Tuesday, July 7, 2009

National Security & Intellectual Property

I am rarely willing to accept conspiracy theories, except maybe the assassination of President Kennedy only because it is highly improbable that a man like Lee Harvey Oswald with the rifle he used could hit a person in a moving car from such distance. Therefore, I do believe in Lee Harvey Oswald's claim that he was "just a patsy" and reckon that Jim Garrison was onto something real after reading his book entitled "On the Trail of the Assassins: My Investigation and Prosecution of the Murder of President Kennedy."Unfortunately, his trails ran cold. We may never find out the truth.

Two days ago another story broke with a whiff of conspiracy. Compared to President Kennedy's assassination, the event seems minor, but appears to fascinate many in the business of stock trades. The incidence was first reported by Tyler Durden in his post on Zero Hedge and Mathew Goldstein in a post on Reuters.

Sergey Aleynikov worked as a programmer in a supervisory function for Goldman Sachs Group Inc. on an application that allows the firm to execute stock trades within milliseconds. The application is known as low latency or high frequency trading (HFT) platform. About a month ago, he started a new post with a start up company for three-times his salary at Goldman Sachs. Before he left Goldman Sachs, he transferred a large volume of files with program code from his computer at the firm to a server in Germany. He encrypted the data and attempted to obscure the transfer.

Weeks later IT security at the firm found out about Sergey's actions and reported the purported "theft" to the FBI. Sergey was arrested last Friday and was freed on $750,000.- bail yesterday, according to Martha Graybow's report on Reuters today. Furthermore, Brent McCool reports on Reuters that U.S. prosecutor Joseph Facciponte told the court in Saturday's hearing of Aleynikov's case that the program in the hands of competitors could cost Goldman Sachs millions. The firm's bearing appears to lend extraordinary importance to what could be just a blatant case of a programmer sloppiness, leaving ample room for speculation about the company secrets that may be contained in the "stolen" files. Conspiracy theories begin to blossom.

Sergey claims in his defense that he intended to copy only opensource files free for anyone's use, but may have included proprietory files inadvertently. He routinely downloaded such files to work on them at home. He did not believe that his actions breached his contract. 

Goldman Sachs is a leader in the business of computed millisecond stock trades, reaping great profits from the transactions. The business is highly controversial because of its considerable impact on the market and its potential of market manipulation. When huge volumes of stock are moved in such short time, fortunes are made and lost before anyone without such fast access can respond. The market changes faster than the trader on the floor can pick up his phone. Critics loath Goldman Sachs for their advantage and surmise that the firm is manipulating the entire national economy in its favor with its fast trades. Hence, some hope that this incident may uncover information that precipitates Goldman Sach's demise. Others elevate Sergey's actions to a case of industrial espionage that may endanger national security, since he transferred sensitive information abroad. Hence, Sergey's purported crime quickly garnered intense media attention in recent days.

I see two possible explanations for Sergey's actions:
  1. either Sergey truly did not understand what he was doing when he transferred the data, 
  2. or he knew exactly what he was doing, but acted that way in order to be able to claim that he did not know what he was doing,once the data transfer was discovered.
Finding out whether he shared the data with third parties and with whom may provide an answer. The download history should be retrievable from the server in Germany he uploaded the files to. Moreover, anyone who was going to use the files needed Sergey's encryption key.

Furthermore, I reckon that even if third parties got hold of the files, the data would be of limited use to them. Direct implementation is impossible, since the program is dependent on file libraries stored in company-localized systems and needs access to company-specific data bases. In addition, you would have to be situated physically close to the New York Stock Exchange in order to achieve the necessary velocity in data transfer.

Data is transferred across the internet via nodes. The fewer nodes the data has to travel, the faster the transfer. Physical distance adds nodes. Even if a firm in Europe could fully implement Goldman Sachs' program, they would not be able to beat the firm's trades because of the difference in the number of nodes.

On the other hand, if you were installed on Wall Street, close emulation of Goldman Sachs' trading program would be discovered swiftly, and the perpetrator would have to face costly litigation over patent infringements.

