NSA: Please Turn off the Lights When You Leave. Nothing to See Here.

Linux Advocate Dietrich Schmitz shows how the general public can take action to truly protect their privacy using GnuPG with Evolution email. Read the details.

Mailvelope for Chrome: PGP Encrypted Email Made Easy

Linux Advocate Dietrich Schmitz officially endorses what he deems is a truly secure, easy to use PGP email encryption program. Read the details.

Step off Microsoft's License Treadmill to FOSS Linux

Linux Advocate Dietrich Schmitz reminds CIOs that XP Desktops destined for MS end of life support can be reprovisioned with FOSS Linux to run like brand new. Read how.

Bitcoin is NOT Money -- it's a Commodity

Linux Advocate shares news that the U.S. Treasury will treat Bitcoin as a Commodity 'Investment'. Read the details.

Google Drive Gets a Failing Grade on Privacy Protection

Linux Advocate Dietrich Schmitz puts out a public service privacy warning. Google Drive gets a failing grade on protecting your privacy.

Email: A Fundamentally Broken System

Email needs an overhaul. Privacy must be integrated.

Opinion

Cookie Cutter Distros Don't Cut It

Opinion

The 'Linux Inside' Stigma - It's real and it's a problem.

U.S. Patent and Trademark Office Turn a Deaf Ear

Linux Advocate Dietrich Schmitz reminds readers of a long ago failed petition by Mathematician Prof. Donald Knuth for stopping issuance of Software Patents.

Showing posts with label Microsoft Windows. Show all posts
Showing posts with label Microsoft Windows. Show all posts

Thursday, December 18, 2014

Your Browser: A General Purpose Remote Code Execution Tool

Google Chrome web browser security warning message


I've been reviewing the current state of Internet Privacy.

It's still a mixed bag and my conclusion is that it will remain so for quite some time.

Efforts to provide Internet Privacy are varied, depending on which ISP is employed.

The primary means for conveyance to a target website to do any kind of task is the web browser.

To put security risk into context, the web browser is a remote code execution tool.

Yep.  Let that sink in for a minute.

Where ever the user goes, the browser is set to 'trust' a remote stream of bytes which get 'interpreted' as program instructions on your PC by the web engine.

Sounds quite troubling when you think about it really.

I mean, your browser is one big catcher's mit and absorbs everything it sees in an attempt to execute instructions sent from a remote web server.

So, this catcher's mit is by default a 'security risk'.

Different software vendors take different approaches to the responsibility of writing their software in a manner that ensures it should always operate securely.

For example, Internet Explorer on Microsoft Windows, is written by Microsoft and employs 'protected mode', something akin to a software sandbox, but, technically isn't.

Google Chrome for Windows is designed with a quasi-sandbox by Google Engineers.  But they have publicly stated it cannot stop certain kinds of exploits (Javascript DLL injection) from successfully executing and gaining administrative control on Legacy Windows.  This is a fact.

But, that isn't really my point.  In each software project some 'defensive' coding has or has not taken place.

I've reported in the past that, where Fedora Linux is concerned, users running Firefox, the default installed browser, are placed in a 'real' sandbox, called Linux Security Modules (LSM) and the particular module used by Fedora is SELinux.

From a security standpoint, this is a prime differentiator between Linux and Windows.

An exploit may propagate on Windows running Chrome.  It will never propagate using Linux with SELinux.

The word 'never' comes with a catch.  You see the browser's memory space is up for 'fair game' and various code, Java, Javascript can execute remotely exposing certain parts of your running PC.

In theory, nothing bad should happen and it is assumed that code in the browser PID will never escalate to the Admin level.

But what it is doing in its own memory space is an open question.  The issue of cross site scripting remains an unsolved problem.

In this context, if a user chooses to employ a browser-based security tool designed to protect their local PC, this sets up the conditions  -- a 'fictional' exploit may, for example, attempt to steal a local browser's in-memory private keys for encryption.

So, you see, I am revising my thinking.  I'm not sure any more about using the browser for any kind of security.  It's that risky.

Using compiled, well maintained free standing open source security applications is entirely a different matter.

For example, I have Gmail.  But I don't use the browser client to access it.
I use GNOME Shell's integrated Evolution Email client, which is also used to prepare outgoing mail using GnuPG (OpenPGP) encryption.

