Wednesday, March 4, 2020

Track and stop Corona Virus spread

I want to suggest a simple device, to track and stop the spread of corona virus. We can mass produce a small RFID tag, which sends the person's mobile number or an alibi to that number, which can be found, from central database. A microphone should be attached to the Mobile phone, pinned in the collar, which detects whether it's a cough or sneeze, with the help of mobile app. Mobile phone will have a RFID reader attached to it. Suppose a person is identified to have corona virus, we can use his device to find whoever talked or stayed close to him for more than say 30 seconds. And the most important, whenever the infected coughs, microphone, pinned in his collar will sense that he is coughing or sneezing and records all other victims' RFID number( or mobile number directly ) near him in the mobile app, with the help of the nearby victims' tag, and RFID reader attached in the infected Mobile phone. So, we can completely track the spread of corona virus from person to person, contact them through their mobile phones and ask them to take a test. We can even segregate them, whether they are high risk, low risk, sure victims, by their time spent with the infected and whether they were with him, when the infected coughed or sneezed.

If we develop technology for this, we can simply create a smiley batch, with all the necessary technical products in that batch and people just need to wear the batch, connected to their cellphone, by Bluetooth or wireless. If we do research further, we can even develop smiley alone, which  works on battery, later retrieving the data, so that children can also wear this. Definitely this is not rocket science. It's just a simple device. Ateast in the future, we should be ready and act immediately, before such virus outbreak starts.

Wednesday, February 12, 2020

Rejuvenating the rural economy profitably

Giving money to rural dwellers unsustainably and unprofitably by schemes like MNREGA is not a good idea. Instead, we can make farmers earn money from their own agricultural land. That can be done by building small resorts in the centre of patches of agricultural land. These resorts should be branded, very good if star hotels collaborates and pay rents for the land use and sharing their profits with all the farmers covering the patch of land. This model is living luxuriously with nature and greenery all around. Also these patch of lands should do organic farming, sharing their crop produce with resorts for food, giving a great dining experience. More can be done by sharing their cultural and heritage, with those staying in the resort. Local food made in collaboration with resort chefs and going to local temples, enjoying festivals and rural dance and art forms will give a great experience for the resort customers. Their is no two views that more urban dwellers want to spend their life atleast in weekends in rural areas, living with nature. So, this is going to be surely profitable model, only we should be careful in keeping the brands good name, without compromising the quality of stay. That's why I prefer star hotels, collaborating with the locals.

Now, let's get to the benefits of this method. It will bring infrastructure to the rural areas. Roads, Clinics, Electricity, Clean water, Jobs for locals will all start to come beginning from the most connected rural areas, gradually getting into deeper rural areas. Sustainable power source, zero carbon initiatives will start like solar powered resorts. We can even make compulsory to ferry resort customers in and out of rural areas only through electric vehicles. Organic farming will become the norm in those patch of lands, not only serving the resort dwellers, but also the farming at large.

Thursday, January 9, 2020

Labour reforms



Before I start, I must tell you that I am against Labor Unions. They make employees inefficient and irresponsible. But, still we should find a way where middle and lower level employees of an organization are fairly paid. Otherwise, there will be huge disparity in the society; with top few percentages of people holding much of their country’s wealth, with the disparity exponentially increasing in the near future.

              The Labor Reform, I am proposing is the salary level for the Primary Hierarchy of a Company, which is the main source of income and the core job, the Company does and for the Secondary Hierarchy of the Company, which does trivial jobs like housekeeping or security for a software Company, unrelated to the core job. Keep in mind that housekeeping is itself is a core job and in primary Hierarchy for super markets and that security is in Primary Hierarchy for Banks. The Primary and Secondary hierarchies never meet and are parallel to each other. The Company can be private or public, salary  in every level of the Hierarchy, should have a Range, whose Center, is twice, thrice or four times, the Center of the Salary Range immediately below its level. Banks may give 2 factor increase in Salary. Software Companies like Microsoft may give 4 factor increase in Salary. The Company can add as many Levels as it wishes, only that the whole Company’s Hierarchical Structure should form a Pyramid.
Example:
             


If in a Bank, Let’s say a Clerk gets a salary, whose Center of the Range is 4 Lakhs per Year. So, the next level in the hierarchy Probationary Officer will get their Center of the Range, the double ( or triple  or Four times, But should be same for the whole Organization ) of the Clerk, which is 4*2 = 8 Lakhs per Year. The Boundaries of Range in every level is calculated by taking multiplication of 2, ( triple or four times, the organization chose) and a constant 5. The Upper Range cut will be 2*5 = 10 % more and Lower Range is 10% less from the Center of the Range. Clerk’s Range of Salary is 3.6 Lakhs to 4.4 Lakhs per Year. Probationary Officers’ Salary Range is 10% less to 10% more of middle 8 Lakhs per Year, got by multiplying Clerk’s mid-Range with 2. Probationary Officers’ range is  7.2 Lakhs per Year to 8.8 Lakhs per Year. Accountant, Cash Officer and Field Officer will get between 14.4 Lakhs per Year to 17.6 Lakhs per Year.
              
