7
6
7
4
8
2
6
1
3
1
2
6
5
6
6
8
1
1
2
6
6
7
1
2
7
8
4
7
5
8
7
1
5
3
9
1
7
5
9
5
8
6
7
6
6
9
2
9
5
6
9
7
9
3
4
2
9
5
3
4
6
6
3
4
7
6
4
9
6
3
8
9
4
1
4
3
6
5
7
4
4
3
6
7
8
9
6
6
7
6
7
9
1
7
8
7
9
7
3
9
4
6
7
2
2
2
5
3
2
4
3
5
6
5
3
8
4
9
5
7
1
1
3
1
7
2
6
4
9
3
9
6
3
7
7
5
6
1
3
8
5
8
7
6
2
2
6
3
9
3
2
2
7
1
7
1
3
2
9
2
7
3
3
2
2
6
7
4
4
4
9
6
7
7
2
6
8
7
9
9
6
2
2
3
1
2
3
7
8
5
8
3
1
6
9
8
5
9
1
3
6
8
6
3
3
7
9
8
4
9
6
1
5
7
7
6
1
1
4
1
5
5
9
2
5
6
2
5
1
5
5
1
4
1
4
4
8
8
6
5
4
6
4
3
6
8
4
6
5
3
5
8
8
2
2
7
1
5
6
1
3
1
4
6
4
1
4
7
9
3
9
3
6
9
7
6
5
4
3
9
4
4
4
2
1
9
5
3
7
3
7
7
7
6
5
3
5
8
3
2
4
7
1
3
6
7
5
6
3
4
4
3
2
9
2
8
2
9
8
3
9
6
5
9
4
4
7
9
2
7
3
4
4
2
5
3
6
1
5
9
1
7
2
2
7
4
1
9
2
9
9
8
4
2
2
9
2
6
8
8
1
2
3
6
5
6
7
9
1
2
1
6
3
9
7
6
8
7
6
3
3
1
9
6
6
6
8
4
3
4
3
4
5
6
8
5
6
7
3
5
3
9
9
1
3
4
9
3
9
1
1
7
2
7
3
5
4
2
5
5
3
5
1
6
1
2
1
8
2
3
3
6
9
2
8
1
3
4
4
2
5
1
6
3
3
1
9
9
2
5
6
7
6
8
1
3
8
5
2
3
7
7
9
1
1
8
3
1
1
5
6
6
3
1
4
2
4
7
5
9
2
6
1
6
5
1
4
2
6
1
3
3
5
7
6
2
6
3
7
2
1
2
1
3
3
2
5
2
6
3
4
2
3
9
4
5
7
4
2
1
6
4
9
6
5
3
5
1
5
9
2
1
5
7
8
1
6
6
4
2
6
4
9
6
5
7
7
5
9
7
2
3
6
3
2
7
8
6
8
6
5
7
7
9
7
2
2
6
3
6
4
4
9
4
9
3
8
6
9
7
6
6
6
8
4
1
5
7
9
8
3
7
6
4
6
8
7
2
9
8
1
7
2
8
4
4
8
6
2
7
5
5
9
3
7
4
3
7
2
7
7
9
3
6
5
5
5
9
3
8
6
4
2
4
1
4
1
8
4
6
2
4
9
8
2
3
7
3
7
3
6
5
6
5
2
2
4
8
8
9
4
5
9
6
1
2
9
1
3
6
5
3
3
2
8
8
2
9
5
6
8
1
7
7
9
3
7
4
5
3
1
6
1
2
3
7
7
4
3
3
9
5
2
3
8
7
5
7
4
6
6
8
1
8
7
4
6
4
7
2
2
7
8
8
9
4
5
1
1
3
5
9
5
7
5
8
1
4
6
1
4
8
6
3
9
2
6
9
4
1
5
6
9
5
8
9
8
5
3
3
5
5
3
9
9
6
7
3
9
4
4
8
8
2
9
9
5
1
2
8
8
1
9
3
7
4
8
7
1
4
4
5
7
9
1
1
3
4
4
3
2
7
7
7
8
9
3
8
6
4
8
4
3
6
5
6
8
5
5
8
4
9
1
8
3
5
9
8
6
3
9
7
8
6
8
6
8
7
1
4
4
4
6
3
9
9
3
7
4
7
3
3
1
6
4
2
9
6
5
2
7
4
2
7
8
7
5
7
8
9
7
1
4
5
7
9
7
8
4
6
3
1
7
2
9
7
4
2
5
7
9
6
9
5
7
4
9
7
4
5
5
9
8
2
5
5
7
3
6
1
7
8
4
7
2
3
4
2
1
8
8
4
6
6
1
3
2
8
4
6
4
7
1
2
4
8
4
9
9
4
7
8
1
7
6
7
5
2
8
4
1
6
1
4
5
8
8
1
8
7
4
6
5
7
9
5
7
5
4
1
9
6
9
5
6
9
1
2
9
1
8
1
1
9
1
6
1
3
2
8
8
4
4
5
9
1
9
2
3
5
3
9
8
4
4
6
7
9
8
8
7
8
7
7
2
4
9
5
3
4
4
9
1
3
9
9
2
7
2
7
5
4
3
7
6
6
2
8
4
9
2
6
5
4
3
9
8
9
4
2
1
2
6
3
8
7
1
2
7
3
5
2
2
9
1
9
2
2
3
4
4
1
8
3
8
8
2
9
5
5
1
4
7
2
1
7
9
8
3
9
6
2
3
8
2
6
3
5
9
8
2
7
9
3
9
7
6
6
7
9
6
9
8
7
9
6
7
8
7
2
7
4
6
3
3
1
8
8
9
8
9
9
2
4
8
8
8
1
8
3
6
9
9
2
9
7
8
7
6
7
6
9
8
7
6
7
8
5
4
3
2
5
6
1
4
9
8
6
3
4
1
4
7
3
1
9
6
2
6
5
8
7
4
2
7
3
5
5
8
1
2
3
8
7
8
8
4
6
1
2
8
4
4
2
2
9
6
7
9
4
6
8
1
3
2
8
4
1
9
8
9
3
1
9
8
4
1
2
5
1
3
6
3
5
4
1
1
3
1
4
6
1
6
9
8
2
1
1
6
4
2
6
2
3
9
3
5
5
2
8
6
8
6
4
7
5
7
2
6
3
1
7
6
3
7
6
6
3
8
4
1
3
9
2
5
7
4
8
2
6
4
2
6
3
3
9
8
9
5
7
5
1
2
7
7
5
2
3
2
4
6
7
7
6
3
1
8
4
8
2
2
8
1
5
6
3
4
8
7
8
5
1
7
3
8
8
6
8
2
4
1
2
2
2
3
2
6
8
5
2
7
9
4
3
6
1
3
9
2
2
4
9
4
1
7
6
3
9
7
5
3
8
6
6
3
9
4
7
5
9
7
1
7
2
2
2
5
4
3
6
7
4
1
1
9
3
4
1
9
9
4
2
6
3
2
1
6
5
9
8
1
5
1
2
7
8
4
6
4
8
4
5
3
1
8
9
7
1
7
3
3
6
7
1
8
3
5
5
6
2
1
3
3
7
6
3
9
5
6
3
8
4
7
6
5
2
5
3
1
9
9
1
4
3
3
9
4
8
3
3
2
7
3
8
4
5
1
4
9
5
6
9
8
7
6
1
2
8
4
9
4
6
8
8
3
6
8
9
6
3
5
8
8
1
3
3
7
3
4
4
1
4
5
9
7
8
4
5
2
8
1
6
5
2
3
4
8
5
7
9
5
3
8
3
2
5
8
1
6
4
5
5
5
5
6
9
3
1
1
9
2
2
1
3
5
7
5
4
2
4
1
6
1
2
2
4
5
9
4
5
4
4
9
3
1
7
1
9
2
7
1
6
2
5
7
5
2
9
6
6
8
5
9
9
3
9
6
9
5
4
8
5
7
1
3
5
5
6
3
2
3
6
9
5
4
2
5
9
4
2
4
8
5
9
9
1
8
2
2
8
3
2
4
3
4
7
9
8
4
6
4
9
6
7
3
5
4
1
3
7
8
4
4
8
4
6
4
8
1
7
1
3
6
6
1
1
2
4
9
2
3
4
9
7
2
9
2
7
9
7
1
5
7
7
6
2
7
5
7
2
7
7
2
8
5
9
3
4
3
1
3
9
4
8
7
6
6
7
1
7
1
9
1
3
5
3
8
9
9
1
4
8
6
9
2
2
1
7
6
8
6
1
7
3
5
1
8
8
9
2
3
3
6
1
1
7
7
5
8
2
8
4
3
4
2
5
5
5
7
7
9
7
2
2
6
2
5
5
4
8
2
5
5
6
5
7
8
1
3
1
7
6
7
1
7
4
4
4
1
8
8
6
3
6
7
1
8
9
2
7
2
4
3
5
6
3
2
5
5
4
7
7
3
5
8
4
4
3
5
5
9
5
8
1
2
3
5
8
5
8
2
1
9
1
7
7
1
1
1
2
1
3
2
4
9
6
9
5
1
2
6
8
2
1
2
1
8
5
1
6
9
7
7
2
3
9
5
2
4
5
6
7
2
3
2
3
2
8
9
6
6
1
1
2
3
5
7
3
8
1
4
7
1
1
3
5
6
9
2
3
3
8
4
8
1
4
8
5
7
3
6
8
6
4
5
2
1
3
2
5
4
3
3
5
9
1
7
2
6
6
7
7
6
2
3
4
1
2
1
8
2
6
2
5
2
2
4
8
6
5
9
6
8
1
4
8
5
6
9
8
8
5
6
8
8
6
5
7
4
1
5
1
6
2
1
5
5
1
2
3
8
9
7
1
1
2
7
7
4
8
6
1
9
9
5
6
4
9
4
1
9
9
3
5
2
7
6
3
7
1
8
9
5
2
6
3
5
2
1
6
6
4
3
8
9
9
9
5
5
8
7
6
7
3
9
2
3
6
3
8
9
4
4
1
8
4
7
2
7
6
8
4
6
7
1
3
5
1
2
4
1
3
3
4
6
3
9
1
1
4
4
3
6
9
7
4
3
8
8
8
9
4
3
1
7
1
6
3
1
7
5
3
6
1
9
6
3
4
4
5
7
3
6
1
7
8
3
5
1
4
7
2
5
3
4
3
8
7
3
9
7
4
6
2
2
3
7
2
1
7
1
8
6
1
6
1
7
2
5
6
4
4
1
2
7
8
4
2
3
5
1
8
8
3
6
8
8
1
8
3
1
5
9
7
9
3
7
9
4
6
6
2
2
3
3
8
9
6
5
8
7
9
2
5
3
3
1
1
5
9
9
1
8
5
8
1
6
4
2
3
2
7
3
7
7
8
4
1
1
5
5
6
5
6
7
4
7
5
5
7
4
6
4
3
1
4
5
7
8
2
4
3
3
1
2
8
5
7
4
8
8
8
3
2
9
3
9
5
2
8
5
6
8
1
1
1
2
4
4
8
1
3
5
6
5
9
2
4
2
2
8
9
8
9
3
2
2
7
8
6
8
8
2
9
2
3
9
6
8
8
1
2
3
7
2
6
5
6
5
7
1
5
9
6
3
4
3
1
9
2
3
3
8
1
2
1
1
9
9
6
5
5
5
3
4
5
7
6
9
2
1
1
3
9
4
7
5
4
6
4
3
4
8
4
1
1
7
8
3
8
3
5
3
5
7
7
9
6
9
7
4
9
1
6
7
7
8
5
9
9
4
5
7
3
7
2
7
4
2
4
4
5
7
6
8
4
1
6
6
4
9
6
5
2
9
8
2
8
6
7
7
4
5
6
8
8
5
5
3
9
9
2
5
6
3
4
5
9
6
1
6
7
8
9
3
4
7
7
6
2
4
1
1
4
2
6
9
5
1
8
6
3
3
7
2
3
6
9
2
9
4
5
4
4
2
5
9
4
6
5
9
8
2
6
2
4
1
8
4
7
2
7
6
2
2
9
2
5
7
9
8
3
3
2
9
2
4
5
1
1
7
5
9
7
2
5
5
4
6
8
5
9
1
7
3
2
3
9
4
3
8
7
6
8
7
1
6
5
8
5
1
1
6
1
8
1
1
Well, the way you guys constantly dog out Microsoft around here it's no wonder it is insecure. A little TLC should get them back in order in no time.
I wonder if he feels personally responsible/remorseful when someone using a product he helped create is screwed over because he didn't do his job of finding/repairing security holes.
Job? I don't have time to get a job! Who will sit around and bitch about being broke and unemployed then?
>
> A: I think any time we find any security vulnerability, we're one of the best in the industry to notify people of the details of them and give them the details to get it fixed.
Conspicuously absent is any description of Microsoft's response when someone else finds the security vulnerability in their products.
Microsoft does focus a lot of effort towards securing their products. Unfortunately the effort is more reactive than proactive. It's a basic flaw in the capitalist model that allows the Marketing and Accounting people to determine release dates--instead of the Developers. The attitude can be paraphrased like this: "As long as the app fires up, it can be released. We'll let the customers be beta testers."
If they were in the car business insted of the O/S business, a lot of people would be dead or mangled.
"What is the sound of one belly slapping?"
Could the blame for Microsofts security issues fall on this man? Rushing products before they are fully tested.
Microsoft's closed-source mode of development guarantees that customers will continue getting cracked and Microsoft will continue pointing the finger of blame everywhere except where it actually belongs.
Man and Goat
llllllaaaaaammmmmmaaaaaa goody goody llllllaaaaaammmmmmaaaaaa goody goody llllllaaaaaammmmmmaaaaaa goody goody llllllaaaaaammmmmmaaaaaa goody goody llllllaaaaaammmmmmaaaaaa goody goody llllllaaaaaammmmmmaaaaaa goody goody llllllaaaaaammmmmmaaaaaa goody goody where did CmdrTaco get his syphlitic penile accesory?
FROM JONKATZ
yup
WHAOOOO
--
$ chown -R us:us yourbase
Unfortunately for those who oppose full disclosure, the issue was discussed on Bugtraq, which finally led to the details of the vulnerability. This means that the Microsoft-supported way of disclosing bugs (Do issue an advisory but do not publish any details that could be used in creating exploits) apparently didn't work out. Ofcourse, there was a (small) delay, but eventually everybody knew about it before the patch was released.
My question regarding this issue is: how do you feel about this issue? Do you really think that not fully disclosing a vulnerability will prevent exploits to be made? One of the arguments for full disclosure is that sysadmins are able to reproduce the error so that they can test if their system is vulnerable, but with limited disclosure this will only be possible for a small (and probably malicious) public.
--
If code was hard to write, it should be hard to read
The article references this. Here are a couple of URLS on it:
0 24 01.html
s m_ militias/20011031_eff_usa_patriot_analysis.html
Full Bill:
http://www.politechbot.com/docs/usa.act.final.1
EFF Analysis:
http://www.eff.org/Privacy/Surveillance/Terrori
For this, as well as for many other reasons, it is essential that one operating system and one software company does not dominate the industry. The cost of dealing with cross-platform issues is the price we have to pay for a competitive market and a resilient infrastructure.
