21 January, 2015

open source

It has been a while already, to some maybe a long time. It was only just today I've found the words for it.

If you still believe in the merits of open-source related to security, you had your head up your ars.

I've had my beliefs and doubts on the merits of open source but now it's time to let go of any remaining beliefs. It's better at providing potentially better, potentially more secure software but it takes commitment. The type of commitment easily orphaned when a project get's absorbed by large entities.

In a way I applaud the plethora of noticeable open-source failures related to security. It shows the deep hypocrisy and arrogance in even the 'coolest' companies. Maybe it is time to forget about encryption and privacy all together.

To have such mind-boggling exploits for such a widely used stack of software is not only an omission. It is a structural weakness in the open model, people get stuck in it and resources are allocated at random.

I hope to see or work on making some change happen though it has already.

A few million have been contributed. It is curious to see now it can while for decades it could not. I cannot fathom the disregard for the public and trust people put into open source projects. Especially by those companies touting from rooftops how great the open model is and how great open source software is.

I'd grown skeptical years before and was not thanked for posting such critical thoughts. More often than not it would cause a screen of deafness or blindness or vague insults.

Don't get me wrong, the model and my respect for the programmers still stand. It is the total disregard for it and them, what these people stand for which is appaling.

an interesting post

It is not often I think of a post as inspiring, unless I saw it on El Reg.

http://www.theregister.co.uk/2015/01/21/users_patches_and_how_to_tell_the_boss_youre_insecure/

It also covers a cisco report on spam ( http://www.cisco.com/go/asr2015 ) evolutions.

There are a number of interesting findings to deduce.

  • SPAM is not going away soon, unless some civilized form of filtering is put in place at ISP level. Crime, like nature looks for the point of least resistance to succeed, in this case low-level traffic spread across a large number of hosts.
  • An unpatched bug is a potential threat, anyway you look at it, even if only one in a hundred get's actively exploited. It also shows the discrepancy between severity and real-world use.
    • more disturbingly this also indicates that many attacker may be using yet undiscovered and thus unpatched bug's
    • remote compromise is key to the usability of a vulnerability, no vendor has a metric for this which is visible to the end-user
  • Browsers are neglected as a weakness in the ICT Infrastructure
    • 90% of Microsoft Internet Explorer communications measured indicated it was NOT patched up to a more recent patch level.
    • 64% of Google Chrome communications measured WAS patched up
  • it is a globalized trend for a boss to get rid of people actually taking their job in security at heart, this should have been long dealt with, OpSec engineers should have a direct line to overrule such bosses or a form of autonomy.

19 January, 2015

A bad case of correlation

I'm a frequent visitor of arstechnica.com, these people write somewhat technical articles on interesting topics not far from reality, yet from a tech-savvy background. It's a good filter for the massive load of news published daily.

Today is one of those days I gaze at the affirmation embedded in the headlines. I'm bad at selling my views, which does not mean I don't have them. People who know me will even say I might have too many.

These two articles triggered my curiosity.

http://arstechnica.com/information-technology/2015/01/google-drops-more-windows-0-days-somethings-gotta-give/

Seriously, Microsoft has defined what is secure and what is not for way too long. I can only applaud Google's actions.

http://arstechnica.com/security/2015/01/survey-says-security-products-waste-our-time/

Now this is interesting. I've worked in or near IT and ICT since 1992. It has stumped me how people tend to look at the jobs which they need to do. 

While most of these people are highly intelligent the solutions offered are often based on formula thinking rather than practicality.

IF you run a system spewing a lot of false positives AND people are actively ignoring them it is time to fire people. More often than not this is a case of few dictating the needs of many.

I'm sure this happens in most companies and this is an 'accepted risk' or 'there is no alternative'. I've cried 'foul' before and I'd cry 'foul' now. It is "the singularity directive" which turn solutions into formula's, the need to deliver and the deliver of need.

It takes craft to make systems work for you, not piling ego's.

12 January, 2015

Buying a build to order laptop, from Belgium

Belgium's been a bit lagging behind of the latest trends in technology, since ever. On top of that the cost of electronics, especially computers, has been higher than in neighbor countries. It's improved but it's still noticeable.

Given my pickyness I wanted to go for a Build To Order laptop ( BTO ) There's a dutch company claiming BTO as a tradename, they lure many people but they're offering Clevo machines like most other vendor's. So it's just a brand.

