NSA: Please Turn off the Lights When You Leave. Nothing to See Here.

Linux Advocate Dietrich Schmitz shows how the general public can take action to truly protect their privacy using GnuPG with Evolution email. Read the details.

Mailvelope for Chrome: PGP Encrypted Email Made Easy

Linux Advocate Dietrich Schmitz officially endorses what he deems is a truly secure, easy to use PGP email encryption program. Read the details.

Step off Microsoft's License Treadmill to FOSS Linux

Linux Advocate Dietrich Schmitz reminds CIOs that XP Desktops destined for MS end of life support can be reprovisioned with FOSS Linux to run like brand new. Read how.

Bitcoin is NOT Money -- it's a Commodity

Linux Advocate shares news that the U.S. Treasury will treat Bitcoin as a Commodity 'Investment'. Read the details.

Google Drive Gets a Failing Grade on Privacy Protection

Linux Advocate Dietrich Schmitz puts out a public service privacy warning. Google Drive gets a failing grade on protecting your privacy.

Email: A Fundamentally Broken System

Email needs an overhaul. Privacy must be integrated.

Opinion

Cookie Cutter Distros Don't Cut It

Opinion

The 'Linux Inside' Stigma - It's real and it's a problem.

U.S. Patent and Trademark Office Turn a Deaf Ear

Linux Advocate Dietrich Schmitz reminds readers of a long ago failed petition by Mathematician Prof. Donald Knuth for stopping issuance of Software Patents.

Friday, January 10, 2014

Linux Advocacy: Lessons Learned in 2013

by Dietrich Schmitz

It's been nearly a year now since I created Linux Advocates.  I am reflecting on what has happened during the past year and appraising what changes I need to make that might make Linux Advocates more effective in terms of its advocacy.

As the website domain name implies, it is all about advocating for the use of Linux.  That is obvious but subtle at the same time.

In doing advocacy, I have discovered some things which have resulted in my making changes that seemingly run counter to the definition of advocacy.





Censorship


Over many years, I have learned from my personal experiences in website forums that readers come in varieties and types.  Taking feedback over the past year on Linux Advocates, I have found it necessary to apply rigid censorship so as to keep trolling from ruling the comments section.

It became quickly evident to me and LA co-founder +Katherine Noyes  that regardless of the cause, there is a sub-population who have no real interest in rational discourse on the topics at hand, who are merely intent to 'troll'.  It is unfortunate, but, part of the landscape and without censorship, I have seen comment feedback quickly regress.  So as to be effective in reigning in the trolls, full moderation has been on for over 6 months now.  Largely, the trolls have gone elsewhere.

But it leaves me with a strong impression of the types of people out there who make 'hating' and 'trolling' a game of sorts, who feel by virtue of their anonymity that they are not accountable for their bad behavior.  That is perhaps the most troubling aspect of today's Internet, along with privacy rights.

It represents a disconnect between how a 'normal' person would conduct his/herself in a public place and doing the same in a forum context.  Psychologists will be studying this type of behavior for years.

So be it.  Trolling is rampant, only I have filtered it out with censorship.  I don't like having to do it, but it is absolutely necessary.


Tribalism

In the real world, when you come to work to earn a paycheck, inevitably, there will be some 'friction' during the day due to human interaction.  Some conduct themselves in keeping with good business practices.  Others depart from that and their professional comportment and/or diminished social skills impact on others who come into contact with them.

Hopefully, you quickly identify who those people are and find ways to avoid unpleasant exchanges and get through your day.  Some days, it becomes impossible.

Personalities get in the way even more so on the Internet.  When it comes to professional conduct in the upstream software developer team setting, I have seen the worst kind of behavior one can imagine.  Even the grand poobah Linus Torvalds has been charged with exhibiting unprofessional, vulgar behavior.  

