Showing posts with label Linux. Show all posts
Showing posts with label Linux. Show all posts

Thursday, March 6, 2014

Is Linux SSL/TLS Flaw an NSA Backdoor?

A code audit conducted by Red Hat in February uncovered a critical bug in the SSL/TLS security implementation in Linux (Secure Socket Layer/Transport Layer Security). This followed a similar bug found in Apple products last month.

The flaw allows an attacker to gain access the SSL/TLS stack which encrypts data being transferred between two points on a network (like the Internet) through a fraudulent security certificate. SSL is used for everything from securing your banking transactions to protecting your email and chats.

The bug effects not only Red Hat but most every Linux distribution and has been in place for a decade or more. The amount of software which uses this protocol and may have to be updated could be staggering.

TLS is an updated form of SSL and uses a protocol developed by the IETF (Internet Engineering Task Force), which was developed in 1999 and updated in 2008 and 2011. (Interestingly, a Snowden leaked documents from 2012 show the NSA had recently added Apple users to it's list of compromised systems.)

Chrome and Firefox users are safe from this bug as they use OpenSSL, which is not affected by this vulnerability.

How could such a gaping hole go so long without being discovered in Open Source software? Don't 'many eyes make all bugs shallow?'

According this article in PCWorld, to David Walser, a security manager for Mageia Linux, explained,
“The code is extremely complicated. Even though the code is freely available for review, only a select group of people would be qualified to accurately analyze and understand the whole system well enough to catch such a subtle bug. It’s also not the type of vulnerability that can be found by automated analysis tools, requiring manual scrutiny instead."
In September of 2013, Linus Torvalds caused a stir in the Linux community when he indicated, through a nod of the head, that the NSA had requested a back door into Linux systems.

Following news of the hint, Linus is reported to have said he was joking. Was this retraction due to the Linux community not getting the joke or was it due to legal advice? Linus is not known for his sense of humor. Rather, he is known for being honestly blunt, sometimes a bit too blunt.

The question has hung in the air ever since: Is there a backdoor in Linux?  And is this SSL/TLS vulnerablity an NSA backdoor?

The FBI has been obsessed with breaking encryption for more than a decade. Leaked documents by Edward Snowden have shown the NSA went to great lengths to access encrypted data. From pressuring companies to install government accessible back doors or provide encryption keys or stealing keys from those who did not cooperate. According to the NY Times:
"The N.S.A. hacked into target computers to snare messages before they were encrypted. In some cases, companies say they were coerced by the government into handing over their master encryption keys or building in a back door. And the agency used its influence as the world’s most experienced code maker to covertly introduce weaknesses into the encryption standards followed by hardware and software developers around the world."
There was also a purported back-door in the OpenBSD operating system, which was disclosed on a mailing list in December of 2010. The writer stated that his non-disclosure agreement had recently expired and he wanted everyone to know that security holes had been intentionally placed in the system:
"My NDA with the FBI has recently expired, and I wanted to make you aware of the fact that the FBI implemented a number of backdoors and side channel key leaking mechanisms into the OCF, for the express purpose of monitoring the site to site VPN encryption system implemented by EOUSA, the parent organization to the FBI."
No known back door was found in FreeBSD when this was reported. But the time frame and data targeted fits with the decade old flaw recently disclosed in Linux systems.

We don't know if this huge security flaw was intentionally placed in Linux systems or it was a coding error. No one can say how it got there. But no one can dispute that it has existed unnoticed for a very long time.

A patch for the bug has been rolled out and is available for most Linux distributions. Update your system now.

Thank you to Red Hat for finding and disclosing this bug. This shows without a doubt that open code does not guarantee security. And automated tools for finding flaws is no substitute for trained eyes.

The days of "Many eyes make all bugs shallow" may be true for actual bugs, but what of intentional vulnerabilities which have been carefully obfuscated or a small but profound mistake in millions of lines of code? Perhaps the adage needs to be changed to reflect the level of complexity in today's code: "Qualified eyes make all bugs shallow."

freedigitalphotos.net/twobee

Sunday, September 22, 2013

Can Linux Be Trusted? Linus Confirms NSA Backdoor Request

NSA Headquarters (from Wikipedia)
At the keynote speech at LinuxCon, Linus Torvalds, creator and lead developer of the Linux kernel, was asked if the National Security Agency (NSA) had asked him to insert a backdoor into the popular open source operating system. Linus responded by nodding yes while saying the word, "no," implying that he had been asked to do so, but was not able to discuss it.

This has caused quite a stir in the Linux community, who has always considered the 'open' nature of the source, that is, anyone can view the code, would make it impossible to hide such a deliberate security hole. But how many actually have looked at the kernel code and how many could identify such a backdoor in the millions of lines, especially if care were taken to obfuscate the process?

This commenter spoke for millions of Linux users when replying to this article on the subject from e-week:

"What they should have asked is: Did you, in fact put a backdoor in the Linux Kernel?"

And there was this:

"All further development on the kernel, modules, etc... should be halted until a thorough audit has taken place by those skilled enough to do so. Linux is no longer trustworthy"

Sound paranoid? Perhaps not so much. Lets look at some facts we know to be true.

NSA Thwarts Encryption Through Influencing Standards, Hacking, Inserting Backdoors:
Recently leaked documents from Edward Snowden show a concerted effort by federal agencies to access encrypted data, either through pressuring companies to install backdoors and provide encryption keys, stealing keys from company servers or hacking the computers of end users. According to this article from the NY Times:
"The N.S.A. hacked into target computers to snare messages before they were encrypted. In some cases, companies say they were coerced by the government into handing over their master encryption keys or building in a back door. And the agency used its influence as the world’s most experienced code maker to covertly introduce weaknesses into the encryption standards followed by hardware and software developers around the world."
A leaked NSA memo from 2006 showed that the NSA managed to not only influence encryption standards, but was able to become the creator and sole editor and pressure international standards groups to ratify it. A year later, a 'fatal' security hole was discovered in the new encryption standard. It appears the security hole was actually a purposeful creation of the NSA.