Suggestions that our salvation lies in uniformity, market dominance by one company, and bigness are more reminiscent of the central planning of the USSR than of what has made our society so successful. It's kind of funny to see that some of the most staunch conservatives and defenders of Microsoft-style laissez-faire economics seem to be falling into the same trap that the communists fell into.
I think it's time for Slashdot to get rid of
trolls
trolls..ff
trolls
trollsfdff
trollsdfd
trollssf.f.
trollsdsfsdf.fds
trolls
trollsf
trollsds
trollsf
trollsfff
trollsf
trollsdsf
trollssdf
trollsfff
trollsdsfsd
trollsf
trolls
trollsas..122
trolls
trollsd
trollsqwd
trolls1
trolls
trollswd1.w1.wd
trolls
trolls
trollswadw
trolls
trolls
trolls/jte
trollsk
trolls
trollsln
trollsr
trollsrt13
trollsg
trollsrth
trollsk
trolls6k
trollsjrg
trolls3
trolls
trollsj5rtj5
trollsj
trolls,
trolls,
trolls
trollsj
trolls
trolls24g
trolls2
trolls4
trollsj35
trollsj
trolls34
trollst2
trollst
trolls1
trollsg
trollsgk,,
trollsth
trolls
trollsg2
trolls43g
trollsj
trollstyj
trolls
trollsh
trollsh
trolls2h5jykk
trolls. It would make Slashdot more enjoyable.
He did coin (or I least I've never heard of it yet) the term cyberhacktivism. So that's gotta be worth something. Cheers
Why does this interviewer have to keep comparing software attacks with the September 11th terrorist attacks? About the only thing they have in common is that they are both malicious. Beyond that, it has no place in an interview about Microsoft security. Very poor taste, IMO.
- Just an AC
Okay, wrong reply (Yes, I scanned the article and saw the words 'microsoft' 'security' 'ask' 'question' and 0 comments, started typing like a wildman to be the first to type an intelligent question ... and realised just a bit too late that it wasn't a call for questions).
:)
Please mod me down before to many people notice my dumbness
--
If code was hard to write, it should be hard to read
Anyone who knows that they're a market leader does have a responsability to see that their stuff isn't going to be the cause of the next great Internet collapse. MS is quickly becoming the leader in getting their bugs exploited, and with so much market penetration, we really could be facing quite a disaster when a better worm comes along.
Does anyone out there work for some other big company with lots of market share? What type of responsability do they assume for the security of their products?
Mac
Does the name Pavlov ring a bell?
A: If you look at the development process, and how long it takes to develop these things and get them out the door, this is not something that people started working on six months ago, and the developer community is saying this is a bad thing. This is stuff that has been in progress for years, which is why we've had to effectively retool the way we do things internally, to meet that new threat environment.
I don't know if the interviewer changed tapes in his recorder or what, but this is the single most important question he asked, and it was completely and totally unaddressed. This one question drives home the problem with Microsoft security, makes him aware that yes, we were all SCREAMING "Stop the madness" BEFORE it rolled out, and he waves his hands saying that hmm, we're meeting the new threat environment. What?
Is there any chance that anyone of importance will see or read this interview? That's the shame. I'd love it if the appropriate congresspeople and/or attorneys-general could see this nonsense made more public.
Not that I expect anyone in his position to actually answer all the questions asked, but it'd be nice if his lips moved in sync to his words, too.
John
John
I think it doesn't make any difference whether it is open source or closed source, it's a matter of identifying them once the product is released.
/home: disk full
So...who cares if there are problems. We'll find them eventually - as soon as someone exploits them and we hear about it. I wonder if they release their code like that for QA as well. It's a matter of identifying bugs once the product is released.
I understand that you problems happen, but this is kinda like shoving things under the carpet and hoping no-one looks - or to use his analogies - letting the burgler in the front door of the apartment complex and hope that all the doors are locked, but ask him on the way out where he got the loot from.
True reason MS won't release the source code for a security audit:
~$ df
/home 200M free
~$ cd windows/source
~/windows/source$ find . -name "*.c*" -exec grep -l gets {} \; > ~/
volume
:)
God damn I ran into Hemos maybe three weeks ago and he is so fucking fat. Jesus God. How can anyone talk about morality when that fat fuck is corralling obesity like we don't remember.
Damn.
Maybe if you keep talking, noone will notice. .
All time record low number of posts for the amount of time this story has been on the front page. Looks like they're all at LOTR. Sad.
HUH? Come On!
A: Security?
Q: ... yeah, security ...
A: Oh... that......... Our policy is to blame the people who find the holes in our software...
Q: What about the people who put the holes in the software in the first place?
A: Yes, of course. We're currently trying to purge the Al Quida factions from our programming team.
Microsoft has been getting better. Many of the current IIS exploits aren't in IIS at all, but in ISAPI extentions like Index Server (Code Red exploited this), and HTTP Printing in Win2K. Almost all of the exploits released last year and this year could've been blocked by simply following MS' security checklist.
Needless to say, sysadmins apparently don't read checklist, follow best practices, or pay attention to alerts. I have seen real movement from MS (on their site, in comments on NT BugTraq, and in other places) that they take this security stuff seriously now, and they are coming out with some good tools (they're even subcontracting them to get them faster and by security companies who have a better track record) to help automate patch downloading and installation, scanning of network resources for missing patches, remote deployment of patches (for those 500 web servers you have in your datacenter), and various checker tools which will basically verify the security checklists for you.
Apparently MS realizes they made a wrong decision in their approach to security (trusting the sysadmin's dilligence), and they are making strong strides to change this now, and in the future.
I know many of you dislike MS, but you must give them at least that.
Sounds more like the head of Marketing at Microsoft than the Head of Security. Most of his answers were the same marketing BS that come out of Micro$oft every time you ask anyone from there a question. I just wish Micro$oft would give straight answers instead of Marketing BS.
"Really, I'm not out to destroy Microsoft. That will just be a completely unintentional side effect." Linus Torvalds
OT III
.II and Incident I. They can also occur at 1 quadrillion, which is the Clearing course materials. They also occur at random dates for different reasons.
[Operating Thetan Level 3]
BODY THETANS
by L. Ron Hubbard
The head of the Galactic Federation (76 planets around larger stars visible from here) (founded 95,000,000 years ago, very space opera) solved overpopulation (250 billion or so per planet - 178 billion on average) by mass implanting..
He caused people to be brought to Teegeeack (Earth) and put an H-Bomb on the principal volcanos (incident II) and then the Pacific area ones were taken - in boxes to Hawaii and the Atlantic area ones to Las Palmas and there "packaged".
His name was Xenu. He used renegades. Various misleading data by means of circuits etc was placed in the unplants. When through with his crime loyal officers (to the people) captured him after six years of battle and put him in an electronic mountain trap where he still is. "They" are gone. The place (Confederation) has since been a desert.
The length and brutality of it all was such that this Confederation never recovered. The implant is calculated to kill (by pneumonia etc) anyone who attempts to solve it. This liability has been dispensed with by my tech development. One can freewheel through the implant and die unless it is approached as precisely outlined. The "freewheel" (auto-running on and on) lasts too long, denies sleep etc and one dies. So be careful to do only Incidents I and II as given and not plow around and fail to complete one thetan at a time.
In December 1967 1 know someone had to take the plunge. I did and emerged very knocked out, but alive. Probably the only one ever to do so in 75,000,000 years. I have all the data now, but only that given here is needful.
One's body is a mass of individual thetans stuck to oneself or to the body.
One has to clean them off by running incident II and Incident I. It is a long job, requiring care, patience and good auditing.
You are running beings. They respond like any preclear. Some large, some small.
Thetans believed they were one. This is the primary error.
Good luck.
* * *
For the purpose of clarity, by BODY THETAN is meant a thetan who is stuck to another thetan or body but is not in control.
A THETAN is, of course, a Scientology word using the Greek theta which was the Greek symbol for thought or life. An individual being such as a man is a thetan, he is not a body and he does not think because he has a brain.
A CLUSTER is a group of body thetans crushed or hold together by some mutual bad experience.
----------
Character of Body Thetans
Body Thetans are just Thetans. When you get rid of one he goes off and possibly squares around, picks up a body or admires daisies. He is in fact a sort of cleared Being. He cannot fail to eventually, if not at once, regain many abilities. Many have been asleep for the last 75,000,000 years. A body Thetan responds to any process any Thetan responds to.
Some body Thetans are suppressive. A suppressive is out of valence in R6. He is in valence in Incident I almost always.
One can't run a human being on these two incidents since human beings are composites and would not be able to run the lot. Aside from that, non-clears are way below awareness required to even find these Incidents.
Huge amounts of charge have already been removed from the case and the body thetans by Clearing and OT I and OT II to say nothing of engrams and lower grades.
Awareness is proportional to the charge removed from the case.
Although a human is a composite being there is only one I (that is you) who runs things.
Body thetans just hold one back.
You will continue to be you. You, inside, can of course separate out body thetans and so solo auditing is the answer. How good do you have to be to run body thetans off? Well, if you didn't skip your grades, Clearing and OT II particularly, you. should be able to'command body thetans easily.
* * *
Incident II is over 36 days long. Capture on other planets was weeks or months before the implant. Those on Teegeeack (Earth) were just blown up except for Loyal officers who were (shortly before the explosion on Earth) rounded up.
Do not scan through the duration of 36 days. The volcanic explosion on Earth to the point where "the pilot" says he is mocking it up is only a few days.
Sequence of Incident II for thetans on another planet -
1. Capture (being shot),
2. freezing,
3. transport to Teegeeack (sometimes via a relay point),
4. being placed near a volcano,
5. beginning implant up to "the pilot",
6. various picture sequences,,
7. the 7s and C.C. and OT II materials,
8. 36 days of picture implants which give a vast array of materials and three explanations for the bombing,
9. transport to Hawaii or Las Palmas for packaging up into clusters.
The pictures contain God, the Devil, angels, space opera, theaters, helicopters, a constant spinning, a spinning dancer, trains and various scenes very like modern England. You name it, it's in this implant we call in its entirely "R6"- if one was a Loyal Officer on Teegeeack, the sequence was (1) capture (2) number 5 above on. If one was a citizen of Teegeeack there was only number 5 on.
The material given at the various "volcanos' was longer or shorter, but dovetailed into the same sequence of pictures. We have the whole text but it is needless.
People who feel dizzy have gotten into the spinning part.
Incident I occurred about 4 quadrillion years ago plus or minus. it is very much earlier than Incident II which occurred only 75 million years ago (a bit less).
Incident II is only peculiar and general on this planet and nearby stars, whereas Incident I is to be found on all thetans.
----------
The Basic on BT's
I've isolated a way a thetan comes to be stuck to another thetan. This gives the basis of clusters and having BT's. A thetan collides with another. That one makes a picture of being collided with. Other BT's get stuck to the picture.
The moment of actual contact of thetans was brief but the picture (containing a stop or withdraw) tends to be permanent.
Thetans then get the idea they can be permanently stuck as they see pictures of it happening.
Thus we get the concept of a "black theta body". This would be actual BT's stuck to a thetan plus pictures of BT's stuck to a thetan.
An answer to all this is to find the first picture a thetan made of contacting another thetan.
If not at once available the earliest instance of a thetan contacting (colliding, running into, attacking) another thetan could be achieved by R3R on being suddenly hit with clusters or strange beings.
The idea is to find and run the "first picture" one made of another thetan.
This opens another way to "blow off" BT'S - run R3R on a BT to the first picture the BT ever made of another thetan.
----------
Instructions
Locate by meter read or an area of pressure, a body thetan or group (cluster). Run Incident II. If the BT does not blow off or 'the group break up and blow, then run Incident I on individual BT's. Each will blow off with an FIN.
When you can find no more on which to run Incident I's, once wore locate a pressure area or by meter read on looking over body run another Incident II. Then Incident 1's on any.
Incident II made clusters of BT's. Severe impacts and experiences ALSO make clusters. (See the data called "Milazzo" in this pack.) Those who do not leave on running the impact or its chain will leave when Incident I Is run on them.
Incident II sometimes forms gigantic clusters. In such there is a leader, an alternate leader and several (eight to eighteen) more. These were all implanted in different volcanic areas with fractions of the nain 36 day implant and then "packaged" in Las Palmas or Hawaii. Thus if you run Incident II as far as "the pilot" it blows up or loosens up and those who don't go away can be run on Incident I's.
Do not speak your commands. Just "intend" them. A BT controls easily. BT's can be ARC broken by rough or careless auditing. You can also run an incident II on a BT and he doesn't blow, but you accidentally run in Incident I on another one and leave the first still there. The remedy is to run Incident I's on anything you find.
A very SP BT can be run on grades and Power and should then respond to Incident II and Incident I.
After a BT leaves, some other BT may copy him or the incident just run.
If you have found a cluster (pressure area) that does not respond or disintegrate to Incident II running, get Dianetic auditing, listing "What impact or incident would cause a cluster?" and R3R on the items found. Then do more Incident I's to clean up the strays with solo. This is a refined "Milazzo".
There are hundreds of BT's you will find.
If you find none, get audited on Dianetics in general and as above (impact list), and if you still find none, get a Review GF40 and handle all items, then go back to solo.
If you find only one or two, get the Dianetic impact list. done. All "none on OT III" cases were later found loaded.
Do Incident II and Incident I's on what you can find to begin with. You will do fine. Good hunting.
Certain "buttons" have to be gotten in where running a thetan through incidents. The EFFORT TO STOP the motion hangs up the action and gives a stuck picture. One gets the EFFORT TO STOP off and the scene races through.
The EFFORT TO WITHDRAW is important also and hangs up the action and creates a vacuum.
RUSH, PROTEST* NOT-IS, SUPPRESS are also present. These were actions - thoughts - the thetan had during the Incident and are picked up only when the incident doesn't run well. Sometimes two "buttons" such as STOP and WITHDRAW are in combination.
Thetans in the body may obsessively copy the pictures of other thetans. Therefore you can find it seems that the thetan who just left is still there because there is a picture left. Spot the fact that someone else copied it and it usually goes.
If you do an S & D on a body thetan be sure you give the right item to the right thetan.
----------
Cross Auditing
When one runs Incident I out of one thetan and then Incident 11 out of another (thinking it was the first one) one can get a partially run body thetan who won't blow, but who may start to go on through the whole of R6 automatically (since the basic-basic Incident I is not run, yet Incident II is). One can get quite ill doing this as the illness in R6 can turn on.
One can also "feel no wish to audit". All "no desire to audit" is some large blunder on a case. The way you can run Incident I out of one thetan and Incident 11 out of another is rather easy. one fails to notice the first one blow on having Incident I run and runs Incident 11 on another.
As a matter of data, the only trouble in a III OT run is running an Incident I on one thetan and an Incident II on another, thinking it was the first one. A pre-OT can freewheel into R6 if you run only an incident II. You can stop a freewheel at once by running Incident I off the same thetan you ran the Incident II on that started a freewheel.
Freewheel means that the PC goes on automatic continuous run. Incident II is R6 75,000,000 years ago. Incident I is about 4 quadrillion years ago. Both, all thetans on this planet and 21 nearby stars have in common. All thetans in the universe have incident I. Only those in this old Confederation have Incident II and R6. All C.C. and OT II materials are in R6 75,000,000 years ago. These are followed by 36 days worth of motion pictures - God, Devil, space opera, trains, cars, helicopters, crashes, stage etc. This R6 is 75,000,000 years ago and this planet and Confederation.