All it takes is one person in a position of 'authority' who controls a project to cause alienation to ripple downstream.  The side-effect of such behavior in the Open Source community includes arrogance and those directly affected by the individual must quickly choose sides -- either adversarial or side with the 'bad behavior' and cliques quickly form.  In psychology, the tendency to behave in cliques smooths out difficulties for the project unit but leaves the organization in a position of exhibiting tribalism towards outside developers who wish to advance a special software feature or change. 



In fact, so as to preserve the purity and sanctity of this advocacy, I have had to discharge more than one contributor by virtue of their inappropriate behavior.  It's not something I will ever tolerate from anyone.

The reputation of Linux Open Source has been given a 'black eye' by tribalism.  It is very divisive, damaging and counter-productive to advancing the cause of Linux advocacy.   I don't know what the future holds but while many upstream projects do not suffer from this malady, all it takes is one 'bad apple' to magnify and spread like a contagion.  I hope things improve.

Living

Living.  What do I mean by that?  Everybody wants the same thing: Life, liberty and the pursuit of happiness.  Living comes at a cost.  Many currently around the globe are in the throws of economic turmoil.  And when you can't pay the rent, you are even more less likely to have any inclination to write code for an Open Source project.

That factors in for many who continue to dedicate themselves to Linux despite their life circumstances.  They are to be commended for their resolve and fidelity.  Others, simply by attrition, have either given up (Cloverleaf and SolusOS) or retired (Fuduntu).  That is the harsh reality.

I have predicted that given the serious economic turmoil, there will be a major consolidation of Linux Distributions resulting in a rapid collapse.  The result will be in the next five years only the strong will survive and that comes down to just a handful of base Distros.  And that has been a major factor influencing my decision to use Fedora -- they will be around.

Conclusion

I sincerely hope to continue providing strong advocacy for all things Linux with original and meaningful content.  I want to thank the readership for visiting my website and hope they will continue to do so throughout the 2014 year.  The average montly pageviews for 2013 was over 60,000.  

A very special thank you goes out to the Linux Advocate Contributors for their continued ongoing support.

Happy New Year Everyone,

Dietrich Schmitz
Linux Advocates, Site Owner



Enhanced by Zemanta

Tuesday, January 7, 2014

Insidious Chromebook, Mega Email Preview, Smartwatches, Pirate Bay Decentralizes, CES 2014

by Dietrich Schmitz

Insidious Chromebook

Yet another major PC vendor has tossed its hat into the Chromebook ring.  Toshiba announced their very own Chromebook.  What a chuckle.  Oh, a 'Flying Chair Alert' memo has been issued at One Microsoft Way.  Be careful if you work there.  Toshiba's unit has 13 inch display, for the amazingly economical price of US$280.  What a chuckle.  I've stopped keeping count -- how many vendors are making Chromebooks now?  Enough said.



Mega Email Preview

I have attempted to reach out to Kim DotCom (born Kim Schmitz) himself in the hopes that I can have a chat with him on his views regarding Privacy.  His intent to further advocating privacy for the masses is clear: Mega Cloud ISP is now out of beta, over a year old, and provides free 50GB of Zero Knowledge Encrypted storage.  Kim DotCom continues to raise the bar and has become, despite his travails with MegaUpload, an iconic 'hero' and source of hope for obtaining true privacy on the Internet.

Most recently, news leaked onto the Internet about Mega's newest project: ZKE Encrypted Email (see screenshot below).  For those who may not grasp its significance, it is, for example, not the case that Google Gmail is encrypted.  In fact, the aged RFC specification for email doesn't even consider encryption and by virtue of its age includes defects that foster wholesale email forgery (it is child's play to insert a forged sender's email address, for example), which is why there is spam in your spam folder.  It can't be stopped without revising the specification.


A leaked screenshot of the soon-to-be-released Mega ZKE Email/Chat system

It is outrageous to contemplate that, despite the recent disclosure of the NSA having taken up camp on the inside of Google's firewall to cherry-pick the public's data (Drive, Gmail) with impunity, Google has not thus far publicly stated any intention to encrypt consumer services data.  Other ISPs, including Yahoo and Microsoft have gone on public record with statements that they intend to shore up their services with strong encryption.

