Site Search

Google
 

Monday, 31 March 2008

OS security.

Here we have yet another meaningless report on operating system security.

Mac OSX was first to fall, then MS Vista leaving Ubuntu as last man standing. The whole thing was so ludicrous as to be utterly meaningless. From my own point of view it was good to see Ubuntu come out on top as the one the hackers, in the new meaning of the word, found uncrackable. But, in the real world on real installations I wonder just how much worth should be given to the whole shebang.

According to the report, Mac OSX web browser Safari was the first to fall then MS Vista fell via a third party program namely Adobe Flash. But as Adobe Flash is ubiquitous across all platforms surely it follows that Ubuntu would suffer the same exploit whicc in turn means Ubuntu fell at the same hurdle MS Vista fell. Perhaps not though <shrug>.

I take issue with the fact they always use Ubuntu and then claim Linux. Ubuntu is not Linux, it is but another distribution in a large pool of distributions. Some more secure than others at the core. Forget the fact for now that Linux is the kernel, nothing more, nothing less and it is what is added around the kernel, programs etc, that makes up the distribution which in this case is called Ubuntu. Ubuntu is one of those horrible distributions that adds all sorts of extra layers of code in the name of making things easier for the user. These extras make it more insecure.

MS Vista, in a default install, is secure. Yes, you heard that correctly. As much as I despise that operating system the truth is it is secure in its defualt state. It is when adding third party applications things start falling apart. One cannot blame Microsoft for what others do to their operating system. Indeed, in the report indicated above it was a third party application, Adobe Flash, that lead to MS Vista being declared second best secure operating system.

Mac OSX is an odd beast. It is a closed operating system which is based on a freely available operating system but is itself proprietary. However, applications created by others and compiled source code can be added to the mix. The fact it was Safari, a closed source application written and created by Apple employees is cause for alarm for users of this operating system.

Overall though, the article above was poorly done in my honest opinion. Not least because of how it was done but also the fact that by declaring one more secure than another in the way they did and how they arrived as that declaration leaves a lot to be desired.

So as someone who installs these operating systems for users and companies will I personally give much credence to this article? In short. No.

Sunday, 30 March 2008

The ISPA need to act now.

The ISPA need to act now before ISP's in the U.K. follow Karoo's lead and hijack DNS requests.

I am a strong advocate of net neutrality which dictates that all Internet traffic should be unfettered. It is bad enough ISP's use traffic management techniques to slow the Internet experience down for customers but this deep level of DNS hijacking is dangerous for all users of the Internet.

What Karoo are doing breaks the Internet insomuch as what users of their services get to see on a mistyped URL in their web browser is not what the user should see. When a user mistypes a URL in such a way as there are no other DNS matches they should be presented with a 404 error page with designed by a web master or a blanket 404 page telling the user that what they typed was not found. By hijacking the DNS request at such a deep level users of Karoo's DNS do not see the 404 page instead they are redirected to a search engine. A poor search engne at that but a search engine nonetheless.

Karoo, of course, get what is called a payback for doing this. This means that once redirected to the search engine, if a user uses said search engine then clicks on one of that search engines commercial links Karoo get a payment. Hence the name payback.

When the seller of .com and .net domain-names Verisign tried to do exactly the same thing back in 2004 the ISPA called it a "scandal" and accused the firm of "presumption that they own the Internet". Quite how they can say such a thing then let a U.K. based ISP get away with doing exactly the same thing only those within the ISPA know.

This sort of DNS hijacking sets a dangerous precedent not only for Karoo customers but also for customers of other ISP's because once it becomes known that on ISP has got away with doing such then you can bet your last penny other ISP's will follow suit. Further, once Karoo realise that even though their customers have voiced concern about it (that is just one such place, concerned voices about this practise can be found elsewhere too) and even though Karoo offer an 'opt-out' alternative once they are sure that they will get away with it, even though they surely know it breaks other aspects of the Internet too, it is only a matter of time before they unleash something bigger, and therefore worse for their customers, like 'phorm' onto an unsuspecting customer-base.

phorm is a company that provides hardware to ISP's, again hijacking the data stream, so that user targeted marketing advertisements can be overlayed on the customers browser no matter what that customer may be doing at the time that the injected hardware spits out it "thoughts" on what the customer may want to see at that time. In all my years of pre and current Internet traveling I have never heard of anything more scary being introduced from a user point of view. ISP's will also get a payback from this too. The backlash again 'phorm' has already begun as you can read on the link provided.

Anything that injects itself at any level of the Internet data stream between the customers computer and the other end of where that customer wanted to be is just plain wrong and breaks the TCP/IP prrotocols on several levels. The sooner the ISPA acts and stops such things the better the Internet will be for all connected to it.

