The Humane Society of the United States

"5 big security mistakes you're probably making"

March 13, 2012 By | InfoWorld

A Comment...

Mr. Grimes often speaks of patching. In the world of Microsoft and other proprietary software, I know of little other choice as a first line of defense. That's a big reason I took back my computers from Microsoft, et.al. a few years ago.

Most businesses can't do that since they've decided they like comercial software companies running their business. They no longer maintain the in-house expertise to have secure systems.

Commercial, proprietary, closed-source software can never be secure.

What about the military, NSA, etc. which have some of the most secure systems in existence? Those are all developed in-house or by contractors to exacting specifications (That's why they cost so much). Those institutions have the source code to everything mission-critical they run and they isolate what little commercial software they have.

There have been so many Windows patches that I doubt anyone but Microsoft has a count. But think about this... Every one of those flaws was either present from the initial release or introduced by a previous patch!

Thus, the vast majority of vulnerabilities over the lifetime of any program will always be uncorrected. And the number of person-hours spent looking for vulnerabilities to exploit dwarfs the person-hours that Microsoft or any other company can afford to devote to patching.

How can we have reasonably secure systems then?

The only way I know of is open-source software.

Here's an analogy... Most theft occurs at night, when the lights are off and the theif can't be seen. The first line of defense for a storefront is to leave lights on when the store is closed so police and everyone else can see inside.

Closed-sourcing hides the software's errors from everyone but those with the skill and motivation to exploit them.

Companies will never have secure systems till they realize that the United States can never compete with developing countries on price. Trying to by outsourcing and using commercial software have been short-sighted.

When they take back control of their computer systems -- the engine their entire business depends on -- they will once again be able to compete the only way a country with our standard of living can... with innovation.
  

Labels: , , , , ,

"Still don't think open source hurts commercial software? Guess again"


A Comment...

Open Source is becoming a radical challenge for premium software companies that depend on what are now exorbitant prices.

These companies have been built on the cornerstone of customer lock-in. Once deployed, their large, complex, expensive products are usually too unwieldy and too costy to replace except as part of a massive system architecture upgrade as we were forced to do for Y2K.

How can a company excel if it's not free to do things differently from its competition? The high cost of enhancements to one of these installations keep most somewhere near the basic package. This stifles innovation and competitiveness.

In short, these premium companies have priced themselves out of the market.

Open Source software, while free in initial price, does have costs that many a CIO has yet to appreciate. Though at least as reliable (usually more so) as its commercial counterparts, Open Source software is largely developed by and for programmers and thus requires a deeper level programming and system administration expertise to maintain. That usually means more, and more experienced, and thus more expensive staff.

Here are two simple rules of thumb in deciding between commercial and open source software...

ONE...
If you have more money than expertise, buy commercial.

If you have more expertise than money, use open source.

TWO...
If software in no way effects your competitiveness, buy commercial like everyone else.

If software can in any way effect your competitiveness, use open source for the freedom it gives you to innovate.

Labels: , , , , , ,

By Extension

December 18, 2011 by Robert C. Watson

Seeing What We Expect to See

I'm a Unix/Linux programmer. It capitalizes on my tendency to take what I see quite literally. By making few assumptions, I'm able to see the problem as the computer does.

By contrast, "normal human thinking" depends heavily on our imagination filling in many blanks. We have to make lots of assumptions. Those assumptions cause us to see what we've seen before... what we expect to see.

With almost all of my attention on Unix/Linux over the years, I've mostly just used Microsoft Windows and Office as tools and not followed their inner workings much. Long ago, I attempted to decipher the raw format of a Microsoft Word document (and failed to do so reliably). It left me with a mental image of Word documents consisting of intermixed binary values and text that only Microsoft understood.

A few years later, someone sent me a document in Microsoft Word 2007's new .docx format that I needed to convert to HTML for the web. I only had Office 2003 and was horrified by the mess Word made when exported "As a web page". So I proceeded to read the document into a text editor to see if I could just cut out the content and reformat it by hand. Knowing it was supposed to be XML, that's what I was expecting to see. What I saw instead was gibberish -- pure binary.

"Damn that Microsoft!"

Sliding back and forth through the sizable document and finding no blocks of text or other discernible patterns, I brought up Firefox and started many hours of Googling.