On the point of ZKE, only a few cloud storage providers currently offer encryption (Mega, Wuala and SpiderOak--promulgator of ZKE and their open source ZKE developer SDK framework).  Other initiatives for encrypted email are few that support ZKE, but, most notably, Mega and SilentCircle are hot on the trail to developing a system that will ensure 100% privacy--meaning the ability to crack/decode messages will effectively become impossible.  Those following this topic will recall SilentCircle initially provided email but found the level of harassment from the government for access to be a breach of the public's privacy and so pulled the plug on that service.  Now, they have stated it will be reopened and reimplemented with ZKE in mind. 

Such luxury comes currently at a cost with, for example, Symantec Corporation (merged with PGP Corporation) providing to Corporations hosted PGP-encrypted email service.

As for the masses, the Government willingly follows 'convention' in accepting US Postal Service mailed parcels and letters in envelopes with both an expressed and implied assurance that your privacy is protected on delivery to its endpoint recipient.  Federal criminal liability is defined for any tampering with your mail even.  Yet, they have no motivation to provide the same level of expectation for privacy with your Internet email.  That stands out ever-more boldly in the backdrop of the NSA PRISM/Snowden disclosure in 2013 and punctuates all the more an unmet need to provide strong encryption on the Internet for not just commercial but consumer privacy.

In an apparent double standard, Google has feathered their own nest, by ensuring that commercial security standards are being met by providing encryption for their Google Cloud service.

Be assured, if Google take no action on this issue, I will exit using Google Gmail/Drive just as soon as Mega ZKE Email arrives.


Smart Watches

Pedestrian1: "Excuse me, Do you have the correct time?"
Pedestrian2: (Proudly brandishes his smartwatch) "Yes I can give it to you to the millisecond and in any time zone.  Oh, if you like, I can tell you the value of pi with 12 decimal places of precision!  Oh wait.  Someone is calling me on my watch."

Sound far-fetched?  Maybe a little.  But if things continue the way they are unfolding (image right: Samsung Smartwatch), we'll see the end of Swiss Watches with ruby jewel-pivot accuracy and a flood of what appear to be silicon-laden wrist watches that condense on their ASIC chipsets all manner of technology providing yet more techno-lust in a smaller, lightweight form-factor, with convergence of smart phone and any other imaginable application that can run in the current nanometer-realm.  There doesn't seem to be any constraint as memory capacity continues to increase, SSD form factor gets smaller, and ARM processors with reduced power consumption grow in power (processor arrays) and operating systems containing a Linux kernel continue to pervade all corners of our lives.


Pirate Bay Decentralizes

Let me be clear.  I am strictly against the theft of Intellectual Property or Copyrighted material.   But I do feel strongly that revision to laws on a country-by-country basis need to keep pace with the level of change occurring around us.  Real-world personal habits have changed, and technology has single-handedly changed our lives in many positive ways that could not have been imagined 50 years ago or more when the laws were originally framed and enacted.  

By virtue of how the Internet works, there is an increased desire and tendency to share.  People conduct sharing on many levels (texting, email, pictures, documents, music, video) and given how easy it can be to do, they do it often without giving any thought to the legal implications.  Generally speaking I think people know when they are doing something wrong, but I maintain, 'fair use' should come into play when doing certain kinds of sharing on the Internet.

By the same token, enforcement of laws governing IP and Copyright Ownership should not preclude consideration for if and when censorship should be applied.   Enforcement efforts have been in effect for some time.  The MPAA and RIAA have rolled out a Six Strikes and You are Out enforcement plan with the assistance of Internet Service Providers (ISP) to 'monitor' user Internet activities.  (Not all ISPs have agreed to participate in this program.  Please check with your Internet Service Provider's policy on this issue.)

This is, to my mind, wrong and smacks of a total breach to the public's right to privacy as well as an overreach of censorship.  How effective their plan has been is not clear, but many new software technologies are coming to bear to provide users with the needed tools and resources to ensure their activities remain private such as ZKE, RetroShare, Mega, Wuala and SpiderOak.