If you are unfortunate enough to have to use Karoo as your ISP and you would prefer, as I do, that the money Karoo gets from this level of DNS hijacking goes instead to a not-for-profit organisation who offer alternative name servers (DNS) that work just as well if not better, than those offered by Karoo then consider using OpenDNS instead. At least by using OpenDNS you will know you are helping to keep a not-for-profit organisation afloat rather than allowing money to go to a greedy grubbing ISP like Karoo.

Saturday, 29 March 2008

A U.S.A. ISP in the U.K.

Sounds straight forward does it not? But, even though this sounds probable there are other things to consider like the huge differences in the U.K. data protection compared to the U.S.A. where privacy for private individuals has historically been weak but in more recent times in increasingly becoming weaker.

Why should we care if companies use U.S.A. type privacy laws against U.K. people? We should care on several levels because if we do not we may find our privacy laws being diluted. This was never more true for ISP's.

My own ISP, Karoo, routinely filter Internet traffic. P2P and Usenet are the two most heavily filtered. Not filtered to stop such Internet traffic but filtered to slow said traffic down. They have claimed they only do this at peek times, defined by them as 6pm until 12pm. This just happens to be the time of day when most users are likely to be on-line, but it was proven that they slow this type of traffic 24/7. It is also proven that they filter other traffic 24/7 as well. The company has often denied this but as I said it has been proven that they do.

Why is Internet traffic so important in the continual fight to keep private data private? The very fact they are touching the data stream at all is important in the fight for 'net neutrality'. Once they know they can get away with this level of interference who knows where it will end. They took another step in fiddling with user generated data streams by filtering DNS requests so that when a user mistypes a URL instead of getting the proper '404 URL not found' error pages they instead get forced to see a search engine web page. This is fundamental breakage of how the DNS works. It should be noted that the ISP gets a monetary return should any user be foolish enough to use the search engine. The 'service', such as it is, is an automatic opt-in service. This means that every user using this ISP is automatically subjected to this breaking of the DNS. There is also an opt-out clause as well but it is so poorly written that your average user would not know where to start. There are two ways around this illegal tampering of DNS requests which you can find at the end of this post.

So, we have an ISP that routinely monitors and alters Internet data streams and is showing that they are willing to be evermore brave in how they show their users they are doing it. They do other things behind the scenes that affect Internet data streams that the user will never see therefore never know about. It would seem a natural progression given that they obviously have no concern whatsoever about users data streams that eventually they will progress to Deep Packet Inspection (DPI) and use targeted advertisements as a revenue stream.

This level of tampering with users Internet data streams is unprecedented in the U.K. but is widely used in the U.S.A. which is where a U.S.A. ISP in the U.K. comes in which is the subject of this post.

Once the European Union (EU) declares that a users IP, given when a user connects to the ISP, is private property it will be much easier to fight against this level of tampering by an ISP and I, for on, will be fighting tooth and nail to stop such tampering. The fact they are doing it at all shows how arrogant this ISP is and we all know what happens once that arrogance goes too far. And it will.

Friday, 28 March 2008

Let children play in the mud.

It never hurt us 40somethings when young and it sure as Hell won't hurt todays siblings either.

Yes, I mean it literally. The majority of todays children are cocooned from danger, dirt and hurt.

This was never more clearly driven home to me as I watched my 10 and 9 year old boys playing with their friends of similar ages in our back garden. Our back garden is at this time all mud and little grass. This is due to recent rainfall levels, a bout of snow and the fact that since we moved in here we have not yet had enough dry days to do the work on it we have planned. That said, we still allow our children to play in it just as my wife, who is 9 years younger than I, and I had done at their ages years before. Notice I said 'in it' rather than 'on it'? I shall explain why later. Present in this little play group was our two boys, five other boys and 4 girls all of similar ages and all went to the same school. All of their parents had been informed prior that we intended to let the children do as they wanted within the confines of the 5ft garden gate. They would of course be supervised. This supervision was done by my wife, 2 of the children's parents and 3 of my mates plus myself. The adults had access to beer and BBQ food which is I reckon why they agreed to monitor the children's activities. Anyway, none got drunk.

As there is nothing but mud and a little grass in our back garden I laid plans of what I had hoped the childern would enjoy playing both with and on a few days prior. Two of my friends had erected an ad-hoc wooden frame that I had designed for the children to play on. Also there was a largish paddling pool and the children had access to a water hose. Dotted about were footballs and other such equipment. On the stone patio type area we put a long table where sandwiches, drinks and such like would be laid on for the children. This was partitioned off from the play area by means of some plasterboard which was not a permanent structure but served the purpose we intended it for and that was as a means to keeping the food area away from the more messy play area.