Perhaps the third party could examine the strategies and methods used in the programs in an attempt to develop superior ones. I was told that this was an undertaking bound to fail because of the sheer endless lines of code that have to be studied closely and the enormous complexity of such program. Perhaps, savants could run tests on the program to discover vulnerabilities that own programs could exploit to edge out the Goldman Sachs trades. Perhaps, they could uncover the secrets of the decision making engine. I assume you need considerable expertise in the field of fast trade programs in order to accomplish these goals.

The above limitations leave one other possibility that has been suggested as the most likely scenario. Sergey copied the code files for the programs in whose development he was most intimately involved to use them as reference in future work on his new job. 

Hence, Sergey's "crime" may consist of nothing more than a misinterpretation of clauses in his job contract and does not merit the media attention it attracted. I find it astounding that a firm like Goldman Sachs was not taking more precautions against such data misuse by employees, particularly when the employees are known to move on to a potential competitor. You only have to monitor the users' shell history and the syslog files. After all, the possibility remains that company secrets vital to the firm's mode of operation are included in the files Sergey knowingly or inadvertently transferred.

We shall find out more. Stay tuned.

Related Posts

Addenda
  • On a funny note, according to Nick Carey's post on Reuter's yesterday a business school professor concluded that Sergey's brain told him to transfer the files. Surprised (07/09/09)?
  • Introducing his latest thriller novel on reckless computer-assisted global financial crime, Robert Harris gave a remarkable interview to Steve Inskeep for National Public Radio's Morning Edition today. The author concludes the interview with the title "'The Fear Index': A Hedge Fund Frankenstein" in reference to the power of networked computers executing high-speed financial transactions that “they are not alive in any recognizable sense, and yet in a strange way, (they are) determining our existence, and (they are) also slightly outside human control. I mean, one cannot see any world leader who has got a grip on the financial markets these days. They're too big, too fast. I think that's quite scary (02/06/2012).”
Acknowledgment
I am grateful for the insights of the coding experts posting comments on Zero Hedge. They helped me better understand the issues involved.

Wednesday, May 13, 2009

Negative Equity, Recovery & Mobility

Les Christie reported in his post for CNNMoney dated May 6, 2009, that according to a market analysis published on Zillow.com about 22 percent of American homes were "underwater" at the end of March. That is, in today's market the value of these homes is less than the outstanding balance on their mortgages. Home owners may wonder, how long recovery may take. The calculator below provides an estimate, regardless of the price of the home. The default entries are explained in the next paragraph. You may replace them with your own data:

Interests:
%
Appreciation:
%
Depreciation:
%
years.
 © You may donate for further development through PayPalhere.

Suppose we bought a home with a down payment of 20 percent and a 30-year mortgage at 5.92% APR two years ago. According to a report on RealEstateabc.com, the annual rate of appreciation for American homes has been on average 6.34 % over the past 40 years. This value seems high. Local rates may be lower. According to my own observations over the past 10 years, and these were years of unprecedented economic growth where I live, property values have appreciated at 5.7% annually. The rate may be substantially less in current circumstances.

Be it as it may, let us take the optimistic view and enter 6.34% as annual appreciation rate in the calculator as default. If we lived in an area of the country hardest hit by the recent slump in the real estate market, our new home may have lost half of its value since we bought it. That is, its value depreciated 50%. According to the result calculated above, we need to keep this home for 21 years to recoup our loss. As a consequence, mobility loses its luster. Many home owners may choose to stay put.

Addenda
  • According to The Economist's daily chart post dated Aug. 21, 2009, Deutsche Bank's securitization team estimates that roughly every second American home with a mortgage will be underwater in 2011 (08/29/09).
  • Lisa Lambert reports in her post on Reuters dated Sep. 17, 2009, that another wave of troubled mortgages is about to ensue, potentially unleashing more foreclosures. That is, adjustable rate mortgages with payment options are beginning to reset in large numbers burdening home owners with ever higher cost. In Arizona alone, 128,000 payment option ARMs will adjust to higher rates within the next 12 months. In the meantime, the unemployment rate rose to 9.7 percent nationwide according to the Bureau of Labor Statistics (09/19/09).
  • According to Les Christie's report entitled "Nearly 25% of all mortgages are underwater" on CNNMoney yesterday, First American CoreLogic estimated that home values are still dropping under the value of their mortage. The company found that in the last quarter of 2009 mortgages on homes underwater increased by one percent to 10.7 million (02/24/10).