NSA Scoops Up Google, Facebook, Apple, User Data 
The Guardian reports the NSA has gained direct access to servers used by Internet tech giants to collect user data. The companies either dispute this is true or maintain they have no knowledge of such access. Google responded with this statement:
"Google cares deeply about the security of our users' data. We disclose user data to government in accordance with the law, and we review all such requests carefully. From time to time, people allege that we have created a government 'back door' into our systems, but Google does not have a back door for the government to access private user data."
Their cooperation with of thousands of FISA Court subpoenas has been widely reported and several companies, eager to reassure nervous customers, have filed a law suit requesting permission to disclose to users what data they have disclosed to the Fed. (See Google, Microsoft, Facebook Sue for More NSA Transparancy, 08/31/2013)

Windows 8 'Trusted Computing' Not So Trustworthy:
Ziet.de is reporting that German government IT officials contend the new 'trusted computing' built into Windows 8, which is supposed to protect against trojans and viruses can be used as a snooping device for the NSA. German government officials suggest staying with Windows 7 for the time being. According to this Business Insider article:
"Experts at the BSI, the Ministry of Economic Affairs, and the Federal Administration warned unequivocally against using computers with Windows 8 and TPM 2.0. One of the documents from early 2012 lamented, “Due to the loss of full sovereignty over the information technology, the security objectives of ‘confidentiality’ and ‘integrity’ can no longer be guaranteed.”
Microsoft Opens Outlook, Hotmail, Skype and SkyDrive to NSA Snooping: 
According to this article in The Guardian, Microsoft has worked closely with NSA and made changes to popular e-mail and video phone programs to make it easier for NSA to obtain full access to user emails and voice communications. According to the article:
• The agency already had pre-encryption stage access to email on Outlook.com, including Hotmail;
• The company worked with the FBI this year to allow the NSA easier access via Prism to its cloud storage service SkyDrive, which now has more than 250 million users worldwide;
• Microsoft also worked with the FBI's Data Intercept Unit to "understand" potential issues with a feature in Outlook.com that allows users to create email aliases;
• In July last year, nine months after Microsoft bought Skype, the NSA boasted that a new capability had tripled the amount of Skype video calls being collected through Prism;
• Material collected through Prism is routinely shared with the FBI and CIA, with one NSA document describing the program as a "team sport".
NSA Collects Millions of Internet and Cell Phone Records
In this report from The Guardian shows Verizon is collecting millions of customer phone record 'metadata' by order of a secret FISA court.  Normally, the national security court requests information on specific customers but this order is significant due to its sweeping nature. According to The Guardian's report:
The order, a copy of which has been obtained by the Guardian, requires Verizon on an "ongoing, daily basis" to give the NSA information on all telephone calls in its systems, both within the US and between the US and other countries.
Lest customers of other cell phone and Internet companies feel safe, you can probably assume your company is also under some type of similar order. It was only a few years ago when it was disclosed that AT&T had a secret switching room devoted to collecting all internet and phone traffic coming through it's hub in San Francisco then sending the data on to the NSA. According to the Electronic Frontier Foundation (EFF):
"The undisputed documents show that AT&T installed a fiberoptic splitter at its facility at 611 Folsom Street in San Francisco that makes copies of all emails web browsing and other Internet traffic to and from AT&T customers and provides those copies to the NSA. This copying includes both domestic and international Internet activities of AT&T customers. As one expert observed, “this isn’t a wiretap, it’s a country-tap.” Secret government documents,  published by the media in 2013, confirm the NSA obtains full copies of everything that is carried along major domestic fiber optic cable networks."
FBI Consultant Claims Backdoors in Open BSD Operating System
In December 2010, man who had worked on funding the Crypto Framework in the Open BSD Operating System claimed the FBI had inserted several backdoors into the Open BSD code a decade before. He said he could not disclose the information before that time because he had to comply with a ten year Non-Disclosure Agreement (NDA). 

In an email to Theo, de Raadt, Gregory Perry, who says he was an FBI consultant working on cryptography for NETSEC, writes:
"My NDA with the FBI has recently expired, and I wanted to make you aware of the fact that the FBI implemented a number of backdoors and side channel key leaking mechanisms into the OCF, for the express purpose of monitoring the site to site VPN encryption system implemented by EOUSA, the parent organization to the FBI."
To my knowledge, no backdoor was found in Open BSD when this was disclosed ten years later. Whether it existed at one time and was quietly removed or if Mr. Perry is being untruthful is left to the reader to decide. In light of the governments obsession with breaking or bypassing encryption (see above) it certainly seems plausible.

What about Linux? 
At this point, we don't know. Linus isn't allowed to tell and hopefully he won't get into trouble with the Feds for the 'heads-up' he gave the community already. I am sure there will suddenly be many more people taking an interest in the Linux kernel or other components in the operating system which may be vulnerable to snooping.

There is an adage in the Open Source Community that "many eyes make all bugs shallow" (Ironically, this is known as 'Linus's Law') Lets hope that applies to backdoors too and if such a thing exists in Linux, it is discovered and (dis)closed very soon.

Thursday, July 11, 2013

A Look Back at Ubuntu 5.10: Breezy Badger


What were you doing in October, 2005?

The original Ubuntu 5.10 CD set
as shipped by Canonical
The Mars Reconnaissance Orbiter was speeding towards Mars and clean up had just begun following Hurricane Katrina. A new Disneyland had opened in Hong Kong. A relatively new Linux upstart company called Canonical released Ubuntu 5.10, codenamed 'Breezy Badger'.