You now, hopefully, have a mental image of the scene.

As I had asked each parent of 1 or more children present on the day to provide their child with an alternative set of clothing they in turn asked what had I got planned for their child and my own. I told them exactly what I had planned. A day playing in the mud with side events such as the paddling pool and climbing frame thrown in and some food for late afternoon. Some looked puzzled, others looked concerned, yet more seemed vaugely perplexed. None objected. So, the afternoon arrived and each child had brought with them some alternative clothing. We directed each child separately to a bedroom where they could put their alternative clothing for later.

Now we had a gaggle of children all stood in our living room. I simply said "Go play. Get muddy. Do whatever you want to do within the confines of the garden and most importantly of all enjoy yourselves." And Off they went out into the mud. There we a total of 11 children. Of those 11, 8 ventured onto the mud while the other 3 stood at the plasterboard surrounded entrance.

Some played in and out of the paddling pool. The climbing frame we had made was a huge success. While the 8 were playing I asked the 3 stood watching why they were not joining in. They replied "My mother has always said that playing in mud is dirty and lead to all sorts of diseases." I stood back and thought a minute then said "What if I told you that when your mother was younger she was the worsed kind of tomboy and always played in the mud and always went home with her clothes dirty as she always played with the boys who always got dirty." They looked at me with that look that only a disbelieving child can give. I rang their mother who promptly came and said to her children, 1 boy, 1 girl, that it was okay to play in this mud and to go and enjoy themselves. They immediately joined their friends who by now where covered in mud from head to toe and also very wet from someone pointing the hose at them.

After about 2 hours of continuous play it was time to call them all in for eats. But, before they could eat they must be cleaned up and have their alternative clothes on. Now we had a problem. We could not each child one by one trudged upstairs to the bathroom so what could we do? We adults got our heads together and eventually one came up with a solution. We made sure the water from the hose was warm then we lined the children up and dosed them with water while they stood there and turned on the spot. The kids absolutely loved it. Shortly, all the mud was off the kids and one by one they moved from the now heavily water and mud area to another area close by where they where blown with warm air from a huge fan one of the adults has got from his garage then from there up the stairs to change clothes. After around 40 minutes all the kids where changed ready to attack the food table already prepared. Whilst eating the chattered constantly about what they had done during the afternoon.

The end of the afternoon had arrived and each child's parent came to collect them. As they waved an excited goodbye to their friends they all, without exception, looked at me and thanked me for a "brill day". Each parent, especially those who gave their time to supervise, all said how much the children had so obviously enjoyed themselves.

Who would have thought it. Todays children in todays world of "Don't do that" actually doing something all children should be allowed to do and better yet all of them enjoying themselves whilst playing in watery mud. No child has developed any mysterious diseases since that afternoon.

I put my two fingers up at those politically correct fools.

The Karoo Technical Forum.

This post only really holds any interest for people from my home city. It may hold reading power for others who see big business as something remote and beyond them.

What is it. Why is exists and what it does. For the benefit of everyone, be they a home user or a business user if you use Karoo, and possibly their other ISP ventures in the U.K. as well, as your ISP The Karoo Technical Forum will have had some say in the services you receive.

I, along with someone else who shall remain nameless, are part of a group which has been dubbed The Karoo Technical Forum. The group members consists of He who shall remain nameless (short: HWSRN), the Head of IT Infrastructure (who shall be called Mike, which is not his real name) and myself. At the first meeting the Managing Director of KCom was also present. Behind us we have broad section of 100+ users who HWSRN and I take our taking pointers from. Although, it must be sai, that sometimes it feels like we to are stuck between a rock and a hard place usually this cross section of Karoo users allows us to get a cross city view of how they, Karoo, are performing and we take the wheat from the chaff as the basis for our meeting's agenda.

This all started with emails being sent to Karoo. At the request of the M.D. a meeting was suggested. HWSRN wanted me present but for whatever reasons the M.D. did not want me there. After a little to and froing and after HWSRN learned that the M.D. was to have someone beside him the M.D. capitulated on the idea of HWSRN having someone else there too. It was decided that this first meeting between the M.D. of KCom, Mike, HWSRN and myself would take place at Telephone House the home of KCom. And so it was.

