2015年4月11日 星期六

Google 美股選股

https://www.google.com/finance?hl=en&ei=ZaEoVcGOEJD6uAT5zIHoCg#stockscreener

Market Capital: > 10B
本益比: 5~40
ROE: > 20%
ROA: > 5%
毛利率: > 25%
營業利益率: >10%
EPS growth rate: >5%


2015年4月7日 星期二

巴菲特原則

1. 一個二流的企業最有可能仍舊是二流的企業,而投資人的結果也可能是二流的。廉價購買所帶給投資人的好處會被二流企業的低收入所侵蝕。華倫知道時間是傑出企業的好朋友,卻是二流企業的詛咒。
    他也發現,一個傑出企業的經濟狀況是完全不同於那些二流企業的,如果能買到某家傑出企業,相對於二流企業的靜態價值,傑出企業會有擴張價值,其擴張價值最終會使股市帶動股票價格。

2. 商品型企業: 一個企業所生產的產品,價格是消費者最主要的購買因素之一。 這些公司所生產的產品,在市場上面臨強勁的競爭。
    商品型企業的未來成長空間非常小,由於價格的競爭,這些公司的利潤一直很低,所以公司較缺乏經費擴充企業,或是投資更新,更有賺錢能力的企業。就算設法開始賺錢,資金通常用來更新工廠的設備,以保持競爭的能力。

3. 當傑出的管理階層碰上了不良的企業,通常是不良的企業依然保持原狀。

4. 商品型企業特徵: 低利潤,低股東權益報酬率,品牌忠誠度低,有大量的競爭者,過度的生產力,經常變動的利潤,以及完全依賴管理階層有效運用公司可見的資產已獲利。

5. 兩個不同性質的企業,同樣都是在年度內賺取200萬美元的淨利。但不同的是,喜斯公司已800萬美元的淨有形資產就創造出200萬美元的淨利,相對的,鋼鐵廠卻以1800萬美元的淨有形資產才創造出200萬美元的利潤。 如果兩家公司都計畫更換生產設備,而生產設備的價格因為通膨的因素上漲一倍,喜斯公司要花費1600萬美元,而鋼鐵廠卻要花3600萬美元的資金進行設備的更新。 => 說明資產報酬率(ROA)的重要性,選擇用較小的淨有形資產卻能創造高獲利的公司。

6. 華倫相信通貨膨脹事實上無所不在,因為通貨緊縮無異是扼殺那些政客的政治生命,而通貨膨脹會造成財富增加的假象。30年前花了10萬美元買的房子',現在價值50萬美元,難保你不會暗自竊喜。縱使你決定賣掉原來的房子買一間和原先大小相符的新房要花費50萬美元,你也覺得自己變得更為富有。 30年前,你的年收入2萬美元,現下你的年收入10萬美元,但實際上購買力並沒高出許多,所以,你變得富有了嗎?其實不然。如果你的收入固定,或者購買長期債券或手中持有現金,你的實質財富大多會減少。

7.格拉罕覺得經濟長期趨勢會偏向通貨膨脹,並穿插一段通貨緊縮時期,而且普通股無疑是一種對抗通貨膨脹的理想保障和避險工具。如果想增加自己的實質購買力,你所設定的投資報酬率最起碼要等於通貨膨脹率加上所得稅率,才是其對實質財富所造成的抵減幅度。

8. 格拉罕發現,如果以低於該股實質價值的價值買進一支股票,持股的時間越愈長,那麼預期的年複利報酬率愈低。因為如果某人以每股20美元改進某支實質價值為30美元的股票,在第一年,該股價格才上漲到其實質價值,那麼年複利報酬率就掉到22%。如果花了3年時間,年複利報酬率為14.4%, 4年則為10.6%,5年則為8.4%,6年則為6.9%,7年5.9%,到了第八年為5.1%。
     為了解決這個持股愈久。報酬率愈低的問題,格拉罕所採取的方法是,唯有在某支股票的價格和它的實質價值有足夠的差距幅度時,才進場買進,這樣才能提供投資人相對的安全邊際 (Margin of Safety),而安全邊際就是用來保護投資人萬一買到那些長時間才能夠充分反應實質價值的股票。

9. 孟格和費雪提出,只要投資人買到一家正在成長的優良企業的股票,而且公司的經營管理階層以股東的權益最為最大考量,那就不必出脫這支股票,除非整體環境發生變化或者有更好的投資標的。他們認為此種投資策略,可以獲得最佳報酬,因為投資人可以充分享受企業運用保留盈餘進而產生的複利報酬效果。