Let’s study one more scenario, what if there are more than one Primary Hierarchies. As long as they are not irrelevant Secondary Hierarchies, they should meet at a point. What if , it has different number of levels. Example, There is a Manager for wrist watch in a watch company and he takes care of sales hierarchy, manufacturing hierarchy and research hierarchy. Sales hierarchy has 3 levels, Manufacturing 4 levels and research 2 levels. First, we have to take the vertical that has maximum employees. They will usually have maximum number of levels. Here Manufacturing.  It has 4 levels, replicate it across all hierarchies. Now, Research and Sales will also have 4 levels. In case, it doesn’t need that number of levels, create hypothetical levels. Like if there are Manager, Supervisor and Salesman for Sales Hierarchy. Add one more Level, Deputy Manager or Chief Salesman, wherever you want, only in theory. If you create Hypothetical Chief Salesman, Salesman will be directly promoted to Supervisor, with 4 factor ( in case the watch company chose 2 factor increase in salary in every level up ) increase in salary. You can introduce hypothetical levels anywhere. But the whole organization should form a pyramid.

              If you increase the number of Hierarchies, Mid-Level Employees will be benefitted. If you decrease the number of Hierarchies, Low Level Employees will be benefitted. Both ways, our objective is achieved. Legal system implementing this system just needs to check Income Tax Filing, if it forms a pyramid, that’s all it cares.

Friday, January 3, 2020

Let's stop viruses

I will start with a little knowledge, i have on viruses. First, like Certificate Authorities on Websites, we will provide CAs for softwares. CAs should have a network of all possible necessary framework to validate a type of software, unattached to the internet. After that, it validates a particular version of software from a certain website. If you have got that software from an unknown source, verify it with the CA online. CAs just need to pickup random bits from the original and unknown source, and verify it. Now, we will see e-mail attachments of files and softwares. If i see a file named hello.txt, why would it run, it's purpose is to show u some text. Always open a txt file in an text editor, jpg file in a photo viewer, .mpeg in a video player. E-mails should only see the files as shown to the viewer. Don't care if it's hidden .txt.exe. If it's shown as .txt, open it in a text editor. If you see code in editor, unwanted information or gibberish,  delete the mail. If you see no picture or video, delete the mail. If it's not a clear known viewable type of file extension( .txt, .jpg,.mpeg,.docx), as viewed by the recipient, like .TxT ,. Mpeg, . txt.exe, . mpg.exe clearly tell them it maybe malicious and advice them to delete the mail. If there is standard non- viewable file format allow only to download and not run. After downloading , ask them to verify with the CA. If someone creates a software ( malign with no CA certificate, maybe even few lines of code) and sends it through mail, check with CA. All these for common man, who suffers most damage. Programmers who want to share their code can ignore the warning and execute. If virus or any malicious software is found, both CA and the software firm is accountable. CA software should be installed in the PC and connected to the internet. CA software will first quarantine and read the version and name of the software by getting into the internal bits and after verifying its validity, by the particular CA who verified it, CA software will allow the software to get installed. Of course you can bypass CA, incase you are a programmer. There can be multiple CAs with expertise in different areas, working separately or collaborating incase the software has multiple utilities,  making the probe more worthy. Search in common CA list for the software name and version, go to that CA and verify its validity.

Thursday, January 2, 2020

Access Badge

I saw a video in which kevin says, i went to a rest room and  created duplicate card, by copying it, by some means, which i don't know. If that person enters the building with the card at the entrance, second attempt with a duplicate card by kevin should have raised an alarm. Even if that person enters second, kevin is trapped inside. If you map all the building, we can stop the security breach. You can even know, if security is breached, by recording entries and all the path the intruder has taken. If the employees are given Microsoft calendars, which has the normal working hours and their holidays, Card can be used during those hours, without dynamic passwords, i wrote a blog about, just by using access badge. Other times, use both access badge and dynamic password. Atleast, mark next day's entry time in the calendar, like i will enter the premise tomorrow between 9 AM and 11AM, exit anytime, along with holidays. Standard times for lunch will be without passwords, if you go out. Otherwise, enter with passwords. Anyways, this is just a better way of security, not cent percent fool proof. If say, i don't care about ease of use and want full security. Put Smard cards + dynamic password + face recognition + no double entries, everytime.

