Stupid Facebook Chain Letter - I’ve seen a bunch of movies, but I swear I have a life
[info]creeva

Originally published at Creeva's World 2.0. You can comment here or there.

Every once in a while I actually do one of the stupid chain letter things - this one seemed right up my alley - so let’s look at the results.  Further discussion at the end.

SUPPOSEDLY if you’ve seen over 85 films, you have no life. Mark the ones you’ve seen. There are 239 films on this list. Copy this list, go to your own facebook account, paste this as a note. Then, put x’s next to the films you’ve seen, add them up, change the header adding your number, and click post at the bottom. Have fun.

(x) Rocky Horror Picture Show
(x) Grease - own it
(x) Pirates of the Caribbean - own it
(x) Pirates of the Caribbean 2: Dead Man’s Chest - own it
(x) Boondock Saints
(x) Fight Club - own it
(x) Starsky and Hutch
(x) Neverending Story - own it
(x) Blazing Saddles
(x) Airplane
Total: 10

(x) The Princess Bride - own it
(x) Anchorman
(x) Napoleon Dynamite
(x) The Dark Crystal -  own it
(x ) Saw
(x) Saw II
(x) White Noise
(x) Vanilla Sky - own it
(x) Anger Management
(x) 50 First Dates -  own it
(x) Fletch
(x) Fletch Lives
Total so far: 22

(x) Scream -  own it
(x) Scream 2 - own it
(x) Scream 3
(x) Scary Movie
(x) Scary Movie 2  - own it
(x) Scary Movie 3
(x) Scary Movie 4
(x) American Pie
(x) American Pie 2
(x) American Wedding
(x) American Pie Band Camp
Total so far: 33

(x) Harry Potter 1 -  own it
(x) Harry Potter 2 -  own it
(x) Harry Potter 3 -  own it
(x) Harry Potter 4
(x) Top Gun -  own it
(x) Can’t Hardly Wait
(x) The Wedding Singer
() Little Black Book
(x) Happy Gilmore -  own it
(x) Mr. Magorum’s Emporium
Total so far: 42

(x) Finding Nemo
(x) Finding Neverland -  own it
(x) The Dark Knight
(x) The Grinch -  own it
(x) Monster Squad
(X) The Gate -  own it
(x) White Men Can’t Jump
(x) The Butterfly Effect
(X) Bubba HoTep -  own it
(X) I am Legend
(x) Money Train
Total so far: 53

(x) Dodgeball: A True Underdog Story
(x) National Lampoons Vacation
(x) National Lampoons European Vacation
(x) National Lampoons Christmas Vacation -  own it
(x) Caddyshack
(x) Caddyshack 2
(x) The Hudsucker Proxy
(x) Fast Times at Ridegmont High
(x) Clueless -  own it
() 9 Months
(x) Death to Smoochy
(x) The Sting
Total so far: 64

(x) SpaceBalls
(x) The Terminal
(x) Robin Hood: Men in Tights -  own it
(x) Forget Paris
(x) Dumb & Dumber
(x) Dumber & Dumberer
(x) Final Destination
(x) Final Destination 2
(x) Final Destination 3
(x) Halloween
(x) Pulp Fiction -  own it
(x) Dirty Dancing -  own it
(x) Eurotrip
(x) Roadtrip
Total so far: 78

(x) Harold & Kumar Go To White Castle
(x) Harold & Kumar: Escape From Guantanamo Bay
(x) That Thing You Do
(x) The Jerk
(x) From Hell - own it
(x) Hellboy
() 2 Girls and a Guy
(x) Rear Window
(x) The Whole Nine Yards -  own it
(x) The Whole Ten Yards -  own it
Total so far: 87

(x) The Day After Tomorrow
(x) Liar Liar
(x) War Games -  own it
(x) Ferris Bueller’s Day Off -  own it
(x) Ten Things I Hate About You
(x) Iron Man
(x) Gothika
(x) Howard The Duck-  own it
(x) Sixteen Candles
(x) Just One of The Guys
(x) Breakin’
() Breakin’ 2: Electric Bugaloo
(x) Ski Party
(x) The Mask -  own it
(x) Son Of The Mask
Total so far: 101

(x) Bad Boys
(x) Bad Boys 2
(x) Joy Ride
(x) Lucky Number Slevin
(x) Ocean’s Eleven
(x) Ocean’s Twelve
(x) Bourne Identity
(x) Bourne Supremecy
(x) Bourne Ultimatum
(x) Bedazzled
(x) Predator I - own it
(x) Predator II
() Kicking and Screaming
(x) Ice Age
(x) Ice Age 2: The Meltdown
(x) Willy Wonka and The Chocolate Factory -  own it
Total so far: 116

(x) Independence Day -  own it
(x) Casino
(x) Resevior Dogs
(x) Back to School
(x) Christine
(x) ET
(x) Children of the Corn
(x) Summer Rental
(x) Batteries not included - own it
(x) Catch and Release
(x) Rush Hour -  own it
(x) Rush Hour 2 -  own it
Total so far: 128

(x) The Crow -  own it
(x) How to Lose a Guy in 10 Days
(x) She’s All That
() Calendar Girls
(x) Sideways
(x) Mars Attacks
(x) Smokey and The Bandit -  own it
(x) Smokey and The Bandit 2 -  own it
(x) Wizard of Oz
(x) Forrest Gump - own it
(x) Big Trouble in Little China
(x) The Terminator - own it
(x) The Terminator 2-  own it
(x) The Terminator 3
Total so far: 141

(x) X-Men - own it
(x) X-2 -  own it
(x) X-Men: The Last Stand
(x) Spider-Man -  own it
(x) Spider-Man 2 - own it
(x) Tango and Cash
(x) Jeepers Creepers
(x) Jeepers Creepers 2
(x) Catch Me If You Can
(x) The Little Mermaid
(x) Freaky Friday
(x) American Psycho -  own it
(x) Jumper
(x) Cruel Intentions
(x) Cruel Intentions 2
(x) The Hot Chick
(x) Shrek
(x) Shrek 2
Total so far: 159

(x) Swimfan
(x) Miracle on 34th street
(x) Old School
() The Notebook
(x) K-Pax
() Little Big League
() A Walk to Remember
(x) Tropic Thunder
(x) Boogeyman
(x) The 40-year-old Virgin
Total so far: 166

(x) Lord of the Rings Fellowship of the Ring -  own it
(x) Lord of the Rings The Two Towers -  own it
(x) Lord of the Rings Return Of the King -  own it
(x) Raiders of the Lost Ark -  own it
(x) Indiana Jones and the Temple of Doom -  own it
(x) Indiana Jones and the Last Crusade -  own it
Total so far: 172

(x) Baseketball
(x) Hostel
() Waiting for Guffman
(x) House of 1000 Corpses
(x) The Devil’s Rejects
(x) Elf
(x) The Big Lebowski
(x) Mothman Prophecies
(x) American History X
() Threesome
Total so Far: 180

() The Jacket
(x) Kung Fu Hustle
(x) Shaolin Soccer
(x) It -  own it
(x) Monsters Inc.
(x) Titanic -  own it
(x) Monty Python and the Holy Grail -  own it
(x) Shaun Of the Dead
(x) Hot Fuzz
Total so far: 188

() High Tension
(x) Club Dread
(x) Nick Fury : Agent of Shield
(x) Dawn Of the Dead
(x) Hook -  own it
(x) Chronicles Of Narnia: The Lion the Witch and the Wardrobe
(x) 28 Days Later
(x) Orgazmo
(x) Super Troopers
(x) Waterworld
Total so far: 197

(x) Kill Bill vol 1
(x) Kill Bill vol 2
(x) Mortal Kombat
() Wolf Creek
(x) Suburban Commando
() Mr Nanny
() I Spit on Your Grave aka the Day of the Woman
() The Last House on the Left
() Re-Animator
(x) Army of Darkness -  own it
Total so far: 202

(x) Star Wars Ep. I The Phantom Menace -  own it
(x) Star Wars Ep. II Attack of the Clones -  own it
(x) Star Wars Ep. III Revenge of the Sith -  own it
(x) Star Wars Ep. IV A New Hope -  own it
(x) Star Wars Ep. V The Empire Strikes Back -  own it
(x) Star Wars Ep. VI Return of the Jedi -  own it
( x) Ewoks Caravan Of Courage -  own it
(x ) Ewoks The Battle For Endor -  own it
Total so far: 210

(x) Point Break -  own it
(x) Dogma
(x) Animatrix - -  own it
(x) Evil Dead -  own it
(x) Evil Dead 2 -  own it
(x) Team America: World Police
(x) Mallrats -  own it
(x) Silence of the Lambs -  own it
(x) Hannibal

Total 219

You see I already knew I had no life, so now you can see my movie choices - I think a bit of it is unfair since I’ve seen the original and remakes of a few movies on that list.  In that scenario should I count them twice.   I guess 219 out of 239 isn’t too bad, it’s also only the tip of the ice berg of what I’ve seen.   Heck tonight in the hotel room I’m in three movies have played so far while I’ve been catching up on blog articles.


Obama’s First Mistake In My Eyes
[info]creeva

Originally published at Creeva's World 2.0. You can comment here or there.

Picture from here

I could pick on a few things actually, once again I didn’t vote for the guy, but I don’t absolutely detest him.   I’m in wait and see mode.  Ars Technica is reporting about Obama’s plead to push back the transition to digital TV.   If we look at the digital TV migration timeline, we can see the originally scheduled date was Dec. 31 2006.   Because of multiple issues it was pushed back and brings us to this upcoming Feb. 17th as the transition time.

