2016-08-18

secring-3 notice

@sohorouter : flight, mon, xw, ops, sn

2015-05-26

man stelle nicht die gretchenfrage

woher weisst du, wer du bist?


workflow: snipping tool, paste slack, copy image, paste here


expansion pattern

2014-12-20

society, veganism: war.



 I strongly affirm the value of the “public intellectual” who can illuminate key issues and controversies of the present day, communicate these in clear and compelling terms to a wide audience, and precipitate critical thinking, education, and progressive social change.' -- best

2014-12-05

ein gedanke zu Vortrag Prof. Dr. Kruse: Zukunft von Führung "Kompetent, kollektiv oder katastrophal?"

sehr feine sache;

mit bedachtnahme auf   und unterstellung, dass ein system auf 2 (operating-system) saeulen aufzustellen ist - cortical vs limbisch erscheint mir analogie fuer eine solche erfolgsstruktur - sollte auch auswertung guenstigerweise gesplittet sein. ~ t=56:42 zeigt das genau nicht, womit evtl lebensnotwendige potentiale unterdrueckt werden.


----
https://hbr.org/2012/11/accelerate - John P. Kotter

----


.

r20141205 evs

context:
*Preparations for 5th EVS wave in 2017 started*

The preparations for the 5th wave of the European Values Study started with the formation of a theory group and a methodology group who will prepare the master questionnaire and guidelines for fieldwork in 2017.
inbound 
mit tools, wie sie hier http://youtu.be/nDhwsNyWdVA?t=39m57s (ab punktgenau / 2 minuten/, ganz anzusehen kein fehler) gezeigt werden
keywords: europaeische wertestudie
refs:
kontakt: EVS@uvt.nl

2014-11-14

open social devices


durch raufheben von http://www.h-online.com/open/features/From-open-source-to-sourcing-openly-1434057.html if it's top-down, it's a business. https://www.movements.org/ [[ betrachte / vergleiche die 'device-manufacturers' global2000, greanpeace, rotes kreuz, amnesty international, wwf, vierpfoten, vgt, ..u dann rueber zu WAFF, AMS, OeGB, AK,.. ]] // laufende bedarfsentstehung (service-requests) drueckt die organisationsform hoeher. eine organisationshuelle, die ihr dasein bewerben muss um dienlich zu sein.. ist ein einkaufsmanagementproblem. buendelungseffekt kann gut sein, kann aber auch zu viel kosten und buerokratie (als gruppe) erzeugen. // [decision management] strikte serviceorientierung muss sich selbst 'vermarkten' {d.i.: gelebte demokratie, weil eine gemanagte idee handlung ausloest; i ggs z abstimmung loest kreativitaetsverwaltung aus}

2014-10-07

wip v editor platform

ja, interessant, aber nur loesbar, wenn man nochmal zuruecksteigt, hinunter (manche: hinauf, im fraktal: hinueber, ref: abbildungsmethoden in der darstellenden geometrie) auf die konzeptionelle ebene, um dort die basis abzusichern

netzwerk
    wikipedia-artikel =^ context
    spinne von zusammenhaengenden gedanken
        mit querverweisen .. hypertext
            =^ fraktale skelett-struktur ::abstrakt
                mit zeitachse (history of edits)
  • auf video clips uebersetzt
  • ‘in permanent editor mode’ ..dh,

- player == dev-env

mit version-tree datastru sidebar

-> analog atom representation (auf video-editor-sprech zu uebersetzen, wie nennt man denn sowas in der video-editor software? .. die sub-clip-partikel vor/waehrend der montage?


antwort:
damit die relevanten tests entdeckt werden koennen muss die konzeptionelle diskussion gefuehrt werden. in diesem wettbewerb wird aber so getan, als ob das problemfeld gar nicht existierte (aus welchem grund immer. ich sag auch nicht, dass das niemandem bewusst waere). heisst aber in der konsequenz: unloesbar. so unloesbar.