If the volcano bit is run as per III directions but the Incident I Is not run on the same thetan, R6 begins to run off on automatic, the Being can't sleep for days, the body dies. That's the way it was designed.
----------
Overrun on III
The only way you can get a read on "Overrun on III" is to have accidentally run Incident I out, and then later run it out again on the same thetan or make a similar blunder. Example: One flattens Incident I by several passes on a body thetan. This body thetan for some reason (mostly because Incident 11 was then not run) does not fly off. Then, not noticing, one again finds the same thetan and once more seeks to run Incident 1. One then gets, in answer to the question "Overrun on III?" a lot of reads and overrun phenomena. The remedy is to find out WHO was overrun and get the charge off by that action. One then runs Incident 11 on that thetan or in any event, by getting off the charge of "overrun", letting the thetan depart. Just because one's meter reads "Overrun an III" is no reason to attest. Find out who was. lt's almost always a body thetan.
A BT can be overrun past erasure. This fact sometimes causes a solo auditor to believe OT Ill is overrun. If he asks "Is OT III overrun?" he may get a read and blowdown. This is actually usually just one BT or cluster that is overrun. The remedy is discovering and indicating the point of overrun. And carry on with OT III.
----------
Running OT III
When running OT III the solo auditor handles body thetans as he would any other PC, for the general idea is to run them standardly and not ARC Break them. He does not scan through anything in order to find body thetans.
When a solo auditor can find no more body thetans he can attest, or run a pressure area down and handle as per his running Instructions.
The pre-OT could be exterior and the Interiorization processes can be run in Review to help him through.
Here are three reasons why a pre-OT might have trouble whilst running BT's on Incident II -
(1) It is the wrong area;
(2) it is not the volcano of the BT being run;
(3) it is not an Incident II, but another incident of a different date.
Check (1) and (2) If you are having any difficulty in running Incident 11 and handle by locating the correct area or finding the volcano of the BT being run. if it is not a II, simply check for the date and if different run it-.
----------
OT III Errors
Amongst OT III errors are "a BT run on Incident I fails to blow". There are three reasons:
a. Auditor is trying to run a cluster with an Incident I. The right thing to do is date and get the character of the incident that made it a cluster and then run Incident Its on those left when it breaks up. Or get Dianetic auditing.
b. There is an earlier Incident I on the same BT. Find it and run it. The BT has a chain of them all by himself.
c. Another BT is copying the Incident I just run so it looks like it didn't blow. Failure to ever run Incident I can also cause a bog. Routine Dianetic auditing by a Dianetic HDC who is also on or above OT III using triple flows and LDN OT III also handles bogged OT III pre- OT's.
----------
Cluster Formation - Cumulative
In doing a cluster one is likely to find it is made up of other earlier clusters. This looks like this. 1898 impact horse accident. When engram 1898 run on R3R, that part blows. No F/N occurs, TA remains up. Remainder will grind after the blow. Earlier portion dates as 93,000,000 years ago, electric shock. When run on R3R, that part blows, no FIN. TA remains up, will grind if run further. Earliest portion dares as 72 trillion implant. When run on R3R, all blow, FIN.
A cluster or engram which is a cluster can repeatedly FIN as BT's blow. Dates as 778 million explosion. After run once or twice an FIN occurs as one BT blows. Run again to second FIN as two more BT's blow. Remainder blow with a wider FIN. The cluster has gone. This happens (repeating FIN) when picture persists and noter check reveals it is not a copy. It will be more BT's in same cluster. So above repeating FIN occurs when pre-OT is moved through it. Clusters are found by meter dating, listing for type of incident and run as an engram. Clusters can occur at Incident
* * *
I have lately been C/Sing a number of failed OT cases and have found them all running well on solo now. The errors are made as follows:
1. The solo auditor cannot audit, needs more training.
2. Cases are not well prepared with Dianetics.
The remedy for all of these is to:
a. Run the PC for at least a score or two of Dianetic items by R3R, done of course by a good HDC,
b. then do a GF 40.
And then repeat it until necessary auditing is complete. These two actions take care of the majority of difficult cases on OT
The real End Phenomena of OT III and OT IV is exterior with full perception. You can and should accomplish full stable exteriorization on doing the materials of III.
----------
Further III remedies:
3. High TA. This comes from not completing the Incidents I and II on body thetans.
4. The solo auditor puts too wide an intention on the BT and runs two or three when he is intending to run only one.
5. A cluster just won't break up. The remedy is a Dianetic session listing for impacts or incidents that would cause a cluster and doing R3R. The principle of earlier similar holds good. When this is completed, the solo auditor is sent back to solo to clean up the BT's shaken loose and to continue with OT III.
6. Rudiments go out on BT's. The remedy of course is to locate BT's who have out-ruds, put in the ruds and run Incident 1, at which the ST should leave.
7. A theta-bopping meter sometimes puzzles a solo auditor -on OT Ill. This means a BT is trying to exteriorize and can't. The remedy is to complete the partially run Incident 11 or Incident I or in extreme cages put the ruds in on the hung up BT.
8. One-hand electrode giving wrong TA read baffling the solo auditor with floating needles with a high TA. The remedy is to have two-hand electrodes handy and trim the trim knob so the one-hand electrode reads the same as two-hand electrodes.
9. A suppressive body thetan sometimes isn't auditable. The remedy is to run Grades IV or V on him.
10. By far and large the corniest error and which has been very prevalent is not knowing the materials of OT III or the content of Incident II or Incident I.
OT III is a vital grade. One fronts up to it and does it. When he is really done, the rewards of OT III and IV exceed his wildest dreams.
----------
Rudiments Going Out On BT's
When the ruds go out on BT's during the session the solo auditor recognizes the following:
BT critical - withhold from auditor
BT antagonistic - bypassed charge in session
No TA problem
BT sad ARC Break
Soaring TA - Overrun or protest (also more than one BT being run in error or it's a cluster)
Auditor tired - no sleep or incomplete Incident I's
Auditor dope-off - bypassed FIN or not enough sleep
Auditor no-interest - out ruds on BT's
A solo auditor who isn't sure what it is, but runs into trouble with a BT is smart to end off the session quickly, write down the full observation and get it to the C/S. The solo auditor who knows what he is looking at as per the above scale (and the C/S the C/S would give), handles it promptly.
BT critical = w/h = pull the withhold
BT antagonistic = BPC assess proper list (such as LlC) and handle
No TA (or case gain) problem = locate the problem and handle
BT sad = ARC Break - locate and handle itsa E/S itsa
Soaring Ta = C/R or protest (also more than one BT being run in error or it's a cluster) - find which and handle (running more than the one intended comes from too wide an intention)
Auditor tired = no sleep or incomplete Incident I's = check which it is and handle
Auditor dope-off = lack of sleep or bypassed F/N = check On sleep or rehabilitate F/N
Auditor no-interest = out-ruds on BT's = put in ruds.
----------
OT III Auditing
OT III pre-OT's got a reputation of being hard to run on Dianetics early on in Dianetic re-development. Only five reasons exist for this.
1. A person that high on OT grades audits fast and a comm- laggy Dianetic auditor can drive him up the wall.
2. Too quiet or too blurred TR 1.
3. A tendency to evaluate instead of using TR 4.
4. The numerousness of BT chains on the same item (the BT's being separated now) making several chains on the same item, which if not all run separately leave the PC ARC Broken with the bypassed charge of unrun BT's.
5. The OT II who is still on OT III and has been on it a while probably himself has no pictures and all the pictures he has are BT pictures.
The lower grades PC (before Clear) reacts as a composite Being, all on one chain, so to speak. He is separated into himself and the individual BT's and clusters of them when he gets to OT II, and so audits differently. He easily misowns the pictures thinking they are his. The big blowdowns you get on such a PC's item indicates several BT's have it in common. A solo III however will be found to have the same item on more than one BT in many cases.
* * *
The reason for low TA is unflat OT III phenomena. If a person has had a low TA in lower grades the keynote is to take it easy as auditor and COS. This applies also to any auditing given on upper OT levels.
That a PC's TA goes below 2.0 is a certain indicator of unflat OT III. He's still got some. When a person cannot handle OT III he is too much at effect. He cannot project his intention. And so can't run OT III. The new OT I and OT II, particularly OT II, are designed to increase a PC's ability to project his intention to others. If he can't, they overwhelm him and you get low TA or "none on III". Harsh, overbearing auditing or life. incidents have to occur, apparently, to drive the TA down.
Overts, disagreements expressed as obsessive agreement and other lower level matters are at the bottom of this in any Being.
But any case of low TA I have ever found has been:
1. overwhelmed in life;
2. unable to project intention;
3. physically inactive;
4. loaded with BT's;
5. tends to go out of valence easily.
in all this number (4) is the important point.
Endless OT III and low TA are alike - inability to project Intention, PC at effect. Remedy by lightly causing PC to come to cause, to be able to project his intention and thus flatten OT III. That will complete and finish off low TA.
* * *
It does not matter whether or not you ran Incident I and II on self. The End Phenomena of III is getting rid of all body thetans. This does not necessarily include self. If you overrun Ill it will be by trying to get rid of tore body thetans than there were or by then, having gotten rid of the others, starting In on self. So Ill is complete for purposes of overrun as above. If you have not done Incident I and II on self when above is achieved, attest completion and then do I and 11 on self.
EP's No BT's left [End Product: no BodyThetans left] - OT III
L. RON HUBBARD
FOUNDER
Is there some sort of steganography going on in the typos of this interview?
"Consider yourself a member of a virtual corporation with Mr. Torvalds as your Chief Executive Officer." - Linux Advocac
of Internic hacking:
:-)
Try "whois microsoft.com"
And you'll get a good laugh at it
(result is in capital letters so cannot be posted here because of lameness filter)
And btw this news has been rejected by slashdot.
-- "Life is easier since I have excluded JonKatz stories from my homepage"
Howard Schmidt is chief security officer at Microsoft. He recently testified before the House Subcommittee on Commerce Trade and Consumer Protection about the state of Internet and computer security. We tracked him down later to ask him about, among other things, cyberterrorism and the Microsoft's level of responsibility for the success of large virus attacks.
... the way we ship products. They will be shipped secure out of the box now. It may be a little more difficult to get some of the features turned on, but it's going to be more secure, because that's what the new picture warrants for us.
Schmidt served in the US. Air Force, the F.B.I, and local law enforcement. After Sept. 11, he was called back to active duty with the Joint Task Force for Computer Network Operations, the Department of Justice and the FBI's National Infrastructure Protection Center.
Q: In your testimony the other day, you listed a series of industries at risk for cyberterrorism or electronic intrusion. One of those you listed was telecom. What weaknesses are there in the telecom industry that haven't been addressed.
A: I think it all revolves around the people and the process. I don't know that there's a specific weakness. I think, generally, that the concern we have as the industry partnerships, are, are we all prepared, as the owners and operators of the critical infrastructure, to be able to respond to three major areas of concern for the value of the country. There's the national-security piece, which we saw, responded in 9/11. There's the law enforcement/public-safety piece, which has some relation to 9/11, but also we've seen in other venues, even simple things like when an ice storm knocks down the ability to communicate. The third thing is the economic viability of the nation. And that's our ability, because so much has been built, from an economic standpoint, around the technology piece.
I'll cite a telecom component during 9/11. I was in D.C. You're based in D.C., aren't you?
Q: Yes, I am, right off K Street, three blocks from the White House.
A: So you know what it was like. I don't know if you tried to use a mobile phone, or you saw people lining up at the payphones, only to be able to get no signal. Those are the sort of things that we probably need to have more redundancy issues and have some resiliency on...
Q: Capacity issues...
A: Right.
Q: Oddly enough, I worked the whole afternoon. I think I was the only person in downtown Washington, and I had no problem getting people on the phone. I was just blessed, I think.
A: I was up at the Capitol, and I tried my darndest to get my cell phone working, and had no success. Interestingly enough, when I got down to Northern Virginia, outside some of the towers, I was able to call around the company with little or no problems.
Q: How big a cyberterrorism threat is there? Let me define that a little better, because it's a meaningless question in some ways. How severe a threat is there of an Internet-based attack that does widespread economic or functional damage by a state-sponsored group or an independent group of terrorists, as opposed to the normal intrusion, denial-of-service attacks and virus problems we usually see?
A: That's a tough question to answer, because I don't know if that question's been asked in all the appropriate circles. If you look at everything from Sen. Nunn's hearing, back in 1997, to the report of the President's Commission on Critical Infrastructure Protection, one of the things that they look at is the availability of being able to do harm relative to the cost. So when you talk about the actual threat piece of it, the cost is relatively insignificant. It's a piece of code that you write to go do something bad, and now the availability of those sort of things is very widespread. People have computers in their homes, connected to DSL and cable modems, so the cost of the ability to do damage is down. The availability, by having a lot of systems out there to attack, is up, so that puts a threat picture out there that's more viable than it was a few years ago.
Q: Like leveraging box cutters to take out buildings.
A: That's correct. That was a relatively inexpensive way to create havoc. And if you do that on the electronic piece of it, some of the threats that out there, we really don't have a handle on how viable they are, but we can do some modeling, and building of threat scenarios, to see, given what tools we know are available to be applied with malicious intent, how much damage can be done.
Q: But do we know of any states or groups that have cyberterrorism efforts underway?
A: I think, publicly, what we know is that there have been a number of nations that have created information-warfare groups, and they've been fairly public about it. But as far as anything beyond the cyberhacktivism we've seen, I don't know if there's been anything publicly discussed about state-sponsored cyberterrorism cells out there, if you would.
Q: Give us the Reader's Digest one-paragraph description of IT-ASAC.
A: The IT-ASAC is a group of some of the key owners and operators of the infrastructure that belong to the IT community. It's a group of us that put aside any competitive differences to share information on best practices and vulnerabilities anonymously among each other to maintain the viability of the critical infrastructure. We also develop mechanisms to share that with the government as a sort of early-warning system, using our collective 24-by-7 information centers and the collective knowledge and expertise of our companies.
Q: You're the chief security officer of Microsoft. Explain for us a little bit how security fits into the Microsoft corporate structure.
A: I think security is recognized as the number-one priority across the company. That goes not only to operational security and securing our assets, but also to product development. In my role, I report to the CTO, and I have Advanced Security Strategy Group, which works on security architecture, security auditing, incubation of security-related tools and security policy across the company that transcends the operational groups as well as the development groups.
Q: One of the things that you took a position on in your testimony was on openness and security, in terms of being against people publishing exploit codes to point out weaknesses -- which in some sectors of the software-development community is considered a good thing.
A: What we're relating to is responsible reporting, and there's a difference. In some cases, it's tantamount to screaming "fire!" in a crowded movie theater. Responsible reporting means if you find a vulnerability, you contact the person in the best position to fix it, normally the vendor of whatever the product is, give them all the information possible so that they can create a fix, and then go out and get the fix installed -- as opposed to going out and telling everyone that everybody in this one apartment complex doesn't lock their doors or leaves their keys in their cars, which then opens them up to malicious attacks.
Q: I was at a cybersecurity event last night. I don't know if you know Richard Forno, CTO of Shadowlogic?