We can argue that the government hasn’t done enough to inform the public or make it easy for the public, but I would argue otherwise.   I was well aware of this migration when it was first discussed over 10 years ago.   All in all the government has pushed out this transition longer then necessary.   You can say that’s it’s a good cautious thing they are doing by waiting and delaying, but every delay costs the tax payers more money.

If we truly want to get through this we need to pull the bandage off as quickly as possible.


VCMA Is Looking For a Band Director in Ohio
[info]creeva

Originally published at Creeva's World 2.0. You can comment here or there.

The VCMA Community Concert Band is currently looking for a director.   If you know someone in the area of Vermilion, Ohio - or they are willing to drive to Vermilion, Ohio - please have them contact me.  Yes it is a paying position, but it’s only enough to be a supplmental income source.   If you know someone that is interested have them email me at creeva (at) gmail.com.


A Month With Mom - Part 15 - If You Have It I’m Entitled Also
[info]creeva

Originally published at Creeva's World 2.0. You can comment here or there.

At one point in this whole debacle where I stopped talking to my mom, Xie thought she would try to mend things. She dropped me off at burger king to eat and went over to my mothers to talk (this is all second hand mind compared to most things I’ve written). Xie sat her down and told her she was going to push her children away one by one if she continued down the path she was going. That my mother had to pick herself up, get a job and move forward being an example (I’m sure Xie will comment on this story to fill in more details).

The selfish thing my mom said to my wife? “You don’t have to have a job why should I?”

Now because this is second hand I normally wouldn’t have included this, but I wanted to point out Xie’s effort. This wasn’t the first time my mother had said this. There are a lot of answers to this.

1. Xie has a supportive husband that hadn’t left her once and possibly will again
2. Xie spends her free time learning and expanding herself - my mothers expansion comes from Oprah and Dr. Phil
3. Xie doesn’t have two children at home not even teenagers yet that need to eat and hopes daddy will give mommy child support money
4. Xie isn’t a leech that feels entitled to it, she has offered to work many times, I don’t understand why both of us need to be miserable for a few extra bucks

While my mother is grazing the home shopping network for things to buy, Xie is doing Algebra out of text books for fun. There is a world of difference. Most notably my mother needed an income she could trust to take care of her kids and not ask friends and family for money to get by.

I will now give you an example I have full memory and first hand knowledge of. It was at a family holiday dinner a few years ago at my grandparents and somehow the morbid subject of what we would like if my grandparents passed on. I stated I would only want one thing, a cedar chest crafted by my grandmother’s cousin. My grandmother chimed in that it was going to be given to her cousins family, well my grandmother has been saying that my whole life, so for thirty years it’s still been sitting there. My mother then said I couldn’t have it because she wanted it. Selfish? Well let’s continue this story.

A few minutes later my mother asked me why I wanted the chest because she thought it was ugly and tacky. I said it was something that would always remind me of my grandparents, their house, and the memories. To me the chest is kind of like a symbol of my grandparents. This prompted me though to ask why did she want it if it was ugly? Her answer? She said she wanted it because I said I wanted it. So I was shocked and called her selfish, I think that was my annual fight that year and I left. It was petty, you would think as adamant as she was when she said she wanted it, that somehow I knew there was a secret stash of money tucked away in it. Nope, she is just worried about someone else getting something she can’t. What a great mother.

Read Part 1 Here

Read Part 2 Here

Read Part 3 Here

Read Part 4 Here

Read Part 5 Here

Read Part 6 Here

Read Part 7 Here

Read Part 8 Here

Read Part 9 Here

Read Part 10 Here

Read Part 11 here

Read Part 12 Here

Read Part 13 Here

Read Part 14 Here


A Month of Mom - Part 2 - The End is the Beginning
[info]creeva

Originally published at Creeva's World 2.0. You can comment here or there.

Rather building up to the explosive end, I figured it better to start at the end and show how it built up to that.   Hopefully this will allow me to end this journey with something nice to say.   Since we’re not finished yet I guess I won’t know.  My family is screwed up, tht’s not a lie.   I don’t think however it’s any more unique or screwed then anyone else’s.   So I guess as I go through this journey I will classify us as normal.   Some scenes may seem absurd.   Some will seem strange.  I however grew up with a better life with then some people I know so she would be responsible for that.   However i can’t go home again.   She told me so, I have no home except my own.

Tomorrow I’ll give more background leading up to the last day I talked to my mother face to face, however we’re looking at that day first.   Time to go back 2.5 years ago.  I arrived over to my mother’s house to help my sister out.   My sister had special juice my father had purchased for her (i don’t remember why), and it was being drank by my other siblings (not my fathers children).  My youngest brother, was actively allowed to enter her room at all time and she wasn’t allowed to lock her doors.   My mother was actively looking to drive her out, though she was waiting until she graduated.

I came over to come to my sisters rescue.   The first thing my mother does is deny any of this happening.   Then she comes and admits it, but comes up with excuses on how the different things happen.   At this point trying to maintain the peace all around I offered to bring in a mini fridge for my sister and buy a lock for her door since my mother can’t maintain boundaries for my youngest sister from both my biological parents.   Since my sister was the last one of the four of us in the house, she got it hte worst.   All the problems that the rest of us went through kept compounding on her (why my sister talks to her now I can’t fathom).

The first excuse is that my mother won’t have a locking door in her house because my sister doesn’t need privacy that no one would invade her space.  Secondly she said she wasn’t going to pay the electric bill a mini fridge would cost, my step father at this point came down the stairs and started to chime in.   I told him to shut the hell up (ok I used stronger language), the man who had abandoned my mother for over a year had no say in this dicussion in my book, he had been back less then month.

I had heard my mom cry about how much she hated him.   The main reason they got back together?  The noble thing would be to say it was love, maybe it will be again for them.   However my mother’s excuse to me over the previous month of deciding if she was going ot take him back was two-fold the first is that she didn’t want to die alone - fair enough.   The second was the part that disgusted me, she didn’t feel she had to work.  She complained that this was her time to enjoy with grandchildren and she shouldn’t have to work.   She told me how she was going to pay all the bills with her inheritance and be happy.  That was the life she always envisioned and she was upset she wasn’t going to get it.  She sounded like the preppy girl complaining that she came in second place in a beauty pagent, and if she cried and screamed loud enough someone else would fix it.

She got back together with him, not for love, but live a more comfortable life.   Why I won’t explicitly say that, someone who lies in bed with someone else for money as the primary reason…….

I knew this, my siblings knew this, my wife knew this.   He held no power over me and I wasn’t going to have any of it.   He had put my mother through months of pain, helping my mother out because of this was part of the reason I moved back to Ohio from Oregon.   I had been a part of that house and family for many years.   At this point he asked me to leave.   As I’m walking out I’m still arguing on my way to the car.   My mother told me the words that are opposite of what I’ve been told that a mother is supposed to say - she told me that it wasn’t my home anymore.

I had grown up my whole life with my mother telling me that it would always be my home.   She however would choose to be with her part time husband and choose his side over mine.   It wasn’t the first time she did that though.  My step father told me to never come back and I wasn’t welcome there anymore.   So be it.   My mother has relinquished what she wants or believes in for her comfort.   She tries now to deny what she said (like she always denies what she says) but my wife heard it also and her jar dropped.   My wife had seen the drag out fights amongst my family, and this wasn’t the worst.  This was my mother clinging to safety and the fear of being alone.  If I thought she did it because she wanted to, because love made her do strange things, then I would forgive.  My mother is more calculating in protecting herself though.  She will protect herself over the expense of others.

For the record if my step father ever shows up on my door step, the first thing I’m doing is calling the police.

This is the incident that is the proverbial straw.  Does it sound stupid?  I’m sure it does.   I won’t deny it.   Starting tomorrow we’ll be working on how we got to here.

Read Part 1 Here


Web Application Developers Can Learn A Bit From Wordpress
[info]creeva

Originally published at Creeva's World 2.0. You can comment here or there.

Picture from here

Just the other day I wrote about cloud computing versus SaS terminology.   A web application isn’t necessarily a cloud computing or SaS platform.   It can be one or the other, it can be both, it can be neither.   Now that, that is out of the way let’s move onto the meat.

I think that all web application developers would do well to look at Wordpress and the product they offer as key points for their own designs.   Obviously I use Wordpress as a blog, I also use it as a CMS, a middleware application system, a database, a word processor and other uses.   Wordpress is extensible far beyond the original blog software it was designed to be.

The reason that Wordpress is so transformative is the ability to use a fairly easy (well not for me but I suck at PHP and programming in general) API that the users can use to extend and transform the core product.  This is done through the use of plugins.   In theory the expandablity of Wordpress would allow it to transform into any functional web application you can imagine.   I’m not saying this should be done however.   Wordpress plugins a lot of times just add band-aids to a product to extend it further then the core company can imagine or support.

Think of your ticket support system.  Most of these are moving to a web based interface.  Easy to manage, no software to install on users computers, easily updated since you only have to update the core server - it’s a no brainer to move everything you can over to a web based centrally managed focus for a company.

Why can’t you extend it though?