Now one thing I've learned over the years is that, for me at least, there's a very consistent inverse relationship between the intractability of a problem and the complexity of its solution. The longer it takes to solve it, the more simple the solution is likely to be. Assumptions and expectations lead me down an increasingly complex path of study, experimentation and failure as I exhaust "obvious" solutions. (Is "Occam's Razor" misunderstood?)

Lots of Googling have also taught me that simple, fundamental facts and concepts about a piece of software are often documented only once and thus rarely found in search results. Assumptions again.

The more intractable the problem, the more likely that the solution hinges on one of these obscure bits of information.

I finally came across somebody in a forum explaining the new format to a newbie (A Newbie! A Noob! How mortifying...) and discovered that in the world of Microsoft...

Though a .docx is named much like a .doc, looks like a .doc and is used like a doc... it's really a .zip!

Labels: , , , , ,

"HP dumps WebOS on open source world"

December 09, 2011 By Ted Samson | InfoWorld

A Comment...

I'm glad HP took my advice, though it was kind of a no-brainer.

I've read a number of positive things about webOS from developers working with it. Unlike in the market-driven world of commercial software, webOS only needs to do something - anything, especially well to be adopted in whole or in part by the purely innovation-driven Open Source community.

Since webOS is based on the Linux 2.6.24 kernel, I would expect future webOS development to probably lean towards being another Open Source alternative to Android on small devices. Maybe Google will adopt it if there's something in it they can use.

Commercial software has become so dominated by market forces to the exclusion of functionality, quality, reliability and value, that the industry seems to be coalescing into two camps -- Open Source, where most of the R&D innovation occurs; and Commercial, where they assemble those innovations into commercially viable packages and market them.

Businesses and individuals that want finished products and have more money than time or computing skill, buy commercial software and support. Businesses that need specialized mission-critical software that gives them a competitive edge over their competition or companies and individuals with more time and/or computing skill than money, choose Open Source for some or all of their operations.

Linux (and perhaps webOS) is the Lowes or Home Depot of software whereas Microsoft is the Ethan-Allen Home Furnishings.

How much you want to bet Ethan-Allen's manufacturers have long-standing accounts at Lowes and Home Depot?
  

Labels: , , , , , , , ,

"Watch out for FOSS advertising"

October 17, 2011 By Susan Perschke | Network World

A Comment...

Most FOSS (Free and Open Source Software) is D-I-Y (Do It Yourself) software.

It is written by programmers, for programmers.

Programmers, government agencies and competitive companies choose FOSS when they need innovation. They choose FOSS for the same reasons they send their staff to Lowes, Home Depot, Staples, and FedEx Office (formerly Kinko's)... to get things from which they can inexpensively fashion unique solutions that make them more efficient.

Why do it yourself?
Like the 1920's, the "roaring" 1990's overheated the economy as everyone clamored for the latest computer technology. While the cost to produce the technology itself dropped like a rock, insatiable demand for related services drove the human costs through the roof. The tech bubble inevitably burst.

The ubiquity of cheap computing power and laissez-faire economic policies had spawned financial instruments too complex for reliable risk analysis. So a few years later, the financial bubble burst as well, putting us in our current "Great Recession".

"The 1%" financial titans still have much more money than time so they continue to buy highly polished commercial software, layoff most of their tech staff, and pay companies like Microsoft, Oracle and SAP enormous amounts for licensing and support. What choice do they have? A major failure could put them out of business very quickly.

But "the 99%" of people, governments and companies, just as in The Great Depression, can no longer afford those high-priced finished products. With layoffs, virtually frozen wages, and less disposable income, Americans now have more time than money. Survival depends on finding new, more efficient and cost-effective ways of doing things.

Is FOSS Secure?
Any retailer with a glass storefront will tell you that police strongly recommend the glass be kept clear of obstructions and the store interior be kept lit after hours so anyone can see in. Transparency is the best deterrent to crime as well as the best way to spot crimes in progress.

That's the principle FOSS security is based on -- transparency.

If you were a careless or malicious programmer, which kind software would you prefer to put your dangerous code in? Closed, where few if any can find it, or Open where anyone can find it and you don't know who or how many will?

It's as simple as that.

The same reasoning combines with speed of development to account for the explosion in scripting languages where the source code couldn't be more accessible.