herleitung der antwort:
die kommentare im artikel zeigen ja schon ungefaehr an, wie das schlachtfeld beschaffen ist.

video als medium hat ein paar aspekte anhaftend, ein ‘unpraktisches’ naturell, wenn man die wikipedia-paradigmen nicht verlassen darf.
das scheint mir nicht loesbar. die geringe verbreitung von video werte ich nur als beweis fuer zugrundeliegende widersprueche. die muessen zuerst geknackt werden, dann kommt die umsetzung und der aufbau von toolkits dran. nicht vorher.

nachdems hochkomplex ist .. ist der evolutionaere prozess, der grad lauft, die schnellste form des erkenntnisgewinns

wir bewegen uns dabei in einem geflecht aus mehreren verhaerteten fronten, die jede fuer sich genommen, in stellungskriegen engebunkert sind. das ist also als ganzes herauszuheben und woanders hin zu verfrachten (auf der konzeptionellen ebene) - oder nicht gewinnbar, egal was man unternimmt.

dafuer haben die wenigsten die energie, und jene die grad diese wettbewerbe veranstalten machen auch nur, so gut sie grad koennen. (auf roger-deutsch: habens vielleicht verstanden, oder spuerens vielleicht, aber die programme die sie anzetteln sind klar ersichtlich nicht die richtigen)

  • drum kurz
    .. die diskussion muss einmal angezettelt werden (gut, das laeuft)
    .. der ablaufrahmen muss ein gesellschaftlich breit akzeptierter sein (foerdergelder sind gut fuer initiativen - fuer den betrieb braucht es aber mehr ‘support’, ala eclipse foundation von ibm voll bezahlt, mehr commitment) .. eventuel dual-license mit kommerziellem aspekt (hosted environment)

[ kurzer exkurs: nachweis des zirkelschlusses: hier geht nix ‘profitabel’, sonst gaebe es diese arbeitsprozesse bereits; methodische innovationen sind zuerst im enterprise context leichter zu starten, und laufen dann in den offenen bereich aus - durch oeffnen der lizenzen. umgekehrt geht’s auch, aber da beginnt meist ein sehr grosser budget pot in sozial geschlossenem kreis etwas zu entwickeln, erreicht die noetige qualitaet, und ein paar der core-leut beginnen dann auch nebenher kommerzialisierung]

darum: hier hakt es gewaltig: mathe ist nicht im demokratischen feld entwickelbar.

  • aktuell setzen sich die mischformen durch: github ist verhandlungsplattform
    (test driven!! haben die wenigsten verstanden)

damit die relevanten tests entdeckt werden koennen muss die konzeptionelle diskussion gefuehrt werden. in diesem wettbewerb wird aber so getan, als ob das problemfeld gar nicht existierte (aus welchem grund immer. ich sag auch nicht, dass das niemandem bewusst waere). heisst aber in der konsequenz: unloesbar. so unloesbar.


scratchpad section

2014-02-10

gegenwart, face detection, pro & contra materialsammler


Photoshop grid
das ist zwar nimmer aktuell, aber die methode verschwindet nicht aus der welt

facebook hat face.com gekauft


Inline image 1

in kombination mit https://lambdahat.com/





2013-11-13

r20131113.tst


statt haustieren displays zu halten.. das zeug lebt, es lebt! es werden immer mehr, sie sind schon ganz nah.. duerfen auch schon im bett schlafen. (haben die router echt abgehaengt, denkt man; ah nein.. da sind welche _dran_) .. // das ist der unterschied zwischen verstehen und erleben von netzarchitekturen also. ob die werbung gelungen ist, muss offen bleiben.

