Linux Advocate Dietrich Schmitz shows how the general public can take action to truly protect their privacy using GnuPG with Evolution email. Read the details.
Linux Advocate Dietrich Schmitz reminds CIOs that XP Desktops destined for MS end of life support can be reprovisioned with FOSS Linux to run like brand new. Read how.
Linux Advocate Dietrich Schmitz reminds readers of a long ago failed petition by Mathematician Prof. Donald Knuth for stopping issuance of Software Patents.
It's
not something the average user thinks about -- security. But as with
most Linux Distributions (Distro) Fedora, a Red Hat community-based
Distro, has some things going for it that are not apparent.
The
single biggest asset going for Fedora is security. You see, just about
everything you do while on Fedora is under what's called 'Mandatory
Access Control'. That's security-speak for basically having everything
you do 'watched' by a third-party 'Linux Security Module', (LSM)
including even actions taken by the system kernel. That may not mean
much to you but to system administrators and security experts alike, it
is 'peace of mind'.
Simply put, bad things won't happen on Fedora's watch.
No,
unlike Microsoft Windows, this 'third-party' is always cross-checking
what your PC is doing and if anything isn't in your SELinux 'policy' say
trying to gain administrative privilege to control your system without
your expressed permission, SELinux steps in and kills the process.
That's
the way security should be. And you can rest assured your PC won't be
hit by silent 'drive-by' javascript DLL injection attack as is still
prevelant with Microsoft Windows legacy x86; even Windows 8.1 uses the
legacy WinNT 2000 kernel. That's ancient by today's standards and it is
fraught with security issues like the one described above.
I've written about how Google's Engineers have posted a general 'disclaimer' on their chromium.org
website for Chrome that effectively says:
"W'eve tried our best to
sandbox Chrome on Windows, but we can't guarantee you won't get
infected. Sorry." (shrugs)
So, if you've been bitten one too
many times by a virus from out of nowhere on Windows, maybe now is a
good time for you to make a switch for the better.
Theatrics. That's all it is. We see blustering, cries of 'outrage' by Eric Schmidt in a public reaction of 'surprise' to the fact that the NSA penetrated their firewall and set up camp reading any and all of their 'clear text' data files with impunity. This same company, prides itself on selling Chromebooks with an unblemished record at Pwnium 2013 of no successful hack which resulted in fully owning the ChromeOS operating system. How is it that so much effort can be put forth to develop ChromiumOS with a sincere intent to make security a prime order of concern yet Google'sdata centers store data in clear text? This isn't being discussed in any of the media stories. The real 'top dog' priority for Google is advertising revenue. And, they know full well that if they encrypted the public's data they could no longer parse it to exploit, mine, for advertising purposes and that would put a major choke hold on a part of their revenue stream they so cherish. The public's trust, good faith, and right to privacy takes a 'back seat' to Google's penchant for profit. Google is colliding directly with 'Do No Evil' as they continue to change their ways with a clear intent to take major portions of their technology base proprietary. That is the bottom line and there is no clear indication from them policy-wise, one way or another, as to what they plan to do at this point, if at all, other than public 'feel good' talk and expletives from Google Engineers seen in today's news. Google. You've been owned real bad and at the Public's expense. It's time for you to fix your F'ing security. I think you just might have screwed the pooch this time. -- Dietrich
Some might not have heard of it but Bodega, a missing piece in the Linuxecosystem, was released not long ago. Many might not have put much thought about how important this little piece of software really is. As I talked about in my previous article the usual approach commercialized Linux take is to have their ecosystem closed. This can be a danger for open source and do limit the participation of others. In a way it takes the benefit and intent away from what open source really is and should be about. What the infamous +Aaron Seigo (shown right) did was to take the complete opposite approach and made his open. An infrastructure the open source world else would have lacked. This is not a small feat and a crucial part of the open source ecosystem have been filled. (Image credit: Wikipedia.org)
It's not just a content redistribution manager either. It is a more complete solution and on top of that almost completely decentralized. It does not just contain a singular entity where a central power enact it's control. It is built as if he took a blueprint of the real world with individual stores and warehouses and applied it to Bodega. People can join up and create their own business so to speak by partnering up. Which is really exactly how it should be done. I think the future will hold many specialized solutions and just as in the real world competition will be at it's core driving it forward. Anyone who have read his blog posts about the subject can see that he has put a lot of thought into this. He must have understood it's potential very early on and made sure to incorporate as much of it he could in Bodega.
