Showing posts with label Book Review. Show all posts
Showing posts with label Book Review. Show all posts

Wednesday, 10 April 2013

Value Writ Large

For both personal and professional reasons I've been reacquainting myself with the various Windows operating systems recently and I chose Mike Meyers' tome for no other reason than it offered broad coverage of XP, Vista, and 7. However, this book proved to be far more than a Windows instruction manual and it has become one of the few books that, when I finished it, I immediately started re-reading!

I have previously been guilty of complaining that computer books are over-priced but this is clearly an exception. With a rrp of £40.99, each page (excluding Appendices & index) costs just 2.8 pence. Given the information density, illustration quality, and the fact that you are unlikely to pay the list price, this represents superb value for money.

Myers keeps the language accessible and eschews the gratuitous use of intensifiers that can make reading (and understanding) technical literature such a chore. This makes this an enjoyable (yes, enjoyable) read! Criticism is limited to Myers occasionally forgetting that the world stretches beyond the borders of the USA and a little too much advertising for his Company. Nonetheless, even if you have no intention of taking the CompTIA A+ exams, this an outstanding introduction to computing for aspiring techs or enthusiastic amateurs alike and I have no hesitation in rating it a five star publication.

Monday, 9 April 2012

The Grifters' Handbook

Kevin Mitnick, it seems, has a tenuous grasp of morality: he argues (p.xii & p.83) that it's OK to steal someone else's property if you're motivated by curiosity and your intentions are benign. I confess that I'm less comfortable with the idea of breaking in to someone's computer system and "snaring copies of files" or "searching emails for passwords" and, I suppose, that's why I think Mitnick's claim to be "a changed person" lacks credibility.

That's not to say that there's nothing to learn from The Art of Deception - far from it - only that the reality is that the book is almost certainly of more use to grifters and conmen rather than "governments, businesses, and individuals" (p.xiii). Throughout, Mitnick provides society's dishonest with templates for deceiving the unwary and his advice for preventing, detecting, and responding to information-security threats never really exceeds a, remain vigilant at all times message. Of course, security awareness among employees and individuals is a good thing, but it hardly needs 352 pages to convey such a message. Given Mitnick's rather childish style, endlessly recycled scenarios, unworkable procedures, and simplistic message, The Art of Deception is probably two-hundred pages too long!

If you really must revel in the gullibility of the masses, I suppose that you might enjoy this book. However, if you're serious about security, try Bruce Schneier's, Schneier On Security or Secrets and Lies.

Thursday, 3 November 2011

Book Review - Ghost in the Wires

Ghost in the Wires
Kevin Mitnick & William L. Simon
Little, Brown - ISBN: 978-0-316-03770-9

Gripping

In Ghost in the Wires Kevin Mitnick's pleads his case that he is (or at least, was) a "hacker" (one of the good-guys) rather than a "cracker" (a mere criminal) and, if you're interested in how easily gifted conmen manipulate their "marks", his account of being the world's most wanted hacker is a gripping read from start to finish. However, Mitnick is a gifted conman and that's the point - it is easy to be persuaded that he was a benign explorer in a virtual world who was victimised by an ignorant and fearful state, but the truth is not quite so simple.

The fact is, that Mitnick freely acknowledges committing criminal acts and he seems to have had little regard for other people's privacy or rights. Sadly, he demonstrates even less remorse for his actions. Indeed, both during and after his incarceration, Mitnick and his supporters have crafted a persona of an anti-hero - a cybercrusader who was somehow immune from the norms of decent behaviour that constrain most of society. Herein lies the shortcoming with Ghost in the Wires: whilst it is undoubtedly a wonderful account of Mitnick's exploits, it reveals little or nothing of the man or his motives. Although we are given tantalizing glimpses into Mitnick's relationships with friends and family and furnished with banal excuses that he was compelled by some "addiction" (p.40), one is left with the feeling that this is a highly sanitised history, designed to put the best "spin" on his version of events.

Nonetheless, Mitnick's treatment at the hands of the US judicial system is shocking. The unaccountable fear and paranoia demonstrated by the authorities when prosecuting him almost beggars belief and it is difficult to comprehend the impact that months of solitary confinement and incarceration without trial must have had on such a free spirit. Undoubtedly, it is this inhumane treatment that generates sympathy for Mitnick and eclipses his criminal escapades in the eyes of his supporters.

It is difficult not to admire the skill and persistence that Mitnick demonstrated in the pursuit of his goals but it is worth remembering that society needs protection from people who employ such talents to take things that don't belong to them: this is a message that seems to have got lost in Ghost in the Wires. However, it is a fascinating account and a thoroughly enjoyable read.

