I usually kick off every year with the aforementioned greeting, but 2015 will stand as the year I really got sick of what the GNU/Linux ecosystem has become... in pretty much the same way I have been sick of what the Windows ecosystem has become. The mainstream Linux distributions have all become painful to me in ways that I couldn't have imagined just a few years ago. It's been a long, arduous slog. You can ask any of my nerd friends. I've gotten pretty salty over the state of Linux in the past year. And don't get me started on the nightmares of El Capitan and Windows 10, also making 2015 especially brutal.
This evening, though, Linux is weighing especially heavy on my mind. I'm sure the recent passing of Ian Murdock has something to do with it as well. We really did lose one of the heroes this week.
I will still use Linux and Windows for the tasks that they excel in. I will continue to experiment with and master their secrets in order to figure out how they work -- just as I do with other operating systems.
My new year's resolution is to get more and more of my personal stuff migrated to some kind of BSD.
Best wishes to all of you in 2016 from Ax0n.
2015-12-31
No more "Hacky GNU Year"
2011-05-19
Why I'm coming home to OpenBSD
Although those who know me will tell you I love OpenBSD, I'm generally an operating system agnostic. I enjoy tinkering with OSes, and always have. There have been a few I tried and couldn't enjoy for the life of me (Mac OS versions prior to OS X, PalmOS, HP-UX and plan9 among them) but since 1997, OpenBSD has always felt like home to me, and I've long been a little bit of a fan.
Labels: openbsd, opensource, rant
2011-04-18
The Real Insider Threat
Today, I saw this interesting piece on insider threats posted to CERT, and was somewhat baffled. I stewed on it a bit, but a Google Reader comment by Carnal0wnage spun up my rant engine. Here, people are actually being urged to spy on their peers then name them and shame then, as if it's totally normal to put bear traps in the server room and roll your own ECHELON, lynching in the commons anyone who dares to raise the ire of the great and awesome security team. They titled their session "What's working to stop these attacks?" It's us versus them.
When I was still a student, years before my real career in information security would take hold, it was commonplace to hear that some unfathomable percent of attacks are from malicious insiders. Maybe it was true in the 1990s. After years of leaving corporate workstations and academic lab computers hanging out on the Internet with public IP addresses and no firewalls, administrators were finally getting a clue, NATting workstations and putting up chintzy first-generation port-blocking firewalls. Students and curious employees were suddenly the ones with unrestricted access to internal systems protected -- if you wish to call it that -- by these prototypical security systems. Maybe this logic made sense back then.
Be that as it may, I've seen more data loss from people bypassing draconian security policy than I've seen data loss from the rare disgruntled trade-secret packrat with one hand in the cookie jar and one foot out the door. That's not to say these things don't happen. They do! But they're not the typical modern insider threat.
At my last job, I would occasionally have the option to work remotely for server maintenance, or instead drive 15 miles to the office at 11:00 PM on a Saturday night, and stay there until 4:00 AM Sunday morning. Working from home meant this:
- Firing up some proprietary piece of VPN software that only ran on Windows.
- Using a 2-factor authentication token to get into the VPN.
- Using RDP to access a "secure" sandbox server, which was pretty much the only thing the VPN would let you access remotely. This required the use of the 2-factor token again, but you had to wait to make sure you didn't use the same one-time key twice in a row.
- Using RDP from that server to get to my desktop, which also ran Windows.
- SSHing from my workstation to a central administration server that was dual-homed and could actually access the servers I needed to work on.
- Performing the work on the servers.
2010-10-18
The ultimate simple guide to Internet privacy
People are making a big fuss about privacy and how companies are invading it. Without further delay, here is my all-encompassing guide to Internet privacy.
- Think about what you're going to post.
- If you can concoct any situation in your mind where it would be bad for any one specific person to see it (e.g., your boss, your parents or even the person you're making fun of,) either now or for the foreseeable future, then do not post it on the Internet.
Also, if you're using someone else's bandwidth, server resources and infrastructure for free, then the service they provide to you is not their product. Their product is the data you willingly give them, which they're more than happy to monetize in any number of ways.