The NSA scandal of 2013 has now galvanized public awareness and catalyzed a renewal of initiatives to offer strong encryption across all Internet services for both consumer and commercial use.

The Pirate Bay has clearly been the target for long-standing IP and Copyright theft.  That cannot be disputed.  Yet, despite what happened to their founders (jailed) and what happened to MegaUpload (take down of central servers) the Pirate Bay lives on. They are now are embarking on a plan to decentralize their network to beat censorship.  At the very least, new technology that curbs inappropriate censorship is needed until the gray area between 'fair use' sharing and outright theft is clearly defined.  This is all complicated by a 'borderless' Internet which doesn't see country borders or know about treaties to offer recognition for differing treatment of existing international laws.

CES 2014

The annual Computer Electronics Show begins today, January 7 and goes through January 10.
I was an avid follower of this event going back to 2006 when many new technologies were first revealed.  In 2007 I recall the level of anticipation was palpable surrounding new technology paradigms like the Nokia N95 (I bought one) and the first generation Apple iPhone (I didn't buy one -- hate it to this very day -- Android is King).

Anyhow be tuned over the next few days for product announcements.  I'll be watching closely.

--Dietrich




Enhanced by Zemanta

Tuesday, December 24, 2013

Wishes for a Merry Christmas and Happy New Year to All

by Dietrich Schmitz

This has been one roller coaster of a year.  But, by the grace of God, I am still here.

And, Linux Advocates hasn't done so bad turning in an average 60,000 page views per month.  I will be around on and off through this and next week, but expect 2014 to be another productive year for story writing on LA.

A special 'Thank You' goes to all those who have made contributions to LA.

Thank you to all of my readership for their support.

Merry Christmas and a Happy Prosperous New Year

Dietrich Schmitz
Site Owner



Enhanced by Zemanta

Thursday, December 19, 2013

Double-Dreaded Fedora 20 Yum "Group Does Not Exist" Error -- Remedy

by Dietrich Schmitz

Okay, things have been going along swimmingly with Fedora 20 and I did have this error message turn up during the beta testing phase.  I thought they nipped it in the bud, but apparently not.  Anyhow, here is a link to a FedoraForum.org post which can fix the error message, including this screen snapshot of the forum page. Oh the Humanity. -- Dietrich

Fedora 20 Yum "Group Does Not Exist" Error Remedy

Enhanced by Zemanta

Wednesday, December 18, 2013

Fedora 20 Linux for the Masses

by Dietrich Schmitz

Hey, you never know.  It could happen.  That is, Fedora will become the 'de facto' long-term Linux Community Distribution standard after 5 years.  I give to you below embedded my Google Plus stream of consciousness uncensored, unabridged for your consumption. :)

-- Dietrich



Enhanced by Zemanta

Friday, December 13, 2013

Money in the Bank: Fedora Btrfs Filesystem With Yum-plugin-fs-snapshot

by Dietrich Schmitz

The IT Scenario


You are a veteran System Administrator.  You know the drill.  You have an operating system upgrade to do.  It must be done in such a way that there is no 'down time' for the end users in your business setting.

Taking Precautions -- Backup


That, usually means doing it over the weekend when nobody is in the office.  It also means that you must apply due diligence in being sure you have a 'viable' backup set of the system -- not just a differential backup.  So creating one takes time with a decent tape archiver, or, if you are lucky you work for a larger Enterprise Datacenter with a dedicated rack NAS server to stream image the drive across to another hard drive.  But that's pricey and many small- to medium-sized businesses simply can't afford to spend $40,000 or more for such technology.

So, tape back up it is.  It might take 6 hours to complete on a Saturday.  And you hope that verify confirms it is a good set.  Any errors, then you may need to start over switching in a different tape assuming the first has media damage.

It's something you incorporate into standard operational procedure to precede any Change Management request for work on any server upgrade.  Never deviate.  Your job depends on it.