The PID for decoding/encoding gmail runs in Evolutions local memory space, not in a browser.  Once the email is encrypted, signed, it is then and only then sent and a copy gets stored (IMAP) on the Gmail web server, in PGP encrypted form.

That's a routine process I feel confident in completely.

The notion that other software vendors can fork GnuPG and refactor it in Javascript troubles me.  This is precisely what Google is doing in their End-to-End encryption project, currently in Alpha.

The whole end to end encryption runs as javascript in the browser.
That puts the whole premise of security in the hands of the browser.

It's not acceptable.  Even now, I am rethinking how MEGA works.  Again, here, there is secureboot.js code running in your browser.

I believe there has to be a total segregation from the browser for any kind of security tool client application.  It must be compiled.  It must be open source and it must employ upstream industry standard GnuPG OpenPGP.

The browser will always be a target for attack.  Always.  Letting it also run your security is a fundamental mistake.  -- Dietrich

Tuesday, December 2, 2014

Lions, Tigers, Bears, and FBI Warnings, Oh My!

Wizard of Oz Movie (Image credit: prairiecloudware.com)


Seriously, do you tire of seeing major news plastered with warnings about cyber attacks, malware and viruses?

It really has grown to a fever pitch lately.

What stuck in my craw today was a Bloomberg report Exclusive: FBI warns of 'destructive' malware attack in the wake of the SONY attack.

Like, I should be mortified maybe?  Do these 'brainiacs' remember StuxNet?

Would it help to revisit the topic?  I'd rather not, thank you very much.  Please feel free to read the Wikipedia link on the subject.

It was the perfect road-side billboard if there ever was for why Microsoft Legacy (x86) Windows should be abandoned on grounds of National Security.

Sadly, the software industry hasn't changed and quite frankly isn't going to as long as 'big business' is married to a security-flawed 'by design' operating system.

What do I mean by 'by design'?  Microsoft provides undocumented APIs through their Trusted Platform to domestic and foreign governmental agencies (the FBI included) to have unfettered access to any Windows PC without the user's expressed permission.  (Insert sound of crickets here.)

That seems to me to be a major violation of public privacy.  And that's what the public get using proprietary software.  Transparency is non-existent.

Could writing code that facilitates having 'back doors' on to computers exist in the Open Source World?  I should think not!

Well, so far, we haven't seen any.

Of course there have been recent documented attempts by the NSA to weaken string constants in Elliptic Curve Cryptography used by Secure Sockets Layer, but it is a different kettle of fish to write a bank of code, spanning perhaps thousands of lines, dedicated to the specific purpose of providing 'backdoors' without going noticed under the Gnu General Public License for Open Source.  That kind of exploitative code cannot exist in FOSS projects.  Transparency is in full force with 'many eyes' providing the much-needed oversight.  As it should be.

Edward Snowden is correct:


“Encryption works. Properly implemented strong crypto systems are one of the few things that you can rely on." 

Unlike Open Source, the Proprietary Software Anti-Virus Business gets a boost every time one of these 'sensational' stories comes out.  It's a stimulus to obtain a desired result: the masses run out to buy AV Tools which get immediately installed.  End users fire up their AV tools, then passively watch a pretty widget on screen scanning, despite for foregoing 'backdoor' api.  The asthetic is dispensed  as the user receives a 'false sense of security'.   AV software vendors make billions of dollars in sales annually.  The partnership between Microsoft and AV Vendors is entrenched and the myth lives on.

None of this would have been mentioned if I didn't know better -- it insults my intelligence.

I know full well that if every Windows PC were to switch to Fedora Linux, all of the security issues would be gone.  Zero.  None.

So, please.  Spare me the FUD.  -- Dietrich


Wednesday, November 26, 2014

Fedora Linux: The Safest Operating System on the Planet

(Image credit: harrisburghelpdesk.com)


Computer Viruses cannot mount an attack on Fedora Linux.

It's a simple fact that millions of Windows users don't know.  In fact, largely, they don't care.  They assume an operating system, like Microsoft Legacy (x86) Windows, comes with AV software to handle the job of fending off viruses as being 'normal'.