Qualification for a new machine are defined by 'as possible'
  • slim
  • powerful
  • quiet
  • energy efficiĆ«nt
  • in budget

If i had the money and time I'd design my own

Besides Apple and to some extent Samsung it seems most of "the industry" is just that, manufacturing, not inventing or improving *sigh*

Places I've visited thus far :

  • http://www.xnotebooks.nl
  • http://www.bto.eu
  • http://www.laptopplus.nl
  • http://mysn.eu/
  • http://www.novatech.co.uk
  • http://www.bytesatwork.be 
  • http://www.originpc.com 
  • http://www.hexacorelaptop.com
  • http://www.mitracom.eu
  • http://www.compal-europe.com/
Shops outside of the EU but inspiring

  • http://www.toshiba.com/us/custom-laptops
  • http://www.maingear.com 
  • http://www.xoticpc.com
  • https://system76.com

Related but no hardware dedicated websites
  • http://trustpilot.com
  • http://www.electronicaonline.be/




28 December, 2014

a rant on Facebook

It's a topic long due and in dire need of some attention, and a rant.

an abrupt and brief introduction

Once more Facebook has managed to grab whatever it sees fit. Admittedly i've yet to read the "new" user-license agreement but i'm fed up with how they handle OUR data.I'm curious how their claims to the content we upload to Facebook will hold in international courtrooms ( updated below .

If i remember well, this is not backed by any proven knowledge, there are major differences between how IP and ownership are defined and enforced. In this particular case between the E.U. and the U.S.A. The example i believe to remember correctly is illustrated below.

In the E.U. people still adhere to natural laws where the message ( e-mail ) sent remains in the ownership of the sender, whereas in the U.S.A. other laws apply where the recipient becomes owner of the e-mail received.

I've banged my head a few times but i cannot excuse this line of thought in any way. These laws on either side seem quite particular on both sides. I've given it some thought back in the days i was asked to do some superficial research. Enough of hyperbole and suggestions, I'm no lawyer and have not ambition to be a spin-doctor for one or other surreal discussion. Back to Facebook.

what on earth or you on about dude ...

Basically, identity theft.

Despite many efforts Facebook has had security issues which are not benign. There have been accounts hacked and the Facebook infrastructure itself has been compromised. Accounts contain private details such as an address, e-mail, phone number, a map of your social network, at times, even credit card information.

This kind of service is not the type one expects a one-way trust relationship from. It should be like we share ( we should not give ), Facebook protects, that simple. Instead they claim and resell.

Facebook is not only demanding people to grow a sense of online presence awareness. It also indirectly demands users to grow an understanding of legal implications of Information Economics where many lawyers are oblivious too.

As such Facebook is demanding a large group of people to make decisions and considerations i do not see them ( or myself ) fit to make based on the little knowledge most people ( including many lawyers ) have on the topic at hand.

the void and oblivion

Basically Facebook is exploiting this ignorance and the gaping divide present in our society. The divide between the people aware of the challenges posed by the Information Age, and those who do not. Obviously ( or sadly ) there are many many people on one side of the divide.

As an indication for the obliviousness we're living in. Ample to no tools exist to manage your content on Facebook. After a short investigation I consider to start writing my own, it seems far from impossible to do so.

In effect, I've not found any tool which offers a more subtle form of control but to delete everything or delete everything in a given time-frame. This deepens my worry we're are in a collective thought-void. Some people obviously care for demonstrating their disdain or discomfort, thus far though no tool has surfaced which offers functional control over one's Facebook content.

[ note ] in some crooked way one could argue Facebook is serving as a leverage to grow awareness on the risks of poorly managed public Information Security, oh yeah.

so eh ?

To me this is indication for a most disturbing trend, we are not gaining in our awareness of what Information Security we should enforce on social media. We're loosing control.

Given the current state ( or lack ) of Information Security capabilities and successful criminal actions against large organisations one cannot but conclude the " No privacy" mentality is not a paradigm shift, it is lunacy. The social and economical impact of possible mishaps is a force to be reckoned with and little has been done thus far.

[ update ] it seems even in the E.U. the legality of the new E.U.L.A. is indisputable since most countries accept Facebook as an E.U. company since it has a stronghold in Ireland. Seriously, such is not an indication of wise men making laws.

25 December, 2014

Log Analysis


Early this year i had the opportunity to build my first log monitoring and collecting solution. Nothing fancy, built on Elasticsearch+Logstash+GrayLog2 paired with nxlog as the log forwarding agent since it is so powerful.

It is amazing how powerful these tools are. Not only do these key-value stores provide easy storage, fast search and indexing but also distribution of data.

If i had more time and specific projects at hand I'd be hooked. For now i consider this type of data-stores a major player in the foreseeable future.



24 December, 2014

3D Printing

The 3D printing hype has gotten to me, at least in theory.