If your system crashes, for whatever reason, you pray your tape backup will restore and the turnaround time to do a restoral can take several hours depending on the tape archiver subsystem being used.

Often Murphy's Law comes into play: "when things can go wrong, they will go wrong."

You discover that something in the install log doesn't look right and the system has decided to abend several times during your post-upgrade testing.

It's now midnight on Saturday.  You need to pull the plug and restore from tape backup so that the system will be 'up' on Monday at 8:00 am.

So, you come back in again Sunday morning and proceed with tape restoral and babysit the job to completion and if you are lucky, the system boots up and is ready for Monday morning's business.  You get to keep your job for another day, maybe the whole week even.

Btrfs and Yum-plugin-fs-snapshot


Today, if you set up your server with Fedora Linux and partition the system using Btrfs filesystem, you get the capability to do snapshots that interleave your hard drive with no need to send the snapshot to an external drive.

The process for doing so is near-instantaneous, a second or two at most to perform.  It's that fast and with Fedora's YUM package manager you also can avail yourself to using the yum-plugin-fs-snapshot plugin which will automatically create a snapshot of your Btrfs filesystem partitions before commencing with your operating system upgrade scenario.  Again, it's just one second to create the snapshot and the yum 'update' to upgrade the O/S proceeds to completion normally.

Post-Install Quick Snapshot Recovery


Were you to encounter problems post-install during your system testing, it takes just one minute to revert to your yum created snapshot and reboot.

This process might take total 2 hours invested time verses the whole weekend consumed using the old tape archiver method.

My Testing


I installed Fedora 20 last evening with Btrfs to test out yum-plugin-fs-snapshot.  Indeed, it works as advertised and all in a matter of a few scant seconds I had a snapshot of the root (/) and home (/home) partitions as backup following my test install of nmap and it's accompanying nmap-frontend gui.  Similarly, it took two seconds to remove the two snapshots.  Below is shown the output from my test:

Install  2 Packages

Total download size: 4.5 M
Installed size: 19 M
Is this ok [y/d/N]: y
Downloading packages:
(1/2): nmap-frontend-6.40-2.fc20.noarch.rpm                | 659 kB   00:01     
(2/2): nmap-6.40-2.fc20.i686.rpm                           | 3.8 MB   00:04     
--------------------------------------------------------------------------------
Total                                           1.1 MB/s | 4.5 MB     00:04     
Running transaction check
Running transaction test
Transaction test succeeded
Running transaction
fs-snapshot: snapshotting /: /yum_20131213160036
fs-snapshot: snapshotting /home/: /home/yum_20131213160036
  Installing : 2:nmap-6.40-2.fc20.i686                                      1/2
  Installing : 2:nmap-frontend-6.40-2.fc20.noarch                           2/2
  Verifying  : 2:nmap-frontend-6.40-2.fc20.noarch                           1/2
  Verifying  : 2:nmap-6.40-2.fc20.i686                                      2/2

Installed:
  nmap.i686 2:6.40-2.fc20           nmap-frontend.noarch 2:6.40-2.fc20          

Complete!
New leaves:
  nmap-frontend.noarch
[dietrich@localhost~]$

Then, I deleted snapshots just created:

[dietrich@localhost~]$ sudo btrfs subvolume delete /yum_20131213160036/
[sudo] password for dietrich:
Delete subvolume '//yum_20131213160036'
[dietrich@localhost~]$ sudo btrfs subvolume delete /home/yum_20131213160036/
Delete subvolume '/home/yum_20131213160036'
[dietrich@localhost~]$

Conclusion


So, there you have it.  Some technologies are just 'better' than others, yes?
This is why I endorse Fedora Linux.

Get your server configured with Fedora's Btrfs and Yum-plugin-fs-snapshot and have some peace of mind.

Money in the Bank. -- Dietrich
Enhanced by Zemanta

Thursday, December 12, 2013

Ignore Linux Standards at Your Own Peril

by Dietrich Schmitz

So, I've been watching the progression of all things Linux for the past few months and noting how many Distributions are falling in line with systemd adoption and those which are not.