2010-10-07
It only happens once every 823 years!
- OR -
Shell Scripting for Pedantry's Sake.
Today's "That can't be true!" moment hit me when I started seeing this making the rounds (in various different paraphrased versions) on Teh Intarwebs:
"This month has 5 Fridays, 5 Saturdays and 5 sundays-Only happens every 823 years!"
Truth be known, I don't really care about how many weekends are in a month except for the fact that I get three paychecks this month. That happens about twice per year, and that's always welcome! Once in a while, though, I just can't help it. I have to disprove something. I figured the easiest way to disprove this particular claim would be to write a shell script that used the "cal" tool, found in every unix variant known to mankind.
For there to be 5 Fridays, Saturdays and Sundays in a single month, there is a basic requirement for a 31-day month that begins on a Friday, and only then will the 31st fall on a Sunday to complete 5 "whole weekends" in one month.
Initially, I was thinking of ways to see what months started on a Friday. That would get me close. It would give me months such as February 2013, which have only 28 days. Then it hit me: Look for any month with a 31st day that falls on Sunday. Using "cal," I can simply roll through the calendar year looking for a line that begins with "31" and guarantee that the month will satisfy the requirements of having five Fridays, Saturdays and Sundays.
So here we go!
#!/bin/sh
ye=2010
mo=1
while true
do
until [ $mo -gt 12 ]
do
cal=`cal $mo $ye | grep ^31`
if [ -z "$cal" ]
then
echo -n ""
else
echo
cal $mo $ye
fi
mo=`expr $mo + 1`
done
mo=1
ye=`expr $ye + 1`
done
Output:
January 2010
Su Mo Tu We Th Fr Sa
1 2
3 4 5 6 7 8 9
10 11 12 13 14 15 16
17 18 19 20 21 22 23
24 25 26 27 28 29 30
31
October 2010
Su Mo Tu We Th Fr Sa
1 2
3 4 5 6 7 8 9
10 11 12 13 14 15 16
17 18 19 20 21 22 23
24 25 26 27 28 29 30
31
July 2011
Su Mo Tu We Th Fr Sa
1 2
3 4 5 6 7 8 9
10 11 12 13 14 15 16
17 18 19 20 21 22 23
24 25 26 27 28 29 30
31
March 2013
Su Mo Tu We Th Fr Sa
1 2
3 4 5 6 7 8 9
10 11 12 13 14 15 16
17 18 19 20 21 22 23
24 25 26 27 28 29 30
31
August 2014
Su Mo Tu We Th Fr Sa
1 2
3 4 5 6 7 8 9
10 11 12 13 14 15 16
17 18 19 20 21 22 23
24 25 26 27 28 29 30
31
May 2015
Su Mo Tu We Th Fr Sa
1 2
3 4 5 6 7 8 9
10 11 12 13 14 15 16
17 18 19 20 21 22 23
24 25 26 27 28 29 30
31
I don't know. It looks like these things happen more than every 823 years. You can rest easy knowing that it will actually happen a total of 825 times in the next 823 years. Yep, I counted them.
One of the derivatives mentioned October specifically, though. Perhaps this only happens once every 823 Octobers?
Slightly modified, we make the script check Octobers...
#!/bin/sh
ye=2010
mo=10
while true
do
cal=`cal $mo $ye | grep ^31`
if [ -z "$cal" ]
then
echo -n ""
else
echo
cal $mo $ye
fi
ye=`expr $ye + 1`
done
Output:
October 2010
Su Mo Tu We Th Fr Sa
1 2
3 4 5 6 7 8 9
10 11 12 13 14 15 16
17 18 19 20 21 22 23
24 25 26 27 28 29 30
31
October 2021
Su Mo Tu We Th Fr Sa
1 2
3 4 5 6 7 8 9
10 11 12 13 14 15 16
17 18 19 20 21 22 23
24 25 26 27 28 29 30
31
October 2027
Su Mo Tu We Th Fr Sa
1 2
3 4 5 6 7 8 9
10 11 12 13 14 15 16
17 18 19 20 21 22 23
24 25 26 27 28 29 30
31
October 2032
Su Mo Tu We Th Fr Sa
1 2
3 4 5 6 7 8 9
10 11 12 13 14 15 16
17 18 19 20 21 22 23
24 25 26 27 28 29 30
31
Nope. More than a decade at times, but not 823 years.