10. 要拔除的是花園裡的雜草,而不是那些會開花結果的植物。

11. 測試一,一眼看出公司的預估盈餘
      投資人只要比較公司歷年每股盈餘是不是呈現穩健的態勢,是否持續成長,還是上下起伏震盪。
      測試二,決定自己的期初報酬率: 每股盈餘 / 每股價錢
      測試三,決定每股的盈餘成長率,比較5年及10年間的每股盈餘成長率

12. 華倫的投資秘訣就是:好企業能抓牢客戶,持續為股東賺取高盈餘,就算本益比非常高,也往往還是合算的買賣。 (因為有持續的高RoE, 盈餘會持續成長,經過的時間愈久,EPS會愈高,長期下來,本益比就下降了,如果股價繼續維持高本益比,獲利更是不得了)

13. 華倫並不特別強調股價。他不說某股價值多少錢,然後像格拉罕的所作所為一樣,希望以半價買下。華倫反而會計算,如果以某價位買入一家公司股票,在已知的公司資料中,他的10年預期年報酬率是多少?決定了這個預期報酬率後,再將它與其他投資機會的報酬率以及超越通貨膨脹率必須的報酬率合併考慮。
     以這樣的心態,華倫可以不管華爾街股價如何反應,逕至決定買賣股票。他知道長期的投資報酬率大概會是多少。他也知道,長期來看,股價會隨公司淨值增加而有所反應。
     如果他的投資心態像格拉罕一樣,當他用5美元買價值10美元的股票,自會在股價到達10美元時,將它賣出。如果這樣,華倫就會每天緊盯著華爾街日報上的股價,忐忑不已。

14. 公司可以藉減少流通股數的方法,提高每股盈餘年平均成長率。分析股票要知道每股盈餘成長的原因。是公司經營績效提升呢?或是財務運用使然? 或者,兩者皆有?
     可以用公司淨利年平均成長率和每股盈餘平均成長率去比較。

15. 投資人所面臨的問題在於: 難以決定是否公司的管理部門在配置非保留盈餘限制上做出明確的抉擇。這是因為公司在主要事業以外的經濟活動上,能創造出鉅額的現金,並且掩飾管理部門在資金配置上所犯的任何錯誤。
     通貨膨脹也有助於掩飾管理部門的表現,物價指數成長10%,等於是產品售價提高10%,而盈餘也會提高10%。
   