Most of the web application companies MAY ALLOW YOU to go as far as put your company logo in the interface.  Allowing you to brand a product to some extent is not the same as extending the product.  I don’t want color changes.  I don’t want a simple image swap.  I want feature sets being implemented without waiting 18 months to have it done.  If you have a robust CRM application, in this modern time wouldn’t you want a spot to add a LinkedIn Profile section?  This would be as easy as allowing customers custom fields that they can rename on the back-end.   What about adding an image?  This would be a bit more difficult then a simple custom field, but still possible doable.  How about however a full blow plugin that looks up the LinkedIn contact info.

This is all hypothetical, but let’s say this is how the plugin would work in generic CRM system.

1.  User logged into the CRM would associate their own - or a corporation profile with Linkedin

2.  User plugins in new contacts e-mail address

3. User is prompted with “Would You Like to Request Connection on Linkedin?”

4.  If users states yes the plugin would go into a state of “Waiting for Remote User to Confirm”

5.  At this point the user could add in all the information they normally would in the CRM database

6.  Later the user would receive an confirmation (or decline) of linking up in LinkedIn

7. If the receive a confirmation they could then pull in the information to the CRM application.

8.  Then the CRM application would have connections and how they relate to each other in their database, home pages, Resumes, etc. - all from a couple clicks.

That is a scenario that would appeal to sales personnel.   Let’s look at something more urbane, a library look up system. A library lookup system is something very simple  and single tasked.  It works well and returns (normally) the following information:

  • Title
  • Author
  • Subject
  • Location
  • If it’s in or checked out
  • Sometimes a Summary
  • Sometimes an Image

Now let’s look at methods we can use to extend this functionality.  The first thing I would make sure is there a public internet accessible site where either the general public, or the Library chooses just card members can access.  Library users are normally people that live in the same town and there are a good number of them that know each others.  What does that buy you?  Word of mouth.  What about a a secondary revenue stream outside of donations or overdue fines?  How can you leverage more people to show up at your fund raising drives?  I’m assuming these are question that library officials ask themselves.   How can we turn that simple search to find a book into something more?

Let’s give the users an option to use the search page as a social platform.  I would give the a users a choice of using the old style simple search functions, but also give them a chance to leverage the public you are serving to work with you instead of you working for them.

Let’s go over an imaginary social library platform.

1.  User opens up a search window into the library database and enters a query.

2. User gets back the title, author, and subject - then a link that states more information (this is where a plugin would take over)

3.  On the plugin page users could get back an image of they are searching.  They also see where it is located, if it’s in or not, and more.   What about a sidebar that allows them to purchase the book/movie/CD at Amazon?  Reviews from other library patrons?  A list of who checked out which book (make this opt-in only on a per title usage - don’t compromise a users privacy).  A listing of library events where the author is signing books, giving a reading, or there is a book discussion covering these topics?

You just made something that is infinitely more “sticky” and let’s the users interact with your site on a much larger scale then previously.  They are no longer browsing alone, but in a group, with people they know from town.

All of this is possible with a platform that allows plugins.  I’m not asking for web application developers to support any plugins directly.  If a plugin breaks or crashes the core site (shame on the user that puts an untested plugin in a production environment) - the web application developer should tell the user they will not support the product with any plugins running at all.   It doesn’t mean the framework, APIs, and access shouldn’t be there.

I’m pleading with web application developers that allow the users to have self hosted servers to please build this extensiability into their products.   I can hack around another platform and get these functions, but sometimes we just want to buy a program from a vendor with support.   Currently your making us choose between function or support.   It should not be that way.  Opening up can only gain customer loyalty in the long run.


Rant On The Myspace E-mail System
[info]creeva

Originally published at Creeva's World 2.0. You can comment here or there.

Now you know if you read my blog regularly that I don’t have the higest respect for Myspace.  I have been using Myspace more and the issues of it’s flaw just become more glaring with me over time.
Issues:

1.  There is no method for saving e-mails.   None, other then copy and paste - which is a huge pain in the ass.   While I do have the first snippet saved in a gmail notification I would prefer to have the whole message saved off and archiving.

2.  After two weeks it deletes your sent messages - WTF?  Why can’t I decide to clean out my inbox - if you want to clean them out why don’t you give me the option to automatically export a copy out for myself in my home e-mail account?

3.  Notifications - theoretically it wouldn’t take much more bandwidth to send me the whole message - I have no problem logging into your site to reply to email - but send me the complete email and not the first 140 characters.

I understand e-mail is not a priority for them, and not a focus of the site.  I understand they are a walled garden.  Dammit though, with the user base some interoperability with their e-mail would be nice.

I hate you Myspace.


Is There a Strong Future For Community Bands?
[info]creeva

Originally published at Creeva's World 2.0. You can comment here or there.

I’ve done the community band circuit for a year now and I’ve played with two community bands.  The one thing I have noticed is that the bands don’t really seem to be growing.  When they do grow it’s usually by an older member decides to join in the band.  The youth market seems to be completely disenfranchised.   I can understand part of that, though I declined to the join the VCMA when it was first formed due to not liking the director.   It wasn’t because I didn’t want to play, I still had the yearly Vermilion Alumni Band to play in, then I moved to Oregon.   While there I hardly ever pulled out my trumpet and when I did it was just for a half hour stint every few months.   My lips didn’t have the range or stamina they once did.   After blowing out my lip the last couple years at Alumni after moving back to Ohio, I decided I need to bring more regular playing in my life.  This led me to community band.  Since I am young(er) I have a different perspective on the band.

The first thing is that the music (at least over the summer) is extremely heavily weighted to music written before I was born.   If we play anything done after I was born it was an arrangement of a pre-existing piece.  I hear the director say things like, “we’ll play this piece because everyone will know it”.   Most of the time this is said, I neither know it, nor do I recognize the melody.  I feel attached and not a part of something I can recognize.  This is not to say that I think the old music should be ignored, no matter how much I dislike traditional marches.  I think we should play a wider variety of music that encompasses all eras.  Young people that really aren’t in to band music should have something that is recognizable to them and not just something that there parents kind of remember or their grandparents danced to on their first date.    There needs to be a mixture.   A mixture that should appeal to all those involved.

Rules I would follow to achieve this if I was choosing the music:

1.  Choose at least one movie/television theme song- preferably something recognizable to all ages.   While we are playing Moonriver in the VCMA and I adore, it is not something that the majority of under-forty crowd would recognize.  I think you would have to go to the over fifty crowd to truly appreciate and remember it.  My wife said she would forever be in love and be inspired to work harder at learning an instrument if she hears The Muppet Show Theme Song.  My personal favorite is video game theme music, something as traditional as The Legend of Zelda Theme Song or a number from the Final Fantasy series.   There is a national company that tours and just does live concerts on video game music, it sells out pretty quickly.  These types of concerts have a great deal of appeal to the under forty crowd and that should be taken into consideration.

Some TV themes I would like to hear:

  • Batman the Animated Series Theme
  • The Muppet Show Theme
  • The A-Team Theme
  • The Adam’s Family
  • The Star Trek Theme
  • Farscape Theme
  • Benny Hill Theme
  • Monty Python’s Circus Theme
  • Futurama Theme
  • The Incredible Hulk Theme
  • Inspector Gadget Theme
  • Macgyver Theme
  • Mission Impossible Theme
  • Quantum Leap Theme
  • Bonanza Theme
  • Scooby Doo Theme
  • Twilight Zone Theme
  • X-Files

Movie Themes I would like to hear:

  • Anything by John Williams
  • Anything by James Horner
  • Harry Potter
  • Anything large movie made in the last 20 years.

2.  Choose at least one pop arrangement - the VCMA did the Beatles and this would fit into this category.  The real problem with pop music is that so little of it actually sounds good for a concert band.   The fifties and sixties popular songs actually sound the best, though there are a few later pieces that sound quite good also.

3.  Choose one classical piece that easily recognized, so far in neither of my community bands have we tackled any classical music.  We have done some “traditional” pieces, but nothing classical.   Where is the Bach, Beethoven, or Chopin?  There is an abundance of this that has been arranged for concert bands, but the bands I belong to seem to overlook anything pre 1880 and post 1960.  Christmas music doesn’t really fall under “classical”

Out of these 3 areas community bands should be able to play one piece from each of these genre’s through out there year of performing.  I’m not saying it has to follow that one of each of these pieces get played every concert, but out the forty or so pieces I have played in both bands, they should be able to accommodate one of each of these in their play rotation.

There are other rules I would follow also.

4.  No more then 20 percent of your music can come from any decade.  If it was all arranged in the eighties, that’s fine but the melodies and original music was composed according to this guideline.   I’m not going to pick on arrangers for doing a modern arrangement of In the Mood, its swing era song.   With this rule you could also still fit in easily a whole concert and still have music written from before I was born.

5.  No more then 40% from any single genre.  Whether this is marches, swing, classical, theme music, etc., etc. - variety makes more people take notice unless you’re doing a theme concert.

6. Theme concerts (usually X-mas concerts for community bands) - In a theme concert you should play a maximum of 80% of the music that follows the theme.   One or two pieces should be reserved for something unexpected and interesting that doesn’t fit the norm of a particular theme.  Whether this is a Christmas march or a summer playing of Sleigh Ride, the unexpected brings peoples attention by breaking monotony.

7.  While conductors normally choose the music in most circumstances, there should be one or two pieces chosen by the band members themselves to work through and play.   These people are there to have fun, play something they really want to play.

8.  Encourage your members to compose or arrange something for your band to play.  This makes the music all their own and gives your band something special.

