NSA: Please Turn off the Lights When You Leave. Nothing to See Here.

Linux Advocate Dietrich Schmitz shows how the general public can take action to truly protect their privacy using GnuPG with Evolution email. Read the details.

Mailvelope for Chrome: PGP Encrypted Email Made Easy

Linux Advocate Dietrich Schmitz officially endorses what he deems is a truly secure, easy to use PGP email encryption program. Read the details.

Step off Microsoft's License Treadmill to FOSS Linux

Linux Advocate Dietrich Schmitz reminds CIOs that XP Desktops destined for MS end of life support can be reprovisioned with FOSS Linux to run like brand new. Read how.

Bitcoin is NOT Money -- it's a Commodity

Linux Advocate shares news that the U.S. Treasury will treat Bitcoin as a Commodity 'Investment'. Read the details.

Google Drive Gets a Failing Grade on Privacy Protection

Linux Advocate Dietrich Schmitz puts out a public service privacy warning. Google Drive gets a failing grade on protecting your privacy.

Email: A Fundamentally Broken System

Email needs an overhaul. Privacy must be integrated.

Opinion

Cookie Cutter Distros Don't Cut It

Opinion

The 'Linux Inside' Stigma - It's real and it's a problem.

U.S. Patent and Trademark Office Turn a Deaf Ear

Linux Advocate Dietrich Schmitz reminds readers of a long ago failed petition by Mathematician Prof. Donald Knuth for stopping issuance of Software Patents.

Showing posts with label Fedora 21 Workstation. Show all posts
Showing posts with label Fedora 21 Workstation. Show all posts

Friday, December 5, 2014

December 9, 2014: The Day Desktop Computing Got Fun Again



Remember when Desktop Computing was fun?

The early days of Ubuntu were a time when GNOME really had things going for it.  Then, one Mark Shuttleworth took the product in another direction.  Unity.

Unity was initially interesting but didn't fit usability and that began the period of when I didn't like what I saw happening to Ubuntu.

During that period, The GNOME Foundation was undergoing its own change.  GNOME 2.x was determined at end of life and GNOME Shell, a concept GUI was established.

As with any GUI paradigm change comes a period of 'growing pains'.  I was really resistant to what GNOME was doing.  And so, I spent a long period in search of a good alternative GUI.  Ultimately, I found myself liking LXDE, and dwelled in Lubuntu.

Then, I tried Fedora 18 LXDE spin.  I concluded it was from a technical standpoint as good as Lubuntu.

Philosophically, I didn't like what Debian and Ubuntu were doing.

When it became apparent that Mark Shuttleworth was running his own railroad and broke ties with The GNOME Project, I thought he was trying to control delays in upstream decision making.  That made good business sense.

But in the process, he flip-flopped on putting full support behind Wayland turning to creating his 'own' Display driver, Mir.

To make it short and to the point, there is no other Distro which uses Unity.  NONE.

Today, Unity is on an island all by itself.

During the period of 'transition' The GNOME Project came out with initial revisions with GNOME Classic 'fall-back' to keep the malcontents happy.  In each iteration, GNOME made feature enhancements in an effort to continually refine the 3.x shell.

Each major revision, I gave it a try and turned away giving it a 'thumbs down' on usability.

Until 3.12, I didn't like Shell.  It was at that level it became truly usable and ready for prime time.  That was a year ago.

Today, GNOME Shell has reached 3.14 and I have been using it for several months on Fedora 21 Alpha/Beta/RC Workstation.

Even with Alpha, I found myself smiling and laughing at just how well the interface meshed.  It is polished, professional and just fun to use.

Yes, it is fun to use.  I really haven't felt that way in a very long time and I look forward to turning on my PC every day because Fedora 21 Workstation with GNOME Shell 3.14 is just that good.  I would add, Red Hat is the largest supporter of The GNOME Foundation and has worked closely in the design of GNOME Shell.  Red Hat also provides web infrastructure for The GNOME Project.  The relationship is close knit.  The end result is what you see and use.

December 9, 2014, has been promised by the Fedora Team as a 'Go' for Fedora 21 Workstation.  The day will be remembered as when Desktop Computing got fun again.  -- Dietrich

Wednesday, November 26, 2014

Fedora Linux: The Safest Operating System on the Planet

(Image credit: harrisburghelpdesk.com)


Computer Viruses cannot mount an attack on Fedora Linux.

It's a simple fact that millions of Windows users don't know.  In fact, largely, they don't care.  They assume an operating system, like Microsoft Legacy (x86) Windows, comes with AV software to handle the job of fending off viruses as being 'normal'.

Truth be told, it isn't normal.  And whether or not your AV Software catches a virus can be 'hit or miss' and a matter of timing.

I'll get to why Windows gets infected and why Fedora does not in a minute.

How AV Software Works


AV software relies on the fact that every virus will have its own exploit characteristics and the exploit code that invades your PC has it's very own unique CRC 'fingerprint' that when scanned for and compared to a database of 'known exploits' will get a match on that CRC value, which is a unique check sum number.