2013-11-01

path / degrees of separation

Hannah Arendt: «Elemente und Ursprünge totaler Herrschaft» - YouTube
Hannah Arendt im Gespräch mit Günter Gaus - YouTube
Hannah Arendt - Wikipedia, the free encyclopedia
Walter Benjamin - Wikipedia, the free encyclopedia
Leo Strauss - Wikipedia, the free encyclopedia
Carl Schmitt - Wikipedia, the free encyclopedia
Ernst Bloch - Wikipedia, the free encyclopedia
Jürgen Moltmann - Wikipedia, the free encyclopedia
Dorothee Sölle - Wikipedia, the free encyclopedia
Ernesto Balducci - Wikipedia, the free encyclopedia
Joel Kovel - Wikipedia, the free encyclopedia
Herman Daly - Wikipedia, the free encyclopedia
Ecological Economics - Journal - Elsevier

The new entropy law and the economic process


The entropy law and the economic problem - ‎Georgescu-Roegen 

John Foster
The new entropy law and the economic process - ResearchGate on www.gobookee.org - free eBook download

http://www.researchgate.net/publication/223632694_The_new_entropy_law_and_the_economic_process/file/e0b4951d73f1818396.pdf






ps: The Worldly Philosophers - Wikipedia, the free encyclopedia (1953)

2013-10-29

arbeitersamariterbund, spenden

wer die spenden einsammelt ist nicht angegeben;


http://www.osgs.at/organisationen/arbeiter-samariter-bund-%C3%B6sterreichs 
konto ist angegeben; direkt einzahlen.

You entered:
Bank Code: 12000, Account Number: 51388914144, Country: Austria
Checks
+
Bank Code 12000: This bank code exists.
o
Account Number 51388914144: We did not validate the checksum of the account number. Either there is none, or we don't know what checksum method this bank uses.
Result
IBAN: AT041200051388914144
Paper form: AT04 1200 0513 8891 4144
BIC: BKAUATWW (Wien)
Last update of the BIC data: 28. 10. 2013 (October 28, 2013).

http://www.osgs.at ..die bankdaten sollten IBAN format haben
http://www.gemeinnuetzig.at/arbeitersamariterbund-oesterreich ditto, IBAN


edt heizsaison

rogeraaut #heizen #studenten #wellness

heizsaison - eine schleife

Elf Prozent der Studenten können sich heizen nicht leisten
29. Oktober 2013, 11:23

Wohnprobleme vor allem in Wohngemeinschaften und Studentenheimen
Wien - Elf Prozent der Studenten können ihre Wohnung nicht angemessen warm halten. Das ist eines der Ergebnisse einer am Institut für Soziologie der Universität Wien erstellten Studie. Am stärksten von Wohnproblemen betroffen sind Studenten, die in Wohngemeinschaften oder Wohnheimen leben.

http://derstandard.at/1381370219501/Elf-Prozent-der-Studenten-koennen-nicht-genug-heizen

heizen schadet der figur

http://madonna.oe24.at/gesund/Heizen-schadet-der-Figur/119056019

2013-10-28

security classifications


publishing










  • Assurance of service
  • Computer crime prevention and detection
  • Computer forensics
  • Computer security
  • Confidentiality protection
  • Cryptography and data protection
  • Database and data security
  • Denial of service protection
  • E-commerce security
  • E-surveillance
  • Fraud detection and prevention
  • Hacker and terrorist detection
  • Information ethics
  • Information privacy issues
  • Information security
  • Information sharing
  • Information system security
  • Information warfare
  • Integrity of service
  • Internet abuse
  • Internet security
  • Malicious code detection
  • National security
  • Network intruder prevention
  • Network security
  • Risk management
  • Safety-critical systems
  • Secure communication technology
  • Secure computer systems
  • Security control measures
  • Security policy models and mechanisms
  • Software and hardware architectures
  • Transaction security
  • Unauthorised access protection
  • Virus/worm controls
  • Wireless/mobile network security

web hacking classification









































Threat classification



Classes of Attack

Authentication
The Authentication section covers attacks that target a web site's method of validating the identity of a user, service or application. Authentication is performed using at least one of three mechanisms: "something you have", "something you know" or "something you are". This section will discuss the attacks used to circumvent or exploit the authentication process of a web site.
A Brute Force attack is an automated process of trial and error used to guess a person's username, password, credit-card number or cryptographic key.