Thus far i know there are several methods of which DMLS and SPS are the most attractive ones, yet far from affordable. One the other hand my main interest is with printing ceramic and ceramic-like objects, unfortunately i'm looking for a base of at least 200mm across. In combination with the requirement for ceramic and ceramic-like printing fillament provides for a yet non-existent 3D Printer.

The only ones i found thus far are DIY and lack the desired depth x width x height i'm looking for *sigh* ... Hypes ...

Segregation of Duties

Ever since I've been introduced to organizational model based on the "segregation of duties" it has me hypnotized. It's many advantages are not so to me, on the contrary. I wonder every time again and find for now i have no definite answers. Maybe my greatest worry is this model has taken the world by storm, in a way it is inherent to a society but has it no gone far out of place.

By now a duty is dumbed down to a task while to my 'sense' a duty would mean much more, it would also invoke being able to work others dedicated tasks. Mentally i often refer to the benefits I've seen from growing skill outside of a domain in ICT. Not just network, not just system adminstration resulted in a fundamental sense of an ICT Infrastructure, in time this has grown into a fundamental sense of Security.

The best example i experienced was in an enormous corporation where a senior specialist system administrator showed me his entire task-range consisted out of template installs, creating pre-defined groups and adding users to them according to a pre-defined scheme. Just one step away from 100% automation.

I had a simple question to validate, since I was once one of a few dozen people requesting a feature to be added to a mail server. But neither he, neither the corporate security could offer relevant feedback regarding my proposal. I even spoke with corporate 'professionals' and 'experts' who seemed to be unable to grasp what was a pretty straightforward proposal.

It took 1 month and a half to motivate, document and defend a change. Which in the end exceptionally was not accepted world-wide. Despite having been documented on the vendor website for almost a decade.

In a way it would be understandable this change had not been accepted, but it had been by some and the region's who did not had displayed a complete lack of understanding what it was about.

To me this is an exemplary situation for the much famed segregation-of-duties being not only counter productive ( proposal-to-decision time explosion ) but also undermine a solid understanding of the corporate (ICT) environment.

I hope to one day advocate an holistic approach to ICT in favour of the s.o.d. approach, paired with smart communication strategies much will be gained and service will improve. After all ICT is the autonomous nervous system of a modern corporation, it should not burden the body but rather support it.

the Open society

Just recently I've learned of a man name Robert David Steele, a former and experienced intelligence officer who is now proposing and advocating a paradigm shift in our perception of society and how we enforce and establish the desired level of security to warrant stability and prosperity.

He is the author of "Open Source Everything" a call for integrity in a world slipping from stability into chaos and oppression. This is not a mere crackpot, though one never really knows i guess. The core values are attractive to any honest and caring person "Transparency, Truth, and Trust"

This article is worth a read if you want to assess how relevant this man's competence is in today's world, someone to consider if our societies are looking for a way out of the mess surfacing.

23 December, 2014

It's been a while

About seven years since i wrote anything on this blog. Needless to say, there's that many blogs out there i see little need for one more.

At least, that's what i was thinking seven years ago. Much has happened obviously. Though nothing out of the ordinary.

I figured it's time for me to try and pick up where i left off and maybe start writing some sensible stuff this time. Let's not get our hopes too high though.

I've quickly written a few pages on topics I've been in touch with over the years.

30 November, 2007

a Gutsy Gibbon Indeed


For the past two weeks i've spent a couple of evenings messing around with Ubuntu's latest and greatest, 'Gutsy Gibbon'.

Since i'm hardheaded i've chosen the alternate-iso to download and use for installation. Mostly since i'm also interested in unattended installations etc.

This has not proven to be the smartest initiative. The first iso appeared to be broken which is a bit of bad-luck. Tried again and booted without any issue.

Since i've ran Debian for a couple of years and wanted to 'go with the flow' i choose Ubuntu as my Desktop-OS of choice. Mostly to make sure i will not fall short of more up-to-date software such as the yummy Gnome 2.20.

So far i'm sad. Though i'm used to installing a Linux Distro and have a fair understanding of what it requires to run. I cannot get my machine to operate by using the available tools. Since i'm running with an ATI Radeon x1950Pro i've selected to use the restricted-driver-manager to get my desktop to work. Which is failing over and over again. I've tried about all i could without resorting to any logfiles and start working the hard-way because my greatest intention is to verify if this OS is consumer-ready. Given from my current experience this is not. I cannot believe any of my neighbours without any IT skills would be able to get this to work.

On my old but sturdy laptop (Compaq E500) the upgrade to Gutsy Gibbon broke the automounter for my external usb-drive.

This night or any other i'll try the Desktop-iso for my more powerfull machine and report back.

Somehow, to me Ubuntu does not seem to be Ready.

29 November, 2007