  • M.P. McQueen's post with the title "The New Rules of Remodeling" for the Wall Street Journal dated Apr. 24, 2010, confirms my prediction on rising immobility. Remodeling seems a good idea. Let us benefit from tax credits and put some energy efficient insulation in our home. Let us upgrade kitchen appliances and make our home a nicer place to live, because we may stay in it for a long time (04/28/10).
  • While modifying my calculator after one reader's cogent comment, I noticed that in the parlance of the Goldman Sachs bankers who testified before Congress two days ago our home, looked at as an investment, definitely qualifies as a very long sale. The banks, however, sold our mortgage short. Our mortgage was sold to Citigroup two years after we closed on the home. Since we could keep up with our payments, it probably ended up buried in tranche A of one of those sh***y CDO's alluded to in the hearing (04/29/10).
  • According to Conor Dougherty's report entitled "More Americans Moved in '09, but Not Far" in today's Wall Street Journal, the Brookings Institution estimates a state-to-state mover rate of 1.6 percent for 2008 and 2009, constituting the steepest decline in interstate migration since the Great Depression (05/10/10).
  • You may wish to listen to some homeowners whose diminished home value considerably affected their mobility in Yuki Noguchi's report on National Public Radio's Morning Edition today entitled "Devalued Homes Anchor Prospective Job Seekers" (08/26/10).
Related Posts

Tuesday, April 7, 2009

Windows 7, Qemu & the Internet

I decided to participate in Microsoft's testing program for Windows 7 earlier this year. I downloaded the 32- and the 64-bit installation package iso-images from Microsoft's website. I envisioned to test the next generation Windows operating system as guest in a qemu emulator (version 0.9.1) using Ubuntu's Hardy Heron 8.04 as the host operating system. Hardy Heron is installed on a MSI K8T Master 2FAR motherboard with two AMD Opteron 242 CPUs and 4Gb of RAM. Binary versions of qemu compiled as applications for for Apple's OS X are available from Q. The installation of Windows 7 should not be different. Below I describe what needed to be done to render a successful installation.

KQEMU INSTALL
To install kqemu on the host, I essentially followed instructions provided on the ubuntu community documentation site here and on alien.slackbook.org here. Microsoft recommends to provide at least 16 Gb for Windows 7. I decided to create a raw image of 20 Gb and reserve 1024 Mb for RAM, that is the maximum qemu allows, in the /home directory for the guest, running the following command in the terminal:
  • qemu-img create -f raw windows7.img 20G

WINDOWS 7 INSTALL
I used the following command to install Windows 7 on the raw image:
  • qemu-system-x86_64 -localtime -net nic,model=ne2k_pci,vlan=0  -net user -m1024 -cdrom './windows7.iso' -boot d windows7.img
I repeatedly attempted to use the 64-bit version of Windows 7 without success. Each time, the installation process halted with a blue screen below.


By contrast, I was successful with the 32-bit version. The install went smoothly. I could login and test the applications. However, I could not connect to the internet. The internet icon in the bottom panel was crossed out. The problem solver suggested that the proper driver was not found. I was asked to provide one. The reader is advised to review the experience I recount below to the end.

INTERNET
I examined numerous threads on drivers for windows and qemu over several weeks. By default, Qemu provides an ethernet interface that uses the Realtek RTL8029 driver. This is a legacy driver that Realtek no longer supports. I found an installable driver v5.08 here.

Installing, the RTL8029 driver resulted in limited connectivity with no internet access. Advice on a windows help forum suggested that this problem may be solved with disabling the firewall. It did not work.

On my continued quest for solutions, I found the following suggestions:
  • Under Properties for the Driver found in the Network and Sharing Center, click Local Area Connection, uncheck the Internet Protocol Version 6 (TCP/IPv6) option.
  • Click Start in the bottom panel,
  • type regedit in the Search programs and files box, and click on regedit in the list.
  • If you are prompted for an administrator password or for confirmation, type your password, or click Continue.
     