That covers my notes from music selection.   So how do you attract new members?   Other then people moving into the community or the rare person finding out about you and showing up, there is little in the means of growth.  Community bands are competing with the Internet, Social Networking, video games, hanging out with friends, going to the bar, or clubbing.   Having lived through my twenties already most of these are more fun at that age then community band.  You need to hook members while they are still young.

I’ve always played for the love of playing.  I really started when I was a sophomore in high school, by my junior year you couldn’t keep me from auditioning or volunteering to play for whatever group was available.  This alone helped me grow into a much better musician.  I used to be able to transpose music from the key of C or the Key of F in my head automatically and play along from that sheet music.   My range and stamina were much better then they are still today.   My technique today is better in a lot of ways, but I feel I was a better player in a larger scope back then.  That was after only a year of playing back then, I have some of that memory still in my head and I’m old enough to have gained wisdom.  My knowledge should have grown.   After my single year of college I stopped playing with any group outside of Alumni band.  It wasn’t out of disinterest as much as effort.   If I didn’t love playing I wouldn’t stay with the community band, there is no one in my peer group and for a large part of it it’s not really “fun”, at least not in the sense it was fun back when I was in high school.

Most players fall off because they are not engaged early enough into the community band cycle.  To give an example what non engagement with playing can do, for alumni band out of the 160 of us that went through 3 years together, only 5 showed up last year to Alumni Band, only two of us regularly play now.  That’s hovering around a 1-2% rate of a player likely to stick with their instrument after school form my personal experience.  Almost all community bands explicitly state that will accept members that are in high school with their band director’s permission.   Now while I would have gladly played with a community band when I was in high school I was not going to go up and have Mr. Henry sign a permission slip or call to ask if I could join the band.   This is a turn off.   What should happen is that community band should be actively engaging the high school and middle school band directors for members every single year.  If community band members are worried about middle schoolers, then they should make a junior community band where the regular band can show up if they so choose and the younger players can show up.

Younger players are looking for people to emulate, to try to sound like.  Having mentoring by accepting is only going to raise their skill level.   Players that show up are not getting school credit, they are not getting paid, and so why have any stipulations.   If the music is too hard for them they are not going to stick around.   If they don’t really enjoy playing and are only in the school for socialization or the fun from that they are not going to show up.   If community bands are there to make its own members better, then the younger the better, they can make the band as a whole be better.  The older players get the benefit of mild teaching and understanding of what they are doing and the younger players gain a mentor.

Once the younger players are hooked they are more likely to stick with music, since they then have a place to play after they graduate.  They will be informed about the community band and will be regular members.   If they are anything like I was they will find a great relief about having some place to play over the summer.  Older members may even make a little bit of side cash by giving lessons, even if they aren’t as good as a true instructor they could still impart wisdom and teach a student to the edge of their abilities, at which point the student could move onto someone else. My high school self could play rings around my present self. I think community bands under estimate the skill levels of these players.

Is there a strong future for community bands?  It depends.   The older generations need to realize that playing in band is not “cool” at least not until your in your thirties, and I still get the occasional snicker about it - I just don’t care.  A community band is considered a tired thing by the younger generation who would prefer most of their live music to contain electric guitars.  The ability to evolve and bring new members in is essential for most community bands to last another twenty years.   Showing players it can be fun by playing music they can identify with and accepting them as peers within their membership.  You could still have a stipulation where the younger members couldn’t vote in elections, I’m sure you wouldn’t want your board run by four sixteen year olds - but having one of them in a position with a voice may give you greater possibilities then someone like me who is already twice that age and out of touch.

I’ve gotten the VCMA website in a stable place.  I can quickly edit it and make changes, so before any radical redesigns I’m now working on moving them over to Google Apps for internal paperwork.  I plan in the near future signing the VCMA up for a Myspace page and a Facebook account.  People in the younger peer group will be able to see it as an organization to identify with.  The older members need to realize why they started a community to begin with, which includes - hanging out with friends, playing for people, becoming better musicians, and having fun.  None of what I have written breaks any of that.  It may take them a little bit out of their comfort zone, but the mantra of business these days is to embrace and extend.   Growth happens once some of these things are followed.  If the bands I play with don’t start embracing this I’m not sure they will last another twenty years and things will get shaky in another ten.   Growth has not continued, but rather it has stagnated, unless there is something done to counter-act this, the downward trend will continue.

In my band I’m still considered just a kid, though my father had his fourth child by my age.   I’m too young to them to be anything but a kid so what do I know.  I’m too old for any of the young people to truly listen to me, plus I’m over thirty so I’m to young to be trusted.  If we go by Cory Doctorow’s book Little Brother - they don’t trust anyone over 22.   Somehow I’m stuck in the adult version of the tweens.  So no one will truly pay attention, but that doesn’t mean this shouldn’t be said.

Picture from here


Daily Digest for 2008-08-21
[info]creeva

Originally published at Creeva's World 2.0. You can comment here or there.

My online activities for you to read:

Yesterday

lastfm 7:25am Scrobbled a song on Last.fm.
leo@leoville.com – net@night 60: Too Hot
delicious 11:25am Bookmarked 2 links on Delicious. (Show Details)</p>
blog 11:29am New Look For The Blog
twitter 11:34am Posted 6 tweets on Twitter. (Show Details)</p>
  • creeva: New Look For The Blog: ….. Read MoreNo tags for this post.
    Related posts No related posts. http://tinyurl.com/6zkd9k
  • creeva: @evilpacket I may be doing the retro look for a different blog I’m configuring
  • creeva: VCMA Concert Tonight: ….. Read MoreNo tags for this post.
    Related posts No related posts. http://tinyurl.com/646lc5
  • creeva: sitting through normal thursday meeting
  • creeva: I Admit it, I Liked Archie Comics Growing Up: ….. Read MoreNo tags for this post.
    Related posts No rel.. http://tinyurl.com/583qnl
  • creeva: I’m told I’m a royal pain in the ass
blog 1:33pm VCMA Concert Tonight
generic 1:35pm Posted an item
problem_with_disqus_and_my_wp_theme (disqus)
blog 6:56pm I Admit it, I Liked Archie Comics Growing Up

VCMA July 12th Concert at Sandusky Harbor Marina
[info]creeva

Originally published at Creeva's World 2.0. You can comment here or there.

Picture from here

On July 12th the VCMA Community Band performed at the Sandusky Harbor Marina.  The concert started at 7:30pm and went on until a little after 9PM.

Here is a video of the performance





Link to the original Google Video Page

The play list was as follows:

1.    MEN OF OHIO
2.    BEGUINE FOR BAND
3.    IRISH TUNE FROM COUNTY DERRY
4.    AMPARITO ROCA
5.    SHOUTIN’ LIZA TROMBONE
6.    MOON RIVER
7.    CLEVELAND MARCH
8.    FANTASY ON “AMERICA”
9.    ARMED FORCES SALUTE
10.  AMAZING GRACE
11.  GETTYSBURGH ADDRESS
12.  SOUSA SPECTACULAR
13.  THE BEST OF GEORGE M. COHAN
14.  MICHELLE/ELEANOR RIGBY/YESTERDAY
15.  LASSUS TROMBONE
16.  INSTANT CONCERT
17.  UTILITY MARCH
18.  TEA FOR TWO
19.  GILLETTE LOOK SHARP MARCH
20.  SALUTE THE DUKE
21.  THEM BASSES

To look at our upcoming performance schedule got to the VCMA homepage at VCMA.net.


How the new Creeva.com works - Part 1 The Visual Look and Layout
[info]creeva

Originally published at Creeva's World 2.0. You can comment here or there.

wt477740e2da703-thumb_medium2-full

Ok so I’m finally happy enough with the migration that I moved all the DNS settings over to my new web host and turned the old creeva.com back to creeva.blogspot.com.   As they say, breaking up is hard to do.   Hard for me since I had some functionality in the old blog that I was missing (until earlier today) in the new blog.

First of all, obviously I have moved to a sparser design.   I like zen-like simplicity.   No distractions and the meat in front of you on the plate.  Part of this reason is that moving from the blogger platform to the wordpress platform I couldn’tuse the same themes and I was being lazy when it came to the idea of converting the theme.   After being distraught and having issues over this fact I then decided I would make a new layout.  After coming to this conclusion I became happier and more excited about the new layout.   There are some more things to do but that will come with time.

The basic design things you will see is less widgets on the front page (and no advertising currently) I moved some of the functionality off to sub pages (something blogger didn’t support).

My subpages are across the top they are:

Random Quotes    -  These are things I’ve collected over time (this page may not make the grade long term)

About Me   -  A Random Self Observation
Security - Some of the Security I’ve enjoyed that I wrote myself

Music - Not finished - but is going to old information about the bands I play in

Photos - My photo album (sourced at flickr)

Videos - Videos I’ve made or uploaded - or just videos I like

Contact Me - My contact information

Links - Links to friends/

It’s late and I’ll get to writing up part 2 of how the new creeva.com works tomorrow.  The next part of this mini-series is which wordpress plug-ins I am using.


Symantec Endpoint Protection 11.0
[info]creeva

Originally published at Creeva's World 2.0. You can comment here or there.

I’m currently in a webex seminar for Symantec Endpoint Security - the moderator has not joined yet. I thought I would share thoughts and ideas as this went along - and for reference to myself at a later date. I realize this is no apple speech or Nintendo launch - but we all have to get our real time blogging skills up to date somehow. I signed and view no disclosure agreement in the invitation that was given to me and I would not have violated it if I did. This is not specific to my job or company so I don’t feel I’m violating any trust.

