NSA: Please Turn off the Lights When You Leave. Nothing to See Here.

Linux Advocate Dietrich Schmitz shows how the general public can take action to truly protect their privacy using GnuPG with Evolution email. Read the details.

Mailvelope for Chrome: PGP Encrypted Email Made Easy

Linux Advocate Dietrich Schmitz officially endorses what he deems is a truly secure, easy to use PGP email encryption program. Read the details.

Step off Microsoft's License Treadmill to FOSS Linux

Linux Advocate Dietrich Schmitz reminds CIOs that XP Desktops destined for MS end of life support can be reprovisioned with FOSS Linux to run like brand new. Read how.

Bitcoin is NOT Money -- it's a Commodity

Linux Advocate shares news that the U.S. Treasury will treat Bitcoin as a Commodity 'Investment'. Read the details.

Google Drive Gets a Failing Grade on Privacy Protection

Linux Advocate Dietrich Schmitz puts out a public service privacy warning. Google Drive gets a failing grade on protecting your privacy.

Email: A Fundamentally Broken System

Email needs an overhaul. Privacy must be integrated.

Opinion

Cookie Cutter Distros Don't Cut It

Opinion

The 'Linux Inside' Stigma - It's real and it's a problem.

U.S. Patent and Trademark Office Turn a Deaf Ear

Linux Advocate Dietrich Schmitz reminds readers of a long ago failed petition by Mathematician Prof. Donald Knuth for stopping issuance of Software Patents.

Showing posts with label GitHub. Show all posts
Showing posts with label GitHub. Show all posts

Friday, June 21, 2013

Open Source Downloads An Endangered Species


With news this week that GitHub is banning storage of any file over 100Mb and discouraging files larger than 50Mb, their retreat from offering download services is complete. It's not a surprising trend; dealing with downloads is unrewarding and costly. Not only is there a big risk of bad actors using download services to conceal malware downloads for their badware activities, but additionally anyone offering downloads is duty-bound to police them at the behest of the music and movie industries or be treated as a target of their paranoid attacks. Policing for both of these -- for malware and for DMCA violations -- is a costly exercise. (Image credit: iconseeker.com)

As a consequence we've seen a steady retreat from offering downloads, even by those claiming to serve the open source community. First GitHub bowed out of offering the service, claiming that it was "confusing" for the clients. More recently Google followed suit, bringing Google Code Download services to an end. They stated that “downloads have become a source of abuse, with a significant increase in incidents recently”. Community reactions to this have been mixed.

GitHub didn’t have an alternative plan for it’s users and clearly has no desire to be a full-service community host. Google suggested using its Drive cloud file storage service to host files, though this is clearly far from ideal as, for a start, no analytics are available for downloaders. Small projects are left with a rapidly decreasing number of options. They could pay of course, for S3, but for a free downloader solution SourceForge seem to be the only high-profile answer. SourceForge are doing everything in their power to make it easy for users of Google Code and GitHub to transition across to their service and GitHub have even included a link to SourceForge in their help pages, recommending them as a viable alternative. SourceForge assures us that they have no intention of shutting down their upload/download services at all.

SourceForge providing an alternative is potentially handy for those whose projects would otherwise be held up by this lapse in services and they will no doubt welcome the wave of new users. The issue shouldn’t be coming up at all though. Confusion for and abuse by users may sound like reasonable pretexts, but perhaps the real problem encountered by both the closing services is a somewhat less reasonable one. There’s a growing expectation that they should regulate the downloads, acting the part of police on behalf of copyright holders.

The pressure to behave that way, whether through a desire to preserve a safe harbour status or simply to tread carefully in the eyes of the law, is an unreasonable hack that appears to mend copyright law online but in fact abdicates the responsibility of legislators to properly remake copyright law for the meshed society and over-empowers legacy copyright barons. These changes to downloads are an inconvenience for open source developers, but should serve as a warning to the rest of us that the copyright system is beyond simple patching.
Enhanced by Zemanta

Wednesday, May 1, 2013

Gentoo Team Isolates Udev from Systemd (eudev)

by Dietrich Schmitz 

I've written a series of articles centered around the development of a new middle-ware initialization daemon service called systemd.