Breezy was the third release following 'Warty Warthog' (4.10; October, 2004) and Hoary Hedgehog (5.04). Ubuntu was built on the shoulders of Debian, but designed to be easy to use and updated regularly.

Live CDs were a new idea at this time. Knoppix had been loading a fully functional OS, complete with hardware detection (hurray!) for a while, but it was not designed to be installed on your system. It was Ubuntu who brought Live CDs to the masses.

In those early days, the Live CD and the Install CD were on separate disks. I came upon my old CDs (ordered free from Canonical in those days) and popped the 'Breezy' Live CD into my Asus netbook.

It still booted fine and hardware mostly worked. It didn't find either my wired or wireless connection and screen resolution was stubbornly stuck at 800 x 600, despite instructing it to use 1024 x 768. Both of these issues could probably have been fixed with a boot code or driver search. Mostly, it worked fine and fast. With system requirements of 2 GB hard drive space and 128 MB RAM, that isn't surprising.

Old Gnome 2.12.1 had that retro-looking blocky style and Ubuntu was experimenting with the brown theme which it would be well known for later. Compiz and it's whiz bang features for window compositing were still under development by Novell.

Many of us have ridden this Ubuntu train for many years. Sometimes we like the direction Canonical takes, sometimes we don't, but we usually can still customize our boxes to our liking. You can't help but smile as you look at how far we have come and yet how little has changed.

Here's some screenshots of Ubuntu 5.10 and some familiar apps as they appeared in 2005. Enjoy the trip down memory lane.


The Install CD and Live CD were separate
Early distros required a Linux boot floppy for installation.
Knoppix brought us on-the-fly hardware detection and setup.



Breezy boot screen.
Add your boot perimeters here.

The Breezy Desktop

Hardware support was sketchy in those days and Ubuntu began compiling their Hardware Database Collection.

Gnome 2.12.1 System Menu

Computer window

File System

A simple 'Add/Remove Programs' simplified software installation.

Synaptic looks familiar

If brown doesn't suit you,
you can change it in Theme Preferences

OpenOffice Writer was becoming a viable alternative to MS Word.
Breezy included OO 2.0 Beta 2

Calc could replace Excel for most tasks.

Firefox browser and Ubuntu home page.
It seems they have kept the promises they made all those years ago.

Firefox was gaining popularity with the public.
Breezy sported version 1.07 by default.

Gimp 2.2 provided a free image editing tool which rivaled Photoshop.

AisleRiot Solitaire hasn't changed much.

System Monitor shows the light footprint of those early applications.

Monday, December 17, 2012

Webcam Auto-Exposure Problems Under Linux - Solved

Too much light on bright days
I have struggled to find a webcam program which could grab decent still images from a webcam running under Linux. I have tried the common suggestions found online, used gvucview, cheese, webcam and webcamd.

All of these programs worked for snapping still images but the auto-exposure never worked properly and the images were poor. Most of the day the picture was either dark or obliterated with glare.

It seems the problem is that most webcam software is designed for streaming video. They all do a decent job of this, but even those programs that build in a delay never worked consistently for single jpg images. Searching the web, it is obvious I am not the only one with this problem and I could find no real solution.

Too dark in low light
After fighting this problem for days, it occurred to
me that perhaps I was using the wrong tool for the
job. I needed to look for a program which was designed specifically to snap still images from a webcam, not capture streaming video.

After some searching, I found a program called uvccapture which does just that. It is a simple, light program  that accepts arguments for resolution, timing, save location, even brightness, saturation, contrast and other basic settings. It is available in the Ubuntu repositories or you can grab it from here: https://github.com/csete/uvccapture

Happily, the auto-exposure is now working and my webcam is finally producing clear and properly exposed images. Here's how I managed it:

Auto-Exposure working properly
After installing uvccapture, I created a folder called 'webcam' in my home directory to store image.jpg and scripts. I set up the program to load on the boot using the Startup Applications tool by entering this into the command field:
uvccapture -m -t600 -q75 -x640 -y480 -o/home/user/webcam/image.jpg
This string of commands loads the program and instructs it to refresh the image every 10 minutes (600 seconds), to use compression on the JPG file at 75% quality. It states the webcam resolution, which must be supported by your device. The last argument includes the location to save the image file.

More info and commands for uvccapture are located here: http://manpages.ubuntu.com/manpages/natty/man1/uvccapture.1.html

The next problem was finding a new program to send the files via ftp to a remote server. Most of the programs I had used included the ftp service with the image grabber. I wanted something light and stable which could run in the background.

I looked at several programs and scripts and finally decided on this simple script which runs every 10 minutes via cron. Copy and paste the following into a text editor. Edit lines 4, 5 & 6 in the top section and line 5 in the bottom section:
# vi ftp-run.sh
#! /bin/sh
#run this file with ./ftp-run.sh
REMOTE='your-remote-server.com'
USER='username'
PASSWORD='password'
FTPLOG='/tmp/ftplog'
date >> $FTPLOG

ftp -n $REMOTE <<_FTP>>$FTPLOG
quote USER $USER
quote PASS $PASSWORD
bin
/home/user/webcam
mput image.jpg
quit
_FTP
Save the file as ftp-run.sh in the webcam folder. Right click on the icon and under Permissions, click to 'Run this file as a program'. I set up a cron job to run this script every 10 minutes with this command:
crontab -e
    arrow down to bottom

Paste:
*/10 * * * * cd webcam && ./ftp-run.sh

Ctrl + x to exit
Y to save
Enter
I rebooted to load the program and settings. I finally have a working webcam and my images are clear, bright and upload reliably to my server. I hope this how-to will help someone else who is struggling with this problem.