Truth be told, it isn't normal.  And whether or not your AV Software catches a virus can be 'hit or miss' and a matter of timing.

I'll get to why Windows gets infected and why Fedora does not in a minute.

How AV Software Works


AV software relies on the fact that every virus will have its own exploit characteristics and the exploit code that invades your PC has it's very own unique CRC 'fingerprint' that when scanned for and compared to a database of 'known exploits' will get a match on that CRC value, which is a unique check sum number.

The problem with that approach is that some of the more clever viruses once they have compromised your system, intentionally alter their own executing code's CRC value on even an hourly basis so as to avoid detection against an AV database which might update only once a day if you are lucky, or worse, once every several days.

And they effectively sit on your system undetected, flying below the radar of your AV software.


Aged Windows NT Kernel


Even today with the very newest Microsoft Windows 8.1 (x86), the WinNT kernel is the same as those going all the way back to Windows 2000.  That's right.  The same.

Microsoft's large base of installed Enterprise systems are running on that kernel and any major redesign would cause hurrendous interruption of service, which simply cannot happen.  So, they continue with their haphazard patch Tuesday sending out updates to known exploits -- that's ones which they 'officially' have taken corrective action on, and doesn't include zero-day exploits.


Zero Day Exploits Prevail


Zero Day Exploits is another matter entirely.  These are exploits which can attack vulnerable unpatched Windows systems for which there is no official fix available.  The wild is filled with a 'black market' for writing Zero Day exploits which sellers sell to criminals who are intent on circumventing your PC on the promise that a Zero Day exploit will be effective.

Around the World, Windows PCs by the millions are prey to attack and this has become quite profitable for a syndicate of criminals intent on parting you from your money.

Such exploits include RansomWare, which is perhaps the most prevalent and pernicious type of virus.  If a successful attack is mounted against your Windows PC, said RansomWare quietly encrypts your hard drive, then puts a private key lock on it, and, only then, notifies the end-user that their PC is locked until they make payment.  It's become like shooting fish in a barrel and the software is now sophisticated enough to even offer the added convenience of payment by Credit Card!  Nice touch ey?  Terrible.

Windows Security is Not Assured


So, you see, running AV on Windows will not guarantee your PC will remain virus-free.  Nope.  Really, from my vantage point, there's nothing that can stop a successful exploit.

Other attacks include Drive by download where the user visits a legitimate website (which is compromised) and by merely going to your 'favorite' website, it can trigger a silent download from your browser a Javascript tag injection of DLL code which then runs unchecked on Windows.

Policing the Kernel's Actions


Unchecked.  The prime defect in WinNT, the aged 2000 kernel, is that there is NO 'third party' policing of what actions are taken by the kernel itself.

Imagine there being a police officer on sentry 24x7 who not only checks the actions taken by your favorite Application, but also those actions spawned by said Application to the kernel to perform specific system functions.

It is at the instant that an Application spawns a SYSTEM call to the Windows kernel (by the injected DLL of a Javascript attack) that a 'third party' should step in to investigate the discrete granular action being taken.  It simply doesn't happen.  The DLL injected code runs and exploit code at this point can perform any SYSTEM related administrative function.  No one called the police.  Your system is owned whether you know it (RansomWare) or not (SpyBot).

Linux Security Modules - A Better Design


Unlike the flawed design of Windows' WinNT kernel, Fedora Linux comes installed with a 'third party' Policing agent -- generically speaking it's called a 'Linux Security Module', specifically the module that is running is called SELinux.

It is this 'policing' aspect of SELinux that sets Linux apart in design and safety from Microsoft Windows.

Any software design which produces an unintended side effect that the software designer never intended to have happen as part of the feature set of a given Application is a 'bug'.  It is also true, that viruses exploit such a bug to induce the Application to behave in an unintended way.  The goal (induced side effect), is to escalate and gain access to the core SYSTEM function API.

SELinux, when your PC boots, binds to the Linux kernel and then makes a 'hook' into the kernel.  This 'hook' is a pause in execution by the SYSTEM at which point SELinux gets the opportunity to approve/deny what the kernel wants to do, BEFORE, execution can happen.  There is no getting by the 'hook' and so anything which is deemed not part of a normal 'policy' for the application which spawned a child SYSTEM call gets a 'deny'.