2015年4月6日 星期一

English Learning

1. in laymen's terms (用外行人的話來說)   the GNP or, in the laymen's terms, the amount of goods produced by a country.
2. at the mercy of  (憑...的擺布)   Workers are entirely at the mercy of dishonest employers.
3. once and for all (一勞永逸)   The core issue can be resolved once and for all.
4. out of sight, out of mind (眼不見為淨)
5. Leaving little room for guesswork (講得清楚,無須揣測)
6. at the bare minimum (最低限度)   We need to hit $20,000 in sales at the bare minimum.
7. includes, but not limited to (包含,但不僅止於...)
8. catch-22 (進退維谷,無法擺脫的困境) You can't get a job without experience, but you can't get experience unless you have a job - it's (a) catch-22.
9. urban myth: 來路不明,證據薄弱,卻廣為流傳的說法。
10. A thief crying to stop thief (作賊喊抓賊)
11. To ship the advantage in our favor (將情勢轉向對我們有利)
12. Bridge the technology gap. 追上技術的落後
13. Build on a rock-solid foundation. 建築在堅若磐石的基礎上
14. Get out of hand 一發不可收拾   If the situation gets out of hand, it cannot be controlled any more.
15. state-of-the-art: 最先進的   state-of-the-art security features
16. in the nutshell: 簡而言之
17. viable 可行的   viable alternative
18. economies of scale: 規模經濟
19. code of conduct: 行為規範
20. incentive: 激勵, 誘因
21. liability: 責任
22. successor: 後繼者  <-> precessor: 前任    -> succession plan: 接替計畫
23. vital: 重要的
24. infrequent: 不常見
25, black swan: 黑天鵝
26. rationale = explanation
27. norm 規範
28. pragmatic 務實
29. in lieu of 替代
30 anchor point 錨點
31, payback period 投資回收期
32. stringent 嚴格的
33. encompass 環繞
34. adaptability 適應性
35. warranty 保證
36. conduct 執行
37. paradigm 範例, 典範
38. intervention 介入 
    manual intervention. 人員介入 => The process is automatic and no manual intervention needed.
39. contemporary 現代的
    contemporary software development practice.
40. adhere to 堅持, 附著
   ensure that the problem escalation procedures are being adhered to properly.
41. in compliance with 合規
   documentation are completed, up to date and in compliance with the established standards.
42. at the present time 在現在這個時刻
   Organization do want to acquire more than what they need at the present time.
43. defer 延遲
   Capacity management increase efficiency and cost saving by deferring the cost of new capacity to a later date and optimizing capacity to business needs.
44. find a niche 找到利基
  OODBMS has found a niche in areas such as engineering, science and spatial databases.
45. glue 膠
   Middleware serves as the glue between two otherwise distinct application and provides services such as identification, authentication, authorization, directories and security.
46. prerequisite 先決條件
   adequate backup is a prerequisite to successful recovery
47. elapsed time 經過時間
   Elapsed time for completion of prescribed tasks
48. conformity 一致性, 遵守
  ensure conformity to applicable laws, regulation and standards
49. unsolicited 不請自來
   unsolicited commercial email or junk mail
50. trivial 瑣碎, 微小
   Organization should know all the points of entry into its information resource infrastructure which, in many organization, will not be a trivial task,
51. enrollment process 註冊程序
   Entering a user's biometric into a system occurs through an enrollment process by storing a user's particular biometric feature.
52. commensurate 相稱
   The frequency of the security administrator's review of computer access reports should be commensurate with the sensitivity of the computerized information being protected.
53. seasoned 老練的
  They require the attention of the most seasoned and experienced person of the software security team.
54. practitioner 從業者
   We trust that the software security best practices and model presented in this book will make this clear to all who read this book, whether you are an executive, manager, or practitioner.
55. concise 簡潔
56. stepping-stone 墊腳石
57. judicious 明智的
   You have to be very judicious with your resources if you plan to be successful.
58. daunting task 艱鉅任務
   You will use recruitment and leverage of software champions to manage his daunting task.
59.empirical 經驗的
   Scrum adopts an empirical approach, accepting that the problem cannot be fully understood or defined.
60. facilitate 促進
   This concept facilitate the ability to handle churn resulting from customer that change the requirement during project development.
61. yield: 產生
   SDL will yield incremental improvements in an overall holistic approach to software security.
62. attestation 認證
  customer required third-party attestation.
63 immune from 免於
64. enormous 巨大
   IaaS provides fer if any application-like features, but enormous extensibility.
65. derivative 衍生物
   There are derivative cloud deployment model emerging due to the maturation of market offering and customer demand.
66. rule of thumb 經驗法則
   As a rule of thumb, perimeterized solutions are less effective than de-perimeterized solution.
67. sole 唯一
   The cloud infrastructure is operated solely for a single organization.
68. on-premise/off-premise
69. agreed-upon goals
   Information security governance should be collaboration between customers and providers to achieve agreed-upon goals.
70. abreast 並肩, 與時俱進
   The parties must keep abreast of the legal and other requirements and ensure that operations remain compliant with applicable laws.
71. plethora of 多如牛毛
   IT in the cloud is increasingly subject to a plethora of policies and regulations.
72. inhibitor 抑制源
   Compliance is not an inhibitor of organizational effectiveness, but a complement to internally determined policies.
73. Attestation 鑑證
74. act on sb's behalf 以某人之身分...
   One type of third party is authorized to act on the company's behalf and use data in accordance with the company's privacy practice.
75. inadvertent: 非故意的
   Prevent inadvertent sharing of PII with unintended audiences.
76. articulate: 說出, 明白地說
   This will help articulate real cost to management.
77. This questions need to be carefully considered to prevent future fire fighting.
78.  In a nutshell: 簡而言之
79. cursory review: 隨意,非正式review
   cursory review of open-source development process without the proper training and experience.
80. anomalous: 異常的
   anomalous interaction
81. joint effort 共同努力
   The test plan is a joint effort by the project management, development and security team.
82. showstopper: and obstacle to further progress.
83. circumvent 規避
   circumvent security feature of the system
84. flesh out: 充實
85. regiment: 一群, 團
   A development organization typically has a very regimented development process.
86. To maximum capability
   In many instances, the security mechanisms of an information system are not configured properly or used to their maximum capability.