Insufficient Authentication occurs when a web site permits an attacker to access sensitive content or functionality without having to properly authenticate.

Weak Password Recovery Validation is when a web site permits an attacker to illegally obtain, change or recover another user's password.
Authorization
The Authorization section covers attacks that target a web site's method of determining if a user, service, or application has the necessary permissions to perform a requested action. For example, many web sites should only allow certain users to access specific content or functionality. Other times a user's access to other resources might be restricted. Using various techniques, an attacker can fool a web site into increasing their privileges to protected areas.
Credential/Session Prediction is a method of hijacking or impersonating a web site user.

Insufficient Authorization is when a web site permits access to sensitive content or functionality that should require increased access control restrictions.

Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization.

Session Fixation is an attack technique that forces a user's session ID to an explicit value.
Client-side Attacks
The Client-side Attacks section focuses on the abuse or exploitation of a web site's users. When a user visits a web site, trust is established between the two parties both technologically and psychologically. A user expects web sites they visit to deliver valid content. A user also expects the web site not to attack them during their stay. By leveraging these trust relationship expectations, an attacker may employ several techniques to exploit the user.
Content Spoofing is an attack technique used to trick a user into believing that certain content appearing on a web site is legitimate and not from an external source.

Cross-site Scripting (XSS) is an attack technique that forces a web site to echo attacker-supplied executable code, which loads in a user's browser.
Command Execution
The Command Execution section covers attacks designed to execute remote commands on the web site. All web sites utilize user-supplied input to fulfill requests. Often these user-supplied data are used to create construct commands resulting in dynamic web page content. If this process is done insecurely, an attacker could alter command execution.
Buffer Overflow exploits are attacks that alter the flow of an application by overwriting parts of memory.

Format String Attacks alter the flow of an application by using string formatting library features to access other memory space.

LDAP Injection is an attack technique used to exploit web sites that construct LDAP statements from user-supplied input. 

OS Commanding is an attack technique used to exploit web sites by executing Operating System commands through manipulation of application input.

SQL Injection is an attack technique used to exploit web sites that construct SQL statements from user-supplied input.

SSI Injection (Server-side Include) is a server-side exploit technique that allows an attacker to send code into a web application, which will later be executed locally by the web server.

XPath Injection is an attack technique used to exploit web sites that construct XPath queries from user-supplied input.
Information Disclosure
The Information Disclosure section covers attacks designed to acquire system specific information about a web site. System specific information includes the software distribution, version numbers, and patch levels. Or the information may contain the location of backup files and temporary files. In most cases, divulging this information is not required to fulfill the needs of the user. Most web sites will reveal a certain amount of data, but it's best to limit the amount of data whenever possible. The more information about the web site an attacker learns, the easier the system becomes to compromise.
Automatic directory listing/indexing is a web server function that lists all of the files within a requested directory if the normal base file is not present.

Information Leakage is when a web site reveals sensitive data, such as developer comments or error messages, which may aid an attacker in exploiting the system.

The Path Traversal attack technique forces access to files, directories, and commands that potentially reside outside the web document root directory.

Predictable Resource Location is an attack technique used to uncover hidden web site content and functionality.
Logical Attacks
The Logical Attacks section focuses on the abuse or exploitation of a web application's logic flow. Application logic is the expected procedural flow used in order to perform a certain action. Password recovery, account registration, auction bidding, and eCommerce purchases are all examples of application logic. A web site may require a user to correctly perform a specific multi-step process to complete a particular action. An attacker may be able to circumvent or misuse these features to harm a web site and its users.
Abuse of Functionality is an attack technique that uses a web site's own features and functionality to consume, defraud, or circumvents access controls mechanisms.

Denial of Service (DoS) is an attack technique with the intent of preventing a web site from serving normal user activity.

Insufficient Anti-automation is when a web site permits an attacker to automate a process that should only be performed manually.


Insufficient Process Validation is when a web site permits an attacker to bypass or circumvent the intended flow control of an application.