The explosion of freely available information makes the ubiquitous concept of "security by obscurity" a complete fantasy promoted to sell software.

Then how do you separate the wheat from the chaff?
FOSS is like an open bazaar or swap-meet with free or virtually free stalls. Anyone with programming skill can distribute their work.

In today's economy, the unemployed can learn how to program with countless free resources on the web. They then can create things others will want and distribute them to thousands. They build up a "portfolio" of work on their blogs and web pages. If they're good, they gain a reputation that gets them hired or allows them to build their own company selling software and/or services.

Here's how to find the best of the best...
  • The less you know about programming, the more discriminating you should be. Look for mature, widely used software like Firefox, Ubuntu Linux, and the LibreOffice suite.
  • Search the internet widely for reviews, comparisons, bug reports and questions on forums. The later will give you a feel for how widely used the software is as well as the kinds of bugs it has and how easy they are to fix or work around.
    • A NOTE OF CAUTION!
      Judge bugs by their quality, not their quantity!
      All software has bugs! Because expensive commercial software is not open, its bugs are not as widely documented as those in free and open source software. You'll find a lot more bug reports for FOSS. If you study them, you'll find many are duplicates as many websites republish bugs listed elsewhere. 
  • If you're not an experienced programmer and are worried about a program that does what you want but is new or not that widely used, find an experienced programmer friend, staffer or consultant who can read the language and get them to scan the code.
    • Is it well organized or is it confusing?
    • Are there suspicious looking sections?
  • Prefer software with the most downloads.
    • Quality ratings are not as reliable as number of downloads.
    • New software will usually have higher ratings due to its small number of downloads and reviewers.
    • A high number of downloads/day factors in to longevity.
      • New or obsolete software will tend to have lower counts.
  • If two programs have similar numbers of downloads and downloads/day, then check the ratings but don't put much stock in small differences. Look for low vs high.

Labels: , , , ,

Secure Boot News - Future Day 1

Microsoft Windows Secure Boot - Then and Now
by RobertC

The newest version of Microsoft Windows finally provides some long-sought enhancements to the Secure Boot feature launched with Windows 8 a few years ago. No longer do storage devices have to be removed and slaved to another computer in order to regain access after lightning strikes, "key hijacks" or boot image corruption. Users can now login from another registered device to their account at Microsoft, the computer manufacturer or any other entity they have keys registered with, and download a new key.

After a multi-step authentication process that includes an email-reply verification and optional phone callback, a user or System Administrator downloads new keys for one or more of the registered machines and copies it to a storage device, usually a memory card or flashdrive. The downside of having to physically be at the computer remains for large data centers, but life is better than it was. At the computer, Secure Boot looks for new keys on the first boot device during powerup. (Anybody remember floppy drives and serial dongles used like this? No? Never mind...) Since the Unified Extensible Firmware Interface (UEFI) software in conjunction with a Trusted Platform Module (TPM) allows multiple, equally valid keys to exist on a "keyring", the new key can just be added and full access restored.

Microsoft has given in after losing market share to Apple, Google, Ubuntu, RedHat, IBM and other Linux and Unix-like operating systems for several years. The "*nix" common underlying operating system architectures used by those companies made the anticompetitive approach of Windows Secure Boot a non-starter with all but Apple. However, even Apple saw the legal liability dangers of purposely locking companies out of their systems due to common events like upgrades, repairs or natural disasters. The companies and many open-source organizations hammered out procedures that greatly reduce vulnerabilities while giving people a reasonably secure way of getting back into their phones, computers and other devices.

Historical References

Labels: , , , , , ,

"HP transfers WebOS from the PC group: The game's afoot"

September 5, 2011 By Galen Gruman | InfoWorld

A Comment...

There is enough technical merit in WebOS and its Palm legacy that it's very unlikely to fall out out of use entirely unless HP kills it by holding on to it in a misguided effort to enhance the company's assets value.

That said, WebOS as a revenue source for HP is a non-starter.

There are only three ways to realize WebOS's value...
  • Used in an innovative new product -- as it was designed to do.
  • Sold for any patents it may have (sadly, reality vs. the future -- End Software Patents).
  • Release as open-source and gain hundreds of volunteer developers, documentors, project-managers and promoters. They will incorporate the best of WebOS into Android, Linux, and other open-source-friendly software, thus growing its market. This larger market will produce product opportunities HP can take advantage of before competitors because of its continuing active involvement in the open-source development.