The seminar is scheduled to be 1 hour and 15 minutes - unless it’s a really short seminar and its only 1 minute 15 seconds - in that case I guess this is a hug waste of time.

Waiting for the moderator - we just got a message that the seminar will start in 3 minutes - 2 minutes late btw.

The presenter according to the slide is Kevin Haley, Director of Technical Product Management in the Endpoint Security Group.

Since my understanding is that replaces Symantec Anti-virus there is a drastic change as they consolidate all the products they have purchased in the past trying to get them to work cohesively.

The seminar just started only 4 minutes late.

Kevin is responsible for Symantec End Point protection.

Agenda:
Goals of the seminar
Overview of the product
Migration and Migration issues
Additional tools

Goals:

They’ve muted the participants for our own anonymity *roll eyes* - I know from experience that this is solely to not get stopped by possible trigger points that listeners may have.

We have options of typing in questions and getting them answered in real time.

Product Overview:

Symantec Endpoint Protection 11.0 and Symantec Multi-tier protections 11.0

Multi tier is the new version of SAV Enterprise Edition 8, 9, 10 - customer with upgrade protection and support with Symantec will get a free upgrade. This also includes SAV for Mac OSX.

Endpoint protection 11.0 - is the upgrade for SAV CE, SCS, Symantec Sygate Enterprise Protection, and Whole Confidence online for corporate PC’s get this in their upgrade contract

They now took a poll if we entered the beta test for Symantec Endpoint Protection - 9% did public - 20% did external and 69% did not (this was a seminar poll for the participants.

They are talking about the reasons for integrating everything

Parts

Antispyware - Leads in root kit detection and removal *unless they are keeping quiet for Sony
Antivirus

Firewall technology - taken from Symantec Client Security and Sygate

Intrusion Prevention - Behavior Based Threat protection - SONAR whole security - network traffic protection

Device Control/ Application Control

Network Access Control - add on client

New client is all bubbly and vista like - take that how you want. New help and support button allows some basic troubleshooting info in one spot. Access to windows accounts info, disk space, log files, and version information. You can also import or export policies from the client. Any client installed by default from the CD are initially self managed - if you want them to be managed by default you need to create an installation package on your management server.

You can change all policies not just the firewall based on location.

The file that tells if the client is managed or unmanaged is located in the file sylink.xml - contains also server list, certificate info, heartbeat, and communications. There is a tool to auto edit the file included on the cd for easy managed to unmanaged deployment. You could also edit this manually and the file is said to be documented.

Intrusion prevention capability - network based intrusion prevention tied into the tcp stack - generic exploit blocking from SCS and Sygate IDS which supports custom signatures - signature format is similar to Snort. Behavior blocking - proactive threat scan from whole security - innovative behavior based analysis - uniquely accurate low .004% false positive rate (testing for 2 years) via the web site and the consumer product (your enterprise beta testers) - enables broad deployment on endpoints. 20 million installations during the test - so 40 false positives for every 1 million PC’s - can also do white listing so false positives only show up once.

Stupid picture of a cookie jar with a digital camera and video camera - cookies disappear in the night and you want to catch who is doing this used camera for random images or camcorder you can review the film later but the camcorder solution is more expensive - so proactive threat scanning takes a picture of all the processes every 15 minutes and analyzes it. *is this seriously the best analogy?????????

Application Control - you can disable certain application

Device protection - block devices by type - trying to stop items like USB, infrared, Bluetooth, serial , parallel , firewire, scsi, PCMCIA - can block read/write execute on burnable media drives - can block all USB except keyboard and mouse - *I would just use a browser

Features overview
email report distribution on a schedule
centralized event logging
customizable reports
real time event viewing
notifications view
event export to SSIM or 3rd part
Embedded and MS SQL support
Client install package builder
patch and update
remote installation
import and sync with Ad
authenticate with AD
customized agent package installation
Migration from SAV, SCS, SSEP,& SNAC
Centralized Web Based console
Simplified interface for SMB and enterprise
Role Based Access
Administrative domains
Assign rights by user or group
User defined multi tier groups
RSA SecurID
Integrated management of all agent components
single console for management of AV, FW, NAC and other policies
Group based polices
- I missed the last two.

Migration

Standard migration steps so far - document, design, install architecture, migrate existing groups and policies, configure reporting, configure server/site (policies, groups, Admins, notifications etc. , create and test client packages,

Java based Management - talk to it on HTTPS (admin and client) clients can be configured for HTTP if you want unencrypted traffic- SQL database for storage.

Database contains
Group structure
policies
patches
logs
content

only replicates
Group Policies/Logs/Content

SQL can be separate from the management sever - many management servers can use a single database. Numbers are to be determined but there is basic info in the documentation - hard numbers will not be available in FCS (First Customer Shipment)

Distributed environment - multiple management servers and databases - Management servers always replicate policies and group information between them - so they will all know about ALL the clients and policies - any client can check into any server - but you can restrict that by server or server group - you can also setup a order it checks in. Logging replication is optional and they call it filtering - if you have a current architecture where all information rolls up to a master server you can still do that - or you can replicate all logs to all servers.

Supports migration from SAV, SCS, and SSEP - clients upgrade to SAV 11.0 will automatically connect to new SESM

Look and feel for reporting data is the same

First use wizard simplifies initial setup

SEPM can run on the save server as a SAV management server since they are designed to coexist since they use different executables.

Migration 1 - on same server as your SAV server
Install SEPM
Move Group and Policy info from SSE
Install SAV 11
Decommission original Parent server

Migration 2 - different server
Policies can migrate with first use wizard - other steps very similar

Reporting migration

Sav 10.1 - you can redirect clients to the new SEP 11 database for reporting.

Client installation - support to install over SAV 9-10.1, SCS 3-3.1, SEP 5.1, SPA 5.1 (don’t have to uninstall these products)

Already rolled out internally at Symantec with 5000 users

First use wizard - which will enable you to migrate your groups, policies, users to your new management server - they will not install the client automatically on a management server-so this will have to be done manually. They warn about installing the client firewall on the servers install - LOL - I can see why but I wonder how many administrators actually did that.

Content distribution

SEPM gets client updates and content from Symantec live update - clients can be patched from management server using only a small difference file that can be pushed down.

Still can get content from central internal live update server or rapid release definitions

Clients send events, operation state, and command status to the SEPM server - commands are sent to client from server, profiles, content, updates sent to client - content and updates only the different micro definitions they don’t’ have are sent instead of all the definitions each time.

Clients with a group update provider - will go to the group update provider for content (av defs, etc.)

The group update providers caches information from the SEPM server - designed for low bandwidth architectures.

Unmanaged clients can still go to live update on their own

Additional tools

http://edm.symantec.com/endpointsecurity/
http://www.symantec.com/endpointsecurity/migrate - migration information
Consulting Services and support

Goodbyes and that’s the end

Questions and Answer from the text box:+

Question: Sorry missed what said… Did you mention Macintosh would be included?
Answer: Yes, MAC will be included

Question: Will the Multi-Tier console server handle Macintosh clients?
Answer: MAC will not be managed by the SEPM console this release

Question: Will it be Vista compliant?
Answer: Yes

Question: Will the Symantec Multi-tier Protection for MAC be able to utilize the Parent Servers for Windows?
Answer: No. MAC has its own console as it stands today.

Question: Asking about the console. Will there still be a seperate console server for Macs?
Answer: Yes

Question: So there won’t be a Mac solution if we’re a SEPM customer?
Answer: MAC is included in the Multi-Tier Protection but it is managed by a seperate console and server structure

Question: What is the upgrade from SAVCE
Answer: Symantec Endpoint Protection 11.0

Question: is the full endpoint suite required, or can you still purchase products separately?
Answer: You get everything as long as you are current on maintenance.

Question: Assuming no more console?
Answer: MAC will be managed by its own console. SEPM will manage all windows clients

Question: Can you turn off various components?
Answer: Yes, you can enable and disable the features as needed.

Question: Will it have built in reporting capabilities or do we need to continue with SAV reporter?
Answer: SEPM has reporting built in.

Question: Will the SEP v11 console be able to managed legacy clients (SAV10, etc)
Answer: No. It will not manage legacy SAV clients

Question: Will this all still be in a single agent?
Answer: Yes, Single Client with all the mentioned technologies

Question: Will these products be Vista logo’d or just Vista compliant? Also will you be providing both 32bit and 64bit clients?
Answer: Yes, we will be providing both 32 and 64 bit versions of the client. Vista compliant.

Question: What? We will need to run multiple consoles? Will they all feed into SSIM?
Answer: SEPM will manage the windows clients only with this release. Yes, we will have a collector for SSIM

Question: Will we go over migrating an existing Reporting Server to the built-in reporting in SEPM?
Answer: There is a white paper that will be available as well as a migration wizard

Question: would this be red if I disabled it from management side?
Answer: Yes

Question: does the user need admin rights to execute a FIX
Answer: The fix can be run as system by the client

Question: Are there different levels of users provided in the SEPM?
Answer: Yes, administrators can have different functions and rights as configured. There is limited administration.

Question: Will the 64-bit client differ by processor type, or will the 64-bit client be universal?
Answer: Universal

Question: Current installation from CD presents you an option to choose the management server if you want to install managed. Why has that been removed?
Answer: You can create packages that are “unmanaged” still it is just a different process.

Question: can it be locked so a cleint can’t remove from a server?
Answer: Yes

Question: In previous versions, we could specify management server. This is not possible

now?
Answer: Yes. It still is possible to specify the server that will manage the client.