In my last post, Systemd: An Accident Waiting to Happen, I shared the concerns of one Developer who wrote about why systemd should not be used in Linux.  I feel strongly that his concerns elucidated are valid and I strongly urge you to consider an alternative to using systemd.

Gentoo programmers announced on December 17, 2012 the fork of udev to eudev.  And over the last several months have arrived at a workable solution.

On their GitHub site they invite other Linux Community Developers to participate in enhancing the eudev project so as to assure it becomes fully compatible with their respective initialization service protocol.  Here is a passage from the text from the README file in their eudev repo:

This git repo is a fork of git://anongit.freedesktop.org/systemd/systemd with the aim of isolating udev from any particular flavor of system initialization. In this case, the isolation is from systemd. 
This is a project started by Gentoo developers and testing is currently being done mostly on OpenRC. We welcome contribution from others using a variety of system initializations to ensure eudev remains system initialization and distribution neutral.

This is an extremely important initiative as it relates to finding a solution that removes all dependency on systemd to so allow eudev to operate with Gentoo's OpenRC initialization routines.

Your participation is encouraged to increase the scope of compatibility of eudev to ensure their continued system initialization independent operation.    -- Dietrich

Enhanced by Zemanta

Sunday, April 7, 2013

Email: A Fundamentally Broken System

by Dietrich Schmitz

Many are too young to remember Phil Zimmerman.  He's the creator of Pretty Good Privacy (PGP) an encryption standard, now perhaps the most-used method of encrypting email. (Image right: Phil Zimmerman)

It was in 1991 when Phil saw the unmet need and brought into fruition a much needed way to encrypt human readable text.  Coincidentally, the Internet had begun to unfold and his method of encryption soon gained in popularity.

Mr. Zimmerman became, as a result, the target of a criminal investigation, brought by the U.S. Customs Service and RSA charged with violating provisions of the Arms Export Control Act.   Charges, however serious, ultimately were dropped in 1996 and Mr. Zimmerman went on to form the PGP Corporation which was bought by Network Associates in 1997.

You see, email is clear text.  Yes.  Naked.  When you casually press 'send' on an email, it travels across the mail transfer agents to its destination as a stream of human readable text which makes it child's play for interception and viewing by any agency or individual.  Essentially, you are placing your correspondence in the mail without an envelope.

Seems odd when it's put that way doesn't it?

We go to great lengths to assure the safety of all paper mail delivery (warnings on mailboxes even) as we diligently place our correspondences in an envelope for what?  Privacy, of course.  There are Federal laws on the books to protect your paper mail but none for the electronic equivalent.

So it begs the question:  Why isn't email encrypted by default?

It seems that no one really thought that question through, or, at least there was a time when the email RFC 2822 (supercedes RFC 822) was used only by a small population of  technology-elite individuals.  Times have since changed and along with change the RFC was never updated to contemplate electronic privacy.  Nor, has there been a Federal Mandate for such, which might have funded meeting a new email privacy standard.

Worse, is the now all too well-known fact that the email RFC standard can be exploited.  How so?

SPAM.  No, not the kind you eat.  Email RFC sending id field can be forged and Spammers exploit that design deficiency and insert forged sending email addresses into emails sent from compromised PCs, which unbeknownst to the user (usually a compromised Windows PC), is running a deamon process (svchost) spambot in the background, sending out literally millions of emails a day, all forged.

Thus, unless you have a spam filter program installed, your email in-box may be filled with unsolicited emails some of which are benign, others contain attachments which if opened will trigger a script to run on the victim's machine, which may be designed to gain administrative rights and install yet another trojan spambot, or, worse ransomware or keyloggers.

It's all fairly well-understood but nothing, to date, has ever been done to correct the RFC standard.

Phil Zimmerman has always been a privacy advocate, and while he developed PGP, others fortunately saw fit to follow and extend his work and developed an open source and compatible equivalent, called Gnu Privacy Guard (GnuPG).