2010-07-27
Really, Verisign?
Verisign's latest snail mail spam included a Verisign-branded USB drive with information on their new SSL Certificate features. The package was heavily loaded with all kinds of "Trust" rhetoric. At the request of the guy who officially got it, I threw it into my Macbook to take a look at it. It wasn't on any network and it's not prone to any known vulnerabilities that might allow something to run directly from the USB without any interaction (unlike Windows)
2010-02-14
Fraud and Identity Theft are not "Hacking"
[H]ard|OCP: Hacker gets record 13-year sentence for hacking.
Labels: computer hacker, hackers, news, rant
2010-02-11
Oh noes! Google Buzz FUD!
Silicon Valley Insider came up with this wonderful sensationalist FUD piece: WARNING: Google Buzz has a huge privacy flaw!
2010-02-09
Juxtaposition - Subscription-walls
A new paper on Johnny's "I Hack Stuff" blog requires a subscription. Meanwhile, Sensepost is abandoning their "Regwall" for research papers.
2009-12-08
Flyback transformers and CRT discharge. OF DEATH.
Last week, our friend Mike was attempting to power an ionocraft with the flyback transformer from an old 15" Gateway CRT. There was a bit of fear (or overdeserved respect) for the high voltage source. I gave a little quick lesson on how to discharge the CRT before diving into the project, but I figured it deserved a little more detail, and that you guys would at least find it interesting.
Labels: Electronics, rant, safety
2009-12-01
Rant: Hackerspaces do not foster cybercrime!
Two things pissing me off today. First: Vitriolic and audacious comments on this otherwise awesome article about hackerspaces in STL Today. Some excerpts from the comments:
The authorities need to keep a close watch on these people. Perhaps their source of funding will be hacking bank accounts.
Trying to include teenagers can get complicated. Personally, I feel open access to tools for cyber hacking, learning how to steal passwords, and other mischief can be inappropriate at that age. Even university students get caught up trying to make a name for themselves. [ . . . ] I was a founding member of CCCKC but these are reasons I chose to leave the group. I don't want to be labeled a cyber hacker by association.
Fortunately, there's some sanity and fact-checking in the comments, too.
And then there's news about Forskningsavd (a Swedish hackerspace) getting raided for something completely unrelated to the hackerspace. Further, the seizure of property seems completely bizarre given the stated reason for police intervention.
So, I'm feeling ranty. Here's some background on how my local hackerspace deals with "Cyber hacking and other mischief"
Shortly after CCCKC's grand opening, a series of courses were taught on cyber-security. These four sessions were very popular, covering the basics such as understanding the difference between hubs and switches, and eventually covering powerful tools such as nmap, Hamster & Ferret, Metasploit, and Maltego. The courses provided enough demonstration to scare people into being more cautious while teaching them how to avoid being victimized. Nothing was covered that hasn't been hashed over online a thousand times already, but it was very cool to get a guided tour through the maze of cyber-security and to be able to tinker around in a hands-on lab environment.
Around the same time, locksport also took off. A solid-core door got drilled out, had eye-screws put into it, and became a standing board of different locks to play with. The Lock Picks & BBQ series was also a big hit. People would come out, grill some meat, and then learn about the mechanics of simple locks.
Critical thinkers absolutely love to explore dynamic boundaries, and very few boundaries are as controversial and exciting as the enigmatic balance of attack resistance vs. usability in both physical security (locks and surveillance) and information security (firewalls, encryption and vulnerability exploitation). It's no wonder some of the worlds most intelligent people have dabbled in security. Richard Feynman, for example, picked locks at Los Alamos for fun and pranks.
Now, several hackerspaces are uniting with an international VPN that's going to be much like a digital Capture The Flag game. We're calling this effort "The Warzone Project" and it'll give people a safe, isolated environment to practice their skills in information security systems.
