03 September 2009

When do you Look Out? It really Matters

The world throws out enough of case studies and sometimes it will stunning that you happen to learn each minute. Only thing that one needs to do is to be open. One of my friends/classmates shared his experience and here it goes. Sometimes, the mangers, who in the name of leveraging or delegating mess up with things. The real shortsightedness makes them so vulnerable without they knowing that they are vulnerable. It is very pathetic and for an outsider it is quite evident. The delegation of your delivery cannot happen across teams but you can always leverage. But when you are leveraging one needs to know what is being leveraged and the risk involved in the leverage.

One risk that comes with leveraging is sudden spike of advantages - immediately you will have advantages however you will not have the experience that comes with building the advantage. But when you leverage you are going against the nature and evolution. In this world, the advantages brought by evolution is relatively stable. When we leverage and if we do not know the associated risk, it is like crossing a free way - you may luckily get away but you may also get crashed. So, the managers need to use "leveraging" as getting to a place fast but always should invest time in getting something organically. Always organic is good. When you look out is more important. If you look out for something which you need to build in-house, the end results will be tragedy. So, always (or most of the times) do not look out for leveraging. If it takes hard work to do, just do it as the hard work will strengthen the system further.

What you are leveraging, when you are leveraging and the associated risks have to be studied before leveraging. Don't leverage something which takes only few minutes to think/build. (It sucks).

02 September 2009

Informative Talk on Entrepreneurship

It took me 29 and odd years to understand that simplicity and modesty is the way to start. I was fortunate to attend a talk by Mr. Raju Venkataraman, a serial entrepreneur at IIT Madras, Chennai. He was talking about entrepreneurship and qualities. When to take risk, how to take risk and how to sustain the own venture talking examples from his life. He quoted in many places about Tata, Ambani, Gates, Steve Jobs and many others.

During his talk one thing that stood out was his - simplicity and modesty. He quite often connected the dots and making the participants to know the unknown through known simple principles of life. He never tried to force things. When some asked a question about being ethical. Without any prejudices, he answered "being ethical" is part of your value system. I would say that is an important take away for me and anyone who is trying to become entrepreneur. Apart from whole a lot of inspiration, having a value system is quite important.

Being ethical or unethical is the manifestation of one's value system. It is "ok" to rob if you are a thief because it is your value system. He doesn't mean or want us to have low value system but his point was to convey the importance of "value system". I feel that I need to spend sometime reflecting about my value system and make it "real" value system.

Great Insights.

01 September 2009

Open Source Appliances

As a follow up to my previous post, this one talks about appliances in open source. When you say appliance and immediately Linux comes to my mind. I haven't seen any other open source operating system that is widely deployed as Linux. Today, most of the appliances (watch, microwave, routers, switches and many more) are powered by Linux. Unlike general purpose computers like workstations or PC, the appliances are built for specific purpose. The appliance should be an "expert" in doing something. For example in the case of router appliance, the appliance characteristics should be throughput and performance in routing packets.

The appliance market is quite heated up and there are many small players turning the heat and screwing up big market players and industry leaders. They do not have "low cost" as their only advantage but they are in a position to give features, performance and throughput on par with industry leaders but at the half the price or even less. From here on, I believe open source appliances is going to get into mainstream and slowly open source appliance will take more market. Making open source appliance (or take it from me, it makes sense to make Linux appliance) is the way to go. The appliance also gives us a viable business model to sell products and services particularly in a developing countries like India.

31 August 2009

Where is education? Is it education Industry?

We are living in the world of commercialization where even relationships are commercialized. Education is no exception. Few years back, I was traveling to Delhi for a conference and fortunate to meet a senior person. Since Chennai to Delhi travel time is two and half hours, I wasn't sure about how to spend time. Fortunately, I happen to sit next to a senior person who is Engineer by profession but retired from service.

He was talking about present education system and commercialization of education. He felt that even the educated were falling in the trap of education industry business magnets. He said that the real education did not happen in classroom and the real education for the student was to connect the dots - ability to know the unknown through known. He said that the students of those days suffered from poor exposure and even these days it didn't improve. It is through exposure and constant practice one can become a perfect engineer. He was suggesting me that I should contribute more the society and share my knowledge with others.