Today, GnuPG or GPG is the linch-pin for the vast majority of Linux Distributions (Distros) and provides a 'keyring' feature to ensure that software obtained from a Distro's repository will be guaranteed to be safe from tampering (trojan horses, viral code insertions).  So, too, GPG is compatible with PGP email and allows users to encrypt (envelope) their email correspondences to guarantee privacy.

Thus far, however, the implementation of low-cost or free, 'easy-to-use' email systems with standard encryption have been few, so there truly is a huge unmet need here--world-wide.

As more users embrace the Internet and become comfortable incorporating it into their daily lives, they have also come to understand the crucial importance of privacy.  In fact, many feel that such privacy is their given right.  I agree with that.  The right to privacy is implicit and incorporated into our nation's Bill of Rights.  It's no different than the paper mail envelope analogy I gave above.

So, as I read about Phil Zimmerman in recent news, I thought, here is a Man who is passionate and truly believes in what he is doing.  You see, Mr. Zimmerman has surfaced once again, only this time he is building is own infrastructure available to the general public to use as a turnkey encrypted easy to use email service, an expansion of a company he opened last year called Silent Circle.

From the story at TheRegister.uk, Chief Technology Officer for Silent Circle elaborates on this new service:


"Email is fundamentally broken," Jon Callas, Silent Circle's CTO, tells The Register, pointing out that security was not a serious factor in the original protocols. Wrapping messages in the best possible encryption will give a measure of security, and the team have spent nearly two years honing their product. 
"We believe we've got it as good as we can get it," he said. "Nothing is perfect, and anything we find there's a problem with, we'll fix it." 
To further test the system's mettle, Silent Circle has put its source code up on Github for analysis by the security community. So far, Callas said, three possible problems have been found. None of them were serious, and all have since been fixed or ameliorated. 
The new email service will take the best of this encryption, plus some extra special sauce and tools from PGP, and aims to offer secure service to subscribers across the world.

This is going to revolutionize and create a new 'de facto' standard for email privacy.  Code for the email service is being published to GitHub for security analysts to examine and provide feedback on including recommended feature enhancements and bug fixes.

As Phil Zimmerman wrote in an essay on his website, Why I Wrote PGP:

It's personal. It's private. And it's no one's business but yours. You may be planning a political campaign, discussing your taxes, or having a secret romance. Or you may be communicating with a political dissident in a repressive country. Whatever it is, you don't want your private electronic mail (email) or confidential documents read by anyone else. There's nothing wrong with asserting your privacy. Privacy is as apple-pie as the Constitution.
The right to privacy is spread implicitly throughout the Bill of Rights. But when the United States Constitution was framed, the Founding Fathers saw no need to explicitly spell out the right to a private conversation. That would have been silly. Two hundred years ago, all conversations were private. If someone else was within earshot, you could just go out behind the barn and have your conversation there. No one could listen in without your knowledge. The right to a private conversation was a natural right, not just in a philosophical sense, but in a law-of-physics sense, given the technology of the time. 
But with the coming of the information age, starting with the invention of the telephone, all that has changed. Now most of our conversations are conducted electronically. This allows our most intimate conversations to be exposed without our knowledge. Cellular phone calls may be monitored by anyone with a radio. Electronic mail, sent across the Internet, is no more secure than cellular phone calls. Email is rapidly replacing postal mail, becoming the norm for everyone, not the novelty it was in the past. 
Until recently, if the government wanted to violate the privacy of ordinary citizens, they had to expend a certain amount of expense and labor to intercept and steam open and read paper mail. Or they had to listen to and possibly transcribe spoken telephone conversation, at least before automatic voice recognition technology became available. This kind of labor-intensive monitoring was not practical on a large scale. It was only done in important cases when it seemed worthwhile. This is like catching one fish at a time, with a hook and line. Today, email can be routinely and automatically scanned for interesting keywords, on a vast scale, without detection. This is like driftnet fishing. And exponential growth in computer power is making the same thing possible with voice traffic.