Shameless Plug:
More fun with your webcam: PortalView Live Desktop Wallpaper for Linux

Sunday, November 6, 2011

Debian Beckons Ubuntu Refugees to Come Home

Debian Live desktop
Dissatisfaction continues over Ubuntu's choice of the Unity Interface as default and, in the most recent release, no obvious way to return to the old Gnome desktop.

Long time Ubuntu users have been complaining loudly about Unity's lack of stability, limited options and an overall unfinished feel.

Distros that have watched Ubuntu gobbling up the Linux mind-share are suddenly getting a second look by unhappy Ubuntu users seeking alternatives to Unity.

Ubuntu started life as a simplified Debian with an emphasis on desktop usability. Recent Ubuntu releases seem focused on blazing their own trail toward a touchscreen, cloud enabled, widget driven environment. This may prove to be a very forward thinking plan, but it leaves traditional Gnome users hungering for their familiar desktop environment.

I decided to take another look at Ubuntu's parent, Debian. They offer live cd/dvds so I downloaded the i386 dvd .iso of the current stable release 6.0, aka 'Squeeze'. (All the Debian releases are named after characters from the 'Toy Story' movies.)

As a test machine, I scrounged up an ancient Dell Inspirion 1150. This dinosaur sports a 30 GB harddrive, 2.6 GHz processor, Wifi and 512  MB of RAM. Although I love my bling, I did not test compiz on this box due to the low specs.

Debian calls itself "The Universal Operating System" and nothing beats its support for a wide variety of hardware and architectures. Sound, video and ethernet were configured and worked automagically from the live cd.

Clicking the Install icon opens a graphical installer which walks the user through the usual steps: language, location, keyboard and timezone. Enter user and administrator passwords, computer and host names.

The partitioner offers a simple, guided install for a range of configurations. More advanced setup options are available by selecting 'Manual' install. The installation is essentially the same as most gnome-gui based installers and virtually painless.

The desktop is plain, vanilla Gnome 2 with a cartoonish space wallpaper (see above). There are many more wallpapers included by default and Ubuntu users will recognize many beautiful favorites, including 'Cosmos' the space slide show.

Live Earth Wallpaper on Debian/Gnome2
I replaced the default background with a Live Earth wallpaper that updates hourly throughout the day. You can find installation instructions here.
 
Neither ethernet or wifi would work after install. A quick google search found this documented bug and fix. Apparently, networking auto-configure is disabled by default.

I edited (as root) /etc/NetworkManager/NetworkManager.conf to show managed=true and following a restart of network manager, ethernet finally connected.

This Dell machine uses an old Broadcom wireless chipset, notoriously difficult to get working due to the closed nature of their firmware. Thankfully, in September of 2010, Broadcom finally began offering fully open Linux drivers for their chipsets.

Per instructions here, I entered in a terminal: sudo apt-get install firmware-b43-installer .Following a reboot, my wireless network was located and after entering my password, I was online in seconds.

I updated my repositories to include non-free software packages  Replace 'Squeeze' with 'Testing' for more current software updates, but slightly more breakage. Upgrades are incremental or 'rolling.' No need to reinstall every six months.

Debian uses apt for package management, with Synaptic as the familiar front end. Update manager notifies you of available updates and the Software Center makes adding and removing applications easy.

Debian came with gnash, the open implementation of Adobe Flash, installed by default. If you prefer Adobe's version, it is available in the repositories.

User friendly distros like Ubuntu and Mepis were built on Debian's stability, massive software repositories and superior apt package management system. Debian may lack the polish of these derivatives, but it is also a blank canvas, ready to take on your own look and feel. Experiment with new themes, icon sets, wallpapers and more at gnome-look.org

I was pleasantly surprised at the improvements in usability and ease of installation in Debian. Gnome2 seems as comfortable and familiar as an old pair of slippers. I think I will give Debian another try as a Desktop OS and it feels surprisingly good to come home.

A full review of Debian Squeeze can be found here.

Article first published as Debian Beckons Ubuntu Refugees to Come Home on Technorati.

Tuesday, October 18, 2011

Broken Windows? Ubuntu Linux Saves the Day

Ubuntu Live CD Desktop
Article first published as Broken Windows? Ubuntu Linux Saves the Day on Technorati.

You may have heard about Linux. Perhaps you imagined it as a clunky DOS-like command line system, used by uber-geeks in dark basements and server rooms to perform their geeky techno-magic.

In truth, Linux has matured into an easy to use operating system, complete with a vast eco-system of free software that rivals Windows and Mac in simplicity and beauty. It rarely needs a reboot and viruses are virtually unknown.

Canonical has just released Ubuntu 11.10, it's latest version of the popular Ubuntu Linux distribution. It calls itself 'Linux for Human Beings' and it aims to be one of the most newbie friendly Linuxes. It's innovative 'Unity' GUI (graphical user interface) is designed for simplicity and functionality.

Ubuntu is not shareware or spyware. It is a full-featured system which is provided free of charge through 'Open Source' licensing.

Open Source is a philosophy as much as a license. It gives developers the right to use and build upon the progress of previous developers. Unlike proprietary software, the source code is provided for review, modification and distribution.

This type of collaborative development leads to rapid progress and innovation. Linux runs everything from desktop systems and smart phones to toasters and super-computers.

You don't have to install Ubuntu to try it out on your computer. Many Linux distributions are offered as 'Live CDs/DVDs which run completely off your CD/DVD player. They come with a full library of software pre-installed for everything from a MS Office compatible Office suite to photo editing and email.
 
Linux Mint is based on Ubuntu, but includes popular software, like Flash, Java and proprietary video drivers by default.

Simply download and burn the .iso (disk image) to a CD/DVD. Drop it in your computers' CD/DVD drive and reboot. Most everything works 'out of the box.' Video, sound, wifi, printers and networking. You can explore Linux and enjoy all the free software without risk. Simply eject the disk when your done and the computer reboots as before.