The exploit simply is stopped cold in its tracks.

So, this was necessarily verbose.  I apologize.  But it is hopefully clearer to you now why I endorse using Fedora 21 Workstation, because it is truly safe and viruses cannot mount an attack.  Ever.

Get Fedora 21 Workstation Prerelease for free (general release December 9, 2014) today, here.

Fedora Linux: The safest operating system on the Planet.

I stake my reputation on it. -- Dietrich

Thursday, September 4, 2014

CryptoWall RansomWare: The Psychology of Mass Insanity

(Image Credit: Geek.com)
Albert Einstein once defined insanity as this, "Doing the same thing over and over again expecting different results."

Are you using Windows Legacy (x86) 8.1 and older?

If you answered yes, then, I am afraid you are technically insane. ;)

Oh.  That Anti-Virus software subscription tool you so diligently run?  It is money and time wasted.  The types of attacks now occurring simply fly 'below the radar' of AV scans and morph their signatures on a daily basis so as to not be seen.


If you aren't thinking about switching operating systems, you really need to have your head examined.  It has become child's play for global crime rings to perpetrate the kinds of attacks such as the one depicted at the top of this story (aka RansomWare) and they get away with it by a process known as 'Drive-By' Javascript DLL injection into Windows Legacy operating systems going all the way back from 8.1 to Windows 2000.  Why?  Because they all share the same legacy WinNT kernel design and because Enterprise has been thoroughly invested in Windows, they cannot change the code or it would break Enterprise systems.

This is their dilemma -- their personal nightmare.  And just as with the slow death of XP, Legacy won't go away any time soon -- it is entrenched and businesses are 'married' to it for better or for worse.

You, the consumer, have a choice.  Distance yourself from a known problem.  Research 'Stuxnet' and then ask yourself how that could possibly happen (cough backdoors).

As long as you insist on using Windows Legacy, you are assuming the role of a 'victim'.  Don't be a victim.  Own your privacy.  It's your right.

Reclaim it with Fedora Desktop Edition Linux: the safest operating system on the Planet.

I stake my reputation on it.

Get Free Fedora Desktop Edition here.


-- Dietrich

Friday, August 29, 2014

The Linux Distro Repository System Safety Assurance

(Image credit: ablogabouthistory.com)
THE LINUX DISTRIBUTION REPOSITORY CONCEPT

Most people don't give a thought to this subject.  In fact, with Legacy Windows (x86), including Windows 8.1, there is no such concept as a 'repository'.

Every Linux Distribution (call it a 'flavor' if that helps), provides its own repository.  What is a repository?  Imagine a Castle (Library of Applications) with a moat around it and a draw bridge.  Only keyholders can get in and get out.

The keyholder conceptually is provided by a technology used extensively with Linux, called GNU Privacy Guard (GnuPG or GPG for short).  The idea is to guard all software in the library to assure that no 'tampering' can ever occur.  Tampering scenarios include adding rogue software (applications with hidden trojan viruses), unauthorized code edits which have negative repurcussions and usually include software exploits, such as the kind that politely advises the user that their drive is now officially encrypted/locked and cannot be used unless a monetary consideration (extortion) is provided that will cause the encryption to be unlocked (CryptoLocker being one such application aka Ransomware targets Windows, not Linux).

This GPG technology allows each piece of software in the Library to be linked to your Linux on the Desktop GPG-keyring and will not install, per se, unless it can be unlocked by your Desktop keyring (Fedora is my Distribution of choice).

The advantage is clear.  The maintainers of the repository for your Distribution are thus able to  maintain strict control over who can contribute code, vetting of software and the author's background, all done to assure that the program being considered for acceptance into the Library is safe for general use, devoid of any rogue code.

The absence of a repository of protected software applications has been an historic security problem of endemic proportions for Microsoft who must continually apply Zero-Day security patches to the operating system once a month to thwart introduction of rogue software onto the operating system.  It is a hopeless, unending situation and the fact that such software as CryptoLocker and Stuxnet exist should be a flashing neon roadside billboard to the average user, but, sadly isn't.  The public is bamboozled and has bought into the accepted practice  of running third-party Anti-Virus software, lulled by its false sense of security and done by the user at their additional out-of-pocket expense for purchasing said software, time and effort.  