A: Yes, I do know Richard.
Q: He said his theory was "D3" -- "declassify, demystify and diversify (software)." All three of those things are not things associated with Microsoft. Is that a policy you'd take issue with?
A: I think any time we find any security vulnerability, we're one of the best in the industry to notify people of the details of them and give them the details to get it fixed.
Q: Microsoft, traditionally, though, although less so of late, has been known for having a relatively closed security-reporting and bug-reporting system compared to the *NIX and open-source communities. Has that changed, and how much?
A: Well, for one I think it's a misperception or an undeserved reputation. One of the things I hear most often is that people responsible for these things at their companies say they're seeing too many of these things. I don't think it's an issue about open-source, I think it's an issue about responsibly, once somebody reports something, we have to replicate what they've reported to make sure it's a product-security issue and not some hardware problem they've got, or some incompatibility with some other application they've got, to replicate that, analyze that, and put the patch out. I don't know of any time in the four years I've been here that that hasn't been a priority. It's probably a misperception and mischaracterization of our reputation.
Q: Today, some of the states came back with a proposal for opening up Microsoft code. What effect would that have about security.
A: [Explains that he is not involved in antitrust issues] I think the position has always been that you check the final product for vulnerabilities. Because there's a whole lot of open source out there that, day after day after day, there's more reports of vulnerabilities. I think it doesn't make any difference whether it is open source or closed source, it's a matter of identifying them once the product is released.
Q: How much of computer and network security should be handled by technology and how much by law enforcement?
A: Law enforcement's role is very much a reactive role. After something bad happens, then they come in, and I think they have an extremely vital part to help investigating these things to deter people from attacking these systems. But the idea on the front end is to use the people, the processes and the technologies to prevent these things from happening as much as we can, and if there's something we can't handle, law enforcement comes in and identifies those that have.
Q: I assume from your testimony that you guys supported the language in the USA PATRIOT Act on cyberterrorism and intrusion. Are we in danger of over-broadening the standard for calling something cyberterrorism to include routine exploratory intrusions and port scans and other minor events, in the heat of the moment after Sept. 11?
A: I have met with a number of attorneys both in the corporate world as well as the justice world, and I don't see that's the case. I think all the changes that were made in the USA-PATRIOT Act relative to online surveillance, relative to any cyber-related investigative capability, have revolved around not changing the thresholds of what it takes to get a search warrant, not changing the threshold of what it takes to get a wiretap, but streamlining the process; you have to prove with probable cause that something has occurred to get most of the court orders .
If I'm tracking somebody that's, say, involved in terrorist activity, and they're using a cell phone, and they can put the cell phone down from having a voice call to use the same cell phone to do an Internet message because they've got a Web-enabled phone, and then they go home and they use an online account to communicate further, rather than go get five warrants for the same thing, they don't have to chase the technology, they chase the criminal activity.
Q: One of the things you opposed in your testimony was federal security mandates for the industry. But there's a strong push for strong industry best-practices policies or government mandates. Christopher Painter (Department of Justice, Deputy Chief of the Computer Crime and Intellectual Property Section] says the industries needs bet practices; he says, too often the industry has no plan for dealing with intrusions at all. Is there going to be pressure for government standards?
A: I hope not. What we've seen from time immemorial, market forces drive a lot of what happens in the development efforts. Standards don't drive it, because what happens, you wind in a situation where standards may turn around and inhibit the ability to innovate and the ability to build more secure products.
Q: In your testimony, you listed several attacks, virus attacks and others, some of them against Microsoft weaknesses, and some of them against Linux and other operating systems. But how much responsibility does Microsoft have because of its market share for security.
A: I think Microsoft has recognized that, because we are the market leader, we have a special obligation to improve security. This is an industry issue we're all working on, but because of that special role out obligation is increased. Which is why we created programs like the strategic technology protection program -- helping people get secure with a number of free tools, then getting them to stay secure by changing, fundamentally, some of our internal processes, to further strengthen the security that we've been working on internally.
Q: Some of the security problems with Microsoft products are things like buffer overflows. That happens in programming, and you fix it. But others seem like boneheaded decisions based on marketing. Things like enabling Windows Scripting Host by default on millions of consumer machines and making e-mail attachments executable. In these big virus attacks, doesn't Microsoft bear some responsibility for those choices?
A: I think that picture has changed. Once again, we've been developing stuff based on ease-of-use for the customer and what the customer requirements are. I think what happens now is that we've seen the threat picture change. I think it goes back to a physical analogy. If I leave my keys in my car because it's convenient for me, and somebody steals my car, is that my fault? Ten or 15 years ago, the likelihood of that happening was very, very low. But the threat picture has changed dramatically in most places.
That's the same thing that's happened with software. Those things were designed to make it easy for people to do the stuff that they were doing. It turns out that criminals and others with malicious intents have turned those good things into bad things. Which is why we've had to fundamentally
Q: But that kind of begs the question, because it wasn't completely unthinkable, like someone flying a plane into a building. At the time when all these features were being rolled out, programmers online were screaming left and right that this was inevitably going to result in these massive incidents, and, sure enough, they did.
A: If you look at the development process, and how long it takes to develop these things and get them out the door, this is not something that people started working on six months ago, and the developer community is saying this is a bad thing. This is stuff that has been in progress for years, which is why we've had to effectively retool the way we do things internally, to meet that new threat environment.
Q: I'll give you a cheerful quote from Rick Forno. He said one of our major security problems is "our continuing blind dependence on Microsoft operating systems."
A: Richard's entitled to his opinion, but I ask Richard or anyone else to look at the security vulnerabilities that have been identified in anything else that's out there, and the response mechanism. Until some time as we develop a society that's perfect in writing code, as you actually pointed out; until some time as we have perfect processes, then we have to do some level of maintenance, some level of fixing things. I agree that we all continue to do more work on it.
Now, that's how to karma whore!
"If I leave my keys in my car because it's convenient for me, and somebody steals my car, is that my fault?"
Just try convincing your insurance company otherwise. I'm just glad Micro$oft don't build houses...based on this quote they'd have plenty of windows (all different of course), and no doors.
Q: But that kind of begs the question, because it wasn't completely unthinkable, like someone flying a plane into a building. At the time when all these features were being rolled out, programmers online were screaming left and right that this was inevitably going to result in these massive incidents, and, sure enough, they did.
A: Well, yes. You're right about that. We were given the signal loud and clear, and completely ignored it. We here at Microsoft are terrible at making software. In fact, please don't ever again buy any of our products. We are very, very bad.
I mean, this guy is speaking on behalf of a multi-billion dollar software giant. He is not going to risk his job by embarrassing his whole company. That's why companies like MS (GM, American Airlines, Exxon) hire guys like this. For reference, consult any presidential press conference.
If you fall off a building, go real limp, because maybe you'll look like a dummy and people will be like hey, free dummy
I think that picture has changed. Once again, we've been developing stuff based on ease-of-use for the customer and what the customer requirements are. I think what happens now is that we've seen the threat picture change. I think it goes back to a physical analogy. If I leave my keys in my car because it's convenient for me, and somebody steals my car, is that my fault? Ten or 15 years ago, the likelihood of that happening was very, very low. But the threat picture has changed dramatically in most places.
Ten or 15 years ago, I still would have stolen his car if he was stupid enough to leave his keys in the ignition.
(When asked about full disclosure, and publishing of exploits)
In some cases, it's tantamount to screaming "fire!" in a crowded movie theater.
Yeah, except there really IS a fire.
So when there is a fire in a movie theatre, he's suggesting the person who notice it just quietly go and tell the management (who will wait to see if it's really a big fire, and then assign some staff to attempt to put it out), instead of telling the people whose lives are in danger?
Yeah, GREAT analogy.
Howard Schmidt: I think the position has always been that you check the final product for vulnerabilities. Because there's a whole lot of open source out there that, day after day after day, there's more reports of vulnerabilities. I think it doesn't make any difference whether it is open source or closed source, it's a matter of identifying them once the product is released.
(bold added by me)
Shouldn't a company with Microsoft's resources be able to identify security holes before the product is released?
Maybe this "release-and-then-check-for-bugs" strategy explains why there are so many MS explots?
___
The way to see by faith is to shut the eye of reason. --Ben Franklin
I've tried it on several 'nix compilers. What does it do, anyway?
In response to the question about MS making Good Times into reality (having scripting in email on by default), he said:
If I leave my keys in my car because it's convenient for me, and somebody steals my car, is that my fault? Ten or 15 years ago, the likelihood of that happening was very, very low. But the threat picture has changed dramatically in most places.
I don't know where he was living 15 years ago, but where I grew up (granted I didn't have a car then), there's no way you'd leave your keys in your car and act surprised when it was gone in the morning.
If your car gets stolen because you left the keys in it, its not entirely your fault because it's illegal to steal the car regardless. But it was still bloody stupid.
If it was my friend who left my keys in the car, I'd be pissed as hell. And if the manufacturer put a spare key on every car in the exact same place so it was easy to find and my car got stolen, I'd join the class-action lawsuit that would surely result.
It's one thing to say that MS has good security, and non-disclosure is the right way to go, etc etc. He has to. But to dismiss this question as though it wasn't their fault, without even a "Yeah, we shouldn't have done that", I think is demonstrative of the thinking that led to the problem in the first place.
The enemies of Democracy are
You're going to hit the 50 point karma cap with three off-topic posts in a row.
Splendid, man, splendid.
How did he get a job in security even the basics of security in microsoft products are lacking......
so many users are creating accounts like administrator with out even a password and being allowed to leave it blank....Why not force a password?....this would also work better for microsoft, if the user forgets their password i am sure they wont mind charging for support.
"I disapprove of what you say, but I will defend to the death your right to say it." - Voltaire
regarding mr. schmidt... > i sure am glad the military/industrial complex is a fiction. otherwise i might think it suspicious that the man responsible for security on most of the world's computers works for the government. love your country. fear your government.
Endless arguments over trivial contradictions in books written by ignorant savages to explain thunder in the dark.
Did someone interview the Security Chief at Microsloft and seriously expect to get somthing besides a politician? The guy even works three blocks from the WhiteHouse.
"God fights on the side with the best artillery." - Napoleon, Marshal of France - speaking truth to power
1. The sport of choice for the urban poor is BASKETBALL
2. The sport of choice for maintenance level employees is BOWLING.
3. The sport of choice for front-line workers is FOOTBALL.
4. The sport of choice for supervisors is BASEBALL.
5. The sport of choice for middle management is TENNIS.
6. The sport of choice for corporate officers is GOLF.
AMAZING CONCLUSION:
The higher you are in the corporate structure, the smaller your balls become.
What does random microsoft subdomains have to do with hacking microsoft? You can call your subdomain anything you want.
It's already been on slashdot. Old news, was in one of the quickies.
"Standards inhibit the ability to innovate"? Do I even need to point out the bashing potential?
The Internet is full. Go away.
But there is a fire. Its only irresponsible to shout "fire!" in a crowded movie theater if there isn't on, just like it would be irresponsible to post non-existent exploits to bugtraq.
Mr. Schmidt is suggesting:
Geez... They must have cut their spin budget recently.
Q: . . . things like . . . making e-mail attachments executable.
A: I think that picture has changed. Once again, we've been developing stuff based on ease-of-use for the customer . . . it goes back to a physical analogy. If I leave my keys in my car because it's convenient for me, and somebody steals my car, is that my fault?
No, it's not. But if the Foo Car Company set all their remote locks to open when you clap your hands thrice, for "when your hands are filled with grocery bags, to save you from searching your pockets for the key", and only allowed this to be disabled by opening the hood and clipping the red wire with the blue tracer, I'd say they would be responsible for my aunt's CDs disappearing.
Opening the hood and clipping a wire is farther than most people want to go when it comes to modifications. I'd even wager that it is more than many drivers are capable of. Searching around in the "control panel" is further than your average MS-Outlook user is likey to feel comfortable with. They are afraid of "breaking" things.
The car keys are in the user interface portion of the car, I guess my point is. It's "easy" to remove them, put them in your pocket, to provent unauthorized use. How "easy" is it to disable the trojan propigation in Outlook?
The previous has been a secret message to my comrades.
Classic Microsoft... standards bad, embrace and extend good... we do it for security reasons, not because we're trying to leverage our monopoly power into yet-another market. I can almost understand the "don't tell anyone about the exploit until we have a chance to fix it" stance, but this makes me sick to my stomache.
I would be in favor of government standards of security. And not just because it would force more open standards, but because it's a good idea. Yes, it will probably not be easy to implement, and it might force MS to ship a product or two late, but at least it will enforce some needed checks from a company who's concept of security is identifying problems after product release.
Those who fail to understand communication protocols, are doomed to repeat them over port 80.
"My server got rooted, and all I got was assurance from Howard Schmidt that we have a special obligation to improve security"
"What is the sound of one belly slapping?"
And while you try, secure this!
I'm sure the position is. We just write software. We're not responsible for anything bad that happens to you if you actually USE it in production.
If we have vulnerable systems, it is likely that terrorists will use our own weaknesses against us. As is mentioned in the interview, the cost of bringing down our communication systems is fairly small.
Remember the Morris Worm? It brought the entire internet to its knees, and Robert Morris didn't mean to release it. What if a "virus" (more correctly, a worm or trojan) is created that destroys every MS-Windows installation? This means more than just Grandma Jane's computer-- I mean military, telecom, and hospital-controlling computer in the world.
The threat isn't that great. Although it wouldn't be expensive in the monetary sense, it would be hard to engineer. But as long as the threat *exists,* it must be considered a potential.
- Tony
Microsoft is to software what Budweiser is to beer.
I think it doesn't make any difference whether it is open source or closed source, it's a matter of identifying them once the product is released.
So...who cares if there are problems. We'll find them eventually - as soon as someone exploits them and we hear about it.
Precicely.
If you want bug-free code you need to start at the architecture/design process (avoiding bug-prone choices), then debug as you go. It's like growing a perfect crystal - you push the impurities out as it solidifies, so only the boundary needs attention. The longer you wait, the larger your search space for each bug, and the bigger the hive of ofspring each bug has produced as new code was added to buggy code.
Security issues are a special case of "bugs", with more than the typical amount of effort needed at precoding stages to avoid building unfixable problems into the basic architecture.
I wonder if they release their code like that for QA as well. It's a matter of identifying bugs once the product is released.
My impression is that Schmidt is completely unaware that software QA, or any other pre-release potential for (securyty) bug suppression, exists. At a minimum his statement implies that Security as a department doesn't participate in architecture, design, code reviews, or QA, and that its leader either feels no need to do so, or is deliberately directing attention away from an inability to affect those stages.
That the head of security for Microsoft could emit such an answer is appalling. But it also goes a long way toward explaining the security problems in Microsoft products.
Bantam Dominique roosters crow a four-note song. Once you've heard it as "Happy BIRTHday" you can't NOT hear it that way
I think security is recognized as the number-one priority across the company.
After the interview, Mr. Schmidt realized that the question was actually about Microsoft's software products, and not about locking the doors each night at MS HQ.