The thing is, there's already a lot of very detailed information on the web and in books when it comes to breaking all kinds of security systems. Demonstrating them in a lab environment gives people a safe place to "get it out of their system" much like Grudge Night at the local drag strip gives teenagers a safe place to race their cars so they aren't endangering people on public roads. The lab environment also allows people to legally learn about more aspects than they could in their own homes, and to take a shot at mastery in defense by understanding both sides of an attack.
"Hackerspaces are about learning, sharing and collaboration."Folks, every hackerspace takes on a personality of its own based on what the members are interested in. Some hackerspaces focus on electronics or take an art, metal/woodworking and maker approach. Some tend to focus on programming microcontrollers or building robots. Others are busy tackling so many eclectic projects that they don't even have a core focus. They all have some things in common, though: Hackerspaces are about learning, sharing and collaboration.
Writing the code and creating the control infrastructure for a botnet takes dedication and lots of work. Poring through source code, looking for bugs and creating a working exploit is no small feat. It can take years to fully master exactly how locks work and how to manipulate the parts inside. Indeed, learning in a lab environment teaches patience. It teaches respect for the systems. Learning is hard, but it's good for you.
Compare that to the modern criminal reality: Right now, anyone in the world can rent a cadre of botnet computers for just a few dollars and use them to send spam, to host fake bank websites, to obscure their attacks or to use in a massive denial-of-service attack. Anyone can look up the latest zero-day exploits and use them for bad things. Anyone can buy a bump key and start opening about 30% of the locks that key will fit into. Subversion is easy.
If subversion is your goal, you would be silly to waste your time learning all the minutiae of systems from hackerspace denizens. Cyber criminals already know this. Apparently, some people still don't get it.
Update
I thought I'd share a quick list of things we've worked on and had talks about lately at CCCKC:
- Assisting JayDoc, a not-for-profit medical charity for the needy
- Joined more than a dozen hackerspaces live via webcam for the synchronous hackathon.
- Projected a game of Tetris onto a wall in downtown KC
- Building, studying and using the MakerBot
- Ran tech support and helped make BarCampKC 2009 a success
- Built a Twitter-bot (that's currently on the fritz)
- Set up a silk-screen lab for emblazoning logos onto things.
- Got good press in INK KC
- Set up a MIDI music workstation
- Built a compressed air T-shirt cannon
- Got a bunch of people familiarized with Arduino programming
- GPSes, computer interfaces for them, and Geoc... "finding things people hid somewhere"
- Search engine optimization
- Robotics
- Hacking the car-buying process
- Intro to Craps (the casino game)
- Server/telecom racks
- Electronics
- Robotics
- Radio Controlled Toys
- Photography
- Scrapbooking/Crafts
- E-Textiles (like gloves that work with touchscreens, LED embroidery, etc)
Labels: hackerspace, rant
2009-11-29
Cyber Monday? How about MAKE some gifts?
This year, I'm planning on building as many gifts as I can. This is why I was so frustrated with Radio Shack earlier this month. So far, I've got three gifts almost completed, all of which are electronic. I start with an experimenter breadboard like the one shown*, then go bananas. Once I have something working the way I like it, I solder it to perfboard.
Labels: Electronics, rant
2009-11-25
Mastery through persistence and gradual learning
- Locations of hundreds of little pieces of configuration data
- Names of scores of system commands
- Hundreds of collective options for those system commands
- Syntax of aforementioned configuration data and system commands
- Menu options and other madness for dozens of popular applications and services such as Apache, sendmail, MySQL and ssh to name just a few.
2009-11-20
Hey Radio Shack. It's us, the makers.
Do you remember in the 80s and 90s, when half of your stores' real-estate was dedicated to sliding pegboards of myriad components 3 layers deep, Engineer's (Mini) Notebooks by Forrest M. Mims III, genuinely good electronics experimenter kits, prototyping breadboards (not these) and Tandy/Archer/Heath-branded customer-soldered kits that were genuinely useful?