Indeed, the Windows Legacy security software business produces multi-billion annual sales all of which does nothing to deflect a Drive-by Download, for example.  The user won't see it, but their machine is infected and there isn't anything they or Microsoft can do about it, short of a complete redesign effort which has gone into their ARM processor based product which has suffered languishing sales.

Below is my system running an update download from the GPG keyring-protected repository at Fedora.  If you run automated updates, this will occur daily with Linux, not monthly as Microsoft does on Patch Tuesday.


Fedora Linux:  The safest operating system on the Planet


Users of Windows Legacy must therefore 'fend for themselves' and go into the 'wild' so to speak in search of software, whatever that may be, with no assurance that it isn't laden with trojans ready to deploy silently, unbeknownst to the victim user, who believes they have found a nice game program, for example.

You may think things are safe with Windows.  They are not.

Fedora Linux: The safest operating system on the Planet.

I stake my reputation on it.  -- Dietrich

Wednesday, August 27, 2014

Patch as Patch Can

(Image credit:  theregister.co.uk)

What happens when you use proprietary code?  This story from The Register is quite representative.

Yes.  Google Chrome is proprietary.  Chromium is Open Source.

Open Source Chromium gets looked at by 'many eyes' and that is by Contributors across the Globe Folks.

Bugs get fixed quickly.

With any piece of proprietary code, including Chrome, only the employees who work as developers can make fixes to source code, no one else.  Unlike Open Source, Proprietary source code is not made accessible to the general public.  Only the binary executables get distributed.

It's a classic problem and has lent to a perpetual tread-mill of security issues for Microsoft Windows Legacy (x86) and the litany continues unabated to such an extent that Microsoft now wants to change the name of Internet Explorer to remove some of the legitimate stigma involved with user market perception.  It ain't gonna work.  The horse is out the barn door.

No, in fact, I made a policy decision some time ago not to use proprietary software whatsoever and wrote specifically about Google Chrome.

So, I strongly urge the readers to avoid Chrome like the plague and stick with Open Source developed software only, such as Chromium.

As for myself, I have Open Source dwb and Chromium installed, but use dwb 95% of the time.  dwb is written in pure C with gtk2/3 bindings and a webkit back-end on steroids.  It is understated, spartan, greased-lightning fast, and super lightweight with a 75MB startup RAM footprint.  Highly recommended.  Chromium is the easier of the two to install and use and will gobble up as much ram as it can find but, then, it has all the bells and whistles going for it.  -- Dietrich

Monday, July 21, 2014

Vokoscreen Screencast Utility So Easy Even a Caveman Can Do It

So, you probably thought I died?  Heh.  Yeah, I know.  I haven't posted in a while.  You know, life happens and I rather not write if I don't have anything good to say so that's why I've been MIA.





But, I am back with a short video to show you a product which is, in my humble estimation, a great, simple, screencast utility.  It is the last screencast utility I tried and turned out to be 'the best'.  Funny how that happened.  Among the contenders for 'drop-dead' easy to use are: recordMyDesktop and Screen-Cast-O-Matic.  Vokoscreen is better as far as I am concerned.

Watch the video, try it for yourself, and see what I mean.  If I can use it, anyone can.  -- Dietrich




Monday, June 16, 2014

Linux on the Desktop: It's Not Me. It's You.

by Dietrich Schmitz


Have you grown tired of Linux on the Desktop?

Does 'familiarity breed contempt'?

At times, I feel I have a 'relationship' and when it reaches the point of saturation, or, I don't see anything in the way of innovation going on, I feel the urge to say in parting, "Linux, It's not Me.  It's You."

Yes.  You.  I'm flipping that famous line, "It's not you, it's me intentionally to make a point.

What is my point?

I am a human from planet Earth.  I am really smart and Linux, you are doing a terrible job of keeping up with things.

So much so, I am just about to break up with you if you don't start shaping up.  I know you've been busy with Android and other embedded devices, but you really need to pay attention to me.  Over here, that's me sitting at a conventional keyboard, monitor, desktop unit (or Laptop).

And I keep hoping you'll begin paying attention to me.