THE lawyers won't just sue Microsoft, they will also be suing the maker of the "killing object" that M$ software was put in, for being so insane as to not to make a more custom bulletproof application.
translated into html escape codes, for those who prefer them to ascii:
9 %6 e%20%74%68%65%20%55%53%2e%20%41%69%72%20%46%6f%72% 63%65%2c%20%74%68%65%20%46%2e%42%2e%49%2c%20%61%6e %64%20%6c%6f%63%61%6c%20%6c%61%77%20%65%6e%66%6f%7 2%63%65%6d%65%6e%74%2e%20%41%66%74%65%72%20%53%65% 70%74%2e%20%31%31%2c%20%68%65%20%77%61%73%20%63%61 %6c%6c%65%64%20%62%61%63%6b%20%74%6f%20%61%63%74%6 9%76%65%20%64%75%74%79%20%77%69%74%68%20%74%68%65% 20%4a%6f%69%6e%74%20%54%61%73%6b%20%46%6f%72%63%65 %20%66%6f%72%20%43%6f%6d%70%75%74%65%72%20%4e%65%7 4%77%6f%72%6b%20%4f%70%65%72%61%74%69%6f%6e%73%2c% 20%74%68%65%20%44%65%70%61%72%74%6d%65%6e%74%20%6f %66%20%4a%75%73%74%69%63%65%20%61%6e%64%20%74%68%6 5%20%46%42%49%27%73%20%4e%61%74%69%6f%6e%61%6c%20% 49%6e%66%72%61%73%74%72%75%63%74%75%72%65%20%50%72 %6f%74%65%63%74%69%6f%6e%20%43%65%6e%74%65%72%2e% d% a%41%3a%20%49%20%74%68%69%6e%6b%20%69%74%20%61%6c% 6c%20%72%65%76%6f%6c%76%65%73%20%61%72%6f%75%6e%64 %20%74%68%65%20%70%65%6f%70%6c%65%20%61%6e%64%20%7 4%68%65%20%70%72%6f%63%65%73%73%2e%20%49%20%64%6f% 6e%27%74%20%6b%6e%6f%77%20%74%68%61%74%20%74%68%65 %72%65%27%73%20%61%20%73%70%65%63%69%66%69%63%20%7 7%65%61%6b%6e%65%73%73%2e%20%49%20%74%68%69%6e%6b% 2c%20%67%65%6e%65%72%61%6c%6c%79%2c%20%74%68%61%74 %20%74%68%65%20%63%6f%6e%63%65%72%6e%20%77%65%20%6 8%61%76%65%20%61%73%20%74%68%65%20%69%6e%64%75%73% 74%72%79%20%70%61%72%74%6e%65%72%73%68%69%70%73%2c %20%61%72%65%2c%20%61%72%65%20%77%65%20%61%6c%6c%2 0%70%72%65%70%61%72%65%64%2c%20%61%73%20%74%68%65% 20%6f%77%6e%65%72%73%20%61%6e%64%20%6f%70%65%72%61 %74%6f%72%73%20%6f%66%20%74%68%65%20%63%72%69%74%6 9%63%61%6c%20%69%6e%66%72%61%73%74%72%75%63%74%75% 72%65%2c%20%74%6f%20%62%65%20%61%62%6c%65%20%74%6f %20%72%65%73%70%6f%6e%64%20%74%6f%20%74%68%72%65%6 5%20%6d%61%6a%6f%72%20%61%72%65%61%73%20%6f%66%20% 63%6f%6e%63%65%72%6e%20%66%6f%72%20%74%68%65%20%76 %61%6c%75%65%20%6f%66%20%74%68%65%20%63%6f%75%6e%7 4%72%79%2e%20%54%68%65%72%65%27%73%20%74%68%65%20% 6e%61%74%69%6f%6e%61%6c%2d%73%65%63%75%72%69%74%79 %20%70%69%65%63%65%2c%20%77%68%69%63%68%20%77%65%2 0%73%61%77%2c%20%72%65%73%70%6f%6e%64%65%64%20%69% 6e%20%39%2f%31%31%2e%20%54%68%65%72%65%27%73%20%74 %68%65%20%6c%61%77%20%65%6e%66%6f%72%63%65%6d%65%6 e%74%2f%70%75%62%6c%69%63%2d%73%61%66%65%74%79%20% 70%69%65%63%65%2c%20%77%68%69%63%68%20%68%61%73%20 %73%6f%6d%65%20%72%65%6c%61%74%69%6f%6e%20%74%6f%2 0%39%2f%31%31%2c%20%62%75%74%20%61%6c%73%6f%20%77% 65%27%76%65%20%73%65%65%6e%20%69%6e%20%6f%74%68%65 %72%20%76%65%6e%75%65%73%2c%20%65%76%65%6e%20%73%6 9%6d%70%6c%65%20%74%68%69%6e%67%73%20%6c%69%6b%65% 20%77%68%65%6e%20%61%6e%20%69%63%65%20%73%74%6f%72 %6d%20%6b%6e%6f%63%6b%73%20%64%6f%77%6e%20%74%68%6 5%20%61%62%69%6c%69%74%79%20%74%6f%20%63%6f%6d%6d% 75%6e%69%63%61%74%65%2e%20%54%68%65%20%74%68%69%72 %64%20%74%68%69%6e%67%20%69%73%20%74%68%65%20%65%6 3%6f%6e%6f%6d%69%63%20%76%69%61%62%69%6c%69%74%79% 20%6f%66%20%74%68%65%20%6e%61%74%69%6f%6e%2e%20%41 %6e%64%20%74%68%61%74%27%73%20%6f%75%72%20%61%62%6 9%6c%69%74%79%2c%20%62%65%63%61%75%73%65%20%73%6f% 20%6d%75%63%68%20%68%61%73%20%62%65%65%6e%20%62%75 %69%6c%74%2c%20%66%72%6f%6d%20%61%6e%20%65%63%6f%6 e%6f%6d%69%63%20%73%74%61%6e%64%70%6f%69%6e%74%2c% 20%61%72%6f%75%6e%64%20%74%68%65%20%74%65%63%68%6e %6f%6c%6f%67%79%20%70%69%65%63%65%2e% d% a%51%3a%20%59%65%73%2c%20%49%20%61%6d%2c%20%72%69% 67%68%74%20%6f%66%66%20%4b%20%53%74%72%65%65%74%2c %20%74%68%72%65%65%20%62%6c%6f%63%6b%73%20%66%72%6 f%6d%20%74%68%65%20%57%68%69%74%65%20%48%6f%75%73% 65%2e% d% a%51%3a%20%43%61%70%61%63%69%74%79%20%69%73%73%75% 65%73%2e%2e%2e% d% a%51%3a%20%4f%64%64%6c%79%20%65%6e%6f%75%67%68%2c% 20%49%20%77%6f%72%6b%65%64%20%74%68%65%20%77%68%6f %6c%65%20%61%66%74%65%72%6e%6f%6f%6e%2e%20%49%20%7 4%68%69%6e%6b%20%49%20%77%61%73%20%74%68%65%20%6f% 6e%6c%79%20%70%65%72%73%6f%6e%20%69%6e%20%64%6f%77 %6e%74%6f%77%6e%20%57%61%73%68%69%6e%67%74%6f%6e%2 c%20%61%6e%64%20%49%20%68%61%64%20%6e%6f%20%70%72% 6f%62%6c%65%6d%20%67%65%74%74%69%6e%67%20%70%65%6f %70%6c%65%20%6f%6e%20%74%68%65%20%70%68%6f%6e%65%2 e%20%49%20%77%61%73%20%6a%75%73%74%20%62%6c%65%73% 73%65%64%2c%20%49%20%74%68%69%6e%6b%2e% d% a%51%3a%20%48%6f%77%20%62%69%67%20%61%20%63%79%62% 65%72%74%65%72%72%6f%72%69%73%6d%20%74%68%72%65%61 %74%20%69%73%20%74%68%65%72%65%3f%20%4c%65%74%20%6 d%65%20%64%65%66%69%6e%65%20%74%68%61%74%20%61%20% 6c%69%74%74%6c%65%20%62%65%74%74%65%72%2c%20%62%65 %63%61%75%73%65%20%69%74%27%73%20%61%20%6d%65%61%6 e%69%6e%67%6c%65%73%73%20%71%75%65%73%74%69%6f%6e% 20%69%6e%20%73%6f%6d%65%20%77%61%79%73%2e%20%48%6f %77%20%73%65%76%65%72%65%20%61%20%74%68%72%65%61%7 4%20%69%73%20%74%68%65%72%65%20%6f%66%20%61%6e%20% 49%6e%74%65%72%6e%65%74%2d%62%61%73%65%64%20%61%74 %74%61%63%6b%20%74%68%61%74%20%64%6f%65%73%20%77%6 9%64%65%73%70%72%65%61%64%20%65%63%6f%6e%6f%6d%69% 63%20%6f%72%20%66%75%6e%63%74%69%6f%6e%61%6c%20%64 %61%6d%61%67%65%20%62%79%20%61%20%73%74%61%74%65%2 d%73%70%6f%6e%73%6f%72%65%64%20%67%72%6f%75%70%20% 6f%72%20%61%6e%20%69%6e%64%65%70%65%6e%64%65%6e%74 %20%67%72%6f%75%70%20%6f%66%20%74%65%72%72%6f%72%6 9%73%74%73%2c%20%61%73%20%6f%70%70%6f%73%65%64%20% 74%6f%20%74%68%65%20%6e%6f%72%6d%61%6c%20%69%6e%74 %72%75%73%69%6f%6e%2c%20%64%65%6e%69%61%6c%2d%6f%6 6%2d%73%65%72%76%69%63%65%20%61%74%74%61%63%6b%73% 20%61%6e%64%20%76%69%72%75%73%20%70%72%6f%62%6c%65 %6d%73%20%77%65%20%75%73%75%61%6c%6c%79%20%73%65%6 5%3f% d% a%51%3a%20%4c%69%6b%65%20%6c%65%76%65%72%61%67%69% 6e%67%20%62%6f%78%20%63%75%74%74%65%72%73%20%74%6f %20%74%61%6b%65%20%6f%75%74%20%62%75%69%6c%64%69%6 e%67%73%2e% d% a%51%3a%20%42%75%74%20%64%6f%20%77%65%20%6b%6e%6f% 77%20%6f%66%20%61%6e%79%20%73%74%61%74%65%73%20%6f %72%20%67%72%6f%75%70%73%20%74%68%61%74%20%68%61%7 6%65%20%63%79%62%65%72%74%65%72%72%6f%72%69%73%6d% 20%65%66%66%6f%72%74%73%20%75%6e%64%65%72%77%61%79 %3f% d% a%51%3a%20%47%69%76%65%20%75%73%20%74%68%65%20%52% 65%61%64%65%72%27%73%20%44%69%67%65%73%74%20%6f%6e %65%2d%70%61%72%61%67%72%61%70%68%20%64%65%73%63%7 2%69%70%74%69%6f%6e%20%6f%66%20%49%54%2d%41%53%41% 43%2e% d% a%51%3a%20%59%6f%75%27%72%65%20%74%68%65%20%63%68% 69%65%66%20%73%65%63%75%72%69%74%79%20%6f%66%66%69 %63%65%72%20%6f%66%20%4d%69%63%72%6f%73%6f%66%74%2 e%20%45%78%70%6c%61%69%6e%20%66%6f%72%20%75%73%20% 61%20%6c%69%74%74%6c%65%20%62%69%74%20%68%6f%77%20 %73%65%63%75%72%69%74%79%20%66%69%74%73%20%69%6e%7 4%6f%20%74%68%65%20%4d%69%63%72%6f%73%6f%66%74%20% 63%6f%72%70%6f%72%61%74%65%20%73%74%72%75%63%74%75 %72%65%2e% d% a%51%3a%20%4f%6e%65%20%6f%66%20%74%68%65%20%74%68% 69%6e%67%73%20%74%68%61%74%20%79%6f%75%20%74%6f%6f %6b%20%61%20%70%6f%73%69%74%69%6f%6e%20%6f%6e%20%6 9%6e%20%79%6f%75%72%20%74%65%73%74%69%6d%6f%6e%79% 20%77%61%73%20%6f%6e%20%6f%70%65%6e%6e%65%73%73%20 %61%6e%64%20%73%65%63%75%72%69%74%79%2c%20%69%6e%2 0%74%65%72%6d%73%20%6f%66%20%62%65%69%6e%67%20%61% 67%61%69%6e%73%74%20%70%65%6f%70%6c%65%20%70%75%62 %6c%69%73%68%69%6e%67%20%65%78%70%6c%6f%69%74%20%6 3%6f%64%65%73%20%74%6f%20%70%6f%69%6e%74%20%6f%75% 74%20%77%65%61%6b%6e%65%73%73%65%73%20%97%20%77%68 %69%63%68%20%69%6e%20%73%6f%6d%65%20%73%65%63%74%6 f%72%73%20%6f%66%20%74%68%65%20%73%6f%66%74%77%61% 72%65%2d%64%65%76%65%6c%6f%70%6d%65%6e%74%20%63%6f %6d%6d%75%6e%69%74%79%20%69%73%20%63%6f%6e%73%69%6 4%65%72%65%64%20%61%20%67%6f%6f%64%20%74%68%69%6e% 67%2e% d% a%51%3a%20%49%20%77%61%73%20%61%74%20%61%20%63%79% 62%65%72%73%65%63%75%72%69%74%79%20%65%76%65%6e%74 %20%6c%61%73%74%20%6e%69%67%68%74%2e%20%49%20%64%6 f%6e%27%74%20%6b%6e%6f%77%20%69%66%20%79%6f%75%20% 6b%6e%6f%77%20%52%69%63%68%61%72%64%20%46%6f%72%6e %6f%2c%20%43%54%4f%20%6f%66%20%53%68%61%64%6f%77%6 c%6f%67%69%63%3f% d% a%51%3a%20%48%65%20%73%61%69%64%20%68%69%73%20%74% 68%65%6f%72%79%20%77%61%73%20%22%44%33%22%20%97%20 %22%64%65%63%6c%61%73%73%69%66%79%2c%20%64%65%6d%7 9%73%74%69%66%79%20%61%6e%64%20%64%69%76%65%72%73% 69%66%79%20%28%73%6f%66%74%77%61%72%65%29%2e%22%20 %41%6c%6c%20%74%68%72%65%65%20%6f%66%20%74%68%6f%7 3%65%20%74%68%69%6e%67%73%20%61%72%65%20%6e%6f%74% 20%74%68%69%6e%67%73%20%61%73%73%6f%63%69%61%74%65 %64%20%77%69%74%68%20%4d%69%63%72%6f%73%6f%66%74%2 e%20%49%73%20%74%68%61%74%20%61%20%70%6f%6c%69%63% 79%20%79%6f%75%27%64%20%74%61%6b%65%20%69%73%73%75 %65%20%77%69%74%68%3f% d% a%51%3a%20%4d%69%63%72%6f%73%6f%66%74%2c%20%74%72% 61%64%69%74%69%6f%6e%61%6c%6c%79%2c%20%74%68%6f%75 %67%68%2c%20%61%6c%74%68%6f%75%67%68%20%6c%65%73%7 3%20%73%6f%20%6f%66%20%6c%61%74%65%2c%20%68%61%73% 20%62%65%65%6e%20%6b%6e%6f%77%6e%20%66%6f%72%20%68 %61%76%69%6e%67%20%61%20%72%65%6c%61%74%69%76%65%6 c%79%20%63%6c%6f%73%65%64%20%73%65%63%75%72%69%74% 79%2d%72%65%70%6f%72%74%69%6e%67%20%61%6e%64%20%62 %75%67%2d%72%65%70%6f%72%74%69%6e%67%20%73%79%73%7 4%65%6d%20%63%6f%6d%70%61%72%65%64%20%74%6f%20%74% 68%65%20%2a%4e%49%58%20%61%6e%64%20%6f%70%65%6e%2d %73%6f%75%72%63%65%20%63%6f%6d%6d%75%6e%69%74%69%6 5%73%2e%20%48%61%73%20%74%68%61%74%20%63%68%61%6e% 