撰寫投影片SIP原則

S (Simple): 單純簡潔、力求易懂
     一張投影片傳遞一則訊息(one slide, one message),不讓重點被過多訊息掩蓋掉。如果圖表很多,最好選擇能和主要訊息容易聯想再一起的圖表,並且以直覺就能懂的形式繪製。 困惑(confusion)會帶來憤怒 (anger)。如果聽者看了很久還是弄不懂,很可能會當場生氣,不可不慎。
     由於投影片標題就是主要訊息,所以可以省略贅字。可以在標題省去be動詞,以company B losing share代替Company B is losing share.

I (Insightful): 提出客戶不知道、沒發現的觀點
     投影片或圖表標題,不能只是描述 (description),更要能提出洞察 (insight),點出客戶不知道且有針對性的主張 (Insight = something client does not know + specific to client)。 洞察就是談對方不懂的,而不是告訴對方已經知道的事情。

P (Pyramidal): 符合邏輯、前呼後應
     投影片的標題就是論點 (argument),下方是支持上方論點的事實 (facts)或圖表。由上往下可以解釋原因 (why so?),由下往上可以導出結果 (so what?)。每張投影片都必須避免矛盾,下一張必須佐證上一張。事實或圖表如果無法支持標題或論點,就會出現矛盾。

自我檢驗:
1. 內容是否太複雜
2. 圖表是否讓人難以理解
3. 標題是否只有描述,沒有訊息
4. 是否指羅列事實,沒有洞察
5. 前後投影片的訊息是否重複
6. 論點是否缺乏事實佐證或前後矛盾
7. 邏輯是否薄弱

如果簡報的對象是時間寶貴的最高主管,必須另外撰寫只講重點的「結論投影片」 (executive summary),通常放在簡報最前面,大約1~2頁即可。

參考至 經理人雜誌 2015三月號 (p.30~31) 作者 徐瑞廷
   

2015年4月5日 星期日

五個領導潛能

1. 認知力 - 能夠從眾多的資訊中,探究出其中的關鍵因果關係。
2. 學習力 - 願意主動學習公司或未來工作任務所需要的各種知識技能。
3. 人際力 - 能夠努力經營與同仁或顧客之間長期的夥伴關係。
4. 復原力 - 歷經挫敗能夠愈挫愈勇、屢敗屢戰。
5. 影響力 - 許多行為表現能引起同仁仿效。

名言佳句

1. 富蘭克林: 沒做好準備,就準備好失敗。 (By failing to prepare, you are preparing to fail.)

2. 金恩在之後的證詞總結中說,自己之所以走入歧途,是因為「站在魔鬼這一方的人,比站在上帝這一方的人更懂得向我推銷。」 - 企業裡的哲學家 <<商業冒險>>

3. 侵權法中有句格言:每條狗都有免費咬一口的法律保護,在一條狗咬人之前,你不能假定牠是凶惡的。<<商業冒險>>

4. 不是三世做官,不知道穿衣吃飯。 (有足夠的錢才能夠享受)  <<茂陵秋>>

5. 勤儉是美德,知足是快樂,工作是幸福,懶惰是罪惡。 - 台達電董事長鄭崇華父親寫的對聯

6. 仁不帶兵,義不行賈。

7. 我們看著自己很偉大,這十幾年幹得多辛苦,歷史怎麼看? 孔老二就是兩頁紙,秦始皇幾十個字,他一嚓,也沒了,所以把自己活好。 <<馬雲內部講話二>>

8. 以正治國,以奇用兵。

9. 小要擁抱變化,大不能擁抱變化,小的跟大的打要靠靈活,大的跟小的打是靠實力,慢慢出手,一拳把你給辦了。 <<馬雲內部講話二>>

10. 貴族懂得花錢,平民懂得掙錢,這個距離是永遠拉不攏的。貴族懂得花錢,懂得生活,他已經看透了,平民總是掙錢,掙錢。我們團隊要學會懂得讓人真正開心起來,錢是讓人開心的一個因數而已。 <<馬雲內部講話二>>

11. 悲觀的人越想越複雜,樂觀的人說那就做吧,開心的人說這就是生活。 <<馬雲內部講話二>>

12. 我以前學英語時有個夢想,早上在倫敦吃早飯,中午在巴黎吃午飯,晚上到布宜諾賽諾斯散步。現在我過上了這樣的生活,我覺得世上做痛苦的生活就是這樣的。 <<馬雲內部講話二>>