Systemd adoption by major Linux Distributions

The freedom to make choices in software design which introduce variation ultimately exacts a cost.  It's not apparent up front but in the long term, introducing 'variation' of any kind into a operating system results in additional complexity.  Only recently has holdout Debian gotten around to recognizing that their sysvinit system is beginning to show its age and 'limitations'.  Uniformity lends to conformity and implied standardization, sometimes in the form of 'de facto' standards.

Today, I am reminding readers of the importance of adhering to standards as the image below shows how being Linux Standard Base compliant can and will lead to lower cost of operation and ongoing maintenance.

Linux Foundation promulgated 'Linux Standard Base'


Does having to adhere to standards stifle creativity and freedom of choice?  


Well, there's room for debate on that question and while to a degree standards compliance does impose a restriction on the respective developer's freedom to deviate, it also results in reducing complexity and to a larger extent fosters an environment in which software vendors and business concerns can reliably make assumptions which utilize those standards, including standard software behaviors, to streamline cost of operation from both consistency and reliability points of view: less complexity, fewer points of failure.  With fewer points of failure, reliability goes up and support costs go down.


Is my preferred Distro 'X' Linux Standard Base compliant?

It's an important question.  Let's take a look at Microsoft Windows for an answer.

Historically, over the past fifteen years preferring to work with Windows has been rightfully perceived by CIOs and CEOs as an implied standard, and despite Microsoft being a Monopoly, every developer knows that they have only one software API to deal with when choosing to code Windows executables on the Windows Legacy x86 platform.  That makes Windows an implied or 'de facto' standard, in lieu of there being any other competitor in a market.  And the choices imposed on Developers are made simple.  There's just one theoretical 'Distro' to think about when it comes to designing a piece of software for a given market.

But, there aren't any 'Distros' in the Windows world.  


Of course, but you see, Distro variation is non-existent, along with the implicit complexity stemming from compiler dialectic variations, differing package management and file hierarchy structure design considerations.  They're all gone and the attendent costs exacted on program development don't pertain in the Windows software development thriving ecosystem.

Should there be fewer Linux Distros?  


I don't argue for fewer Distros.  However, I do maintain that if the designers of Distro X conform to a base standard and not deviate, they will not have compromised their right to creative choice.  One need only look to the richness and diversity of software written to the Windows API to have an answer.

As long as Linux developers continue to clone new Distros and cheerlead the way, all the while ignoring standards, the chance for long-term survival of their work is put at peril.

Big Business Craves Stability

Simply put, Big Business Enterprise cannot afford downtime and thus the reputation of any Enterprise grade software system hinges on its stability and reliability in addition to effectiveness in providing a business solution.

There will not be as many Distros in five years as there are today.  

That fact is a certainty.

By attrition, some Distros will simply fade away into disuse.  The sturdy long-termers will consolidate and survive by adopting common standards and as there will be far fewer Distros, more programming effort will be spread across the few remaining base Linux Distros.  My prediction is there will be no more than six remaining in five years.

But be assured, Linux will continue to endure and survive, flourishing on a base set of LSB-compliant Distributions for many years to come.  -- Dietrich
Enhanced by Zemanta

Monday, December 9, 2013

G+ Conversations on Fedora 20, KDE User Perceptions

By Dietrich Schmitz

We had a lively exchange over at Google Plus on Fedora 20, due out tomorrow, 12/10/2013.  (Image credit: www.infusivefive.com)

+Tycho Softworks, a regular participant, initiated the post and shared his thoughts on Fedora 20 and the 'free association' thread of comments took off leading to KDE Plasma Desktop and some of the issues users are confronted with, legitimate or otherwise.

Per usual, perception is reality and I solicited +Aaron Seigo for his view on all things KDE.  He is as always the 'Thinking Man' and has no shortage of interesting things to say.

Here is the Google Plus Post in its entirety (you will need to click through the G+ post's "time" to see the full thread of comments):


Enhanced by Zemanta