  • Locate and click the following registry subkey: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip4\Parameters\Interfaces\{GUID}. In this registry path, click the {GUID} subkey that corresponds to the enabled ethernet interface. 
  • On the Edit menu, point to New, and then click DWORD (32-bit) Value.
  • In the New Value #1 box, type DhcpConnEnableBcastFlagToggle, and then press ENTER.
  • Right-click DhcpConnEnableBcastFlagToggle, and then click Modify.
  • In the Value data box, type 1, and then click OK.
I added one more step:
  • Locate and click the following registry subkey:
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{GUID}
  • On the Edit menu, click on New, and then on DWORD (32-bit) Value
  • In the New Value #1 box, type DhcpConnForceBroadcastFlag, and then press ENTER.
  • The Value data box remains set to: 0.
  • Close Registry Editor.
Note a DhcpConnForceBroadcastFlag value of 0 disables this registry entry. You can use this registry entry to prevent Windows from using the DHCP BROADCAST flag. After you set this registry entry, Windows never uses the DHCP BROADCAST flag.

Taking these steps did not render the ethernet connection with the RTL8029 driver functional either. Eventually, I disabled DHCP and entered the static IP addresses proposed on ubuntu's community documentation site manually:
  • qemu-emulated Windows 7 I.P. address: 10.0.2.15
  • Gateway address: 10.0.2.2
  • SubMask address: 255.255.255.0
  • DNS Server address: 10.0.2.3
Disabling the DHCP server did not help either. At that point, I concluded that connecting to the internet was not going to work with the legacy driver. Instead, I found here that recent versions of qemu may support the rtl8139 driver, though warning was given that this option would not provide any connectivity. Despite, restarting qemu with 
  • qemu-system-x86_64 -localtime -net nic,model=rtl8139 -net user -m1024 -cdrom './windows7.iso' -boot d windows7.img
produced a working connection to the internet, miraculously automatically. The system loaded the RTL8139C+ Fast Ethernet NIC driver from its own driver directory. The interface uses DHCP and found the correct IP addresses. I did not have to edit anything manually. The pre-installed driver can be replaced with the most recent driver from Realtek for Vista 64 and Vista bundled in the newest auto installation program (Submission ID: 1310628).

Further experimentation showed that the RTL8029 driver can be used as well. Once specified on the Qemu command line with the "-net nic,model=ne2k_pci" option, Windows 7 will load the RTL8029 driver, if it has been previously installed in the system's driver directory and configure an ethernet connection. The same will happen, when you start qemu with the default option "-net nic".

A crucial prerequisite for Windows 7 autoconfiguration to work successfully is that the RTL8029 driver must have been installed beforehand, because the driver is not included in Windows 7. By contrast, if RTL8139 is specified with the qemu command, the system loads the RTL8139C+ Fast Ethernet NIC driver pre-installed in Windows 7.


IE 8
Finally, I was ready to install the latest updates from Microsoft and test applications. I remain unimpressed with the Internet Explorer (IE) 8. This browser denies access to sites like this blog which are perfectly accessible with older versions of IE, Google Chrome, Firefox, Opera, Safari, and Seamonkey. IE 8 help does not suggest any precise actions to remedy the problem. Hence,
I opted for Google Chrome instead.

SHARED FOLDER
To access a shared folder on the host system, kqemu must be started with the following command in the terminal:
  • qemu-system-x86_64 -localtime -net nic -net user -m1024 -boot c windows7.img -smb /home/user/qemu_share
In order to access the qemu_share folder from Windows 7, the folder's permissions must be set for sharing on the host. In Windows 7, the folder can then be mounted following the sequence below:
  • Click Start in the bottom panel, choose Computer,
  • right-click Network and choose Map Network Drive...,
  • enter \\10.0.2.2\qemu_share on the folder choice line,
  • choose Reconnect at logon,
  • and click Finish.
SOUND
Qemu provides several options for sound hardware, the only option Windows 7 recognized on my setup was:
  • -soundhw es1370
Ensoniq's ES 1370 technology dates back at least ten years. I found an acceptable driver on the Ensoniq support site. The driver installer location can be accessed, using the following path:
E-MU Legacy Hardware support
Audio PCI
PC
Windows 3.1 Driver Version 3.30.06.

Alternatively, you may wish to download the driver installer directly here.