67%65%64%2c%20%61%6e%64%20%68%6f%77%20%6d%75%63%68 %3f% d% a%51%3a%20%54%6f%64%61%79%2c%20%73%6f%6d%65%20%6f% 66%20%74%68%65%20%73%74%61%74%65%73%20%63%61%6d%65 %20%62%61%63%6b%20%77%69%74%68%20%61%20%70%72%6f%7 0%6f%73%61%6c%20%66%6f%72%20%6f%70%65%6e%69%6e%67% 20%75%70%20%4d%69%63%72%6f%73%6f%66%74%20%63%6f%64 %65%2e%20%57%68%61%74%20%65%66%66%65%63%74%20%77%6 f%75%6c%64%20%74%68%61%74%20%68%61%76%65%20%61%62% 6f%75%74%20%73%65%63%75%72%69%74%79%2e% d% a%51%3a%20%48%6f%77%20%6d%75%63%68%20%6f%66%20%63% 6f%6d%70%75%74%65%72%20%61%6e%64%20%6e%65%74%77%6f %72%6b%20%73%65%63%75%72%69%74%79%20%73%68%6f%75%6 c%64%20%62%65%20%68%61%6e%64%6c%65%64%20%62%79%20% 74%65%63%68%6e%6f%6c%6f%67%79%20%61%6e%64%20%68%6f %77%20%6d%75%63%68%20%62%79%20%6c%61%77%20%65%6e%6 6%6f%72%63%65%6d%65%6e%74%3f% d% a%51%3a%20%49%20%61%73%73%75%6d%65%20%66%72%6f%6d% 20%79%6f%75%72%20%74%65%73%74%69%6d%6f%6e%79%20%74 %68%61%74%20%79%6f%75%20%67%75%79%73%20%73%75%70%7 0%6f%72%74%65%64%20%74%68%65%20%6c%61%6e%67%75%61% 67%65%20%69%6e%20%74%68%65%20%55%53%41%20%50%41%54 %52%49%4f%54%20%41%63%74%20%6f%6e%20%63%79%62%65%7 2%74%65%72%72%6f%72%69%73%6d%20%61%6e%64%20%69%6e% 74%72%75%73%69%6f%6e%2e%20%41%72%65%20%77%65%20%69 %6e%20%64%61%6e%67%65%72%20%6f%66%20%6f%76%65%72%2 d%62%72%6f%61%64%65%6e%69%6e%67%20%74%68%65%20%73% 74%61%6e%64%61%72%64%20%66%6f%72%20%63%61%6c%6c%69 %6e%67%20%73%6f%6d%65%74%68%69%6e%67%20%63%79%62%6 5%72%74%65%72%72%6f%72%69%73%6d%20%74%6f%20%69%6e% 63%6c%75%64%65%20%72%6f%75%74%69%6e%65%20%65%78%70 %6c%6f%72%61%74%6f%72%79%20%69%6e%74%72%75%73%69%6 f%6e%73%20%61%6e%64%20%70%6f%72%74%20%73%63%61%6e% 73%20%61%6e%64%20%6f%74%68%65%72%20%6d%69%6e%6f%72 %20%65%76%65%6e%74%73%2c%20%69%6e%20%74%68%65%20%6 8%65%61%74%20%6f%66%20%74%68%65%20%6d%6f%6d%65%6e% 74%20%61%66%74%65%72%20%53%65%70%74%2e%20%31%31%3f % d% a%49%66%20%49%27%6d%20%74%72%61%63%6b%69%6e%67%20% 73%6f%6d%65%62%6f%64%79%20%74%68%61%74%27%73%2c%20 %73%61%79%2c%20%69%6e%76%6f%6c%76%65%64%20%69%6e%2 0%74%65%72%72%6f%72%69%73%74%20%61%63%74%69%76%69% 74%79%2c%20%61%6e%64%20%74%68%65%79%27%72%65%20%75 %73%69%6e%67%20%61%20%63%65%6c%6c%20%70%68%6f%6e%6 5%2c%20%61%6e%64%20%74%68%65%79%20%63%61%6e%20%70% 75%74%20%74%68%65%20%63%65%6c%6c%20%70%68%6f%6e%65 %20%64%6f%77%6e%20%66%72%6f%6d%20%68%61%76%69%6e%6 7%20%61%20%76%6f%69%63%65%20%63%61%6c%6c%20%74%6f% 20%75%73%65%20%74%68%65%20%73%61%6d%65%20%63%65%6c %6c%20%70%68%6f%6e%65%20%74%6f%20%64%6f%20%61%6e%2 0%49%6e%74%65%72%6e%65%74%20%6d%65%73%73%61%67%65% 20%62%65%63%61%75%73%65%20%74%68%65%79%27%76%65%20 %67%6f%74%20%61%20%57%65%62%2d%65%6e%61%62%6c%65%6 4%20%70%68%6f%6e%65%2c%20%61%6e%64%20%74%68%65%6e% 20%74%68%65%79%20%67%6f%20%68%6f%6d%65%20%61%6e%64 %20%74%68%65%79%20%75%73%65%20%61%6e%20%6f%6e%6c%6 9%6e%65%20%61%63%63%6f%75%6e%74%20%74%6f%20%63%6f% 6d%6d%75%6e%69%63%61%74%65%20%66%75%72%74%68%65%72 %2c%20%72%61%74%68%65%72%20%74%68%61%6e%20%67%6f%2 0%67%65%74%20%66%69%76%65%20%77%61%72%72%61%6e%74% 73%20%66%6f%72%20%74%68%65%20%73%61%6d%65%20%74%68 %69%6e%67%2c%20%74%68%65%79%20%64%6f%6e%27%74%20%6 8%61%76%65%20%74%6f%20%63%68%61%73%65%20%74%68%65% 20%74%65%63%68%6e%6f%6c%6f%67%79%2c%20%74%68%65%79 %20%63%68%61%73%65%20%74%68%65%20%63%72%69%6d%69%6 e%61%6c%20%61%63%74%69%76%69%74%79%2e% d% a%41%3a%20%49%20%68%6f%70%65%20%6e%6f%74%2e%20%57% 68%61%74%20%77%65%27%76%65%20%73%65%65%6e%20%66%72 %6f%6d%20%74%69%6d%65%20%69%6d%6d%65%6d%6f%72%69%6 1%6c%2c%20%6d%61%72%6b%65%74%20%66%6f%72%63%65%73% 20%64%72%69%76%65%20%61%20%6c%6f%74%20%6f%66%20%77 %68%61%74%20%68%61%70%70%65%6e%73%20%69%6e%20%74%6 8%65%20%64%65%76%65%6c%6f%70%6d%65%6e%74%20%65%66% 66%6f%72%74%73%2e%20%53%74%61%6e%64%61%72%64%73%20 %64%6f%6e%27%74%20%64%72%69%76%65%20%69%74%2c%20%6 2%65%63%61%75%73%65%20%77%68%61%74%20%68%61%70%70% 65%6e%73%2c%20%79%6f%75%20%77%69%6e%64%20%69%6e%20 %61%20%73%69%74%75%61%74%69%6f%6e%20%77%68%65%72%6 5%20%73%74%61%6e%64%61%72%64%73%20%6d%61%79%20%74% 75%72%6e%20%61%72%6f%75%6e%64%20%61%6e%64%20%69%6e %68%69%62%69%74%20%74%68%65%20%61%62%69%6c%69%74%7 9%20%74%6f%20%69%6e%6e%6f%76%61%74%65%20%61%6e%64% 20%74%68%65%20%61%62%69%6c%69%74%79%20%74%6f%20%62 %75%69%6c%64%20%6d%6f%72%65%20%73%65%63%75%72%65%2 0%70%72%6f%64%75%63%74%73%2e% d% a%41%3a%20%49%20%74%68%69%6e%6b%20%4d%69%63%72%6f% 73%6f%66%74%20%68%61%73%20%72%65%63%6f%67%6e%69%7a %65%64%20%74%68%61%74%2c%20%62%65%63%61%75%73%65%2 0%77%65%20%61%72%65%20%74%68%65%20%6d%61%72%6b%65% 74%20%6c%65%61%64%65%72%2c%20%77%65%20%68%61%76%65 %20%61%20%73%70%65%63%69%61%6c%20%6f%62%6c%69%67%6 1%74%69%6f%6e%20%74%6f%20%69%6d%70%72%6f%76%65%20% 73%65%63%75%72%69%74%79%2e%20%54%68%69%73%20%69%73 %20%61%6e%20%69%6e%64%75%73%74%72%79%20%69%73%73%7 5%65%20%77%65%27%72%65%20%61%6c%6c%20%77%6f%72%6b% 69%6e%67%20%6f%6e%2c%20%62%75%74%20%62%65%63%61%75 %73%65%20%6f%66%20%74%68%61%74%20%73%70%65%63%69%6 1%6c%20%72%6f%6c%65%20%6f%75%74%20%6f%62%6c%69%67% 61%74%69%6f%6e%20%69%73%20%69%6e%63%72%65%61%73%65 %64%2e%20%57%68%69%63%68%20%69%73%20%77%68%79%20%7 7%65%20%63%72%65%61%74%65%64%20%70%72%6f%67%72%61% 6d%73%20%6c%69%6b%65%20%74%68%65%20%73%74%72%61%74 %65%67%69%63%20%74%65%63%68%6e%6f%6c%6f%67%79%20%7 0%72%6f%74%65%63%74%69%6f%6e%20%70%72%6f%67%72%61% 6d%20%2d%2d%20%68%65%6c%70%69%6e%67%20%70%65%6f%70 %6c%65%20%67%65%74%20%73%65%63%75%72%65%20%77%69%7 4%68%20%61%20%6e%75%6d%62%65%72%20%6f%66%20%66%72% 65%65%20%74%6f%6f%6c%73%2c%20%74%68%65%6e%20%67%65 %74%74%69%6e%67%20%74%68%65%6d%20%74%6f%20%73%74%6 1%79%20%73%65%63%75%72%65%20%62%79%20%63%68%61%6e% 67%69%6e%67%2c%20%66%75%6e%64%61%6d%65%6e%74%61%6c %6c%79%2c%20%73%6f%6d%65%20%6f%66%20%6f%75%72%20%6 9%6e%74%65%72%6e%61%6c%20%70%72%6f%63%65%73%73%65% 73%2c%20%74%6f%20%66%75%72%74%68%65%72%20%73%74%72 %65%6e%67%74%68%65%6e%20%74%68%65%20%73%65%63%75%7 2%69%74%79%20%74%68%61%74%20%77%65%27%76%65%20%62% 65%65%6e%20%77%6f%72%6b%69%6e%67%20%6f%6e%20%69%6e %74%65%72%6e%61%6c%6c%79%2e% d% a%41%3a%20%49%20%74%68%69%6e%6b%20%74%68%61%74%20% 70%69%63%74%75%72%65%20%68%61%73%20%63%68%61%6e%67 %65%64%2e%20%4f%6e%63%65%20%61%67%61%69%6e%2c%20%7 7%65%27%76%65%20%62%65%65%6e%20%64%65%76%65%6c%6f% 70%69%6e%67%20%73%74%75%66%66%20%62%61%73%65%64%20 %6f%6e%20%65%61%73%65%2d%6f%66%2d%75%73%65%20%66%6 f%72%20%74%68%65%20%63%75%73%74%6f%6d%65%72%20%61% 6e%64%20%77%68%61%74%20%74%68%65%20%63%75%73%74%6f %6d%65%72%20%72%65%71%75%69%72%65%6d%65%6e%74%73%2 0%61%72%65%2e%20%49%20%74%68%69%6e%6b%20%77%68%61% 74%20%68%61%70%70%65%6e%73%20%6e%6f%77%20%69%73%20 %74%68%61%74%20%77%65%27%76%65%20%73%65%65%6e%20%7 4%68%65%20%74%68%72%65%61%74%20%70%69%63%74%75%72% 65%20%63%68%61%6e%67%65%2e%20%49%20%74%68%69%6e%6b %20%69%74%20%67%6f%65%73%20%62%61%63%6b%20%74%6f%2 0%61%20%70%68%79%73%69%63%61%6c%20%61%6e%61%6c%6f% 67%79%2e%20%49%66%20%49%20%6c%65%61%76%65%20%6d%79 %20%6b%65%79%73%20%69%6e%20%6d%79%20%63%61%72%20%6 2%65%63%61%75%73%65%20%69%74%27%73%20%63%6f%6e%76% 65%6e%69%65%6e%74%20%66%6f%72%20%6d%65%2c%20%61%6e %64%20%73%6f%6d%65%62%6f%64%79%20%73%74%65%61%6c%7 3%20%6d%79%20%63%61%72%2c%20%69%73%20%74%68%61%74% 20%6d%79%20%66%61%75%6c%74%3f%20%54%65%6e%20%6f%72 %20%31%35%20%79%65%61%72%73%20%61%67%6f%2c%20%74%6 8%65%20%6c%69%6b%65%6c%69%68%6f%6f%64%20%6f%66%20% 74%68%61%74%20%68%61%70%70%65%6e%69%6e%67%20%77%61 %73%20%76%65%72%79%2c%20%76%65%72%79%20%6c%6f%77%2 e%20%42%75%74%20%74%68%65%20%74%68%72%65%61%74%20% 70%69%63%74%75%72%65%20%68%61%73%20%63%68%61%6e%67 %65%64%20%64%72%61%6d%61%74%69%63%61%6c%6c%79%20%6 9%6e%20%6d%6f%73%74%20%70%6c%61%63%65%73%2e% d% a%51%3a%20%42%75%74%20%74%68%61%74%20%6b%69%6e%64% 20%6f%66%20%62%65%67%73%20%74%68%65%20%71%75%65%73 %74%69%6f%6e%2c%20%62%65%63%61%75%73%65%20%69%74%2 0%77%61%73%6e%27%74%20%63%6f%6d%70%6c%65%74%65%6c% 79%20%75%6e%74%68%69%6e%6b%61%62%6c%65%2c%20%6c%69 %6b%65%20%73%6f%6d%65%6f%6e%65%20%66%6c%79%69%6e%6 7%20%61%20%70%6c%61%6e%65%20%69%6e%74%6f%20%61%20% 62%75%69%6c%64%69%6e%67%2e%20%41%74%20%74%68%65%20 %74%69%6d%65%20%77%68%65%6e%20%61%6c%6c%20%74%68%6 5%73%65%20%66%65%61%74%75%72%65%73%20%77%65%72%65% 20%62%65%69%6e%67%20%72%6f%6c%6c%65%64%20%6f%75%74 %2c%20%70%72%6f%67%72%61%6d%6d%65%72%73%20%6f%6e%6 c%69%6e%65%20%77%65%72%65%20%73%63%72%65%61%6d%69% 6e%67%20%6c%65%66%74%20%61%6e%64%20%72%69%67%68%74 %20%74%68%61%74%20%74%68%69%73%20%77%61%73%20%69%6 e%65%76%69%74%61%62%6c%79%20%67%6f%69%6e%67%20%74% 6f%20%72%65%73%75%6c%74%20%69%6e%20%74%68%65%73%65 %20%6d%61%73%73%69%76%65%20%69%6e%63%69%64%65%6e%7 4%73%2c%20%61%6e%64%2c%20%73%75%72%65%20%65%6e%6f% 75%67%68%2c%20%74%68%65%79%20%64%69%64%2e% d% a%51%3a%20%49%27%6c%6c%20%67%69%76%65%20%79%6f%75% 20%61%20%63%68%65%65%72%66%75%6c%20%71%75%6f%74%65 %20%66%72%6f%6d%20%52%69%63%6b%20%46%6f%72%6e%6f%2 e%20%48%65%20%73%61%69%64%20%6f%6e%65%20%6f%66%20% 6f%75%72%20%6d%61%6a%6f%72%20%73%65%63%75%72%69%74 %79%20%70%72%6f%62%6c%65%6d%73%20%69%73%20%22%6f%7 5%72%20%63%6f%6e%74%69%6e%75%69%6e%67%20%62%6c%69% 6e%64%20%64%65%70%65%6e%64%65%6e%63%65%20%6f%6e%20 %4d%69%63%72%6f%73%6f%66%74%20%6f%70%65%72%61%74%6 9%6e%67%20%73%79%73%74%65%6d%73%2e%22% d% a
%53%63%68%6d%69%64%74%20%73%65%72%76%65%64%20%6
BAHAHAAHAH...