Question: Will the client upgrade handle all current individual components that may be installed on the desktop (SSEP, SAV10, etc.)?
Answer: Yes, absolutely

Question: Does the new policy import/export replace the usage of GRC.dat and the need to at times manually implement it.
Answer: Yes. Sylink.xml is the new file used.

Question: Will the SPEM have the ability to set security access for other users/groups to manage their servers or sites?
Answer: Yes

Question: So the sylink.xml replaces the grc.dat except it doesnt disappear once processed by the client?
Answer: Yes, exactly

Question: When will this release be available?
Answer: End of the month

Question: can you import SNORT signaturs?
Answer: No, we support REGEX and have a language similiar to snort

Question: Is there a maximum network latency value between a policy sevrer andf end client that we should consider when determine the count and location of policy servers on our global network?
Answer: We will have a scalability document for distro

Question: Does the current license also include the signature subscription for IDS?
Answer: Yes

Question: Has the port range for communication between SErvers and Clients decreased? Or will it still range from 1024-4999?
Answer: It will be SSL

Question: Will this presentation be available for download so we can share with upper management?
Answer: Via email

Question: Does the client upgrade require a reboot from version 10.x
Answer: to start the firewall but not for AV protection

Question: We currently install the SAVCE client on Windows Server OS managed by a Parent server. Which product is recommended for Windows Server OS or which components are recommeded to be disabled on Server OS?
Answer: SEP can be run on servers and clients. All technologies are portable

Question: is the management console still MMC based?
Answer: No

Question: Is there a reporting server for this similar to the SAV 10 reporting server?
Answer: No, it is integrated now.

Question: When will training be available for SEP 11?
Answer: At release

Question: will we be able to customize the white list
Answer: Yes

Question: Does Behavior blocking handle rogue keyloggers?
Answer: Yes

Question: Will the new console be able to communicate with “legacy’ SSEP agents (or, can we upgrade the SSEP-PM without requiring the SSEP agents to upgrade at the same time)?
Answer: It will support legacy SSEP clients but not SAV.

Question: so just 443 and 80
Answer: Exactly!

Question: Can specific applications be “black listed”?
Answer: Yes

Question: what are the functionality differences between Sym Endpoint Protection and Sym Multi-tier Protection?
Answer: Same technologies SMP includes email protection and MAC/linux

Question: will the clients listen on a port for server initiated communication, or is the communication only initiated by the client?
Answer: no client listen port. Client initiates all communication to the server

Question: Will SEP require SQL?
Answer: You can use SQL but the embedded (included) DB is Sybase

Question: Will mobile devices be supported? If so, what devices?
Answer: Seperate product

Question: Will the Q&A be made available after the call?
Answer: Yes

Question: any chance of getting a copy all the slides to review after the meeting?
Answer: Yes

Question: Is there an estimate available of the resource impact on a host machines due to the proactive threat scanning?
Answer: We will have this documented and available in a whitepaper
Question: Will SMS5 - Symantec Mobile Security Suite 5 integrate into SEP?
Answer: No.

Question: Do the antivirus capabilities within SEP 11 use less resources on a typical client and server? We have many problems with SAV 10 chewing up too much memory and CPU utilization, especially on virtual servers.
Answer: Yes, lower memory footprint

Question: Is there an override for the USB blocking?
Answer: Yes

Question: Can devices be blocked based on Manufacturer / Model?
Answer: No- windows class ID, not vendor class ID…..coming in the future though

Question: can usb thumb drives be blocked but other usb devices, ie scanner, printer be allowed?
Answer: Absolutely!

Question: is patch/maintenance release management going to be simplified over previous versions? (i.e. all inclusive rollups not requiring previous upgrades to a base version)?
Answer: Definitely

Question: so SMP includes the sygate firewall technology?
Answer: Yes!

Question: A new version of packager come with this - I am aware its unsupported but if new version does come with it will it be supported? If not any idea when?
Answer: Packager is gone. The packaging mechanism is the Sygate technology

Question: Will the schema be available for the database, so we can query it?
Answer: Definitely!!!

Question: Will SMSDOM (Mail Security for Domino) Still be supported as well as Premium Anti-Spam? How about for Exchange?
Answer: Yes

Question: Are the INTEL portions from previous NAV/SAV versions been eliminated altogether?
Answer: Yep

Question: Are the policies for the client available to be pushed via Group Policy in AD?
Answer: Yes

Question: can you restrict file types allowed to write to USB drives? i.e. allow MP3, but not DOC or XLS?
Answer: Yes.
Question: Can the Class ID blocking be managed by OUs, say the Director level can use usb drives, regular sales cannot?
Answer: Yes, using grouping

Question: Can individual components - say, the firewall portion - be disabled selectively? For example, we may want AV on a server but not necessarily firewall (even more specifically, for performance savings?).
Answer: YES!

Question: What version of java?
Answer: Local version

Question: how much space is required for the sql ie per machine?
Answer: DB size will vary by client count

Question: Does this version get away from storing client information in the registry?
Answer: Yep

Question: Can the management server be installed on VM?
Answer: Yep!

Question: Did he say the client port is 80?
Answer: Or 443 depending on selection by administrator

Question: is a certificate server required?
Answer: no

Question: In the current version of SAV10 Reporting, there is a vulnerability of the PHP component. Will SEPv11 provide better response to layered components that have known vulnerabilities?
Answer: Absolutely!

Question: the client/server traffic is based on port 80/443 correct? How is that going to affect clients running websites using port 80/443?
Answer: There should not be a conflict but the ports are configurable

Question: from the remediation aspect, will SAFE mode be required for a 100% detection and cleaning?
Answer: Depends on the threat. SEP 11 will clean better than SAV 10 though

Question: For replication what type of nbandwidth does it use over a WAN?
Answer: All documented in the scalability doc

Question: Since the client information is no longer in the registry how can we check AV status through scripts? Is there a WMI interface?
Answer: Some status can still be checked via the registry
Question: Since this is running on 80 or 443 is it using some type of web server underneath for communication (e.g. Tomcat/Apache/etc.)?
Answer: on the manager yes. There is a tomcat server and IIS

Question: We have encountered issues with the volume of network traffic generated by corrupted defs. How does the 11.x version address this issue?
Answer: corrupt defs should be a thing of the past.

Question: are there any JRE versions that are not supported or are recommended for the management console? Will the client itself require JRE to be installed for SEP to work?
Answer: CLient does not require JRE. The version installed is a local version specific to SEPM.

Question: will registry still use intel\landesk\virusprotect6 structure?
Answer: Nope. All intel technologies for management are gone and the registry has been changed as far as structure

Question: How can we obtain the scalability document?
Answer: It will be posted at release

Question: has sepm been certified for vm
Answer: We support VM environments. Not sure if it is certified by VM

Question: Why is this not backwards capable with SAV 10 or 9? Upgrading an entire enterprise can take a while.
Answer: Completely different management architecture.

Question: is there a method for users to alter administrative scan schedule (but not any other option)?
Answer: Yes

Question: what about Sygate 4.1?
Answer: no

Question: Will you be able to save all the old data from the SAV 10.1?
Answer: yes, migration wizard will cover this

Question: no over intall for 7.x is that correct
Answer: right

Question: OVerinstall of 10.2 for Vista supported?
Answer: yes

Question: he said that scalability doc will be available about a month after SEP 11.0 release
Answer: probably sooner
Question: when you overinstall does this require a reboot on the endpoint
Answer: Yes, but not for AV, just for the FW

Question: Will the overinstall work even if the previous client is password protected? Or will it still require a registry hack to remove?
Answer: It will work

Question: can SAV10 client groups be migrated, or is there granularity to support that type of group?
Answer: Migration wizard will allow this

Question: Does SEP support NT4.0 clients?
Answer: no
Question: does it work on vm . Currently version 10 I have on vm
Answer: Yes

Question: Is the upgrade to SAV 11 more reliable than the upgrade to SAV 10? We were forced to use NONAV to pre-clean the SAV 8 and SAV 9 systems before going to SAV 10
Answer: Yes.

Question: What is the SEPM blog URL?
Answer: https://forums.symantec.com/syment?category.id=endpoint

Question: Is the installer follow standard MSI best practices?
Answer: Yes

Question: will management server install require reboot (windows server 2003)?
Answer: no

Question: This includes central management and reporting for the FW?
Answer: Yes

Question: Any problems creating an SMS package for installing to clients?
Answer: no

Question: to install over 4.1 do you need to uninstall 4.1, reboot and install SEP or can you uninstall 4.1, install SEP and reboot?
Answer: Yes

Question: Can our TAM answer questions regarding SEP 11 yet? Or do we have to wait until the release?
Answer: Yes

Question: We run Symantec Mail Security for Exchange. If we run SEPv11 on the same box, are the defs compatible? Can they co-exist?
Answer: They can co-exist

Question: you mentioned earlier that the client initiates all contact with the server. What about Virus sweeps, updates that you want to push, do you have to wait til the next time the client checks in
Answer: No

Question: does the patch require a reboot? We have lots a 24×7 servers.
Answer: no

Question: Will the dif patch require reboots on the clients?
Answer: no

Question: No problem to run in a mixed environment, e.g. legacy clients reporting to previous management console, newer clients reporting to newer management console?
Answer: no problem with a parallel environment

Question: We are going to have a lot of language requirements (Thai, German, French, Russian, Swedish, Japannesse, Chinesse). Is there a link on your web page to the supported language versions?
Answer: It will be posted but is not right now. Should be at release time. We are localizing alot of languages

Question: For definition distribution, what is the approx size of the diff-defs? If a client has been off the network for a week or longer, what is the approx size of the diff-def?
Answer: will vary

Question: Thanks for the GUP!!
Answer: :)

Question: If a client goes to a GUP and then that client goes to another group will it still look for the GUP group A
Answer: no

Question: With ver9 and > Symantec expanded the feature set to combat spyware and malware, many customers complained of CE being bloated, memory-intensive, and causing issues with many line-of-business applications. With all these added features in this new product release can you point to any documentation related to this version benchmarks and/or performance specs compared to previous releases?
Answer: Its all documented. Check the portal

Question: will rapid release definitions be available for the Liveupdate server?
Answer: yes with LUA 2.5

Question: Not sure if this was asked. But when a client connects to a 11.0 server does it use a certificate like in the past for communications?
Answer: no

Question: Can the gups be configured as Primary, secondary, and can the clients recognize that
Answer: no

Question: when will this be available for download from the platinum site?
Answer: end of the month

Question: Thank You
Answer: You are welcome


The Creeva Murkado Diaries - part 1
[info]creeva

Originally published at Creeva's World 2.0. You can comment here or there.