The problem with that approach is that some of the more clever viruses once they have compromised your system, intentionally alter their own executing code's CRC value on even an hourly basis so as to avoid detection against an AV database which might update only once a day if you are lucky, or worse, once every several days.

And they effectively sit on your system undetected, flying below the radar of your AV software.


Aged Windows NT Kernel


Even today with the very newest Microsoft Windows 8.1 (x86), the WinNT kernel is the same as those going all the way back to Windows 2000.  That's right.  The same.

Microsoft's large base of installed Enterprise systems are running on that kernel and any major redesign would cause hurrendous interruption of service, which simply cannot happen.  So, they continue with their haphazard patch Tuesday sending out updates to known exploits -- that's ones which they 'officially' have taken corrective action on, and doesn't include zero-day exploits.


Zero Day Exploits Prevail


Zero Day Exploits is another matter entirely.  These are exploits which can attack vulnerable unpatched Windows systems for which there is no official fix available.  The wild is filled with a 'black market' for writing Zero Day exploits which sellers sell to criminals who are intent on circumventing your PC on the promise that a Zero Day exploit will be effective.

Around the World, Windows PCs by the millions are prey to attack and this has become quite profitable for a syndicate of criminals intent on parting you from your money.

Such exploits include RansomWare, which is perhaps the most prevalent and pernicious type of virus.  If a successful attack is mounted against your Windows PC, said RansomWare quietly encrypts your hard drive, then puts a private key lock on it, and, only then, notifies the end-user that their PC is locked until they make payment.  It's become like shooting fish in a barrel and the software is now sophisticated enough to even offer the added convenience of payment by Credit Card!  Nice touch ey?  Terrible.

Windows Security is Not Assured


So, you see, running AV on Windows will not guarantee your PC will remain virus-free.  Nope.  Really, from my vantage point, there's nothing that can stop a successful exploit.

Other attacks include Drive by download where the user visits a legitimate website (which is compromised) and by merely going to your 'favorite' website, it can trigger a silent download from your browser a Javascript tag injection of DLL code which then runs unchecked on Windows.

Policing the Kernel's Actions


Unchecked.  The prime defect in WinNT, the aged 2000 kernel, is that there is NO 'third party' policing of what actions are taken by the kernel itself.

Imagine there being a police officer on sentry 24x7 who not only checks the actions taken by your favorite Application, but also those actions spawned by said Application to the kernel to perform specific system functions.

It is at the instant that an Application spawns a SYSTEM call to the Windows kernel (by the injected DLL of a Javascript attack) that a 'third party' should step in to investigate the discrete granular action being taken.  It simply doesn't happen.  The DLL injected code runs and exploit code at this point can perform any SYSTEM related administrative function.  No one called the police.  Your system is owned whether you know it (RansomWare) or not (SpyBot).

Linux Security Modules - A Better Design


Unlike the flawed design of Windows' WinNT kernel, Fedora Linux comes installed with a 'third party' Policing agent -- generically speaking it's called a 'Linux Security Module', specifically the module that is running is called SELinux.

It is this 'policing' aspect of SELinux that sets Linux apart in design and safety from Microsoft Windows.

Any software design which produces an unintended side effect that the software designer never intended to have happen as part of the feature set of a given Application is a 'bug'.  It is also true, that viruses exploit such a bug to induce the Application to behave in an unintended way.  The goal (induced side effect), is to escalate and gain access to the core SYSTEM function API.

SELinux, when your PC boots, binds to the Linux kernel and then makes a 'hook' into the kernel.  This 'hook' is a pause in execution by the SYSTEM at which point SELinux gets the opportunity to approve/deny what the kernel wants to do, BEFORE, execution can happen.  There is no getting by the 'hook' and so anything which is deemed not part of a normal 'policy' for the application which spawned a child SYSTEM call gets a 'deny'.

The exploit simply is stopped cold in its tracks.

So, this was necessarily verbose.  I apologize.  But it is hopefully clearer to you now why I endorse using Fedora 21 Workstation, because it is truly safe and viruses cannot mount an attack.  Ever.

Get Fedora 21 Workstation Prerelease for free (general release December 9, 2014) today, here.

Fedora Linux: The safest operating system on the Planet.

I stake my reputation on it. -- Dietrich

Wednesday, November 5, 2014

Fedora 21 Workstation Preview - YouTube Video

Sometimes you can talk a subject to death and it won't matter.  So, it helps greatly for people who have no Linux experience to get a visualization of what Fedora is all about.

The next Fedora is just around the corner and I have spent extensive time testing Fedora 21 Workstation, currently in beta as of November 4, 2014.

With that, I present to you a YouTube video I created this morning to give a rudimentary view of Fedora 21 Workstation running Gnome Shell 3.14.1.5 and Linux Kernel 3.17.2.

I particularly hope it helps sway new users to come on board. 
-- Dietrich