13. 天與不取,反受其咎。

14. 最可怕的事情不是別人比你聰明,而是比你聰明的人比你更努力。

15. 拳頭大的是哥哥,胳膊粗的是爺爺

16. A belt-and-suspenders approach ensures that a gentleman’s pants stay up.

17. 尼采:「唯有能夠控制自己情緒的人,才能得到真正的自由。」

18. 在商場上,重點不在於別人有沒有輸,而是你會不會贏。

19. 快快學,快快錯,快快改,最後快快會。

20. Performance is not how well a system works; performance is the service perceived by user and stakeholders.

21. failure is not an option

22. efficiency only is established, along with effectiveness

23. 吳淡如:「年輕人不應再你最能吃苦時,卻選擇了安逸。」 否則年老之後,將面臨更淒涼或流離的老年生活。


2015年4月4日 星期六

Common Software Insecure Design

1. Improper implementation of least privilege
2. Software fails insecurely
3. Authentication mechanisms are easily bypassed
4. Security through obscurity
5. Improper error handling
6. Weak input validation

2015年3月29日 星期日

永恆的價值

1. 賺錢的秘訣不是鋌而走險,而是迴避風險。

2015年1月11日 星期日

電梯演說

有時光是在腦子裡想,會有盲點而不自知。你可以試著將自認為掌握到的問題核心說給別人聽,關鍵在於能否在三十秒內說完。真正的問題通常是很簡單易懂的,當你的說明太過冗長,就表示還沒抓到問題核心。

簡潔有力的發問=> 問題 + 解決策略 + 實施方法

2015年1月1日 星期四

CISSP Note(Ch4 Security Architecture and Design)

Memory Mapping

The physical memory addresses that the CPU uses are called absolute addresses. The indexed memory addresses that software uses are referred to as logical addresses.

Protection Ring

Ring 0: OS Kernel 
Ring 1: OS
Ring 2: Drivers. OS Utilities
Ring 3: Application, DB



















Bell-LaPadula model

1. simple security rule: a subject at a given security level cannot read data that reside at a higher security level. => No read up
2. *-property (star property): subject in a given security level cannot write information to a lower security level. => No write down
3. strong star property rule": a subject that has read and write capabilities can only perform those functions at the same security level

Biba Model

1. *-integrity axiom: A subject cannot write data to an object at a higher integrity level => No write up
2. Simple integrity axiom: A subject cannot read data from a lower integrity level => No read down
3. Invocation property: subject cannot request service (invoke) of higher integrity.

Clark-Wilson Model

Access triple: subject (user), program (TP), and object (CDI). A user cannot modify CDI without using a TP

Integrity verification procedures (IVPs) Check the consistency of CDIs with
external reality

Covert Channels

1. Storage: uses a shred storage, such as a temporary directory, to allow two subjects to signal to each other.
2. Timing: relies on the system clock to infer sensitive information.

Brewer and Nash Model (Chinese Wall model)

access controls that can change dynamically depending upon a user’s previous actions. The main goal of the model is to protect against conflicts of interest by users’ access attempts.

TCSEC classification

A. Verified protection:
   - A1: Verified Design: A more stringent change configuration is put in place with the development of an A1 system, and the overall design can be verified.
B. Mandatory protection: The architecture is based on the Bell-LaPadula security model, and 
evidence of reference monitor enforcement must be available. 
   - B1: Labeled Security: system must compare the subject’s and object’s security labels to ensure the requested actions are acceptable
   - B2: Structured Protection: Subjects and devices require labels, and the system must not allow covert channels. A trusted path for logon and authentication processes must be in place
   - B3: Security Domains: the programming code that is not necessary to support the security
policy is excluded. The design and implementation should not provide too much complexity. system must be able to recover from failures without its security level being compromised.
C. Discretionary protection
   - C1: Discretionary Security Protection:It would be a trusted environment with low security concerns.
   - C2: Controlled Access Protection: isseen as the most reasonable class for commercial applications
D. Minimal security

ITSEC and TCSEC Mapping












Evaluation Assurance Level (EAL)

• EAL1 Functionally tested
• EAL2 Structurally tested
• EAL3 Methodically tested and checked
• EAL4 Methodically designed, tested, and reviewed
• EAL5 Semiformally designed and tested
• EAL6 Semiformally verified design and tested
• EAL7 Formally verified design and tested

Maintenance Hooks

are a type of back door. They are instructions within software that only the developer knows about and can invoke, and which give the developer easy access to the code.

Time-of-Check/Time-of-Use Attacks(TOC/TOU)

deals with the sequence of steps a system uses to complete a task. This type of attack takes advantage of the dependency on the timing of events that take place in a multitasking operating system. Attacker manipulates the “condition check” step and the “use” step within software to allow for unauthorized activity.