Wednesday, 20 July 2011

Essential Reading

Secrets & Lies: Digital Security in a Networked World
Bruce Schneier
Wiley Publishing Inc
ISBN: 978-0-471-45380-2

Put simply, everyone who owns (or uses) a computer that is attached to a network should read Secrets & Lies. Schneier himself recommends reading it "through a second time" (p.xxiii), but I'm not sure that even reading it twice will be sufficient to absorb all the lessons and wisdom that the author offers his readers to keep them safe online! Without doubt, this is the finest book on computing (of any type) that I have read to date and throughout I found myself wishing that I had read it when it was first published.

Sure, this seminal treatise on digital security is starting to show signs of age, but then it was originally published in 2000 and the fact that technology has developed so quickly over the intervening decade is a testament to both the simplicity and the enduring relevance of the underlying message: "[s]ecurity is a process, not a product" (p.xxii). As our personal information and virtual existence is increasingly spread across the Internet, this is a lesson that we should all heed. Fortunately, Schneier's uncomplicated approach coupled with his lucid and inclusive prose means that non-technical readers should not be intimidated by the book's four-hundred or so pages and it seems to have been written as much for the layman as for technicians and geeks. Indeed, the book's format and layout are designed to make digital security as accessible as possible and Schneier breaks it into logical sections that provide: the context and justification for digital security (The Landscape); the tools for providing security (Technologies); and how best to deploy these tools (Strategies). However, this is no technical manual - there's very little in the way of direct implementation advice - more, it is a way of thinking about and planning for security and this is the real secret of the book's durability.

Throughout, there are echoes of Schneier's despair with his earlier manuscripts and the lack of hope the early drafts gave his readers (p.396). Nonetheless, this serves only to reinforce the importance of the message and the urgency of the risks. Schneier's epiphany in 1999 (p.397) that led to the resurrection and publication of this book provides us all with the hope that, once we understand the risks and plan our responses, even when those risks are manifest we can mitigate the damage.

Whether you have an interest in network security generally or you are one of the computer security's mystified majority, Secrets & Lies is essential reading.

Monday, 4 July 2011

Great....BUT - Book Review

PGP & GPG: Email for the Practical Paranoid
Michael W. Lucas
No Starch Press
ISBN: 9 781593 270711

Michael Lucas certainly knows his stuff when it comes to encrypting email and he imparts his wisdom with a light, uncomplicated style that makes this book an easy and enjoyable read. As an introductory text on the subject, it's difficult to imagine a better single-source of information for anyone considering encrypting their private information before sending it across the public network.

Lucas takes his readers through the installation and configuration of his two chosen encryption programs (PGP & GPG) and provides useful insights and excellent practical advice throughout. There's also a brief (but fascinating) introduction to the origins of PGP as well as absorbing discussions on key management and the principles that underpin the web of trust concept. But (and this is quite a big but), there are problems with this book that make it questionable as to whether the cover price represents value-for-money.

Firstly, this really is an introductory text and, unless the reader is a complete computer novice, much of this book is pointless: most users will already know how to install a program using the default installation settings (or know enough to be able to follow the installation wizard) and therefore, the significant portion of the book that describes these processes seems somewhat redundant. That's not to say that there is no useful information in the descriptions (for instance, using hashes or checksums to confirm the integrity of the download), only that too much time is spent describing processes that will be patently obvious to virtually everyone that reads this book.

Then, there's the layout: Lucas glibly skips from discussing one program to another in alternate chapters and this has a calamitous impact on the text's rhythm. In fairness, Lucas does warn his readers that they can skip the chapters that are not germane to their circumstances, but that's not entirely helpful to reader with either a general interest in the topic or is concerned with multiple operating platforms or single encryption programs. Perhaps a better approach would have been to separate the contents into three sections allowing readers to have an overview of the subject followed by comprehensive (and uninterrupted) discussions about each encryption program.

Finally, Lucas provides no information here that is not freely available on the Internet: for instance, try searching online using the simple text string, "installation guide PGP". That there are alternative sources of information is not a problem per se, nor is the fact that many comparable guides are available free-of-charge; however, it does make the near twenty quid cover price extravagant!

If you're too lazy to find your own sources and have some money to burn, this is a great introduction to encryption.

Wednesday, 15 June 2011

Cryptic - Book Review

Cryptography: A Very Short Introduction
Fred Piper & Sean Murphy
ISBN-13: 978-0192803153

This excellent series of books has always been a great way to "plug knowledge gaps" and the Cryptography title is no exception: however, notwithstanding the slender format and its purpose as an introductory text, this should not imply either an absence of gravitas or effort-free knowledge.