Labels: , , , ,

"Linux Foundation chief: 'You are an idiot' if you don't give back to open source"

August 30, 2011 By Julie Bort, Network World, InfoWorld

A Comment...

Until Linux and the Open Source concept came along, software development followed the "industrialization" model of change typified by the classic "waterfall" development process (plan, specify, build part 1, build part 2,..., test, deploy). Despite no project ever successfully being completed that way, that's how they were approached.

The astronomical advances in microprocessing wrought by Kennedy's space program intersected with that reality late in the last century to make iterative development (plan, build, test, repeat till works, deploy, fix/update, redeploy, repeat ad infinitum) actually sound practical. Which was great given that all software development had always been done that way (though none could bring themselves to speak such anarchist blasphemy).

Linux however, like capitalism, is a human-created system based on an "evolutionary" model of change.

In nature, genetics and environment interact to produce near-infinite diversity, thus providing many "mutations" that are better suited to the new conditions.

So too in business. Though most businesses fail, things are learned by those failures which result in creating better new businesses.

The comparatively limited planning of Linux projects results in greater innovation and software better adapted to task. Development is driven by functional necessity, peer-review and reliability (cause programmers really hate repeated debugging) rather than rapid development.

Think cabinet-maker verses assembly-line shelving.

Canonical is trying to succeed by "industrial computing" rules in an "evolutionary computing" world. An almost impossible task (see Microsoft). And they don't have hardware sales to pay the bills while they try to monetize "free software" (see IBM).

The next IBM, Apple or Microsoft will be the company that figures out how to measure, and thus monetize, "value" in this new paradigm. Google is the most promising at the moment, but so far has only been able to make money (albeit: A lot!) selling tickets to the spectacle. IBM and Apple have seen the future but aren't entirely sure how to get there from here.

Microsoft -- Well, I doubt that the dinosaurs were even aware of the existence of those little burrowing mammals except when one went squish between their toes. We know how that turned out.

Labels: ,

Updating a GoDaddy Website with rsync

Though GoDaddy.com hosting supports commandline access via SSH including use of scp and sftp commands, it does not support rsync.

How do you update a website without rsync?

After much scripting trying to duplicate a small subset of rsync's functionality, I've recently discovered a way to rsync files to a GoDaddy.com website.

With ssh, scp and sftp, GoDaddy.com has all that's necessary on the receiving end to support SSHFS (Secure SHell File System) mounts.

SSHFS is built on the FUSE userspace filesystem and so, if installed on your system, should allow any user to mount devices with it. This lets us transfer files over a secure, encrypted link using rsync since rsync thinks it's doing a local copy from one directory to another. The cp command as well as all of the other Linux utlities are likewise at our disposal.

Here's how I used it on my system...
  1. I created a mountpoint directory
    mkdir /ABCwebsite
  2. Then added an entry to /etc/fstab
    sshfs#user@abcwebsite.com:/home/content/a/b/c/abcwebsite.com /ABCwebsite fuse defaults,_netdev 0 0
  3. Then mounted the remote GoDaddy.com filesystem
    mount /ABCwebsite
  4. Then rsync'ed the desired directory
    rsync -lDz0 /root-of-dir-tree-to-upload /ABCwebsite/dir-to-upload-to

The rsync switches used are...
  • l - Copy symlinks as links instead of copying the file linked to
  • D - Recreate devices
  • z - Zip(compress) files for transfer
  • O - (capital O) Omit setting timestamps
    This prevents the "failed to set times" error that occurs when the owner on the remote website does not have the same user number as the file owner on the local host the files are being sent from, which will always be the case when uploading to GoDaddy.com.


See Also

Labels: , ,

Clean and Disinfect Your Computer

Always on the lookout for better products to keep the pests at bay, I keep coming back to the reliable combo of CCleaner, AVG AntiVirus, and SysInternals RootKitRevealer.