Talus, it was an odd place. How did I end up here? Why am I here? Why am I during personal introspection? That’s right I want to make a name for myself, a place in the universe that I can carve out on my own. I want to be Creeva Murkado.

I managed to get here with my friend Xie ‘Lanthia. We kind of ran away from home is the proper way to put it. I knew Xie from school and she was escaping a future that her parents had set forth for her. Now we were here and we were having the time of our lives.

We were exploring the seedier side of town, visiting the local cantina was quite an experience. We had been used to the finer things in life. A cantina, especially on a planet like Talus was an unheard of place for either of us to ever visit. The air smelled of burnt death sticks, that sickenly sweet smell that just hangs in the air and begs for you to inhale. The smoke stung the eyes at first but after a couple minutes they adjusted and were fine with haze hanging in the air. It was wonderful, exciting, and invigorating to be here away form the life and on my own.

As we were watching the band perform through their piece (a number they said they picked up from a band on Tatooine), a wookiee slitherhorn player asked us to join them. I fumbled through the words the best I could in galactic common that I had no training, no knowledge, and I had 2 left lekkus. Unfortunately for us, the wookiee noticed that we each had a slitherhorn with us. We had “borrowed” these from some classmates, the idea was that we could have something to pawn if we got stuck somewhere. Slowly we took them out; we knew better then to make a wookiee angry (at least at this point in our lives).

I was tepid at first, squeaking and squawking away. After a couple hours it started to come natural and I even learned a few dance steps from the local dancers. I could almost taste my life. This was one of the few times I had ever felt at complete peace within myself and I wanted more. The evening was growing late and the customers started drifting out.

The local entertainers told us that since there is less population on Talus that this is what happens, the patrons have a natural rhythm that makes them an organism all of their own style. I couldn’t stop; I didn’t want the night to end. I wanted to do this forever and I wanted capture and relive this moment for all of eternity I grabbed Xie by the arm as I rushed for the door and she slapped me. Thankfully she thought I was some weird Rodian that was trying to hit on her all night and slapped before she saw who it was.

I explained my plan, my dream, and hopefully our destiny. We headed to the local starport and went to see what flights were available. The last ship for the night was leaving in 15 minutes. We didn’t care where it went, it was just a place to move onto and according the tickets we bought as we were running for the shuttle. The place where we were headed was called Tyrena.


AFK Entertainer
[info]creeva

Originally published at Creeva's World 2.0. You can comment here or there.

Here are the lyrics as performed at the IJB by the Def Stars

The AFK Entertainer

I’m the afk entertainer
And I know just where to stand
Another AFKer
Another macro band
Today I am your healer
I may have won your creds
But I know the game
You’ll forget my name
And I won’t be here for a jawa beer
If I don’t stay on the star charts

Chorus:
Oh yeah, macro baby macro
Oh yeah, macro baby macro

I’m the afk entertainer
And I’ve had to pay my price
The things I did not know at first
I got free training, NICE!
Ah but still it comes to haunt me
My tailor I need to pay
So I’ve learned to dance
With a macro and hot pants
I rub their neck and give my macro a check
As they tip because their BF goes way

Chorus:
Oh yeah, macro baby macro
Oh yeah, macro baby macro

I’m the afk entertainer
Been all around the worlds
I’ve said “tip me” in every cantina
And I’ve spammed with my dancer girl
I can’t remember faces
I don’t remember names
Ah but what the heck
I give my macro one last check
‘Cause after a while and a thousand galactic miles
The grind is still the same

Chorus:
Oh yeah, macro baby macro
Oh yeah, macro baby macro
Oh yeah, macro baby macro
TIP ME!!!!!!!!!!!!!


Symantec Enterprise Firewall - Solutions Guide for Load Balanced NAT Issues
[info]creeva

Originally published at Creeva's World 2.0. You can comment here or there.

<!– /* Style Definitions */ p.MsoNormal, li.MsoNormal, div.MsoNormal {mso-style-parent:”"; margin:0in; margin-bottom:.0001pt; mso-pagination:widow-orphan; font-size:12.0pt; font-family:”Times New Roman”; mso-fareast-font-family:”Times New Roman”;} @page Section1 {size:8.5in 11.0in; margin:1.0in 1.25in 1.0in 1.25in; mso-header-margin:.5in; mso-footer-margin:.5in; mso-paper-source:0;} div.Section1 {page:Section1;} /* List Definitions */ @list l0 {mso-list-id:572855412; mso-list-type:hybrid; mso-list-template-ids:-1186181492 67698703 67698713 67698715 67698703 67698713 67698715 67698703 67698713 67698715;} @list l0:level1 {mso-level-tab-stop:.5in; mso-level-number-position:left; text-indent:-.25in;} @list l1 {mso-list-id:1128162760; mso-list-type:hybrid; mso-list-template-ids:-592835512 67698703 67698713 67698715 67698703 67698713 67698715 67698703 67698713 67698715;} @list l1:level1 {mso-level-tab-stop:.5in; mso-level-number-position:left; text-indent:-.25in;} @list l2 {mso-list-id:1157769049; mso-list-type:hybrid; mso-list-template-ids:1523214700 67698703 67698713 67698715 67698703 67698713 67698715 67698703 67698713 67698715;} @list l2:level1 {mso-level-tab-stop:.5in; mso-level-number-position:left; text-indent:-.25in;} @list l3 {mso-list-id:1258293677; mso-list-type:hybrid; mso-list-template-ids:-1536103412 67698703 67698713 67698715 67698703 67698713 67698715 67698703 67698713 67698715;} @list l3:level1 {mso-level-tab-stop:.5in; mso-level-number-position:left; text-indent:-.25in;} @list l4 {mso-list-id:1437094087; mso-list-type:hybrid; mso-list-template-ids:1230905382 67698703 67698713 67698715 67698703 67698713 67698715 67698703 67698713 67698715;} @list l4:level1 {mso-level-tab-stop:.5in; mso-level-number-position:left; text-indent:-.25in;} @list l5 {mso-list-id:1599633008; mso-list-type:hybrid; mso-list-template-ids:-493076830 67698703 67698713 67698715 67698703 67698713 67698715 67698703 67698713 67698715;} @list l5:level1 {mso-level-tab-stop:.5in; mso-level-number-position:left; text-indent:-.25in;} @list l6 {mso-list-id:1631399832; mso-list-type:hybrid; mso-list-template-ids:417990644 67698703 67698713 67698715 67698703 67698713 67698715 67698703 67698713 67698715;} @list l6:level1 {mso-level-tab-stop:.5in; mso-level-number-position:left; text-indent:-.25in;} @list l7 {mso-list-id:1964076882; mso-list-type:hybrid; mso-list-template-ids:-135861800 67698703 67698713 67698715 67698703 67698713 67698715 67698703 67698713 67698715;} @list l7:level1 {mso-level-tab-stop:.5in; mso-level-number-position:left; text-indent:-.25in;} ol {margin-bottom:0in;} ul {margin-bottom:0in;} –>

I wrote this document for a customer back in 2005 when I was a Symantec Consultant - posting it from 2008 in the right time period.

Solutions Guide for Load Balanced NAT Issues

These are solutions to possible load balancing issue you may encounter with the Symantec Firewall load balancing methods. The assumption is problems you would encounter going from an internal network to an Internet host or network. These problems also rarely occur and are usually an issue depending on the security of the remote host.

Scenario: Multiple TCP connections on the same port leaving with different outside NAT addresses causes the remote server to reject the connection.

Example: HTTPS connections that do not use a client side cookie.

Solutions:

  1. We can use stateful failover for the TCP traffic and all traffic would leave as the VIP address. The downside is some increased load on all the firewalls in the cluster.
  2. Have a one to one NAT configured, this would correct that issue as the client would always be seen as the NAT address you configured. The downside is that you need a public IP address for every machine you would do this for.
  3. We can use original client address. The downside of this would require you to have publicly routable addresses going to the outside of the firewall. It would also allow the outside world to see your internal networking schema.
  4. Pass the traffic through a filter. The downside is that this passes below the proxy level and tight controls would need to be in place to maintain security. Also you would need publicly routable IP addresses or NAT the traffic on the upstream router. If you use public addresses internal and do not on the router it would allow the outside world to see your internal networking schema.
  5. Use traffic grouping, this ensures all traffic to the configured host goes through only one firewall at a time. The downside is administration level is higher due to the need of configuring remote hosts manually.
  6. Hardware Load balancer. The downside is that this is out of Symantec’s control and immediate scope. It would require reliance on a third party product.
  7. Manually route traffic through only one firewall. This would have the traffic corrected by having traverse one firewall only. The downside is administration level required to perform this. Another issue is if the firewall that is passing the traffic goes down the connection would not work or network administrators would have to configure a route change on the router directing this traffic.