I have another simple method to confuse card copying. Provide a two plastic dials, each with 6 to 10 points in the access badge. It will make the badge little thick. You will be assigned a number between 00 to 55, in case of 6 point dial or 00 to 99 in case of 10 point dial. Or instead of dials, lines can be used, the more the lines, the more the numbers. Every time you swipe( inserting inside card reader), it will check the magnetic code and the plastic dials. If both are correct, give access and changes the plastic dial to a random number. Every time you swipe, change the dial to ur assigned number manually and after that, let the reader itself confuse the copier by changing it to a random number. Your effort reduced. Plastic dials, first of all can't be copied. It will not emit any magnetic field. Card Reader will detect the assigned number by the raised plastic mould used. It's like a password, only that you don't waste time on quees and the one behind you, won't peek into ur password. We can use plastic number checks during entry and exit of the building, leaving the rooms inside to check only the magnetic code. Also, we will design, the dial in such a way that no finger prints can find the number. The dial will have a small flat hole. A plastic pen will be provided at the side of the card. Insert the tip of the pen in the hole and rotate it. Without the pen you can't rotate the dial. And the dial will always rotate in one direction. Dial and the card will be at same flat level. Obviously, this technology will not be used in FBI. But if a small or mid-sized company wants security, this is a very cheap, high security method with that cost. Also can be commercially mass produced.

Thursday, December 12, 2019

Let's play with Passwords

Let's Play with Passwords. So, I am going to propose a method, where all you need to remember is a number between 1 and 9 ( or a letter between a to z)and a mathematical method. That's it. Your password is ready. For that first we need a two way authentication. First authentication method could be finger print, face recognition or waving or whatever you fathom. Let's take a Face recognition system. You open Windows Laptop or a Windows Mobile ( Maybe), it recognizes your face, checks its validity and generates a say 7 digit number or a 7 character stream. You should already configure your Windows Laptop, with the 1 and 9 ( or a letter between a to z)and a mathematical method. 

Let's say, I configured number 2 and method, altearnately add the chosen number. After first level recognition, it gives you 2749164. So, now my Password is 4769366. In case 9+2 =11( take the last digit). Every time, the 7 digit number you get, will differ. And you can create password just by knowing your number and method. Each of your device can have same method and number, so that, it is easy to remember passwords and not to write it anywhere or different sets. Very very simple to remember. The methods can be unlimited. Even for alphabets and 100 different methods possibility is 24 * 100 = 2400 possible passwords, every single time. You can even program your own method, which makes the possibilities literally unlimited. So, i guess nobody will allow someone to try thousands of times for a commercially available personal device. Even if someone tries at different intervals, the user should be notified of wrong password attempts and adviced to change password. Anyways, password is Very simple to remember. Try for high security systems yourself. For multi digit results of a number, if operated on a given place in the given 7 digit number, always use the last digit. For fractions, use the digit before decimal and for negatives leave out the negative symbol. As they have more chances of variation. I hope, mathematicians and experts will figure out all these small small things. This is not about deciphering.

 In case, you want to stop deciphering, jumble the numbers or increase or decrease the number of digits in the result. Like if u are given 7 digit, you may enter 8 digit, 9 digit or even 5 digit as output of your method or different number of digits as outputs everytime, with a single method, which i guess is totally impossible to decipher.  The trick really lies in choosing or creating methods. It doesn't mean you have to deal with  complex division or fractions.  Just innovative methods. Like  don't operate with the same digit you have chosen, with  all the digits, you are given. One simple method will be first, 

Multiply chosen number 2 with first digit and use the outcome to multiply with second digit.

Subtract the chosen number 2 with third digit and use the outcome to subtract it with fourth digit.

Add chosen number 2 with fifth digit and use that outcome digit to add with sixth digit. 

Keep seventh digit unchanged.

Like 4285431. Outcome 8661691. 

To change the number of digits in the outcome of a given 7 digit number is also simple. 

Multiply chosen number with last digit and drop that place digit. Like 2*1. Drop second place. Outcome 861691. Simple.

Another trick, generate a number. Take a digit you get, when you operate the chosen number with a particular place and mingle it with outcome anyways you like.

Example, 
Given number 6387426
Chosen number 2.

Step 1: Multiply 2 with all the places.
Step 2 : Half reverse the number. 
Step 3 : Choose the last digit and multiply with chosen number to get the generated number.
Step 4 : Modulus the generated number with total number of digits, which is 7 and remove that place. ( Simplest usage of generated number ).