Indeed, given that the information density in this volume is as high as its sister titles and the fact that cryptography is meant to be hard to decipher, this book is quite challenging in places and newcomers to the subject will almost certainly benefit from taking plenty of time to absorb the content and reflect on its lessons. Nonetheless, despite its complexity, Murphy and Piper have produced an excellent introduction to the topic and those exploring the potential of encryption for for the first time will find it an invaluable resource that provides the much needed context that is largely absent in the usual “how to” manuals.

Obviously, 130 pages or so isn't really sufficient space for a wholly comprehensive treatise on encryption but the authors manage to provide both historical and modern perspectives as well as discussing the practical application of encryption without loosing sight of its security implications or vulnerabilities. This is an astonishing feat given such a compact form and Murphy and Piper are to be congratulated on their achievement.

Sources:

Thursday, 20 January 2011

Thanks Mum


The Definitive Guide to Samba 3 [Paperback]
Roderick W. Smith
ISBN: 978-1590592779

Sometimes a bargain comes along that's just too good to pass up. This book popped up in my Amazon recommendations the other day (probably after I searched for "Using Samba") and I couldn't believe the price!

Amazon has this available from one of its resellers for £5.47 + p&p so I snapped it up! I have no idea whether it's any good, I suppose that time will tell: but my Mother taught me that you can always afford a book and, at this price, I guess she's right. I ordered it after business hours on 14th January and it arrived in the post this morning - excellent.

Thanks Mum!

Monday, 3 January 2011

Almost But Not Quite!

Sams Teach Yourself Networking in 24 Hours
Fourth Edition by Uyless Black
ISBN: 978-0-7686-8576-3

Aimed at the entry-level networking professional, Sams Teach Yourself Networking is unlikely to satisfy the needs of readers interested in an introduction to managing home networks. Much of the discussion centres on network operating systems, dedicated servers and keeping system users happy: hardly high priority topics for non-professionals who tend to be more interested in getting (and keeping) a disparate collection of hardware devices working in harmony! However, this observation should not be construed as criticism and Black's treatise is an excellent aid to developing expertise beyond the typical hybrid desktop routers supplied by most ISPs.

Black uses the OSI network model to introduce the concept of layered protocols and it is a theme used throughout the book to describe how data moves through networks. Not only is this model an excellent vehicle for explaining the fundamentals of networking, but it is also useful for understanding how PCs prepare data for transmission and interpret data on receipt: suddenly, those cryptic error messages will start to make sense and troubleshooting errant PCs becomes a little easier.

However, despite imparting some excellent guidance this book does have some flaws. For instance, Black squanders a couple of his “hours” discussing the role and responsibilities of a network administrator: whilst this might be interesting per se, its inclusion suggests that learning about networks requires less than twenty-four hours! Similarly, Black spends the last chapter speculating on the future of computer networks. It is almost as if he has run out of technical advice and resorts to conjecture to fill some space (and the requisite number of hours).

Overall, this book provides a useful insight into professional network management and offers an excellent description of layered protocols. However, the shortcomings diminish the desired effect and, given the relatively high cover price, the result is an offering of questionable value that fails to deliver the promise of the title.

Friday, 26 November 2010

Networking For the Rest of Us


Network Know-How: An Essential Guide for the Accidental Admin
John Ross
No Starch Press
ISBN: 978-1-59327-191-6

It is unlikely that those with extensive theoretical and practical experience of designing, building and maintaining small computer networks will find much of interest in John Ross' book. However, if like me you are the archetypal "accidental admin", this may just be the most useful computer book that you ever buy!

In Network Know-how, Ross introduces the novice network manager to the basic concepts of networking and provides important insights into why things work (or sometimes don’t work) in small network environments. He offers practical advice on LAN design as well as equipment and infrastructure installation, giving concise instructions on how to setup and operate a range of servers, clients, and peripherals. All this Ross achieves without resorting to unnecessary jargon or gross over-simplification: in short, it is networking for the rest of us!

Given the extensive range of hardware and software available, the book does tend to be understandably vague regarding hardware and, in places, a little Windows-centric. Nevertheless, Ross has been careful to provide pointers for Mac and Linux users even if it is not as comprehensive as one would have liked and, because he explains the principles of networking so well, these signposts are more than sufficient to cope with all but the most specialised kit. Reading this book has resulted in significantly improved security in my own network and the ability to share files and services across multiple operating platforms (Windows, Windows Mobile, & Linux) and devices.

Overall, this book is a thoroughly recommended tract on networking for non-specialists. As with all books of the genre, this one is over-priced. However, don't let this fool you into believing that it is not value for money: if you want a secure and reliable network over which you can share data and resources, this is an excellent introduction.