But it seems like things are, well, boring, unchanging.  You've made a few attempts to sweeten things up.

Like Gnome Shell, for example.  Okay you worked hard on that, but, it's just that it is easy to use, but too simple.  Why is it so hard to innovate?

Unity?  You've really gone out of your way to be 'different' but again, the gui is not usable and limiting.

I've stuck with you this long only because of LXDE.  Now, after all of the upstream struggles to get Gnome 3.x to a point of 'usability', I have resorted to using lightweight LXDE.  Why?

Because, it doesn't reinvent the wheel.  Don't fix what isn't broken.

Panels, Desktop, Desktop folders, icons, menus, terminal windows, they all work in a classic intuitive way which is why I have always liked you Linux.

I think the problem is, you are trying to be different but no matter how hard you try, the technology just comes up short, deficient.

Maybe you should just be yourself again?  You know like when Ubuntu first came out?  Gnome 2.x worked so darned well.

Why did you change?  I don't like you as much anymore.

Please change.  I mean, innovate, in the truest sense of the word.
Let's not make new widgets that replicate existing functionality.  We already have in my estimation too much of that.

And please.  STOP cloning yourself.  You could go blind doing that.

How many of you do we really need?  I think you should just work on making one Distro better.  No, perfect.  That's right, perfect.

Make yourself sexy with a purpose, but let's stick to just the Linux Standard Base (LSB), one Filesystem Hiearchy Standard (FHS), one graphical API (like Windows GUI).  Yes?  Come to think of it, isn't that what makes Windows so successful?

Please.  Don't put on pretenses for me.  I know you.  I just want what's best for you and think you should really strive to simplify.  And, never mind what the other clones are doing.  They are just copy cats trying to emulate.  You are better than that.

Linux on the Desktop:  Be the best that you can be and I won't leave you.  Promise.

-- Dietrich

Saturday, May 3, 2014

It's Love All Over Again With New Improved Mozilla Firefox 29

Firefox logo
Firefox logo (Photo credit: Titanas)
by Dietrich Schmitz

I go back to a time when in Linux Firefox didn't exist.  Then, I used Mozilla.  For me, Mozilla Application Suite, a fork of Netscape's Communicator, was the best browser available in Linux Distro-Land and when it came out with 'Tabbed-browsing' I thought that was the greatest thing since sliced bread.

It was 'love at first sight'.  My infatuation with Mozilla grew and I became a loyal user overnight.

Enter Mozilla Firefox.  The genesis of Firefox was born out of many of Mozilla's features and overnight it became a hit.

Naturally, I switched away from Mozilla to Open Source Firefox and remain a loyal user.

Today, when I think about Open Source, I cannot stress its importance enough.  The need for Transparency in today's world has become magnified by world events and the increased public awareness that software can be exploited for nefarious purposes has become all the more clear.

How can we overcome such exploitation?  I believe that Open Source is vital to ensuring that rogue software exploit code becomes a thing of the past.  Proprietary code, that which cannot be seen, vetted with oversight by the general public, has the increased potential to become exploited on various levels.

Take for example something as simple as your average Microsoft Windows license.  Most people never read it.  And nobody other than Microsoft's programmers know what is specifically in their code base on an intimate level.  


How did Stuxnet happen?  


I am inclined to believe, it could not have happened if Windows was Open Source and I am also inclined to believe that it could not have happened without Microsoft's participation on some level.  There are 'back doors' into Windows legacy (x86) software, of that I am sure.

These 'back doors' are undocumented APIs which facilitate various control levels and, depending on the need, Microsoft shares those APIs with law enforcement and governmental agencies who request their assistance, unbeknownst to the general public.

This is only possible if the code base is proprietary and thus the programming APIs remain hidden.  And, proprietary being what it is, the ability to not disclose the full extent of how software governs itself is always an option and that is why I believe Proprietary Software = Exploitation.

Recently, I wrote WARNING: Google Chrome UNSAFE FOR GENERAL USE.
In that story, I disclosed my decision to stop using Chrome was based on its not being Open Source.


With world events in mind, Stuxnet, North Korean satellite launch systems (Windows) disabled, Flight 370 Boeing 777 'fly by wire' remote control software being undocumented and alleged to have been used for controlling and diverting said flight, I remain a staunch Advocate of Open Source and Transparency.