We want it back. You see, DIY electronics is en vogue again. Guitarists are excited about their stomp boxes. Teenagers are building awesome robots that are more than just cheap plastic toys. The economy is fostering a serious DIY revolution. People are going on MakeCations (staying at home, making things) or doing weekend projects instead of weekend road trips. We are once again learning how to fix our ailing gadgets rather than chucking them into the garbage, and looking for ways to make our own simple and useful electronic gizmos and toys instead of buying them. It's cheaper and a lot more fun. Building and fixing things yourself instills a sense of joy. Who doesn't LOVE a sense of joy!?
Just as the old-school PIC gave way to the easier-to-use BASIC Stamp, the electronics deities have given us the Parallax Propeller and Atmel AVR Microcontrollers, and the easier-to-use pre-packaged versions: SPIN Stamp and Arduino. There are literally thousands of well-documented and useful projects out there for budding electronics engineers and computer scientists, yet we no longer have a good, local source for discrete components to help us finish these projects. That used to be you, Radio Shack, but you've lost your way.
Last night, I was horribly saddened at what your component selection has become: a dozen drawers or so containing only two or three of the most popular values of components, and only a lone 555 timer hanging out with a few different SCRs and op-amps in the IC bin.
We are the makers. We are many. Hear our plea: Lose some of the chintzy, easily-broken children's toys and pare down (or get rid of) your selection of overpriced and useless home theater junk. Other stores do consumer electronics much better than you can with your small, shack-like storefronts. Bring back the big sliding racks full of components, chips, and kits. Bring back the spring-jumpered crystal radios and projects that kids can build with their parents. Bring back the shelf full of electronics project books and experimenter kits. Bring us Arduinos, SPIN Stamps, stepper motors, servos and robotics platforms.
You were once our hyper-local, affordable source for all kinds of DIY electronics hackery. We liked that. We do not like having to beg all of our friends to go in with us on a huge order from the all-encompassing catalog companies.
Also, a bit of a shout out: here in Kansas City, we do have the HMS Beagle store and Electronics Supply. Unfortunately, they lack the ubiquity and convenience of Radio Shack and they still have to special order a lot of things. Mostly, I'm just being a ranty retro-grouch as usual. I'd really like to see "The Shack" return to its roots. The things they currently do, they're doing poorly, and there's a huge niche left behind by their old business model that I feel would probably thrive quite well. I hoarked over $1.49 each last night -- happily, I might add -- for a pair of LM386 Op-Amps. I'm betting Radio Shack made 700% profit on each of them, at minimum.
Labels: Electronics, make, rant
2009-11-17
Tales from the other side of helldesk
2009-11-02
Windows 7: Is its success really a surprise?
I've been messing with Windows 7 since the beta, and my wife has the Ultimate edition installed on her laptop (having replaced Vista, for the most part).
- Windows XP, a decade-old platform that's been patched to hell
- Vista, a chubby three-year-old toddler replete with nagging, resource-hogging character flaws
- Windows 7, the shiny hotness built after pay-to-participate beta testers shook out Vista's worst features and bugs over the course of 3 years
2009-10-21
Viral marketing
As seen in my Facebook notifications. Facebook apps in general are shady business, but this just seems downright predatory.
Labels: privacy, rant, socialnetworking
2009-10-12
On cloud computing
It seems everyone is blaming a general failure of cloud computing for the massive data loss that hit Danger, Microsoft and T-Mobile over the weekend.
From what I've read, a failed storage upgrade occurred without a good, solid backup in place. That sounds a lot more like a failure in backup, planning and design than a failure of cloud computing to me. Had the storage folks at my office made the same mistakes, that's what would have been said -- right before the human resources folks came to "have a talk" with the team.
It just so happens that T-Mobile's sidekick phones rely on a lot of back-end storage, so there's the whole "cloud" element to things. I'm not familiar enough with the Danger platform to know how easy it is to back up your own data, but I'd hope it's possible.
I think it goes for any service where you've entrusted storage of your data to someone else: make sure you back it up yourself, if you think it's important. The difference with the Danger/T-Mo disaster, I think, is that it was a lot less obvious to end-users that the data wasn't all stored permanently on the phone. Clearly, "cloud computing" was collateral damage in the wake of a much more mundane failure. The fact that it was completely avoidable offers little comfort for those affected.