Bodega - An open market for digital content
This means the reach for a content provider could be direct and limitless. It could even create jobs and lower the barrier for people who want to start a business. It is truly a vital piece filled that have been missing. At this point it might only be dream to be able to generate enough revenue to pay a rent but who knows about the future. Someone very service minded and driven could make something really good from it. The potential is really there and as it has just been release a true potential for anyone interested.
As it is still early days it do lack some parts I want to see. The only client I've seen so far is the one for Plasma Active. That is nice but I am missing a GTK one so if someone is up to it, give me a ping. I would love to test it. I know Aaron would love to see one too. He wrote about it on gnome-look.org.
I have lately contemplated over Linux and it's market share on desktop. We have seen a little upswing the last year and depending who you ask it is somewhere between 1.6-3 percent of all desktop computers. It's a small percentage but what people tend to forget is that it is a HUGE number. There are around 2 billion desktop computers running in the world today. The estimation is hard to do but it's the general number I tend to see on this. So that means it would be roughly 30-60 million desktop computers running with Linux in today's world. Not a small number. Even if you only took a third of that number it would still be 10 million computers which are actively being used. That is a lot of people.
I mean how many people do we need to have an active ecosystem? I have no clue, but would guess a couple of thousand is enough. That means a couple of thousands technical users. Those who can develop and maintain. It's a non-issue for desktop Linux currently. It's always nice to have a couple of more developers but a general feel is that we are good. So I have no fear to be honest. As long as we grow I am good. It doesn't need to jump several percentages to make me happy. Just a steady slow grow is enough and that is how it looks today. For me it's more important the openness is preserved than a market majority.
Sure I am happy to see Valve and gang joining the club. I mean it is good to have the choice. It also improves the support for drivers and hardware which could be better on Linux. I am not complaining though. My hardware on my machines has worked more or less flawlessly since 2008 or so.
So does it really matter?
Yes, I think so. The state of Linux today are big changes. We are watching Linux being commercialized at a rate never seen before. Android and ChromeOS have been good for Linux but Google are no RedHat. Sure RedHat do have some proprietary solutions but mainly aimed at enterprise. With Google we get core functionality like the distribution of software closed off. That is an essential difference from what we are used to. We are seeing Canonical taking steps toward a similar business model and others are surely thinking of it too. Heck even Apple have a similar solution with some parts open but others not. Is this the future of open source? Is the future a mix of open and close?
Maybe. I hope it is not but money talk and Linux is dependant on businesses donating developers to make code. In a perfect world this would not be needed but the world today is anything but perfect. Just because we need some commercialization does not mean I am happy about Google and Canonical. I wish they could have taken a more similar approach to RedHat and SUSE which base their revenue on support. If so it would have meant they might have not felt the need to use CLA and closed source on core functionality. So my main concern today lay in the commercialization of Linux and what that might bring us tomorrow. Not so much in the actual percentage of market share.
It could be fine but it could also mean that openness proves to be a failure. I hope on the former. We have to stay vigilant and especially on software with core functionality that is not open and demand opening them up. The danger lay in dependence on commercial software with core functionality. We as a community can not allow such things to happen. If we do it would mean the end of openness and the end of Linux as we know it.
So to me supporting Systemd, Wayland and Bodega are important for the future of Linux.
As a result of drawing a line with Google, I've spent considerable time considering a range of options to avail myself to in replacing Google services. As for Blogger, I intend to use Wordpress and will convert my Linuxadvocates website soon and am hoping to have some of Kev Quirk's guidance on tap as I move forward.
As for my browser, I've turned to looking at Chromium.
Why?
Because The Chromium Projects is fully open source and not proprietary, unlike Google Chrome. The two are quite different beasts. In fact, I am using Chromium right now and it is working nicely as many of my colleague Friends have reported. That word 'proprietary' will mean more to you below when you continue your reading of this piece of verbosity.
So, I've also shifted from Lubuntu 13.10 to Linux Mint 15 "Olivia" Xfce Edition. That's Mint below for those of you interested in making the 'leap' from Windows to Linux who may be wondering just how difficult the transition may be.