CCleaner
If you're "not a computer person", make friends with (or hire!) someone who is and point them to this program. (They probably already use it.)
CCleaner is a freeware Microsoft Windows (98/NT4/ME/XP/Vista) registry and files cleaner. It's not automatic like AVG because, like another fine freeware product - HijackThis, not all of the suspicious registry entries and files it finds are necessarily superfluous or malicious. That said, I've found that by unchecking certain of its many categories, I can routinely let it delete everything it finds without corrupting the system and still getting rid of most of the bad stuff.
AVG AntiVirus (Free)
AVG AntiVirus is the core of my disinfecting suite.
AVG AntiVirus 8.0 is one of the many commercial products that began life free and still distributes a fully free version, albeit missing some functionality from its commercial brethren. Once setup through the very nice user interface, AVG automatically keeps itself updated and watches for malicious files coming down the pipe. This product pretty much "just works". They've done a better job than most at making it easy to use yet robust. A "poor stepchild" (version 7.5), though quite functional, Linux version is also available.

The commercial product adds anti-rootkit, website-screening and support for $34.99 with the full Internet Security product adding anti-spam and a firewall to that for $54.99. Not a bad deal. See the feature comparison for details. See Wikipedia article, AVG Technologies, for info on the company which was formerly known as Grisoft and AVG (software) for more about the products.
SysInternals RootKitRevealer
Like having a good set of mechanical tools, the SysInternals utilities have never let me down.
I picked up the TBSS rootkit a while back on a machine running just AVG Free (no anti-rootkit) so I got to scan the field of (free) rootkit detectors and found this one to be reliable and robust with excellent rootkit detection and a simple, solid user interface. Microsoft now owns the rather extensive array of free SysInternals utilities which can be downloaded individually or all together in the entire SysInternals Suite. Highly recommended.

Labels: , ,

Linux & Windows Synergy

Synergy eliminates the need for a KVM (Keyboard, Video, Mouse) switch when you want to use one keyboard and mouse across multiple computers. The one difference is that video is still routed to each computer's own monitor. Perfect for anyone who wants all the screen real estate they can get!

Contrary to my usual highly critical assessment of most software written today, I'm happy to say that Synergy works as advertised and classifies at the top of my quality ratings as "Way Cool".

Excerpt from Synergy documentation...
Synergy lets you easily share a single mouse and keyboard between multiple computers with different operating systems, each with its own display, without special hardware. It's intended for users with multiple computers on their desk since each system uses its own monitor(s). Redirecting the mouse and keyboard is as simple as moving the mouse off the edge of your screen. Synergy also merges the clipboards of all the systems into one, allowing cut-and-paste between systems. Furthermore, it synchronizes screen savers so they all start and stop together and, if screen locking is enabled, only one screen requires a password to unlock them all. Learn more about how it works.

Synergy installs like any other software on Windows and needed only simple configuration through the GUI to work between two Windows XP machines. Installation through the built-in Synaptic Package Manager on Xubuntu 6.06 ("Dapper Drake") and 7.10 ("Gutsy Gibbon") was a breeze though it required some config file editing. I'm upgrading a machine from Xubuntu 7.10 to 8.04 ("Hardy Heron") now so those experiences are forthcoming. Don't anticipate any problems. A separate GUI setup utility is available called QuickSynergy that simplifies things a lot.

First Linux install was a couple of years ago on SuSE Linux 9.0 (pre Novell takeover) with SuSE's YaST installer, which made the actual install as easy as on Windows. Getting it configured to work both before and after login took some fiddling though. Contrary to the online documentation, the 3 lines needed to start the synergy client (i.e. kill it if it's running, sleep 1, then start it) only have to be invoked in /etc/X11/xdm/Xsetup (which enables Synergy for the linux login screen) and /etc/X11/xinit/.xinitrc (which enables Synergy after login for all KDE user sessions).

Synergy installs under Xubuntu are much like the SuSE install. Client configuration (have not configured server on linux since am using Windows laptop as server) requires modifications to:
  • /etc/X11/Xsession:
    Add startup call just before the "# use run-parts..." line.
  • /etc/gdm/Init/Default:
    Add startup call right after the function definitions.
  • /etc/X11/gdm/PreSession/Default:
    Add startup call right after the function definitions.
  • /etc/X11/gdm/Xsession:
    Add startup call just before the "# use run-parts..." line.

    Synergy is open source and released under the GNU Public License (GPL).

    Highly Recommended!

Labels: ,