These live CDs are a great tool for malware infected Windows computers. In a pinch, they can provide you with a fully functional and secure system, loaded with the latest software and hardware drivers. Use them to back up files from a dying hard drive or fix a borked master boot record. At least you will have a working system until you can get Windows fixed (again).

Use a Live Linux CD to clean an infected Windows system yourself. Boot using a live CD and simply visit a reputable online virus scanner like TrendMicro, Bitdefender, Kaperskey, or use a free malware detection tool kit like the Kaspersky Rescue Disc.

If you choose to keep Linux on your computer, most Live CDs will walk you through installation, either completely replacing Windows or along side it (called dual-booting).

So head on over and download one of these great free systems. Explore thousands of free software titles from games to utilities.  Keep the live CD handy to rescue malware crippled Windows computers or retrieve data from an unbootable hard drive.

You don't have to be a geek to enjoy the freedom that Linux systems offer. They are simple to use, virtually virus free and solid as a rock.

And while you're at it, take a moment to remember Dennis Ritchie, a father of C and Unix, upon which most modern computing is based. He passed away last week, but these fundamental contributions will live on. RIP and thank you from all of us.

Tuesday, October 4, 2011

How Can You Contribute to Open Source?

Open source software is a group effort and requires the participation of everyone in the community including you.  How can you give back to your favorite project if you are not a programmer? There are many ways you can help including participation in the online community, writing and translating, donations or just spreading the word.
Open source projects depend on you. They count on users to help test the packages on a large variety of hardware configurations and software combinations. They rely on your feedback to help the project grow and mature. They depend on your participation in forums and IRC channels to aid end users. They need your expertise to create useful documentation and translations. They depend on your donations to cover the costs of hardware and hosting.

Previously we took a close look at Apport, the bug reporting program included with Ubuntu. It works with Launchpad to coordinate bug tracking and fixes and makes it relatively simple to perform this most basic and vital task to contribute to the community.

Besides bug reports, there are many ways of giving back to the open source causes. Participation in the projects  online community is a good way to start. You don't have to be an expert to visit the projects' forums  or IRC channel and offer suggestions on topics you are familiar with. There is almost always someone newer than you that will appreciate your advice.

Documentation is an on-going chore for developers and assistance is always appreciated. Contact the project maintainer and offer to write readmes or help articles for specific tasks. Create how-tos and tutorials and post them on your blog or youtube. Contribute to the projects' wiki page. Look here for some tips on writing software documentation.

Translators are needed to make software and documentation available in other languages. Contact the project maintainer and offer to help translate the interface or help files. Check out 'Open Source Tools For Translators' to help you get started.
Donating money to worthy open source projects is always welcome. Most developers receive very little compensation for all their hard work. Most supply their own hardware and bandwidth. Many pay for hosting project websites where they interact with end users via forums or message boards. Even small donations help keep the project running.

Here are a few worthy causes to get you started. There are many more:


Finally, advocacy is a powerful tool and just being able to share information about Linux or your favorite software package when the opportunity arises is perhaps the most important contribution you can make. Talk to your friends,  family and coworkers. Post comments in forums and social media.

Burn a few live CDs of a newbie-friendly distro such as Ubuntu or Linux Mint.. Keep them in your car with your music CDs. The next time someone complains about how their computer won't boot or is running so slowly it is barely usable, just pull out one of the live CDs and show them how it works.

Explain that it wont change anything on their computer and comes with a complete collection of software for common tasks. Show them how it can give them a secure, perfectly usable system until they can get Windows fixed, or if they choose to keep Linux, you will help to install it on their machine.

Even if you can't write a line of code, open source depends on you. They need your bug reports, community involvement and donations. They depend on you to spread the word through personal contact and social media. Contributing your time and skills to these projects will benefit you as the user and the open source ecosystem as a whole.

This article was originally published on UbuntuManual.org

Monday, October 3, 2011

Tizen Consortium Takes On Android and iPhone

In a joint announcement on Sept 28, The LiMo Foundation and the Linux Foundation reported they are developing a new mobile operating system called 'Tizen'. It is a combination of the LiMo and MeeGo Linux-based mobile operating systems and will compete directly with Google's Android, Apple's iPhone and Blackberry from RIM. According to the announcement on their website:

 "LiMo Foundation is pleased to give its full endorsement of the Tizen initiative as an important step forward for the mobile industry. LiMo is confident that Tizen brings together the necessary critical mass of market and technology leadership so as to enable the establishment of a single, open and independent Linux-based platform for mobile devices."

Hosted by The Linux Foundation, Tizen is being developed by a consortium of major technology companies led by Intel and Samsung. They have worked to create an open, cross-architecture and standards based mobile platform. Tizen will  power smart phones, tablets, netbooks, smart TVs and vehicle entertainment systems.

LiMo brought together industry leaders including Motorola, NEC, Samsung, McAfee and others to help increase the adoption of Linux in mobile platforms. The Linux Foundation members include industry heavyweights such as Intel, IBM, Fujitsu, Hitachi, Oracle and Qualcomm.

Founded in 2007, the goal of LiMo was to create an Operating System which could unify the mobile industry and prevent continued fragmentation. It would provide a common computing platform which would simplify creation of third party applications by developers by using HTML5 and WAC API implementations and toolkits.

MeeGo was launched in February of 2010 and is also a Linux-based mobile platform. It is backed by Intel, Nokia and Novell. MeeGo was decended from Moblin, developed by Intel and Maemo from Nokia.

According to Morgan Gillis, Executive Director of the LiMo Foundation:

 "The most important thing about mobile Linux it that it's not owned by any one industry party, and therefore it can be adopted without any difficult business model conflicts."