Just the other day Mozilla released their newest version of Firefox, version 29.

My good Friend Igor has scorned the design decisions made by Mozilla.  Okay, let's get it out of the way -- it 'looks' (to a degree) like Chrome.  But, if you really stop to think -- so what?  These are critical usability design considerations which I feel, on net, make Firefox all the more usable and at the same time extend its feature set with new much-welcomed rich functionality.

Firefox 29: A big win for Mozilla.  


When you combine the open source features of Firefox with the vast repository of plugins at users' disposal, the result is a powerhouse web browser.  There is no equivocating on that!

In fact, I'll go as far to say, I am in love all over again with Firefox and would like to thank the Mozilla Firefox Developer Team for all the innovative work done to date.  


Thank you.  Thank you.  -- Dietrich
Enhanced by Zemanta

Thursday, March 13, 2014

Step off Microsoft's Cost-Prohibitive License Treadmill to FOSS Linux

by Dietrich Schmitz


Step off Microsoft's Cost-Prohibitive License Treadmill to FOSS Linux.  Linux Advocate Dietrich Schmitz explains why.
These are critical times when many CIOs are budget planning and need to make across the Enterprise costly hardware refreshes -- especially now, given that Microsoft is officially ending support for the aged Windows XP on April 8, 2014.

Naturally, Microsoft licensing doesn't allow license transfer to new hardware. That's too bad. Because, it means, if your concern insists on staying with proprietary Microsoft Windows (x86 Legacy), it must be in full compliance with their licensing terms and so, not buying new hardware with ancillary licensing for software application upgrades is unavoidable.

It's good for Microsoft -- they recoup dollars on the operating system upgrade, and they also garner additional revenue for any Microsoft software applications your concern may need on each Desktop.  But that adds up quickly in terms of multiple machines across the Enterprise and puts pressure to bear on already tight IT budgets.  Now the remainder of those 'hold outs' XP Desktops must be dealt with.  Yet another round of costly refreshes to avoid the April 8, 2014 end of support deadline.  Ughhhh.

That refresh scenario has been a given for many years and Microsoft naturally while providing a service reaps the benefits of making the licensee pay for what I prefer to call 'recycled bits' of software.  Much of it is the same bits recompiled with a new face, or gui.  Sure there are software feature enhancements but I would submit that most offices won't use more than 20% of Office's features.

CIOs are effectively 'married' to Microsoft and being 'coerced' to refresh their hardware when they logically know full well that Windows XP would have been 'good enough' easily for another five years.


Forego the deadline?  Nope.  Can't risk it.  Enterprise systems must be available 24x7 and your job is on the line.  You have no choice.  Or, do you?

Step off Microsoft's cost-prohibitive License treadmill today. That XP Desktop system may be ten years old, but it still remains a 'fact' that it is a perfectly viable piece of hardware.



Fedora 20 LXDE Linux running LibreOffice 4.2.2


It can be 'repurposed' and given a 'new lease' on life by simply installing Free and Open Source Software (FOSS) Linux (Fedora is my recommendation) along with a vast repository of free software and support.

It's a 'no brainer' really. 


So, how many XP Desktops did you say are ready for the dumpster in your organization? The CFO should be happy to learn that you are effectively zeroeing out thousands of dollars of additional expense by switching to Linux.

Please.  Don't throw that XP Desktop away.  Be frugal.  Most of all, be smart. Reprovision it with FOSS Linux.  It will run like new.

-- Dietrich

Enhanced by Zemanta

Sunday, February 16, 2014

Microsoft Windows 8.1 Legacy (x86) - UNSAFE FOR GENERAL USE

by Dietrich Schmitz


You are reading this wondering what that means. Google Engineers have, in earnest, attempted to bolster Chrome for Windows by placing it in their own crafted (Not Microsoft -- they don't have one) security sandbox.

Despite their best efforts, they have posted to their Chromium developer website that they cannot guarantee your security if you use Microsoft Windows.