So, are you just a little bit incredulous about this story now?  Well, you should be and I hope you will exercise due care in your Internet activities.  

This service cannot come soon enough.

-- Dietrich




Enhanced by Zemanta

Friday, March 15, 2013

Perl: The Language Everybody Wants to Declare Dead

by +Dietrich Schmitz

I keep looking, but I still haven't found a language that compares with Perl.  The level to which one can go with it soars above other languages with ease.  Perl will take you through a project and provide the deliverables.

It seems that many react and cringe when they hear the word Perl.  It's a funny reaction to me.  Because, all of the documentation for Perl is superb.  Writers like +Randal L. Schwartz or +Gabor Szabo will guide you with great thoughtful tutorials in their respective books and on-line websites.

My reaction to comments to the negative is that most are ill-informed and if a prospective student were to spend just two hours reading +Randal L. Schwartz's Learning Perl, they will have built a solid foundation upon which to expand their technical skill set.

Perl is found resident on most Unix, BSD, and Linux systems by default.  It often plays a large part in many 'behind the scenes' activities running on your system.  If you invest the time to learn, I would say it would not be a wasted effort as once done, Perl will be their in your toolbox for you to grasp and use on so many occasions throughout life.

Will Perl eventually die?  Some say it will.  But if you go by a recent study from RedMonks that measures the spectrum of programming languages in use on GitHub, it is evident that Perl is quite alive and well.


The RedMonk Programming Language Rankings: January 2013



Put forth the initial effort to learn Perl.  While the initial hill climb is steep, once mastered, Perl is powerful in the hands of the learned.  Perl can and does do the 'heavy lifting' in so many ways as exemplified by the CPAN repository.  CPAN is one step away  for anyone with Perl with a diverse set of open source modules ready to fill gaps in your programming needs.

Perl isn't just for writing projects; it is also good for quick 'one-off' utilitarian functions and can be quite convenient when invoked right from the Bash command line.  This one-liner upper-cases an entire text file:

$ cat sample.txt
Practical Extraction Report Language

$ perl -pi  -e “tr/[a-z]/[A-Z]/” sample.txt

$ cat sample.txt
PRACTICAL EXTRACTION REPORT LANGUAGE


Often, I visit +Gabor Szabo's excellent Perl5 Maven website to see what he is up to and come away learning something I didn't know before.  At his site you'll find his most excellent new book Perl Maven for Beginners, including in eBook downloadable format.  You can also find regular posts of his ideas and a dedicated section to tutorials especially made to coddle and encourage the newcomer to venture into this feature-rich, powerful programming language.  Here's a tutorial on reading a comma separated value (CSV) file and the requisite code:

#!/usr/bin/perl
use strict;
use warnings;
 
use Text::CSV;
 
my $file = $ARGV[0] or die "Need to get CSV file on the command line\n";
 
my $csv = Text::CSV->new ({
  binary    => 1,
  auto_diag => 1,
  sep_char  => ','    # not really needed as this is the default
});
 
my $sum = 0;
open(my $data, '<:encoding data-blogger-escaped-die="" data-blogger-escaped-fields="$csv-" data-blogger-escaped-file="" data-blogger-escaped-my="" data-blogger-escaped-n="" data-blogger-escaped-not="" data-blogger-escaped-open="" data-blogger-escaped-or="" data-blogger-escaped-ould="" data-blogger-escaped-utf8="" data-blogger-escaped-while="">getline( $data )) {
  $sum += $fields->[2];
}
if (not $csv->eof) {
  $csv->error_diag();
}
close $data;
print "$sum\n";

I can assure you from experience that for every 1 line of Perl, writing an equivalent piece of code in C will yield a ratio of 10 or more lines to accomplish same.  This is not to suggest that Perl serves to replace the venerable C language--certainly not.  But there are many applications where Perl excels and is the right tool for the job, particularly systems integration and the Internet web development.

So, please.  Make the investment.  Randal and Gabor will be there to help you.  I promise.   Learn Perl and it will be with you to serve your needs always.

-- Dietrich
Enhanced by Zemanta