The driver's setup wizard refused to fully install the software. Intriguingly, the following Windows 7 update detected and upgraded the ES 1370 driver, I needed to set the variable QEMU_AUDIO_DRV in my environment. Which drivers are supported depends on your host operating system. The options can be reviewed with qemu -audio-help. I chose alsa. Therefore, the launch of the emulator must be preceded with the comands :
  • export QEMU_AUDIO_DRV=alsa
  • export QEMU_ALSA_DAC=dmix
  • export QEMU_ALSA_ADC=null
Though I turned up full volume in all controls, the speaker sound remained exceedingly attenuated. The problem does not reside with the host. My Windows 2000 XP system emulated with the same qemu version produces great sound. This shortcoming still remains unresolved.

RUNNING WINDOWS 7
At this point, the complete command line to boot Windows 7 on kqemu includes the following options:
  • qemu-system-x86_64 -localtime -net nic -net user -m1024 -boot c windows7.img -smb /home/user/qemu_share -soundhw es1370
I recommend to save this command line in an executable shell script. The blue screen still erratically pops up during boot. The system will boot up after a couple of tries.

Addenda
  • I applied the same procedure to successfully install the release candidate that became available for download on May 5, 2009. Reboot does not always work during installation. You may have to go through a number of lengthy repair routines that Windows suggests and be patient. Eventually, it will work (05/10/09).
  • I recently upgraded Ubuntu to Karmic Koala (9.10). This upgrade comprises a new version of qemu (0.11.0), changing the available options. With the new version, I can run the emulator with two central processing units, that is -smp 2. More types of emulated ethernet cards are available. As a consequence of the update, windows 7 uninstalled the rtl8139 ethernet driver after the next boot. I had to re-install the system-provided drivers with the Device Manager (Control Panel & System and Security & System). For sound, the es1370 option is still listed following the command qemu -soundhw ?. However starting qemu with this option now fails. I am investigating (11/28/09).
  • The sound problem is unrelated to qemu. After I removed the environmental variables for alsa from the start-up script, windows 7 recognized the virtual ensoniq sound card and installed the es 1370 driver. The loudspeaker icon on the bottom menu bar of windows 7 turned unstruck, indicating active sound. However, no sound is to be heard yet. The environmental sound variables many need to be set differently in Karmic, possibly because Karmic appears to use pulse audio instead of alsa by default. I am investigating further (12/22/09).
  • If pulse audio is used for sound, the above environmental sound variables must be replaced with: QEMU_AUDIO_DRV=pa (04/15/10).
  • The download link on www.softwarepatch.com for the RTL8029 driver provided above does not seem to work at times. I found an alternative at www.techspot.com here (08/03/10).
  • Because of recently exploited vulnerabilities, the use of the RTL8029 driver is highly discouraged. You may wish to read more here: The Stuxnet Worm, Windows & The Internet (09/29/10).
  • For those who are not obligated to use qemu as emulator, I am pleased to share that I have had great success with installing and running Microsoft Corporation's Windows 8 Consumer Preview (64 bit) on VirtualBox 4.1.10. VirtualBox is emulation freeware maintained by Oracle (formerly Sun Microsystems). The installation proceeded without impediments. I followed the suggestions for the best suited settings, and made sure that no warnings remained, before I started the installation. Red triangles alert to sub-optimally selected parameters in the settings pulldown menu. The most important choice may be to dedicate no more than half of the RAM installed in your computer to emulated base memory, even if the Windows operating system can be used with more. Since I installed the system on an old Apple MacBook (2.26 GHz Intel Core 2 Duo; OS X Snow Leopard, version 10.6.8) with only 2 GB DDR3, I limited the base memory to 1 GB. In addition, I limited the emulator video memory to 128 MB. I dedicated 20 GB to static disk storage, choosing the vmdk-format. With these settings the emulated operating system performs astonishingly well. Internet access is flawless. The virtual machine is accessible on our home network. For installation, I used the downloaded iso-image of Windows 8. Therefore, I had to make sure that the CD/DVD drive option pointed to the image for the initial boot. The image can be selected under the disk icon on the bottom bar of the virtual box or from the pulldown settings menu. Good luck (03/28/2012)!
Screenshot of VirtualBox running Windows 8 on virtual machine (Read more here).



Related Posts