Tizen holds to four basic goals: first, to use HTML5 and web standards for application development. Second, build a truly open software ecosystem. The third guarantees partners the opportunity to customize and individualize the system and finally, participation and support by many of the biggest players in the technology field.

Tizen is due to be released in early 2012 and the first Tizen-powered devices should be available to the public soon after.

Article first published as Tizen Consortium Takes on Android and iPhone on Technorati.

Monday, September 26, 2011

Hands On With Xubuntu 11.10 Beta

Xubuntu 11.10 Beta 1 Desktop
On September 2, Canonical released beta versions of Oneiric Ocelot for Ubuntu, Kubuntu and Xubuntu.  This is the third article in a series looking at these newest releases. Today we focus on Xubuntu, the lightweight Ubuntu, designed for older computers or those that just want a fast distro with a comprehensive software collection that is easy on system resources.

I downloaded the .iso from here. You can pick between Desktop and Alternate Install CDs, with choices for x86 PCs and 64 bit PC (AMD 64) versions.

Using UNetbootin, I loaded the image to my flash drive and booted into the Xubuntu desktop.

This version uses XFCE 4.8.3 with the Thunar file manager which now supports remote shares browsing and an eject button for removable devices.

The panel has had numerous improvements, including positioning, transparency, an item editor and the ability to create launchers with drag and drop.

The new desktop uses these panel upgrades to create a customized bottom panel which resembles Docky or Cairo Dock in appearance but without the animations or advanced options.

The top panel is similar to the one used in Ubuntu, but sports a small icon on the left which opens the main menu for applications and system settings.

Software Center
Xubuntu comes loaded with a complete software library for most common computing tasks. The included applications and utilities are generally lighter with fewer options than the software included in Ubuntu or Kubuntu but all alternatives are available in the repositories.

Synaptic Package Manager is included along with the Ubuntu Software Center. Using the new Software Center, you can browse by general category or search by name or task. Choosing the right application is easy screenshots and  reviews and ratings from other users.
gThumb Picture Viewer

The new software center provides reviews, ratings, and screenshots from other Ubuntu users. Unfortunately, the Software Center seems to still be rather buggy as it crashed several times as I attempted to install packages. This felt very similar to problems I noticed in Ubuntu 11.10 beta, using the Unity interface.

Kubuntu includes gThumb, a simple picture viewer, but also GIMP for more advanced image editing.

Thunar File Manager
gMusicbrowser is the default music player. It is a simple, easy to use player with many of the features found in heavier programs.

Plugging in an Android phone, Xubuntu recognized it as a USB storage device and launched the Thunar File Manager. I was able to move files easily between phone and computer. It did not recognize the file types or offer to open a picture viewer or music player.

Abiword and Gnumeric are included for Office applications. Both are lightweight but surprisingly full featured programs. Save files in open or proprietary formats, including pdf and MS .doc and .xls file types.

Thunderbird Email Reader

Thunderbird is the the default mail reader and it imported my mail and contacts without a hitch. Mozilla Thunderbird is a full-featured mail program with advanced search and filter capibilities. Tabbed email allows easy movement between multiple messages. Add-ons are quickly installed with the new Add-ons Manager, which provides descriptions, recommendations and pictures.

Onboard on-screen keyboard
Xubuntu now includes 'Onboard', an on-screen keyboard with a full qwerty keyboard, including function and other common keys. Click the orange area to the right to access the number pad and create 'snippets', macros which can be executed with a click.

Firefox 7.0 is included but repeatedly crashed, especially when accessing webpages using Flash. After several restarts, I was able to get Flash installed, despite the Software Center saying it was not available.

Gnome users may find this Desktop Environment slightly familiar, albeit less feature rich. I found it plagued by many of the same bugs I encountered in my review of the Ubuntu/Unity version of Oneiric. I experienced numerous crashes when using the Software Center, Firefox and even the Thunar file manager.

Xubuntu is the minimalist member of the Ubuntu family. It is a full featured distro, designed for those who prefer a fast, lightweight desktop environment, but be prepared for some frustration and bug reports if you decide to test this release.

Find more info at XFCE and Xubuntu Oneiric Ocelot beta1web sites.

*Hardware specs:
Asus eeepc 900
16 + 4 GB SSD
2 GB RAM
900 MHz Celeron Processor
Atheros AR5001 wireless adapter
Intel 915GM Graphics Controller

This article originally appeared at UbuntuManual.org on Sept 23, 2011.

Wednesday, September 14, 2011

Prominent Linux Servers Hacked


UPDATE: The Linux Foundation and its sub-domains, including Linux.com have announced they too have been hacked and it appears to be related to the breach of kernel.org, discovered on August 28.
As previously reported, one of the developers with root privileges, was found to have a trojan on his personal computer.

The Linux Foundation and Linux.com websites are currently displaying the following warning:

Linux Foundation infrastructure including LinuxFoundation.org, Linux.com, and their subdomains are down for maintenance due to a security breach that was discovered on September 8, 2011. The Linux Foundation made this decision in the interest of extreme caution and security best practices. We believe this breach was connected to the intrusion on kernel.org.
We are in the process of restoring services in a secure manner as quickly as possible. As with any intrusion and as a matter of caution, you should consider the passwords and SSH keys that you have used on these sites compromised. If you have reused these passwords on other sites, please change them immediately. We are currently auditing all systems and will update this statement when we have more information.
We apologize for the inconvenience. We are taking this matter seriously and appreciate your patience. The Linux Foundation infrastructure houses a variety of services and programs including Linux.com, Open Printing, Linux Mark, Linux Foundation events and others, but does not include the Linux kernel or its code repositories.
Please contact us at info@linuxfoundation.org with questions about this matter.
The Linux Foundation