Our journey ended when the flight landed in Delhi airport and he wished me for my talk that afternoon and blessed me. I cannot forget the travel and it comes to my mind today because I m so excited to architect a prolonged training for students from computers background to make them employable. I am going to put all my seven and odd years of experience in this initiative. I am going to do this through Internet with the help of web applications. I ll keep you posted and you can expect a post in a month.

30 August 2009

Java Decompiler - Reverse Engineering Java Bytecodes

For quite sometime, I have been working on reverse engineering and particularly on reverse engineering Java applications. When we say reversing, we immediately think of generating source code from the binaries. For Java too, we have a decompiler that works like a charm. The tool is Java Decompiler. Few months back, I tried using this tool for reverse engineering an enterprise web application. I did not face any issue either interpreting the output (source code) and in using the tool. It did a decent job in reversing the bytecodes.

Java Decompiler comes as three components. JD-Core is core for decompiling that has the logic for bytecode interpretation and creating source code. JD-GUI is the frontend for JD-Core. Apart from these two packages, it also has JD-Eclipse. As the name suggests, it is a plugin for Eclipse. I didn't get a chance to use JD-Eclipse. I used JD-Core and JD-GUI and recovered source code of more than 1000 class files. If you are security expert, this is one of the tools that you should have in your toolkit.

The homepage of Java Compiler can be accessed through this link.

29 August 2009

Scope for Open Source Products in India

India is pioneer in IT services and the number of products that are made and marketed in India is very little. Today, when we take IT for a commoner who wants to automate his business he often goes for a proprietary software. Multinational product companies like Microsoft typically use India as they marketplace and I feel that there are lot of market to be tapped in India as we are at early stage of computerization. When there is a rapid computerization, we need many product companies in India to serve our markets. There is a big problem with existing products - the big price tag. Neither the companies will be able to spend thousands of dollars for infrastructure nor it is sensible to buy even if they are willing to do so. Even if you have open source products, again most of them are developed elsewhere in the earth and still there will be moderate price for their services. The next shift in Indian market will be commercialization of open source with an intention of serving Indian markets. We need much better service for a smaller price tag.

There are open source products available for almost everything however that needs to be customized for specific needs. This gives an opportunity to use existing open source product (for free or for a minimal through away prices) as base and pay only for services (like support or customization). Moving forward, the concept of products is going to erode and move towards services/solutions model. Within next few years, we will witness a drift towards open source products in India and there will many open source companies. The companies which understand this will be a big hit in India and potentially go global with the help of open source.

What do you think?

28 August 2009

Leadership 101 - Look Inwards

This is post can be tagged by many words - experience, confession, realization and outcome of pure hard work. Of late and after reading many books and discussing with many of my friends who are trying to make a difference and add meaning to themselves and this world. My professional experience of first six and half years is simple to summarize "I looked outwards and I failed". I was literally looking things that are materialistic and often liked by others. I was driven by lust towards accomplishment. This last half year is full of learning and learning beyond horizon. I started to look inwards and things that interests me. There are lot of questions pop out of my mind - most of them are discarded immediately, few of them are discarded after a while and I retain few things. For example, in past few months you would have found few discontinuous posts. I would have promised you that I will post something continuously but failed. These are things that I felt interesting and later realized that are not so interesting and dropped those.

But this experience has given me the required guts to take up things that I like and in the process I started to look inwards. Looking inwards (to one's self) will do a miracle and it is when one understands one's own potential. On a contrary to looking outwards which is supposed to exciting, looking inwards will be thought agnostic and thought provoking. As one of my friends said that looking inwards will generally be a slow start and then suddenly at one point of time it will lead to an avalanche effect. Look Inwards is one of the priceless lessons I learned from my friends.

27 August 2009

Reverse Engineering Java Apps

Professionally, I am a Java developer and had worked sparingly in C++ and other scripting languages. I always felt that Java is easier and with the modern day IDEs like Eclipse and Netbeans, you don't even need to know what is compilation and building and similarly you dont even need to know OOPS. As an interviewer, I always face candidates, at least handful, who do not know how to set the classpath and compile using "javac".