Scenario: A connection that requires multiple TCP destination ports.

Example: Passive mode FTP (which the FTP daemon can handle this without modification; lack of a more common protocol as an example is not immediately available.)

Solutions:

  1. We can use stateful failover for the TCP traffic and all traffic would leave as the VIP address. The downside is some increased load on all the firewalls in the cluster.
  2. Have a one to one NAT configured, this would correct that issue as the client would always be seen as the NAT address you configured. The downside is that you need a public IP address for every machine you would do this for.
  3. We can use original client address. The downside of this would require you to have publicly routable addresses going to the outside of the firewall. It would also allow the outside world to see your internal networking schema.
  4. Pass the traffic through a filter. The downside is that this passes below the proxy level and tight controls would need to be in place to maintain security. Also you would need publicly routable IP addresses or NAT the traffic on the upstream router. If you use public addresses internal and do not on the router it would allow the outside world to see your internal networking schema.
  5. Use traffic grouping, this ensures all traffic to the configured host goes through only one firewall at a time. The downside is administration level is higher due to the need of configuring remote hosts manually.
  6. Hardware Load balancer. The downside is that this is out of Symantec’s control and immediate scope. It would require reliance on a third party product.
  7. Manually route traffic through only one firewall. This would have the traffic corrected by having traverse one firewall only. The downside is administration level required to perform this. Another issue is if the firewall that is passing the traffic goes down the connection would not work or network administrators would have to configure a route change on the router directing this traffic.

Scenario: A mixture of UDP and TCP traffic.

Example: This is usually seen in custom applications such as streaming media where the connection starts on TCP and migrates over to UDP for media delivery.

Solutions:

  1. Have a one to one NAT configured, this would correct that issue as the client would always be seen as the NAT address you configured. The downside is that you need a public IP address for every machine you would do this for.
  2. We can use original client address. The downside of this would require you to have publicly routable addresses going to the outside of the firewall. It would also allow the outside world to see your internal networking schema.
  3. Pass the traffic through a filter. The downside is that this passes below the proxy level and tight controls would need to be in place to maintain security. Also you would need publicly routable IP addresses or NAT the traffic on the upstream router. If you use public addresses internal and do not on the router it would allow the outside world to see your internal networking schema.
  4. Use traffic grouping, this ensures all traffic to the configured host goes through only one firewall at a time. The downside is administration level is higher due to the need of configuring remote hosts manually.
  5. Hardware Load balancer. The downside is that this is out of Symantec’s control and immediate scope. It would require reliance on a third party product.
  6. Manually route traffic through only one firewall. This would have the traffic corrected by having traverse one firewall only. The downside is administration level required to perform this. Another issue is if the firewall that is passing the traffic goes down the connection would not work or network administrators would have to configure a route change on the router directing this traffic.

Scenario: TCP and IP traffic mixture.

Example: Microsoft’s PPTP VPN. This product uses port 1723 TCP and IP type 47 to pass traffic.

Solutions:

  1. Have a one to one NAT configured, this would correct that issue as the client would always be seen as the NAT address you configured. The downside is that you need a public IP address for every machine you would do this for.
  2. We can use original client address. The downside of this would require you to have publicly routable addresses going to the outside of the firewall. It would also allow the outside world to see your internal networking schema.
  3. Pass the traffic through a filter. The downside is that this passes below the proxy level and tight controls would need to be in place to maintain security. Also you would need publicly routable IP addresses or NAT the traffic on the upstream router. If you use public addresses internal and do not on the router it would allow the outside world to see your internal networking schema.
  4. Use traffic grouping, this ensures all traffic to the configured host goes through only one firewall at a time. The downside is administration level is higher due to the need of configuring remote hosts manually.
  5. Hardware Load balancer. The downside is that this is out of Symantec’s control and immediate scope. It would require reliance on a third party product.
  6. Manually route traffic through only one firewall. This would have the traffic corrected by having traverse one firewall only. The downside is administration level required to perform this. Another issue is if the firewall that is passing the traffic goes down the connection would not work or network administrators would have to configure a route change on the router directing this traffic.


Scenario: UDP connections using multiple ports

Example: No known examples available for reference.

Solutions:

  1. Have a one to one NAT configured, this would correct that issue as the client would always be seen as the NAT address you configured. The downside is that you need a public IP address for every machine you would do this for.
  2. We can use original client address. The downside of this would require you to have publicly routable addresses going to the outside of the firewall. It would also allow the outside world to see your internal networking schema.
  3. Pass the traffic through a filter. The downside is that this passes below the proxy level and tight controls would need to be in place to maintain security. Also you would need publicly routable IP addresses or NAT the traffic on the upstream router. If you use public addresses internal and do not on the router it would allow the outside world to see your internal networking schema.
  4. Use traffic grouping, this ensures all traffic to the configured host goes through only one firewall at a time. The downside is administration level is higher due to the need of configuring remote hosts manually.
  5. Hardware Load balancer. The downside is that this is out of Symantec’s control and immediate scope. It would require reliance on a third party product.
  6. Manually route traffic through only one firewall. This would have the traffic corrected by having traverse one firewall only. The downside is administration level required to perform this. Another issue is if the firewall that is passing the traffic goes down the connection would not work or network administrators would have to configure a route change on the router directing this traffic.

Scenario: UDP and IP traffic mixture.

Example: This traffic would mostly be associated with IPSEC VPN traffic.

Solutions:

  1. Have a one to one NAT configured, this would correct that issue as the client would always be seen as the NAT address you configured. The downside is that you need a public IP address for every machine you would do this for.
  2. We can use original client address. The downside of this would require you to have publicly routable addresses going to the outside of the firewall. It would also allow the outside world to see your internal networking schema.
  3. Pass the traffic through a filter. The downside is that this passes below the proxy level and tight controls would need to be in place to maintain security. Also you would need publicly routable IP addresses or NAT the traffic on the upstream router. If you use public addresses internal and do not on the router it would allow the outside world to see your internal networking schema.
  4. Use traffic grouping, this ensures all traffic to the configured host goes through only one firewall at a time. The downside is administration level is higher due to the need of configuring remote hosts manually.
  5. Hardware Load balancer. The downside is that this is out of Symantec’s control and immediate scope. It would require reliance on a third party product.
  6. Manually route traffic through only one firewall. This would have the traffic corrected by having traverse one firewall only. The downside is administration level required to perform this. Another issue is if the firewall that is passing the traffic goes down the connection would not work or network administrators would have to configure a route change on the router directing this traffic.

Scenario: Multiple IP types only connections.

Example: No known examples available for reference.

Solutions:

  1. Have a one to one NAT configured, this would correct that issue as the client would always be seen as the NAT address you configured. The downside is that you need a public IP address for every machine you would do this for.
  2. We can use original client address. The downside of this would require you to have publicly routable addresses going to the outside of the firewall. It would also allow the outside world to see your internal networking schema.
  3. Pass the traffic through a filter. The downside is that this passes below the proxy level and tight controls would need to be in place to maintain security. Also you would need publicly routable IP addresses or NAT the traffic on the upstream router. If you use public addresses internal and do not on the router it would allow the outside world to see your internal networking schema.
  4. Use traffic grouping, this ensures all traffic to the configured host goes through only one firewall at a time. The downside is administration level is higher due to the need of configuring remote hosts manually.
  5. Hardware Load balancer. The downside is that this is out of Symantec’s control and immediate scope. It would require reliance on a third party product.
  6. Manually route traffic through only one firewall. This would have the traffic corrected by having traverse one firewall only. The downside is administration level required to perform this. Another issue is if the firewall that is passing the traffic goes down the connection would not work or network administrators would have to configure a route change on the router directing this traffic.


Scenario: A connection using TCP, UDP, and IP types all in conjunction.

Example: Older VPN connections that did not adhere to the IPSEC standard.

Solutions:

  1. Have a one to one NAT configured, this would correct that issue as the client would always be seen as the NAT address you configured. The downside is that you need a public IP address for every machine you would do this for.
  2. We can use original client address. The downside of this would require you to have publicly routable addresses going to the outside of the firewall. It would also allow the outside world to see your internal networking schema.
  3. Pass the traffic through a filter. The downside is that this passes below the proxy level and tight controls would need to be in place to maintain security. Also you would need publicly routable IP addresses or NAT the traffic on the upstream router. If you use public addresses internal and do not on the router it would allow the outside world to see your internal networking schema.
  4. Use traffic grouping, this ensures all traffic to the configured host goes through only one firewall at a time. The downside is administration level is higher due to the need of configuring remote hosts manually.
  5. Hardware Load balancer. The downside is that this is out of Symantec’s control and immediate scope. It would require reliance on a third party product.
  6. Manually route traffic through only one firewall. This would have the traffic corrected by having traverse one firewall only. The downside is administration level required to perform this. Another issue is if the firewall that is passing the traffic goes down the connection would not work or network administrators would have to configure a route change on the router directing this traffic.