Here is their disclaimer:

Other caveats

The operating system might have bugs. Of interest are bugs in the Windows API that allow the bypass of the regular security checks. If such a bug exists, malware will be able to bypass the sandbox restrictions and broker policy and possibly compromise the computer. Under Windows, there is no practical way to prevent code in the sandbox from calling a system service.

In addition, third party software, particularly anti-malware solutions, can create new attack vectors. The most troublesome are applications that inject dlls in order to enable some (usually unwanted) capability. These dlls will also get injected in the sandbox process. In the best case they will malfunction, and in the worst case can create backdoors to other processes or to the file system itself, enabling specially crafted malware to escape the sandbox.
That's quite troublesome when you think about it. Google Engineers post up a 'caveat' -- their legal disclaimer, if you will.

Simply put, Windows 8.1 legacy (x86) uses a legacy code base going all the way back to the Windows 2000 WinNT kernel.

Microsoft cannot fix the security issues which are under eternal attack unless they completely rewrite the operating system from the ground up. Enterprise is 'married' to the operating system with applications which must run 24x7. Microsoft cannot rewrite the code which is heavily depended upon. They have a dilemma and they really don't want you to know about it. They just keep diverting your attention to 'the attackers' away from themselves as though they have no responsibility.

This is the cost of using proprietary software. Unlike Open Source Linux, no one can see the code of Microsoft Windows, review it, inspect it for defects -- FOR MICROSOFT EMPLOYEE EYES ONLY.

This is the disadvantage that one accepts when agreeing to the Microsoft software licensing terms. Microsoft own the code -- the Licensee does not.


So, why not consider making a switch today to Gnu Public Licensed Linux and own the code? It's yours for free and it is so secure, I'll even say Fedora 20 Linux is the safest operating system on the Planet.


Fedora 20 Linux running LXDE


Be safe with Fedora Linux.

I stake my reputation on it.

-- Dietrich

Enhanced by Zemanta

Saturday, February 15, 2014

Debian, Ubuntu Cave In: Standardize on Systemd

by Dietrich Schmitz


It's almost too painful to watch.  Really.  

Whenever Debian gets around to getting off their collective hands and coming to grips with reality, it's as though a new Pope were being selected and we are all waiting with great anticipation for the 'smoke signal' indicating a decision has been made.

Good grief.  This is what constitutes progress for Linux.  It's really border-line funny how Debian committees work through the pros and cons of adopting Upstart vs. systemd.

Do these Folks realize they are running the risk of becoming irrelevant in their inaction while the earth continues to turn on its axis?  Seriously, systemd is a foregone conclusion and while it took time for me to digest the technical issues during the past year, I do see its importance.

The thing is, this does represent not only a technical advancement, but also galvanizes the Distro community into a level of conformance which begets standardization.

Oh there's the standardization word again.  I said it.

Let me pose a hypothetical question for you developers out there:

What would happen if you dropped all of your current development efforts on your Distro X and enlisted to work on one mainstream Top 5 Distro, such as Fedora?

Think about that question for a moment.  What would you be giving up and what would you be gaining?

The initial knee-jerk reaction might be to say "I'd be losing my right to choice".  But would you?

Is the act of being independent and creating variation 'because I can' and "it's my right" of higher importance than say putting forth the effort to build a superior singular Distro?  Imagine if you would, hundreds, thousands of developers going to work on one Distro.  Leveraging the intellectual resources and manpower would be amazing.

But wait, all of that 'variation'?  It would fall to the wayside and we as developers could all focus on working with one software API, one file hierarchy structure.  The effect would be the same as if overnight we all chose Android and focused on application development in that ecosystem.

Honestly, I wonder where Linux will wind up and hope that if consolidation occurs as I predict, more effort will be redirected to a single Distro which can be forged, annealed, hardened to become as popular as Windows.

The success of Windows is as much about a monopoly as it is about one standard, one api, which was embraced and flourished.  Microsoft Windows legacy 8 is aged and I believe we have reached a turning point where Corporate Enterprise knows it must do something to unshackle itself from a marriage to an ever-restrictive proprietary solution.

Mark Shuttleworth acts like a defeated Man in his Losing Graciously concession to adopting systemd.  It's silly.  Look at the big picture.

One Distro, one API, with thousands of developers behind it, is a powerful thing.

-- Dietrich 

Enhanced by Zemanta