Kernel.org Hacked
Sept. 2, 2011

Kernel.org - the Official Linux Kernel Archive announced on its website that it's servers have been compromised. The statement reads, in part :

“Security breach on kernel.org
Earlier this month, a number of servers in the kernel.org infrastructure were compromised. We discovered this August 28th. While we currently believe that the source code repositories were unaffected, we are in the process of verifying this and taking steps to enhance security across the kernel.org infrastructure. "

This revelation is disturbing on many levels. Once again, it proves that even Linux is vulnerable to attack, despite its reputation for superior security. It proves that even the most experienced sys admins can fail in their efforts to ensure the integrity of their networks. It shows the vulnerability of simple human error, like a trojaned laptop, can have wide ramifications and over-dependence on a flawed web security system, like SSL cert signing, leaves all systems at risk. (See this excellent article regarding the recent compromise of Dutch company DigiNotar which an intruded generated 531 fake certificates, including for popular sites such as Google, Facebook and Skype.)

What Happened?
Sometime before August 12 an intruder gained access to the Hera server at kernel.org using a compromised user credential. Starting around August 19th, user interactions were logged, and a trojan startup file was added to rc3.d. (Interestingly, an attempt was made to attack 3.1-rc2, but this was blocked for some reason.) SSh files, including openssh, openssh-server and openssh-clients were altered and running live.

It appears that one of the developers with root access may have had a trojan on his personal computer which allowed an attacker to gain access to his ssh key and root password. The same trojan was found on the servers Hera and odin1, with possible infections of three others.

The intrusion was detected on August 28 when xnest /dev/mem starting throwing errors. Xnest is an X Window system server and was not installed on the infected machine.

After the intrusion was detected, the boxes were taken offline and reinstalled from clean backups. The folks at kernel.org were open about the breech and posted details on their website right away. They explain how using git, the exposure to the public should be minimal.

Git was developed by Linux Trovalds in 2007 as a fast, efficient distributed revision control system. It is used to keep track of software revisions and allow collaboration on projects among developers across diverse networks.

One of the features of git is its cryptographic authentication of revision history. As Wikipedia explains:
"The Git history is stored in such a way that the name of a particular revision (a "commit" in Git terms) depends upon the complete development history leading up to that commit. Once it is published, it is not possible to change the old versions without it being noticed. The structure is similar to a hash tree, but with additional data at the nodes as well as the leaves."

So each revision is named according to its revision history and each of its parent revision histories all they way up to the top level. This creates a 'tree' of revision hashes which contains the entire history of the project. If you change anything, it creates a cascade of changes to the hashes which will throw errors when attempting to merge the changes into the main repository. Attempting to force the changes would result in a separate branch.

So what does all this mean to Linux users? Are they at risk? Generally, the risks appear small. Most Linux users get their updates through their distos package manager and these are generally signed and maintained on their own servers. Most of the maintainers of these distors use git to update their packages. Therefore, most users can consider themselves safe.

I have seen some discussion as to whether a user who directly downloaded a kernel tarball using ftp or http between August 12 and August 28, possibly bypassing git, could have received an infected copy of the file. I have found no clear answer to this question as yet. If you have recently built your own kernel, using files from kernel.org, downloaded via ftp or http, you might consider a re-install to be safe. Also, look for errors involving xnest, as this was the clue which led to detection of the intrusion. As noted on the website:

"Trojan initially discovered due to the Xnest /dev/mem error message w/o Xnest installed; have been seen on other systems. It is unclear if systems that exhibit this message are susceptible, compromised or not.  If you see this, and you don't have Xnest installed, please investigate."

Linux users like to believe we are nearly immune from malware attack. Occasionally, reality proves this not to be true.

A bit of history:
Intrusion into four servers that host the project's bug-tracking system, mailing lists and various Web pages.

In case you believe those were ancient history, that it can't happen today, consider these:

August 2007: Ubuntu had to take 5 of its 7 production servers offline after they were being used to attack other servers. The effected servers were found to be out of date on security patches and using insecure protocols (FTP without SSL).

August 2008: Red Hat servers hacked.

There is also the infamous Debian SSL flaw in 2008.

The point here is that no OS is 100% secure. No sysadmin is 100% perfect. Human error, when combined with millions of lines of complex code, will occasionally fail. For now, the Linux community appears to remain safe and git, developed by Linus himself, has done its job.

Sunday, August 14, 2011

Setting Up a Free Weather Webcam


"Everyone talks about the weather, but no one does anything about it." - Mark Twain

Weather webcam image
The weather effects our lives everyday and weather websites are among the most heavily trafficked on the web. They tell us whether we will need an umbrella today or what to pack for a trip across the country.

Weather webcams are always popular and it is easy and free to set one up yourself. Whether you run Windows, Mac or Linux there are tools and hosting available which only requires you own a webcam to be up and running on the web.

Basically you need three things: a webcam, software which can upload via ftp and a website which will host and publish your images.

Webcams are ridiculously cheap these days and if you don't have an old one in a drawer somewhere, they are available online or at your local department store for 10.00 and up. Generally, you want the best resolution you can afford with back light and white control, if possible.

Webcam software is usually included with your webcam or is widely available online. You will need a program which can upload your images to the web via ftp or sftp.

Free software for Windows is available here:
http://www.lundie.ca/fwink/

For Mac:
http://www.klieme.com/EyeSight.html

And Linux:
I use uvccapture, designed for still webcam images, it handles auto-exposure better than software designed for streaming video. It is available in the Ubuntu repositories or you can grab it here:
https://github.com/csete/uvccapture
See "My Linux Setup" below for instructions. 

Camorama Software
Regardless of the software, the process will be the same: Capture an image, save it to your computer, use ftp (or sftp) to upload it to a remote server, view it online.