Step 1: 2664842
Step 2: 2662484
Step 3 : Generated number : 8
Step 4 : 662484 

Trick always lies in choosing the method.

Phishing is the single biggest threat for this method. If you are careful about it, even + 2 is suffice. It is always advisable to keep two methods of creating passwords, one for money transactions and highly safe requirements and one for not so critical necessities. Like, one for net banking password and one for chatting websites. Don't go and reveal your highly secure password methods in petty websites. Mostly, there will be no requirement to change password generating methods for years, if you choose a tricky method.

Even if you phish, you can maximum get hold of tens of password combinations, which is obviously not sufficient for even a super computer to decipher, not because there are lot of possible passwords, but because for the same password there are unlimited possible methods. Making that worse will be to use multiple levels of creating passwords, like using different methods again and again on the passwords, which are getting created. 

Also, no website allows you to check more than 3 attempts. If a site asks password for fourth time, it is a phishing site. Go and change your method. The phishing site has to ask for fourth time or lock the user, if it is a phishing site, because otherwise you have to login. By the way, with 3 password combinations, it will be impossible to find the method. There is an advantage for using a number along with method, because if you want to change the password, which you may keep in many sites, just change the number in all sites. Also, we can check the authenticity of phishing sites, by first entering the username, and asking it to fetche out the age of the person or organisation. Only if it's correct, go for entering password. We can ask name or date of birth to display, but it will be little exposing the account holders information. Age is in neither extreme. So, it further affects the phishing sites to a very great degree.

If you say, first you will use simple methods to solve it, shows you have not understood the problem. I will explain you with a simple example. Just using only addition and only one level of operation. First, add the chosen number with first digit. More than 9 possibilities, because two digits may come as result of addition. Then add first and second digit with chosen number, more than 9 possibilities. Like wise. Leave zero gap, more than 9*5= 45 possibilities. One and third digit. Two and fourth digit. Leave one gap Likewise another more than 9*5 = 45 possibilities. 45*5 = 225. Second. Add three numbers with chosen digit. Continous. With gap. Change the gap. Unlimited simple possibilities, with simple one level addition.

Creating methods can be made simple by providing building blocks, so that even non programmers can use it to create their own method. It's not difficult, so i leave it to developers.

I tell you there is no way to decipher it. It's like working with enigma for every single password.

All member one digit or a letter and a method. My job ends here.

If say, the customer isn't good at numbers, we can create a Microsoft Password App, that will give you the output, on giving the input, as programmed by you in say, internet banking. Create a Password generator Program in Microsoft Password App. It will be converted to bits and the password method will be unrecognisable or unrecoverable. But it is not recommended for high security needs, because if you lose your phone, maybe people can give input to that App and get output, only if they are highly sophisticated hackers. Otherwise, it's quite safe.

Let's critically analyse this password technique. Is there a way to break it. Sort of. You just have to avoid certain pit falls. So, first if someone gives 1234567 or 7654321 sort of numbers, he may be able to guess it. We can avoid that. Now comes the interesting part. What if i create a phishing software that works as a bridge between the real website and fake phishing website. Puff. All hell will break. So, does that mean this password method is not effective. No, it is better than plain passwords. Also, we should not forget that it is not alternative to OTPs. It is not only good practice, but a necessity to send the Amount and beneficiary account number along with the OTP. How avoid such phishing methods. Confuse the phishing software by dynamically altering the source of display numbers which are shown in the real website. Graphic Captcha will help. Hackers have to depend on the phishing software. Because they can't manually enter anything, within minutes and the number of hackers and their timing will give problems to them.. Even if we don't use any of these methods. Getting hold of this account and to send money will require OTP. If the hacker wants to change the phone number and get access to OTP, he needs profile password and a process which needs old mobile's OTP and Debit card details. We can make profile password very easy to remember, by just altering one critical digit change. These profile password can't be accessed, because, the hacker has to show what is inside the Netbanking site, which will be very dynamic based on each individual customer. And also, the customer just wants to send money not to change mobile number. Other than phishing, i don't think there is any other application like entry to high security buildings or safes and vaults, which has this slight drawback.

Wednesday, November 6, 2019

Training Suit

It's a very simple idea to help people learn Yoga, Tai chi, Athletics, Dance, etc. Wear a training suit which has stripes across its body to enable you to find the position of body parts in accordance with a standard training pattern. It records your every move and helps you analyze your moves. You just need to buy the suit that fits you and select the program according to your suit size.