Thanks d00d. I've been wondering when someone would convert this into my prefered reading format.
QED
The guy even works three blocks from the WhiteHouse.
The software is developed in a suburb of Seattle Washington (state) and the company's security chief works in Washington (DC), nearly as far from the software department as you can get and still be in the continental US.
THAT explains the security problems in Microsoft products!
B-)
Bantam Dominique roosters crow a four-note song. Once you've heard it as "Happy BIRTHday" you can't NOT hear it that way
Microsoft's head of security works 3 blocks from the White House? The last I heard, the rest of MS campus was in Washington state, not Washington D.C. I would have asked him how the hell he effectively manages security for an operation the size of MS from 3000 miles away. He seems more like Microsoft's liason to Congress, not any kind of security manager. He's fully integrated into the MS management hive-mind it seems from the way his answers mirror what we always hear from MS executives. Wait a minute, maybe that's how he manages his teams at the main campus? :)
and your still screaming, all the time, about anything and everything, which is why the only people who listen are fellow screamers.
...clearly one the least candid and varbally honest individuals on the planet today, and the Bush administration is making one whopper of a mistake taking this guy's advice on anything more important than decorating tips for the White House xmas trees.
CSO, my ass, this guy's just another corporate frat boy if you ask me.
"A microprocessor... is a terrible thing to waste." --
GeneralEmergency
This interview assures me that Microsoft is continuing down the road to success. Based on their past performance, and their constant vigilence on computer security issues (extremely minor incidents withstanding), I will be switching away from some of my Red Hat Linux servers.
Frankly, the ease of use and support I've seen with Windows XP, not to mention the stability and compatilibilty i've seen have finally swayed me back. Red Hat has a long way to go, and I'll be recommending to all my collegues not to try out this so called operating system. Even more so for the dying BSD lineage. Microsoft is going strong and will continue on into the forseeable future. I can't frankly say the same about other Operating Systems.
Head for the hills!
No, this is not flame bait, but the guy points out a perfectly valid point: every other OS has the same problem in terms of vulnerabilities. The difference comes from the user base. If you look at the typical linux user vs. the typical windows user, you're looking at two different people. My grandmother could never use linux, and by the same token, could never turn stuff OFF in windows. So if IIS is turned on, or Remote Assistance, she's not going to know a darn thing on how to disable it or secure our machine. Me on the otherhand, I've got the virusscan doing daily updates, the firewall, etc. It's not that windows is any less secure than linux, its just that it COMES less secure and users can't fix it easily.
- gtaluvit (prnc. GOT-tuh-LUV-it)
Leave their keys in their cars, I mean. Is it stupid? Maybe, but so long as they don't get stolen (hint: after twenty odd years of this, they haven't) then you can say that in their situation it works.
Really, this parallels the whole trust on the Internet thing. I don't leave mail relays open anymore, I don't run ftp or telnet services; hell, I don't even let my computer respond to ping or finger.
Microsoft should have fixed their default settings problem a couple years ago. I wouldn't blame them for having it like that, though. Most Linux distributions come somewhat secure out of the box now, but a year ago most didn't.
Even Slashdot wants to hide some things
You discover that a theater's reel-room lock can be bypassed with a credit card. You corroberate this by calling a friend in a neighboring city, and the doors in his theater are similarly weak. You are now the only two people who know that it is easier than expected to perform a criminal act against the theater.
Should you
Is this not a good analog of a digital security vulnerability? It's not a fire except in the figurative sense when it's being aggressively exploited. It's just like discovering a certain door can be bypassed with a particular trick that most doors aren't vulnerable too.
By the way, I'm not telling you where I live, because my front door was hung poorly. The stupid anti-creditcard-trick-tongue on it falls into the jam opening when you close the door all the way, so it's useless. I don't consider it a big risk most of the time, since I also have windows in my house, and if you steal physical stuff I can have the police go after you using physical evidence... but that's off-topic.
Cheers,
Sandy
"It's a piece of code that you write to go do something bad, and now the availability of those sort of things is very widespread. People have computers in their homes, connected to DSL and cable modems, so the cost of the ability to do damage is down.
I see! Maybe this is where Microsoft's idea that security is made by the ignorance of the public comes from. So they want to suppress the knowledge of security holes in order to make their software "more secure". But the larger issue (obviously) is that the people want to know. We want to know about and understand these holes so we can learn from them. The only people who are afraid of letting this knowledge out are those who fear they couldn't understand it so other "bad" people would have the upper hand... and companies who want to hide and control all advanced knowledge of their products in order to maintain lower costs to them.
Please help! I'm stuck inside my virtual reality headset!
I think security is recognized as the number-one priority across the company. That goes not only to operational security and securing our assets, but also to product development. (emphasis mine)
Anyone else find his priorities in terms of security, shall I say, interesting?
-- B.
This sig does in fact not have the property it claims not to have.
Yeah but the potential of a terrorist attack against our computer resources wasn't the focus of the interview (or at least it didn't start out that way). There are many things people are freaking out about right now. Take for instance, the U.S. nuclear plants.
Sure, it would be scary to see a plane fly into a nuclear plant. But given the considerable thought and planning that went into the WTC attack, would an Islamic terrorist _really_ want to attack a power plant? Probably not. Why? Well, their immediate objective is to get the U.S. to butt out of the Middle East. How do you do that? Make it not worth their while to be there.
Destroying a nuclear plant makes the U.S. MORE dependent on foreign oil. Counterproductive.
Much in the same way, attacking the Internet on a large scale is counterproductive to them. The Internet doesn't reinforce U.S. oil dependence. Additionally, it isn't something the public truly FEARS losing. Deaths scare people, whether that's by large explosions or little microbes. Disrupting the Internet, though, just costs money and inconveniences people and companies.
In the end, immediate monetary costs have LESS impact on the U.S. economy than a large drop in consumer confidence. That's why the Trade Center attacks were so effective, especially as seen by the airline industry.
On the other hand, the Internet does provide a medium of communication that is useful to the terrorists themselves. So it really isn't in their best interest to destroy it.
Still, going back to the main point: this interviewer was interviewing Microsoft's head security honcho about _software_. Terrorism should have been left out of the discussion. Now if you want to interview U.S. government and military officials and see what they are doing to secure their systems, then the interview certainly takes on a new tone and that type of questioning is justified. But I'd wager that mission critical systems are not using "out of the box" Microsoft software in the first place, and many aren't even on the Internet.
Just my opinion.
I always wondered how they had the DoJ in their pocket to drop the anti-trust case. It's obvious the ex-FBI, ex-Miltary, current head of MS Security is the ace in the whole.
I only need the Preview button when I haven't used the Preview button.
'Nuff said...
I have no problem with your religion until you decide it's reason to deprive others of the truth.
In some cases, it's tantamount to screaming "fire!" in a crowded movie theater. Responsible reporting means if you find a vulnerability, you contact the person in the best position to fix it,
Bob, decided to be a responsible reporter, silently walk out of the movie theater when he found the toilet was on fire. He then dialed 911 across the street for somebody to fix the problem "Hi, are you sure you are the person in the best position to put the fire off? I wouldn't report until I get to this guy."
I really am not interested in anything Microsoft has to say. It's all fettered with lies anyway.
They are in it to control the world which ultimately leads to money, and they will attempt to gain this by any means necessary, lies and oppression included.
Q: So, you're the chief security officer here at Microsoft?
A: Yes I am. I'm Ex-FBI, Ex-cop, Ex-lover of Liberace.
Q. Ok, I didn't need to know that last part. So what does your job require of you?
A. Well, in the morning I get coffee and donuts. Then I usually spend the next 8 hours or so watching CCTV monitors.
Q. So, you watch monitors with software and code? Interesting.
A. No. I watch monitors of people coming and going in different hallways. There's this little hottie secretary on floor 5 in the XP wing that's really got a nice..
Q. What? You're just a security GUARD and not a software security expert?
A. Yeah, who the hell told you otherwise? Well this was real fun and all but I gotta get back to watching the bathrooms.
As of Dec. 20, 2001, the total number of published security bulletins is only 58 compared to 100 in 2000 and 60 in 1999. This year, there are 4 cumulative patches so the actual number of published security threats is around 54.
.NET server hopefully will do better than W2K servers.
The last 3 security vulnerabilities for XP relate to IE, Windows Media, and USB plug and play feature.
I should say that the products of Microsoft are just becoming mature right now. It is unfair for Linux and Unix since they I believe they have been ages before Microsoft introduced Windows. So it terms of maturity, Linux took years just as Microsoft is.
Like in service packs, the Windows 3.51 had around 13 (or more if I remember correctly.) Windows NT4.0 had 6 (the 7th was not released officially.) Windows 2000 now has 2 (and they are releasing SP3 Q1 2002.) There is WindowsXP although there is no SP around (I believe it may be in the alpha stages.) The number of service packs that is released actually decreases due to the maturity of their products. And most people even some *nix guys say that WindowsXP is actually more stable than ever.
It is also noteworthy to say that the base OS of Windows is getting more secure. It is just the apps integrated with the Internet that have most of the security threats like IE, Outlook, Office. For the servers in W2K, the services are the ones problematic and the user has the freedom to deactivate some and use an alternative. Like in Linux, the same thing applies where a server may use the services from different publishers.
I am not saying that Microsoft is good or anything but I say that comparing Windows (PRO/HOME) and Linux/Unix is like comparing apples and oranges. They are built for different purpose thus designed differently.
In the server arena, I think that it is only in Windows 2000 that they released their 1st server OS and not in Windows NT 4.0. Their Windows
Live your life each day as if it was your last.
Q: Capacity issues...
A: Right.
Howard failed to see the sarcasm in Paul's response - he's being totally irrelevent in answering Paul's question. Paul asked you security in telecom not freaking capacity issue!!!
Talking about we ain't got enough clueless people to run the security....
So that makes him a good cop. Good at the "reactive role", lousy at prevention. Explains the MS model of security perfectly.
We've all been saying that Microsoft should improve their security, but all the time Microsoft has! Here, have a look at what he says:
I added the emphasis, but look at it! They are securing their assets. He lists security in product development is an afterthought.
So now you know why they are so anti-piracy: they are securing their products.
Microsoft's head of security
Isn't that like the taliban having a minister of women's rights?
Disconnect your television. Do your own research. Draw your own conclusions. They're probably lying. Don't be a sheep.
Q: [...] Explain for us a little bit how security fits into the Microsoft corporate structure.
:)
A: I think security is recognized as the number-one priority across
the company. That goes not only to operational security and securing our
assets, but also to product development. [...]
Perhaps I'm not reading this right, or reading into his wording too much, but it seems they put more effort into securing their company instead of securing their product? That explains a few things.
Is this how it's always been, or how it's going to be? hmmm....
As I understand it, the pressure vessels surrounding nuclear reactors are strong enough to contain a severe meltdown within- this also makes them supposedly strong enough to withstand an airliner impact.
Alcohol, Tobacco and Firearms should be the name of a store, not a government agency.
>[quote]"If I leave my keys in my car because it's convenient for me, and somebody steals my car, is that my fault?"[unquote]
You are responsible for the consequences of your actions.
That goes for leaving keys in cars because you're a dumbass or creating lousy software that constantly gets exploited because you're a dumbass.
As we all know, one of the greatest things about living in these here United States of America is that you never have to take responsibility for your actions even if you are a moron (or Microsoft).
1) As Multics taught us, security with significant hardware support is significantly easier to do than without. A result of this is that we need to be asking Intel (etal) about help (like tagged memory blocks) in hardware. It really is time that we got away from just the stale VonNeuman ideas that Mr Cray graciously gave us in the 1960s and 1970s.
2) Once the hardware exists, then we can move to implement better O/Ses that are significantly more robust. Everyone will win, even MS.
-- Multics
have a look at the OpenBSD homepage... OpenBSD "Four years without a remote hole in the default install!"
And Damn proud of it too! Perfect Secrurity does exist!
For instance. Even with all the security patches Microsoft has provided with IIS, their FTP server is still insecure. How do I know this. Because some warez dudez managed to use my server, even though I had applied all the patches and set the FTP directory to be read only.
Now, if this ever happens to you, let me tell you, these guys play a dirty trick so you can't easily delete their directory. They name their folders with names that cannot be deleted the normal way, names like COM1 or DEL, names that are reserved somehow when you try to delete the files and folders.
The amusing thing about this is that the only way to get rid of these files is to install the posix utilities and use rm to get rid of them.
Now here's the kicker. If you use rm -r CO* to get rid of a directory called COM1 you might find out that this directory is really called "COM1\
Yes, I perform backups, so I proceeded to restore the files. But insidiously, SQL Server on the same machine refused to run, because it felt the installation had been corrupted. I basically had to figure out how to trick it into running again, because(another hideous design fault) you can't just uninstall SQL server and reinstall it and hope your data directory is OK. I had no way of doing an up to date backup of my data on this machine. So I had to trick it into believing it wasn't a corrupt installation, or I would have lost data.
Now, how many things can you count that would have never happened with an open source system. You certainly wouldn't have files with the latter part hidden. You can back up data directories to completely different servers by simply copying the directory. Its very easy to drop in other FTP servers without loss of functionality. And there is certainly nothing that will stop a program from running if all its files are there and the execute permission is set.
All, in all, I had a very frustrating experience that never would have happened with a Linux system. With Microsoft, its their way or the highway, and you can't change things or fix them when the design is bad. Rather than the user dictating what the software does, Microsoft dictates to you how their software will work. Because of that, closed source is less flexible and configureable, is less managable and nimble, and therefore cannot respond nearly as well to any number of problems, including security.
No, Thursday's out. How about never - is never good for you?
Gotta LOVE this exchange ...
...