For free weathercam hosting and making the images available online, I use weatherunderground. They will broadcast your images, create a video of the last 24 hours and even provide a weather calendar of the last month which offers videos for each day.

Ok. Lets get started.

Plug your webcam into a usb port on your computer. Point the camera out the window. This sounds simple enough, however there are considerations which may complicate your choice of view.

Direction: Pointing your camera either due west or east will result in direct sunlight on your camera and window glass during part of each day. This usually results in overwhelming glare which can obliterate the image. If possible, it is best to point your camera either north or south so it will not be pointed directly into the sun.

Distance: USB looses signal strength with a cable over 15' long. This can cause corruption of your images and an unreliable source. Choose a window which you webcam can reach without using an extension or keep the total distance under 15 feet.

Sky Cam
Subject: Choose a view which gives the info you are looking for. Are you watching for snow so you know if you need to leave work early? If yes, then make sure you can see the ground. Are you watching the sky for approaching threats of bad weather? Point it toward an open area of sky, preferably in the direction which weather usually approaches (avoiding due west/east if possible).

Once you have decided on a view, next you will need to create an account with your host. In the case of this article, that will be weatherunderground.
Go here to setup an account:
http://www.wunderground.com/members/signup.asp

Setup your webcam here:
http://www.wunderground.com/webcams/signup.html

You can choose to upload images via FTP or URL. This means either you will send the pics directly to weatherunderground via FTP, or point them toward your own website where your webcam already exists. We will be using the ftp option.

Streamcam Software
To setup your webcam, you will be asked a few questions:
First, select the FTP option and give some general information about your organization (if any) and location. Select your timezone. Your address is requested, but general area info is fine. Enter the City, State and Zip Code. Your latitude and longitude will be calculated.

If you have a Personal Weather Station (PWS) and would like to upload the data, you can enter the address, IP or url here.

Finally, you can choose to share your camera type and this info will appear on your webcam page.

Click 'Save Changes' and you will be taken to a page where your camera will be listed with a name like mywebcamCAM1. It will show the location you entered and allows you to add another webcam if you have one.

Go to your webcam software and use the following settings, per the WunderCam FTP Wiki:
   "FTP SERVER: webcam.wunderground.com
    Username: You will be provided with a Camera ID on the sign up page in the "Your Current Cameras" box.
    Password: You will need to log in with the same password you use to access the Weather Underground site.
    Directory: We actually move the file for you, so if your software requires a directory you should set it as '/', but otherwise leave it blank.
    Filename: We also change the filename of your image, so a default name can be almost anything you'd like but 'image.jpg' is preferred.
    Binary: Please make sure that you are uploading your images through FTP using the binary setting.
    Image Resolution: There is no minimum or maximum resolution. However, the larger the resolution, the larger the file size, so please adjust your resolution and image quality settings to get the best image within the size limitations. "
If you click on the link which is your CameraID, it will take you to your own webcam page, which displays your current image, date and time, current local conditions, camera type and you will start building a calendar which shows still and videos of each day.

 

Bookmark this page or link to it from somewhere else for a reliable free weathercam, accessible from anywhere (including from your smartphone). You will also see your webcam included in their weathercam 'library', which is available by clicking on the 'webcams' tab on the weatherunderground site.

Last, monitor your new webcam for a few days and adjust as necessary to reduce glare (clean the glass, inside and out), fine tune the image and make it as useful to you and interesting to others as possible. Finally, If desired, you can submit your webcam to a site such as 'EarthCam', to be included in their listings of worldwide webcams.  As their tagline boasts, "Where the World Watches the World".

As Mark Twain noted, we may not be able to do anything about the weather, but we can monitor it closely and be prepared for it. Your new weathercam makes that easy and fun.

*********************************

EDIT: In November, 2017, Weather Underground announced that it was discontinuing it's free webcam hosting. Over the next month, webcams started dropping off or rarely updating. Many users found other hosting or risked losing their web presence.

Happily, Weather Underground users were vocal about their "passionate support" for their weather webcam network and on December 7, 2017 announced they would "continue to allow users to add webcams to the Weather Underground Network."

Thank you, Weather Underground for listening to your customers and continuing this valuable public service and a big thank you to WU webcam users who spoke up and saved this network of free weather webcams around the world.


*********************************

My Linux Setup

Install uvccapture, then open Startup Applications and paste the following code into the 'command' section.
uvccapture -m -t600 -q75 -x640 -y480 -o/home/user/webcam/image.jpg
This string of commands loads the program and instructs it to refresh the image every 10 minutes (600 seconds), to use compression on the JPG file at 75% quality. It states the webcam resolution, which must be supported by your device. The last argument includes the location to save the image file.

More info and commands for uvccapture are located here: http://manpages.ubuntu.com/manpages/natty/man1/uvccapture.1.html 

For basic ftp upload of images, try this simple script.
Copy and paste the following into a text editor. Edit lines 4, 5 & 6 in the top section and line 5 in the bottom section:
# vi ftp-run.sh
#! /bin/sh
#run this file with ./ftp-run.sh
REMOTE='your-remote-server.com'
USER='username'
PASSWORD='password'
FTPLOG='/tmp/ftplog'
date >> $FTPLOG

ftp -n $REMOTE <<_FTP>>$FTPLOG
quote USER $USER
quote PASS $PASSWORD
bin
/home/user/webcam-folder
mput image.jpg
quit
_FTP
Save the file as ftp-run.sh in the webcam folder. Right click on the icon and under Permissions, click to 'Run this file as a program'. I set up a cron job to run this script every 10 minutes with this command:
crontab -e
    arrow down to bottom

Paste:
*/10 * * * * cd webcam && ./ftp-run.sh

Ctrl + x to exit
Y to save
Enter

More fun with your webcam: PortalView Live Desktop Wallpaper for Linux