Linux Mint 15 "Olivia" Xfce Edition - My Desktop
If you are new to Linux, you may think of the graphical user interface (gui) as being 'loosely coupled'. Linux doesn't care if you have one or not. In fact, linux web servers are set up without one in command line 'headless' fashion. But, as far as choices go, the move to Mint Linux is a safe bet. You see, they are #1 on Distrowatch.com for a reason. It's that good. I call it Ubuntu +1.
The choice of guis was easy for me. Xfce. It's still a lightweight gui, like Lubuntu's LXDE, but it is really more feature complete. There are trade-offs for using LXDE which for me are taken in stride but for a newcomer, Xfce will make any Windows user feel quite at home. There is little to do after installation. Just boot and use.
Many newcomers will find the naming of things in the Linux world funny, but that's open source for you. It is rather benign but much of it will make sense as you become accustomed to the "Linux Way" of doing things.
The "Linux Way" of doing things incorporates many concepts but there is none more important in light of the Snowden revelation than open source 'Transparency'. This is a good place for you to stop and read a link on the topic to frame in your mind this abstract but yet so vital concept:
It's basically this. Proprietary = Exploitation. That's how I see it. And at growing levels I see Google's expansion in the name of profitability colliding with their "Do No Evil" mantra that so many of us, including myself, believed in.
So, on principle, I am looking to non-Google solutions to continue using the Internet.
I find using Chromium safe and acceptable by virtue of the pure open source footing on which it is developed. That will assure transparency going forward as with Mozilla's Firefox.
As for the array of Google services like Drive, Gmail, etc.?
I don't need them. I am looking at Kim Dot Com's Mega for its Zero Knowledge Encrypted free 50MB space support and also their upcoming encrypted end-to-end email. Phil Zimmerman, the Founder of Silent Circle and Lavabit's Ladar Levison are forming Dark Mail Alliance.
Those are my two target email solutions going forward.
Another revelation has been made that the NSA have been camping out on the inside of the Google cloud firewall, cherry picking data -- yours -- like taking candy from a baby -- the method for how the NSA exploit to break through the front-end SSL server is documented in slides like the one shown above.
Sadly, the data fest has been going on for quite some time and Google and Yahoo officially disclaim any knowledge that such activities have been occurring.
It's too bad because the entire cloud behind the firewall has been 'clear text' as shown in the above slide, which means your data isn't encrypted and directly human readable.
Why hasn't Google taken steps to protect your Drive data with encryption?
The truth of the matter is: MONEY
Advertising revenue is obtained by parsing your documents and positioning adverts in the gutter margins as users of Google services like Drive and Gmail go about their daily business. If Google were to encrypt your data, then they could not read it and run adverts any more.
It is outrageous that Google chose not to take action because of this and I would suspect the same pertains for Yahoo.
This is a major error of negligence and abrogation of responsibility on the part of Google to protect the public's right to privacy.
The technology has been available right along which is now routinely used by other cloud services like SpiderOak, Wuala, and Kim Dot Com'sMega to encrypt the entire data stream of data space in the cloud. It's not difficult to implement and even SpiderOak have now offered their own software framework, Crypton.io, for Developers to implement Zero-Knowledge Encryption (ZKE) at any Cloud ISP.
This is no longer an option. ZKE should be considered a mandate and, as such, consumers and businesses should insist upon having it or boycott using the respective Cloud ISP's services. If we all insist on it, we will have power in numbers and can have an effect on the outcome hopefully in a positive way.
The benefit to the user of rented Cloud data space employing ZKE is that all data stored in the Cloud is first encrypted locally (in the memory space of the user's PC) and a private key is maintained locally by the user not physically present on the Cloud data drive. This makes the data on the Cloud transparent and as such the ISP will have Zero Knowledge of what is being stored other than an encrypted byte stream written to a block level drive.
With ZKE for a third party to request access would then require their serving the owner of said data with a warrant before viewing the personal and privately protected information. Good citizens presented with a warrant will comply and unlock their data if the warrant is justified by a Court Judge as having 'probable cause' for issuance. That has always been historically the case up to 9/11 but with the Patriot Act, the erosion of the U.S. Constitution was begun.
Today, some twelve years hence, the degree to which the law has been disregarded is allowing unobstructed intrusion into all corners of our private electronic communications.
