CQ-Contest
[Top] [All Lists]

RE: [CQ-Contest] LoTW Fee Schedule just released !!! (Long)

To: "'R Johnson'" <k1vu@tmlp.com>, <cq-contest@contesting.com>
Subject: RE: [CQ-Contest] LoTW Fee Schedule just released !!! (Long)
From: "Darryl Wagoner" <darryl@shecora.com>
Date: Tue, 30 Sep 2003 10:13:35 -0400
List-post: <mailto:cq-contest@contesting.com>
Greeting Bob and the group,

> -----Original Message-----
> From: R Johnson [mailto:k1vu@tmlp.com] 
> Sent: Monday, September 29, 2003 9:00 PM
> To: Darryl Wagoner
> Subject: RE: [CQ-Contest] LoTW Fee Schedule just released !!!
> 
> 
> Darryl:
> AGN ???

Huh?
    
> Are you speaking for yourself or the ARRL LoTW team using the 
>CQ Contest List for a forum for the League ???

I am speaking strictly for myself.  If I wasn't I would not have
pointed out that TrustedQSL can work outside of LoTW and outside
of ARRL.

> After doing a TEOMA.COM  search on your callsign WA1GON, I 
> found that "The logging software modules are being developed 
> as part of the Trusted QSL open-source project headed by 
> Darryl Wagoner, WA1GON
> 
> See  http://www.arrl.org/news/stories/2001/08/02/3/ !!!

I was selected to lead the client TrustedQSL development after I
had started a group to create a open source TrustedQSL software.
My design almost fit ARRL concept of what the client should be and
the part that didn't ARRL saw the error of their ways. ;-)

Then I got laid off from my programming job and had to start
working manual labor jobs to make the house payment.  It didn't
take me too long to figure out that there wasn't enough of me
to work 10-12 hours a day, 7 days a week  and do TrustedQSL, 
so I turned over the project to ARRL.  I really regret letting 
ARRL down when they was counting on me, but they still turned 
out a great product.
 
> I personally consider it poor form for the ARRL, their 
> employees or advisors to use a Public List in this manner.

Why is that?  

Is it because your argument has no merit so you have to use 
the logical fallacies:  Attacking the Person (argumentum ad hominem)

For all those who want to know the truth when they hear it there is
a great guide at:

http://www.intrepidsoftware.com/fallacy/welcome.php

This site gives detailed examples of logical fallacies and what they
are and most important how to counter them.

> Other member associated with the development LoTW have 
> refrained from using Non-ARRL list to respond to LoTW questions !!!

Who better to answer questions than the team to design and develop
the system?  Why would you want to exclude the very people that
may have the answers to questions others need.

You seem to be trying to imply that ARRL is evil and eQSL.cc will save
us from the evil ARRL. (I have just stated is a logical fallacy.  False
Dilemma: Given two choices when there is 3 or more (there is also
another
logical fallacy can anyone find it?))

Ok lets look at some facts:

1.  Open Standards

ARRL released TrustedQSL under the  GNU Library or Lesser General Public

License (LGPL) which means that anyone can take the source and do
just about anything they want as long as the keep the LGPL license
with any fees being paid to ARRL.  True that ARRL has not release
sources to the server side of LoTW, but they are using open standards
such as the X.509 standard for certs.

eQSL.cc has a disclaimer at the bottom of their page:

No part of this web site may be reproduced, duplicated, printed, copied,

or downloaded without permission.  Patent Pending on most aspects of 
the eQSL.cc technology. If you find another online QSL card exchange 
similar to ours, let us know. It is probably infringing on our patents. 

In other words eQSL is saying that even if you create an eQSL buro and
you do something the same way I did, then I will sue you.  To me this 
flies in the spirit of Amateur radio of share ideas and information.

(Note:  This statement was what caused me to start the TrustedQSL group
in the first place)

2.  Security

ARRL and LoTW provides a good compromise between security and easy of
uses.  It isn't as good as Verisign but this is still a hobby.
Authentication
is a pain if it is done right.  ARRL is doing it right.  TrustedQSL can
be trusted regardless of the domain they are in.  That means that a DX
station can put a TrustedQSL on a floppy send it by mail to a sleazy QSL
manager (that didn't work that DX station and needs it for DX200) and
have
complete faith that the sleazy DX manager could not change that tQSL
before
forwarding it on to LoTW.

Once the tQSL is in LoTW it is still in the trusted format.  That means
that if another sleazy DX chaser breaks into ARRL's database he/she
can NOT add fake records no matter how much access he/she gets to the
system.

eQSL.cc doesn't use TrustedQSLs or any form of digital signatures
therefore
they can not be validate once they leave the logbook of the sender.  You
have to take eQSL.cc word for that the eQSLs have not been alter and
that
they really came from the real station, etc.  

Also eQSL is using Microsoft servers which has been plagued with
security
holes.  There also isn't any secure encryption of passwords or other
data
over the internet.

Given the best case that eQSL.cc has a 100% uncrackable system, that
there
AG program is 100% fool proof and everyone that has access to eqsl.cc
is 100% trustworthy.  The fact remains that eQSLs can only be trusted
in the domain of eQSL.cc.  Once it leaves eQSL.cc it can no longer be
trusted.

You might have notice that I didn't say anything about LoTW/ARRL server
security.  That is because I didn't need to.  It could be wide open
where anyone could log in to it and the TrustedQSLs would still be
secure.
The only possible thing a hacker could do the a TrustedQSL is deleted.

Sorry this was so long, but computer security some times hard to get
a handle on with lots of gotcha (just ask Microsoft).  Digital
signatures
is the most fool proof way to protect digital data from being tampered
and 
validating that the data came from the source you think it did.


73 and happy dxing

-darryl WA1GON

---------------------------------------------------------------
    The world's top contesters battle it out in Finland!
THE OFFICIAL FILM of WRTC 2002 now on professional DVD and VHS!
       http://home1.pacific.net.sg/~jamesb/
---------------------------------------------------------------

_______________________________________________
CQ-Contest mailing list
CQ-Contest@contesting.com
http://lists.contesting.com/mailman/listinfo/cq-contest

<Prev in Thread] Current Thread [Next in Thread>
  • RE: [CQ-Contest] LoTW Fee Schedule just released !!! (Long), Darryl Wagoner <=