Shifting gears: Along comes this piece on how e-mail is becoming less and less relevant.
The thing that separates e-mail as we know it from other messaging platforms is the fact that e-mail is decentralized. Using information stored in DNS, all Internet-facing e-mail servers can properly send mail to the correct server for a given address. IRC is another decentralized communication protocol. The days of decentralized infrastructure are fading fast, though, being replaced by walled gardens that want your constant attention, and many of them requiring a separate account and password. These walled gardens are supposed to be "the new way" of communicating.
You can't easily backup everything you've received through Twitter or Facebook, and the people who communicate with you there have to have accounts. Sure, anyone can get an account. What about Google Wave? Very few of the people I REALLY want to collaborate with have an account. So, while I do see a lot of value in these services for certain things, I don't think that any of them are quite ready to fill the roll that e-mail currently provides. Chiefly: if I have a local e-mail client running on my system, I don't need to suckle at the teat of the Interwebs in order to rifle through my data. It's right there, on my computer. Web mail has indeed blurred the line, but the good web-mail providers still offer mechanisms to back-up your data or use an offline mail client such as Thunderbird.
OpenID somewhat fixes the need to have multiple accounts and passwords scattered all over the web, but shifting authentication "into the cloud" just means that each OpenID account we have will be more catastrophic if compromised. OpenID is tantamount to using the same username and password everywhere, and we know how well that works for security.
How do you backup your cloud data? Well, for starters, you can try a native-client RSS aggregator such as Liferea. One thing that "Cloud" is doing is making syndication possible through ubiquitous RSS feeds. Backups won't work perfectly on every site, for example: you won't actually download all of the photos from Flickr with RSS, you'll only get links to them. It will nicely archive text content, though. This is good for things such as blog posts, twitter conversations and the like.
2009-09-18
Verizon Wireless customers: Privacy Fail
I got this lovely IED of Privacy Fail in my inbox this morning. See the circled text. It looks like we get opted-in by default! If you don't want to be sold and traded at Verizon's every whim, you should probably try to hunt this down or access the setting in your VZW account.
Update: According to Mike Fratto (@mfratto) it's old news. How long have we been opted in, anyways!? He points out in your account, go to VZW→My Profile→View/Edit Privacy(CPNI) Settings to change
2009-08-04
I need a Kia.
No, not really. It is about time for a new phone, though. My two-year subsidized phone contract is up in a few weeks, and not a moment too soon. I've had a great run of things with my 2nd Generation LG Chocolate VX8550. But it's showing signs of being on its last legs and it's gotten pretty beat up the past few years.
Mine is on the left. My wife's is on the right. Nicks, scratches, a non-working soft-button... Yeah, I am kind of rough on my phones. All that bicycle riding, dumpster diving, and setting the phone down on concrete takes its toll...
When asking for advice on what new phone to get, I put forth the following requirements
- Decent battery life
- MMS/SMS ability
- WAP Browser (gmail's WAP interface is good enough for me)
- Tethering ability (even if it's under-the-radar like I do with my Chocolate)
- I'd really like a qwerty keyboard, not required though.
- Affordable. Like under $100 after renewing my plan.
Then, it seems the entire world is out to tell me how awesome smart phones are and decide to chastize me for my adamant stance of not needing one. In essence, these folks are preaching about how practical their Ferraris of the phone world are.
The thing is, I carry my laptop most everywhere I absolutely need a computer. Until I can buy a phone that's got 200GB of storage, Wifi AND 3G (or equivalent), and can do some pretty solid web browsing, SSH, and things like that, I really can't justify replacing my laptop with a phone. Therefore, it makes little sense to overlap functionality while spending a lot more on a phone than I need to.
Also, you're more than welcome donate a VZW-compatible smart-phone to me if you really, really think I absolutely must be converted. You won't find me bankrolling your experiment, though. I'll do my best to go about my daily grind while using it, and try hard not to completely destroy it. Note: I've busted a few touch-screens in my day. Things like BB Storm wouldn't stand a chance with me.
Serious suggestions wanted. Tell me in the comments.