The first meeting was mainly us two against them to. Us being HWSRN and myself and them being the Head of IT Infrastructre and and the MD. That first meeting set about sorting out what we should be aiming for. Quite why they allowed us a platform at all is only known to them. But they did and we aired the grievances that several customers of Karoo, a subsidiary of KCom, had told us about plus a few of our own for good measure. It was at that first meeting that the moniker The Karoo Technical Forum was coined, and it stuck as that is what we are now known as. The talk was wide ranging. From the help-desk to Customer Service and from connection speeds to technical matters. Overall, this first meeting went very well. We came away with the feeling of mission accomplished.

Shortly after this first meeting an email arrived explaining how they also felt the meeting had been a success and off the back of this a second tele-meet would be organised and so it was. Feeling somewhat puzzled, but confident, and armed with more grievances from the wider customer-base HWSRN and I entered into the unknown. The call was placed and a 3 way conversation ensued. The 3 present where Mike, HWSRN and myself. We were informed that several things we had talked about at the first meeting had been actioned and where in the process of being done. Of course, we were warned, that these things take time. We knew this but Mike felt the need to say it, several times. Again, after the tele-meet ended HWSRN and I felt things had gone well. At least, we felt, they had been listening and where in the process of changing in several areas. We took information we had learned back to the masses and while some recieved what we told them with acceptance others where aggressive towards both the information relayed to them and us two. Some also had issues that whatever was not sorted out right now rather than in 6 months time. Explaining that Karoo is like a behive and that each section plays a part and that several meetings must be undertaken before anything is resolved within made no difference.

Still, HWSRN and I plodded on into a third meeting.

The third meeting, again a tele-meet, was organised. Then rearranged due to Mike (I later learned these where personal issues). Then rearranged again, due to Mike. By the time the meeting was set in stone HWSRN had personal problems that meant he could not attend. So, it was decided at the behest of HWSRN that Mike and I should hold the tele-meet and that I should inform HWSRN via other means after the meeting had taken place. And so it was to be. That meeting was full of off the cuff and keep under your hat talk that Mike requested no-one else, except for HWSRN, should know about except perhaps in the most vaguest of ways. Lots of discussion about technical issues (as an aside here I think Mike was both surprised and delighted at how much I knew about the ISP procedures and how the whole thing is driven) as well as some further get to know you type talk. I also learned that a lot of what was previously discussed had been implemented and on the back of what HWSRN and I had told them we the users wanted that a major change of offerings by the ISP was on its way. Mike could not, or would not, go into detail about these offerings other then to say that there will be major changes. Further I was told that the fundemental way they shape traffic was seriously flawed and that that too was going to be changed. What they have planned to change it with, only a fool would think traffic shaping would go away, Mike would not say. All he did say about it was that the current method will be gone when the new offerings come to market.

So, now you know about the meetings and some of what was said. There are some questions that are being asked and some we two have ourselves.

Why is a large international company, as KCom are, talking to two of their home based customers? That is something only they can answer, but my guess, as part of this, is that they want to be seen to be doing something. There is a large discontended base of customers in their own back yard and they must be seen to listening to them so they created this Karoo Technical Forum which I reckon they had planned long before we two got involved. We two just happened to be the two who where in the right place at the right time.

Are they really listening to us? Again only they can answer that question, but my gut feeling is that yes they are taking on board some of what we are telling them and they are, or have, acted upon that information. But again, I have this gut feeling that a lot of the changes coming where decided on long before we two got involved and of those changes only a very small part was due to what we told them their home customers want.

Why then, if you apparantly do not believe them, are you doing this? The answer to that is that for many years, long before they started offering Internet services, I have tried to better the services they offer by various means. I have been the proverbial thorn in their side for years. Once they started offering ISP services there too I tried to seek out ways that I could get to them in my continuing efforts to get them to improve there service offerings. As they have an effective monopoly in this city of all telephony provisions and because of that they have no competition from other ISP's and because of that they are lazy when it comes to what they offer. Their ADSL services for the home and business sectors are a joke in that there are basically no additional benefits between the various offerings at this time. We, that is HWRSN and I, told them this and was told in return that they would "look into it". The result of that is that they are changing their offerings structure so that "there is more to separate them." Only time will tell how that reflects in actual offerings.

Basically, I became involved at the behest of HWSRN and being the type of guy that goes with the flow more than one who bucks any trend I went along for the ride. Has it been worth the effort? Yes, I feel it has been. How this Karoo Technical Forum pans out in the future we shall have to wait and see but for now, at a technical level, it has been interesting and while I would like to think we have affected change I have this nagging feeling that these changes that are coming where planned a long time before this started. Sure, some of the changes I have no doubt we did change but overall I have this gut feeling the major changes were planned before we came along.