Java by its inherent nature is very easier than C/C++ and these IDEs make it much easier. If forward is easier then in most of the cases the reversing should also be easier (but there are exceptions like security algorithms). Unfortunately, reversing Java applications is much easier and I would say it is much easier than developing it. In the next couple of weeks, I ll be writing few posts on my experiences with reversing Java applications and my inputs on how to carry out effective penetration testing for Java applications.

26 August 2009

Most Fruitful Day

Today was a fruitful day. As I told yesterday, I needed to give a technical talk to Bank of America office at Chennai (this is Merrill Lynch office to be precise) on Security. It was raining later in the afternoon, but I had a little window when the rain stopped and started from my office around 3.15 pm. The journey to Merill Lynch took almost an hour. After going through security check (like the one in airports), I met my friend who invited me for the talk. Within few minutes we were ready for the talk.

The talk itself was very interesting to me and the audience asked me questions from basics to advanced. The management made the event lively by giving away some gifts to participants who answer questions. I felt like this was most interactive session I ever presented. I talked about Security, why it fails, myths and attack spectrum of a banking application. Due to lack of time, I cut shot the presentation by 15 minutes but overall I felt that I learned a great deal by giving this talk. I received a feedback of 3.5/5 and shows that I got to improve. During this talk, I met new friends.

On the way back to my home, I had an appointment with my college friend (who is research scholar in IIT Chennai). He was explaining me about his new venture and his business plans. We discussed about his consulting experiences, stock market, education system, social responsibility. We planned to collaborate in few initiatives that greats impact in society. I spent around four hours with him and it was quite a learning for me. We also discussed about algorithms, mathematical modeling, fiber optics, network security, open source and philosophy.

Overall, today (particularly the afternoon), went like a super fast express.

25 August 2009

Security For Thinkers - Tech Talk

Tomorrow (26-Aug-09), I will be giving a technical talk in one of the famous US banks IT department at Chennai. After reading few pages of Beyond Fear and few pages in System Thinking, I tried to put together a presentation that primarily focused on security from system thinking point of view. So many things fail or produce adverse effects due to poor understanding and security is one. The attacks that are published are only very few percentage of the attacks and many do not like to report it. We never think about how to have our software/hardware secured. It is quite a irony that an attacker who knows about our application hardly anything cracks the software in no time or in few hours.

This shows the incapability in thinking and still we are playing a catching up game. In this presentation, I am planning to give system thinking view about security, the proactive security and sensible security. Unlike other security talks, I will not be presenting or discussing about Top 10 attacks as we never know which will be in Top 10 and we cannot predict when 100th attack will move to Top 10. We need a view that protects us always. Here is what I m planning to cover.

Credits should go to my friend M.S. Rajkumar Pandian for recommending me to BoA friend. Thank you Raj. I would have been much happier if we present this talk together.

23 August 2009

Why Security Fails? - One Reason

All organizations pay huge price for security, something like running a separate department and spending millions of bucks to just secure from outdated attacks. Most of the software or devices just secure the assets from a worm that pampered few years back. We think that the attackers are naive (again and again they prove that they aren't). Why do we think that they are naive? It is simply because we never want to think differently, we never want to squeeze our brain and we don't know how to use our brain.

We focus on luxury part of life and so most of us discount ideas which needs hard work (like thinking). Thinking and productive thinking is stressful exercise and now you know why attackers keep winning. Attackers have great mindset (but obviously bad motive). But we say that our motive is good but we lack the attitude of hard work. We still think that someone's devices/products/software alone secure our assets and we fail to appreciate "thinking" is necessary to secure the assets.

This blurred view leads to "panic and patch", "let it happen, we have products to secure" situation. The situation becomes pathetic where the people are ready to offer sympathy and ouch. If you want to secure your asset, you need to be hard working thinker and build the ability to see through the system and emerge with good understanding of the systems. It is our understanding about system will secure not the devices.

So, the security fails due to poor thinking. This is going to be my topic for my upcoming talk in Chennai.