Q: Some of the security problems with Microsoft products are things like buffer overflows. That happens in programming, and you fix it. But others seem like boneheaded decisions based on marketing. Things like enabling Windows Scripting Host by default on millions of consumer machines and making e-mail attachments executable. In these big virus attacks, doesn't Microsoft bear some responsibility for those choices?
A: I think that picture has changed. Once again, we've been developing stuff based on ease-of-use for the customer and what the customer requirements are. I think what happens now is that we've seen the threat picture change. I think it goes back to a physical analogy. If I leave my keys in my car because it's convenient for me, and somebody steals my car, is that my fault?
Okay, but what if the manufacturer ships the car with the keys attached to the steering column with a chain,because THAT way I don't have to worry about losing the keys? Now I have to find out (from someone other than the manufacturer, since the manufacturer's customer support staff is clueless) how to detach them. NOW is the manufacturer responsible, in any way, when my car is stolen?
utter rubbish
This is Microsoft for gods sake. Think real hard, look over the last 20 or thirty things some top level MS exec said in public. Find one interview, statement, debate, press release or anything that did not contain at least one lie. I dare you.
Every corporation has a culture. The culture MS has chosen to develop is one of lying, cheating and stealing.
War is necrophilia.
What's black, blue and green and doesn't like sex? The Girl Scout locked in my basement. What's the worst part about having sex with a six-year-old? Getting the blood out of your clown suit. What's the best thing about getting a hand job from a five-year-old? That little hand makes your thing look really huge. Guy comes home from work to find his girlfriend sitting on the porch, crying. "What's wrong, honey?" "I'm leaving you!! I just found out you're a pedophile!!!" "Pedophile?? Why, that's a pretty big word for a ten-year old..." How can you tell when your sister's on her period? When your dad's dick tastes like blood! Two pedophiles are lying on a beach tanning, one turns to the other and says, "excuse me, you're in my son." What's 18 inches long, blue, veiny, and makes a woman cry? Crib death. How could the man's 7-year-old son tell that his dad has farked his 8-year-old sister? His dad's weiner tasted like blood! Watson returns home to find Holmes in bed with a child. He shouts, "Is this some sort of a schoolgirl?" Holmes replies, "Elementary, my dear Watson." So I was having sex with my girlfriend, and I decided I wanted to get kinky and try and do her in the ass. So I slipped around back, she looked over her shoulder at me and said... "My, how presumptious of you." And I said "presumptious? That's a big word for a 10-year-old." Two guys are walking down the street when a beautiful woman passes. The first guy says, "Damn! I'd love to tear her clothes off, do her in the rear, smear my feces all over her, slice off her breasts, chop her into little pieces, put her in a garbage bag and toss her into the river!" Second guy says, "Yuck! You're a sick bastard!" First guy says, "What're you? A fag?" The kidergarden teacher is asking the kids what their father does for a living. All the kids answer except for Little Johnny. The teacher asks Little Johnny what his Dad does and Johnny replies "My dad is dead." The teacher say's "That is terribile, but what did he do before he died?" Little Johnny replies, "He turned blue and shit all over himself!" A guy calls in sick to work. "What's wrong?" asks the boss. "I'm sick," the guy replies. "You sound all right." "No, I'm really sick. Believe me." "Listen, you were fine yesterday, and we have a lot of work today. I want you in here. You can't be that sick!" "Dude, I just banged my sister. Don't tell me I'm not sick." A little girl accompanied her father to the barbershop. While her dad received a haircut, the little girl stood next to the barber chair, enjoying a snack cake. The barber smiled at her and said, "Sweetheart, you're going to get hair on your Twinkie." "I know," the little girl replied. "I'm gonna get tits, too." An older man and a small boy walk hand in hand through the woods. Boy: "These woods sure are spooky!" Man: "You think you're scared, I've gotta walk out of here alone." What's the difference between Neil Armstrong and Michael Jackson? One walked on the moon, and the other rapes little boys. Has anyone read Michael Jackson's new book, "The Ins and Outs of Child Rearing"? Q: What's the difference between a dead baby and a golden delicious apple? A: I don't cum all over the golden delicious apple before I take a bite out of it. Q: What's the difference between a dead baby and my girlfriend? A: I don't kiss my girlfriend after sex. Q: What is special about a dead baby over all other forms of life? A: You can achieve deep throat from whichever way you enter. Q: What do you have when you have 4 dead babies, take away two, and add 5 more? A: An orgy! Q: What's the difference between a dead baby and a table? A: You can't fark a table. Q: Whats white and bobs up and down in a baby's crib? A: A pedophile's ass. Q: Whats the safest way to play with a baby? A: With a condom. Q: Whats more fun than feeling up a dead baby? A: Feeling up a dead baby with three nipples. Q: What does a baby and a Pinto have in common? A: They're fun to ride until they die. Q: What do you get whan you dislocate a dead baby's jaw? A: Deep Throat. Q: Whats the difference between a baby and a grandmother? A: Grandmothers dont die when you fark them in the ass Q: What's the best sound in the world? A: Hearing dead baby's hips crack under pressure! Q: Whats worse than a having sex with a dead baby? A: Having sex with a dead baby filled with razor blades. Q: How do you stop a baby from choking? A: Take your dick out of its mouth. Q: What's worse than finding a dead baby on your pillow in the morning? A: Realizing you were drunk and made love to it the night before. Q: How do you make a baby cry twice? A: Wipe your bloody cock on his teddy bear. What's better than sex with a 12-year-old boy? Absolutely nothing.Thanks, Fark.com!
________________________________________J. Wipo Troll, Esq.
Crapflooder Associates
Slashdot.org
that everyone keep quiet if they see a fire in a crowded apartment building because, horror of horrors, people will actually try to save themselves rather than waiting for the MFD to come and save them (market forces permitting, of course).
Goddamn, you're a comedic genius.
C:\
C:\DOS
C:\DOS\RUN
Number 1. Adding new product features
Number 2. Getting products on the shelves
Number 3. Security
The reason for this is that people can't tell whether a product is secure by looking at reviews or even trying it out (and they sure as hell can't tell by looking at a shrink wrapped box). So, there are very few dollars in it short-term.
Longer term, issues of reputation kick in - and Microsoft are finding that their poor reputation in this area is now biting them, especially as they move into net services.
Unfortunately, turning an entire corporate culture around on a dime is not possible. Even if it was, there's way too much legacy software around, requiring compatability. It will therefore be some time before their product security is all it should be.
"Well, put a stake in my heart and drag me into sunlight."
Heh
.. I must remember that :)
But indeed, I didn't know that this kind of posts worked so well
(yes, I was honest, no, I won't be in the future)
--
If code was hard to write, it should be hard to read
digital rights management operating system protects rights-managed data, such as downloaded content, from access by untrusted programs
To protect the rights-managed data resident in memory, the digital rights management operating system refuses to load an untrusted program into memory
If the untrusted program executes at the operating system level, such as a debugger, the digital rights management operating system renounces it's trusted identity (it lobotimizes itself)
To protect the rights-managed data on the page file, the digital rights management operating system prohibits raw access to the page file, or erases the data from the page file before allowing such access.
operating system also limits the functions the user can perform on the rights-managed data and the trusted application
provide a trusted clock used in place of the standard computer clock
It's good to see Microsoft finaly getting tough on security!
-
- - You can't take something off the Internet! That's like trying to take pee out of a swimming pool.
Let the technicians rise up and overthrow the reign of the marketting and accounting global hegemony!
All will code according to their ability and run programs according to their need!
And while we're at it:
"As long as the app fires up, it can be released. We'll let the customers be beta testers."
Isn't that the whole way OPEN SOURCE works??!?!? Open source releases software with numerous more bugs but has a very broad test cycle. I feel confident with open-source solutions with the commonly used apps, but to be honest (and maybe it's just me) I don't have that much confidence at all in some of the most obscure and rarely used packages that hang around in woody or potato.
How do you clap your hands thrice when your holding a couple of grocery bag?
The nice thing about standards is that there are so many to choose from. - ast
i think i will go for the chief of security job too :P
That has to be the most cluefull AC post I've seen here ever, wish I had points to rise it above 0!
I agree that it would be an extremely bad idea to use NT / Windows 2000 for anything that is mission critical (such as running a semaphore network), and that would be a misuse of the product, but there are plenty of proper uses that can produce really bad results due to software failure, and companies should be held accountable for these failures.
Overcaffeinated. Angry geeks.
BIND
wu-ftpd
Open-SSH
TUX HTTPD
lpd
SYNcookies
Lion
Ramen
Torn
Adore
etc...
We get several attacks from compromised LINUX boxes every fucking day of the week!
gee, that Microsoft software sure does suck...
Some guy once said "Let him who is without sin cast the first stone."
Do you see what I'm getting at here?
"Information wants to be paid"
With software, testing starts at the requirements stage. When you have captured the requirements you then force the customer to review them. You don't just get them to sign off documents, because they will happily do that without reading them. You get them to sit through a presentation. The same applies after the functional specs and you cross check the functional specs against the requirments.
All this before you have written one line of code!!!
As regards exploits if you code defensively against exploits, you will produce better code. You should never trust data that hasn't come out of a checked process and only through a failure-free path.
I also agree that Writing Solid Code by Steve Maguire is a good book. It is a pity that Microsoft seems to regard the practices described in these books as a luxury!!!!
See my journal, I write things there
Nobody can access my computer then - pretty neat, eh?
Seriously, 2K is much better than NT was but I wonder whether Microsoft actually knows what computer security is? We were taught the initials C.I.A. That is Confidentiality, Integrity and Availability.
It doesn't matter how a product fits into these categories as long as the customer knows what it is being provided. If you are selling a system and application to a customer and telling them that they can bet their business on it, then it had better not go down every other day or let the whole world and their dog every time you connect to the Internet.
See my journal, I write things there
1. Marketing != PR
2. Marketing != advertising
3. Marketing != reactive
Marketing is about Product, Price, and Position. It proactive and its scientific, what Microsoft confuses with Marketing is like confusing Socialogy with sleazy used cars salesmanship.
What they need to do, like the vast majority of corperations is completely seperate Marketing from advertising, and accounting. Real Marketing is much closer to R & D and should have a closer relationship to product developement than any other department.
1. Product needs work I think the real market has slipped out from under them.
Security, Stability, Speed in that order is where the market seems to be heading. Less consern with feature creap and more attention to make basic functionality rock solid and easy to use.
2. Price, who can beat free? that's what the consumer pays; after all it comes on the machine, very few people write a seperate check. Businesses on the other hand are kicking and screeming over liciensing costs lately. I guess they are tired of subsidising the consumer grade product. I chuckle when some suit says "open software is worth the price you pay for it." when their company is running 2K oem M$ licienses.
3. M$ has position down pat; they're everywhere.
Apocalypse Cancelled, Sorry, No Ticket Refunds
It's not about security.
It's about functionality.
The people chose functionality,
so Microsoft gave them that.
Like in service packs, the Windows 3.51 had around 13 (or more if I remember correctly.) Windows NT4.0 had 6 (the 7th was not released officially.) Windows 2000 now has 2 (and they are releasing SP3 Q1 2002.) There is WindowsXP although there is no SP around (I believe it may be in the alpha stages.) The number of service packs that is released actually decreases due to the maturity of their products.
The reason Win2000 has "only" 2 SPs and NT4 has 6 is not better security, but quite simply the time these products have been on the market. The longer the product's life cycle the more updates you have to make. This really can't be taken as a sign of maturity of *new* products.
All Rights Reversed.
Microsoft itself is a major problem when it comes to security...
Let's give some credit where credit is due. Criminals are a major problem when it comes to security. Yes, it should be Microsoft's responsibility to produce a secure product, just as it should be every CIO's responsibility to make sure their deployments are secure.
But it's also law enforcement's responsibility to track down and punish those who get around -- or even attempt to get around -- any security holes.
If I build a vault, then accidentally drop the combination out on the street, you're still breaking the law if you come and steal something from it.
If I build an incredibly secure vault, and someone finds you outside it with a crowbar and explosives, you'll still get arrested even if you didn't steal anything.
Yet there's very little discussion here of what law enforcement agencies do (or don't do) to track down and punish e-criminals.
Is it a lack of faith in the ability of law enforcement?
Or an assumption that e-criminals are somehow exempt from laws guarding property?
You'd expect the police to do everything in their power to catch someone who burned down your home... why not expect the same if they crack your servers?
Microsoft's argument is "any popular OS will have viruses, so we might as well all run Microsoft software". But what we really need is a dozen substantially different operating systems with equal market share. Then, viruses will have virtually no chance of doing much damage.
As an aside, the term "Linux" itself stands for many different distributions, often with largely disjoint vulnerabilities, so several Linux distributions could make it simultaneously in the marketplace and still give people the benefit of diversity. Microsoft actively aims for standardization and a single code-base. In fact, the term "Linux" doesn't even really stand for a single OS, while, with XP, "Windows" pretty much does.
Linux will not dominate the market, and I don't think it should. But, on balance, I think we'd be better off if shared the market equally with Windows and if there were several other big players, including some that actually innovate a bit.
...you have to remember that a correctly behaving browser will presume that a file is whatever MIME type the server sends it.
Internet Explorer is the only browser I know of that tends not to trust server-given MIME-types. (IE loaded PNGs from a malconfigured server that Netscape 4.76 and 6.1 refused to touch.)
What's this Submit thingy do?
You know, I was thinking.... maybe it's within their agenda to release poor insecure applications. Everyone hates M$, and so goes out of their way to find security flaws in their programs... so they don't have to.
Think about how much money they save not having to security test their products, cuz they know that the moment it's released, it's gonna be pounded on by all the Microsoft haters. Sure, they pay the coders to fix the problems that are released in the press and submitted to them, but testing is a HUGE expense for software companies.
They have a huge market share, and are pretty locked in to the corporate desktop... do you know how much proprietary middleware there is in the corporate world for MS Word and Excel?? And large corporations, where M$ gets most of the cash, never upgrade right away, they wait until the kinks are worked out (usually a couple years - Certain parts of the NASD was still using Windows 95 in 2000!). Thus all the individual users and hackers have already pounded the crap out of the software for them.
All I'm saying is, it may be purposeful? Thoughts??
"BadTimes will make you fall in love with a penguin" - Laika
I'll probably be quoting that somewhere, if you don't mind.
You're right of course - all I was trying to say was that only testing the finished software product, and only then by usage testing, is a poor development methodology. I wasn't intending to imply manufacturing does do that either, just that in my mind a manufacturing process has a more concrete 'finished product' - I get the impression you might have some ties to that part of industry :)
It's interesting to read in Writing Solid Code that before the practices in the book were made standard across MS, they had products cancelled because of runaway buglists. The book was published a few years ago now, so all current products were theoretically built using those methods, yet there are still some pretty fundamental mistakes being unearthed - use of a good libc would expose a lot of the buffer overrun problems that IIS has had, for example.
"don't fall into the fallacy of believing that Perl can solve social problems. Maybe Perl 6 can, but that's a ways off"
Let's see... The very first release of the Linux kernel was introduced in 1992. Windows 3 was released in 1990.
Of course, that's not a very fair comparison -- Windows 3.1 had much more functionality than Linux 0.01, and came from an older code base including DOS and earlier versions of windows.
Someone else has already addressed the falsity in the comparison of number of service packs.