I still have some reservations about why they are making it look like we have some involvement in shaping how they operate and what their service offerings will be. But Kudos should be given to them for grabbing an opportunity and trying to run with it. Even if this initiative tails off like so many others have before it it will I feel, have been worth it, if only so KCom, and its M.D. inparticular, can see I am not the ogre and troublemaker they painted me internally. They are talking to two guys now who have years of networking and telephony behind them and these two guys want improvements for everyone.

So, there we have it. The Karoo Techical Forum. What it is. Why it is with us. What we do and why we are doing it.

Open soucery.

Open source has become synonymous with free software which itself has become synonymous with the Linux operating system or more correctly, an operating system distribution based around the Linux kernel and GNU software. Phew, quite a mouthful eh? That mouthful can be said thusly GNU/Linux operating system. However, the whole modern idea behind open source software goes much deeper than this. In fact, it is my opinion that this commercialised way of looking at it is damaging to the whole ethos behind it. Let me try to explain my reasonings.

Many Microsoft Windows home based users do not even know there are free software alternatives for 99.9% of the programs they use. I mean freely available alternatives on their current Microsoft based platform not an alternative operating system though alternative operating systems do exist and do have software within them to match the proprietary ones they currently use. Just like the home market do not know likewise it is for businesses. Many home based computer users and businesses know they exist but are tied into expensive contractual agreements forbidding them to seek out and implement alternative solutions and many simply use the operating system that comes pre-bundled with the machine for no other reason than it gets the job done. There is nothing wrong with that. Many of the pre-built computers bought in to the home come pre-installed with a none free operating system and often come with many none free software choices. The none technical home user is none the wiser about free software alternatives being available such as those collections from theOpenDisc and others.

And so it goes. Upon this bundling of software on pre-built machines a foundation was built around vendor lock-in.

Then there those, like me, who with 30+ years in the computer industry under his belt has only ever paid and used on a personal level only 2 propriety operating systems in that time and has, and still does, pay for a GNU/Linux operating system that is otherwise freely available. Why do I pay for something I can get for free? Well, it comes down to ethics and my ethics dictate that as someone created the operating system I use he/she deserves some recompense for his time and expertise. Of those 2 proprietery ones, 1 was a UNIX operating system bought in the days before freely available clones came to market and the other was AmigaOS that came bundled with the Amiga range of computers.

Nowadays I use a Linux based distribution and many freely available open source softwares, some of which accept donations which if they do and the program is used often enough, I duly pay into.

So, what is the difference between freely available software an open source software and why is it so important that the distinction is made and kept alive?

A guy called Richard Stallman, he of GNU software fame, says it better than I can here. Even though I advise you to read it all the first paragraph says it all. He says "When we call software “free,” we mean that it respects
the users' essential freedoms: the freedom to run it, to study and change it, and to redistribute copies with or without changes. This is a matter of freedom, not price, so think of “free speech,” not “free beer.”

For me, the GNU term is the correct ethically pleasing term. How you view open source software versus free software could be important to the future definition and acceptance of the term so it is vitally important to GNU softwares authors that you understand the differences being banded about by marketting teams. I hope in this short piece to have helped you in that goal.

Tuesday, 25 March 2008

Bad bad bad.

My ISP, the hapless Karoo a subsidiary of KCom, has decided to redirect mistyped URL's to a search pgae at Ask.com. By forcing their user-base to automatically opt-in to a search engine they are obviously watching peoples connections. Any mistyped URL will not show the proper 404 page not found page but will instead show the Ask.com search engine. This breaks several rules on several levels.

If I wanted to go to a search engine I would type that search engine URL in the browser URL bar. I do not want to be forced to do this just because I typed something wrong. We use a router here and the first time this forced redirection hapoened to my son he asked me what the hell was going on. Because he uses MS Windows he thought he had got a virus. I am sure many other users of Karoo experienced something along the same lines. They do have an opt-out option which they have everso helpfully shown how to do but only for the crap routers they support.

This hi-jacking of people Internet connections is quite simply wrong. It IS hijacking of peoples connections. Nothing more, nothing less and because it is hijacking of peoples connections it should be declared illegal to do. There used to be an RFC that declared intransit Internet traffic should not be hijacked. It seems these days as if ISP's quite simply have no regard for their customer base whatsoever.

They, Karoo, obviously get a payback for this as I can see no other reason for them doing it.

I now use opendns for my dns requests so this level of underhandedness will not catch me any more. i know opendns do something similar but at least it is MY chose to use them. No-one has forced me to use the facilities OpenDNS offer unlike my ISP. Karoo a subsiduary of KCom who have foistered this on their customers.

The fight begins to regain control of our in-transit Internet traffic.