I am drawing the line here. Google must take steps immediately to adopt ZKE for all of their media storage used by consumers and businesses or I will no longer support and use any of their services whatsoever.
They have two weeks to come up with a clear public plan to protect the public's data from unwarranted access or I will end it. Boycott Google Cloud services if they fail to act.
[Edit: Some raised concern about sharing their F2F key via regular email. To use a 'darknet' method, try either cryptocat.bin or cryptocat.org]
It's all starting to make sense now. We've heard rumors that this National Security Agency was snooping around in our private affairs.
Turns out, it's been going on for longer than we think, like, since 1952? That's the latest.
So much for the book 1984. Should have been 1952. Okay so what if George Orwell was off by about 32 years. Still, it's amazing how he pegged the future with such eery accuracy.
Okay great so, now what do we do given that our every move is being examined like getting a colonoscopy?
You should now not worry what people think if you take extra precautions with your privacy, particularly on the Interwebs. That's right. Let them call you paranoid and then throw one of these stories in their face and say with confidence: YES, I AM PARANOID AND I AM FINE WITH THAT!
So seriously, is there anything that can be done on the Interwebs without having it owned and/or seen by someone these days?
Actually, I am glad you asked the question. It just so happens there is.
An interesting piece of software has been in development going on several years now, called RetroShare. Errrm okay, sooooo.
So let's check it out.
RetroShare
What is RetroShare?
RetroShare is the next generation sharing network, which provides:
Reliable Identification and Authentication of your friends.
Plus an Introduction Scheme which connects you to the friends of your friends, and facilitates network growth.
Encrypted Communication, ensuring all shared information is known only to you and your peers.
A Communication Platform which can potentially support services such as Secure Email, File Sharing, Streaming, Video or Voice over IP, Photos, Wall and Messaging
A Decentralised Social Sharing Network designed **For the People** with no dependancies on any corporate system or central servers.
You see, this is a 2048-bit RSA-encrypted SSL tunnel through which your activity travels but every node along the P2P network is on its own 'private' channel. In other words, there may be thousands of users using RetroShare but you only see those 'Friends' with whom you explicitly take the step of sharing your private F2F key.
Setting up RetroShare is easy. Once installed, you send an email to your Friend(s) with a copy of the F2F key. Then, they do the same, by installing RetroShare and sending you their F2F key.
The result? Log into RetroShare and immediately you'll see your Friend on the private chat, and if you choose you can also share file folders with them and also emails.
Probably one of the most interesting aspects of RetroShare aside from being P2P is that email is a totally closed loop--just between you and strictly your Friends. For an email to reach you, the sender must possess a copy of your F2F key and you must have their F2F key.
It completely eliminates spam. And provided that you are only friending people with whom you are personally familiar, there's no loss of privacy whatsoever, in terms of your private activities.
Aside from eliminating spam, it's going to be really hard for any kind of eavesdropping on this system because of the SSL tunnel and 2048-bit length RSA encryption key cipher strength. How hard? Reheheheheheheheheheheheheheheheheheheheheheeeeeally hard. Here is an example of how hard:
I fully expect to see comments stream in with assurances that this key is crackable. No one has been able to substantiate such claims to me. But please, bring it.
So Folks, this is really is a nice implementation and I seriously recommend you try it. Now that cat has been let out of the bag that 'big brother' truly IS watching (like we didn't know pfffft chaahhh), go get your copy of RetroShare and let your paranoid Friends know about it too.
We can all live in a state of paranoia together, you know, as the paranoid circle of Friends on RetroShare. ;)
RetroShare is not circumventable by the NSA or any other agency.
Enjoy fool-proof privacy-assured communication with your dear and closest Friends and Family, including chat, audio/video calls, spamless-email and file sharing.
RetroShare is a peer-to-peer encrypted, decentralized (cannot be taken down like MegaUpload) system where you choose only those you deem to be 'known' friends with whom to explicitly share your Friend-to-Friend (F2F) RSA 2048-bit encryption key.
The NSA 'hate' RetroShare. It's open source and free and replicated on mirror servers around the globe so agencies cannot block its use by the general public who wish to maintain their 'right to privacy'.
Versions are available for Windows, Mac, Linux, and BSD Unix.