# South Lake Tahoe Caldor Fire Timelapse

Friday, September 3, 2021

Sentinalhub Playground is an excellent resource for near real time, albeit not quite google earth 1m resolution, satellite images.  One of the cool features is being able to adjust the mapping of the satellite bands to RGB outputs.  For example, using Sentinel-2 L2A image data of South Lake Tahoe between 2021-08-17 and 2021-09-01 and remapping the 2190nm (SWIR2) to red, which tends to highlight fires though isn’t thermal, 783nm to green, a vegetation band (though it is NIR to humans) to make vegetation cover more obvious, and 443nm to blue instead of 490nm as shorter wavelengths tend to be scattered more by aerosols and smoke the fire line (bright red) and smoke (obvs) is very visible while vegetation is (false) green. Burnt earth shows as dark red, compared to bare ground, which tends to show tan in this mapping, thus revealing the current line of fire, the recently burned areas, and the wind direction carrying smoke, which tends to correlate with the advancing line, and fuel (vegetation) still standing.

Then using the history controller to generate and save a sequence of stills, we can animate the progress of the fire with a simple FFMPEG command:

ffmpeg -framerate 1 -pattern_type glob -i '*.jpg' -vf crop=1754:1146 -c:v libx264 -r 30 -pix_fmt yuv420p fire.mp4


and you get:

# Merry Christmas from Gaylords

Wednesday, December 24, 2014

# Cat day

Tuesday, October 29, 2013

Happy cat day.

# 28C3 Scariest Talk of the Day

Wednesday, December 28, 2011

We attended Effective Denial of Service attacks against web application platforms by Alexander “alech” Klink and Julian | zeri where they described a really, really easy to implement denial of service attack that exploits an artifact of hash checking which is computationally intensive when the hash table is filled with hash collisions. It is fairly easy to find 2-4 character hash collisions for a given hash functions (and there are only a few variations in use) and as hash operations are performed by default on all POST and POST-like functions, which take (by default) from 2-8MB of data, one can easily tie up a computers CPU effectively indefinitely.

The researchers tested the attack on most web languages in use (and all in common use – only Perl is deployed safe (since 2003) and Ruby 1.9 has a patch available. Every other OS is vulnerable. Today. The attack is only a POST option with a table of delimited hash collision values. You could copypasta a working exploit, it is that easy. The vast (vaaast) majority of sites on the web run PHP, and 1 Gbps of attack vector bandwidth could take down 10,000 cores. With ASP.NET, that 1 Gbps can hold down 30,000 cores cRuby 1.8 (not patched, about half of Ruby installs): that 1 Gbps can keep a million cores tied up.

Yow.

# A Very Energetic Band at Borgo a Mozzano’s Halloween

Thursday, November 3, 2011

This band was playing a small stage along Via Roma at Borgo a Mozzano’s Halloween festival.   I haven’t been able to figure out their name yet (will update when I do).  The singer managed to put out an amazing amount of vocal power from such a small frame.

# Halloween at Borgo a Mozzano

Wednesday, November 2, 2011

Borgo a Mozzano hosts the biggest Halloween festival in Italy and this year was the biggest yet. The streets were so packed with people it was almost impossible to move in some places. There were at least 8 stages, each hosting several different bands through the night playing all sorts of music from heavy metal to gypsy punk to polka, but one of the best was the marching band which had our town butcher out dancing with a cows head.

# Lucca Comics and Games 2011

Tuesday, November 1, 2011

Lucca Comics and Games is a bit like Comic-con except in a medieval walled city, which goes well with a lot of the costumes.

World of Warcraft?

# Passaggio del Terrore

Monday, October 31, 2011

The first night of Halloween at Borgo a Mozzano (it is a 3 night extravaganza here), we visited the famous Passaggio del Terrore. The highlight was seeing the owner of our local hardware store as a crazed psychopath.

# Miscreants of Taliwood Free Tonight

Wednesday, February 24, 2010

Carolyn and I saw the Miscreants of Taliwood at the Telluride Film Festival last September and had an opportunity to talk with the director, George Gittoes. We felt the movie was an important record and George an important resource for the people we work with in DC and arranged to have him come for a screening.

Miscreants is the only western film by the only western observer in the Tribal region of Pakistan along the Afghan border during the tumultuous period starting with the siege of the Red Mosque/Lal Masjid in June of 2007 and including the assassination of Benazir Bhutto.

This is a unique document, the sole direct, ground-level view of the geographic heart of Taliban ideology and a core operations center for Al Qaeda. Further, the opportunity to speak with Gittoes is particularly exceptional as his two years in the region were marked by extraordinary encounters that he was unable to incorporate into his documentary because “when people are pointing guns at you, taking out your camera gets you killed.”

We are screening it tonight, Wednesday, February 24th at 8pm at the Letelier Theater at 3251 Prospect Street, NW (upper courtyard – above Café Milano) Wash, DC 20007 202-338-5835. Admission is free. A parking garage is located between Café Milano and Café Peacock.

There will be a Q & A with George Gittoes immediately following the screening.

# 26c3 Berlin

Thursday, December 31, 2009

26c3 was a blast, as was Berlin. It’s a good conference in the olde school hacker style: mostly younger people, mostly wearing black. There weren’t a lot of women, but Carolyn, Isabella, and Meredith tried to even out the ratio a bit.

Some of the best lectures included one by some German engineers working on the lunar x-prize. They had their prototype rover with them and gave a great talk about the various challenges.

Another great one was Dan Kaminski’s talk on PKI. I don’t agree with the premise that SSL should be a reliable method for identifying the owners of websites as people just can’t tell the difference between bankofamerica.com and bancomerica.com and so it doesn’t make anyone safer if the bankofamerica site is super green if bancomerica.com is also super green, and so the complexities of getting an accepted certificate simply reduce the use of secure connections and the overall security of the internet. But he had some pretty great attacks on the security of SSL that causes problems no matter what.

We enjoyed fuzzing the phone as well. It was a very entertaining talk on attacking phones with crafted SMSes. The method of creating the attacks was very clever – rooting the phone, redirecting the radio to a wifi link to a CPU so they could try zillions of SMS and see what would happen. In the process they discovered they could remotely root the communications manager (which runs as root). And %n to specific windows phones and they’ll crash and fail to reboot until the SMS is cleared out of the inbox.

Berlin is a great city and it was fun working in the shadow of the TV tower.

We made reservations for lunch but we could tell it wasn’t going to be a great day. In the end it was a very intimate lunch with pretty clouds pressing against the glass.

The fog lifted but was replaced by snow, which is a lot of fun in a city when you don’t have to drive.

