<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>trivia &#187; trivial musing</title>
	<atom:link href="http://baldric.net/category/trivial-musing/feed/" rel="self" type="application/rss+xml" />
	<link>http://baldric.net</link>
	<description>another voice in the babble on the net</description>
	<lastBuildDate>Sat, 19 May 2012 20:18:49 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>pure bubble</title>
		<link>http://baldric.net/2012/05/19/pure-bubble/</link>
		<comments>http://baldric.net/2012/05/19/pure-bubble/#comments</comments>
		<pubDate>Sat, 19 May 2012 20:18:49 +0000</pubDate>
		<dc:creator>Mick</dc:creator>
				<category><![CDATA[trivial musing]]></category>

		<guid isPermaLink="false">http://baldric.net/?p=1589</guid>
		<description><![CDATA[El Reg reports that facebook share dealing opened at $42 per share (up $4 on the opening IPO price of $38). As they wryly point out, the Telegraph reports that that price makes the company &#8220;worth&#8221; more than Boeing. That is nonsensical beyond belief. Boeing actually make things. Big things, that other companies pay a &#8230; </p><p><a class="more-link block-button" href="http://baldric.net/2012/05/19/pure-bubble/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<p>El Reg <a href="http://www.theregister.co.uk/2012/05/18/facebook_debut/">reports</a> that facebook share dealing opened at $42 per share (up $4 on the opening IPO price of $38). As they wryly point out, the Telegraph reports that that price makes the company &#8220;worth&#8221; more than Boeing.</p>
<p>That is nonsensical beyond belief. Boeing actually make things. Big things, that other companies pay a lot of money to buy. Facebook&#8217;s sole revenue source is advertising. </p>
<p>A small prediction. This time next year, facebook&#8217;s shares will be trading at less than $5 each &#8211; tops.</p>
]]></content:encoded>
			<wfw:commentRss>http://baldric.net/2012/05/19/pure-bubble/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>disappointing satnav</title>
		<link>http://baldric.net/2012/05/13/disappointing-satnav/</link>
		<comments>http://baldric.net/2012/05/13/disappointing-satnav/#comments</comments>
		<pubDate>Sun, 13 May 2012 18:09:10 +0000</pubDate>
		<dc:creator>Mick</dc:creator>
				<category><![CDATA[electronics]]></category>
		<category><![CDATA[linux and unix]]></category>
		<category><![CDATA[trivial musing]]></category>
		<category><![CDATA[linux]]></category>

		<guid isPermaLink="false">http://baldric.net/?p=1582</guid>
		<description><![CDATA[One of my hobbies is motorcycling. I have travelled extensively by bike in central and southern europe over many years, but oddly, I have never visited scotland before. I intend rectifying that shortly. When travelling in europe I have always made do with the excellent Michelin range of 1/1000000 (1 cm to 10 km) maps. &#8230; </p><p><a class="more-link block-button" href="http://baldric.net/2012/05/13/disappointing-satnav/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<p>One of my hobbies is motorcycling. I have travelled extensively by bike in central and southern europe over many years, but oddly, I have never visited scotland before. I intend rectifying that shortly. When travelling in europe I have always made do with the excellent Michelin range of 1/1000000 (1 cm to 10 km) maps. These maps are of sufficient detail to aid serious navigation and they also fold quite neatly to fit in a motorcycle tank bag top. Never before have I felt the need of a GPS satnav device.   </p>
<p>My wife, however, has a TomTom in her car and I noted that the device has two distinct advantages over a static map. Firstly it is immensely useful in the &#8220;last 5 mile stage&#8221; when you are hunting for a B&#038;B in an unfamilar town, and secondly (of most use when in trouble) it has a &#8220;where am I&#8221; function that pinpoints location so that you can give your co-ordinates to a rescue service. This latter function is reassuring to someone travelling alone (or to someone left behind by someone travelling alone). So, since I shall be travelling alone in Scotland over some wild and windy expanses where the weather is notoriously less predictably friendly than it is in southern europe at this time of year, I saw the sense in getting a satnav. I bought a garmin (small, light and cheap). Mine even came with a free lifetime subscription to map updates. The device itself is a doddle to set up and works very well. But it has a fatal design flaw &#8211; all software and map updates assume that you have a microsoft windows or apple OSX desktop at home. Well, guess what. I don&#8217;t.</p>
<p>The garmin update mechanism uses a plugin to IE, firefox, safari or chrome. But only if you are using a &#8220;compatible&#8221; operating system. No matter how hard I tried to fool the site using a user agent switcher I couldn&#8217;t get the plugin to work. I even tried using wine (which according to one or two sites on-line) should have worked, but no, garmin refused to play ball. I can happily mount the satnav as a removable drive on my linux desktop so copying maps (or even software) to the device should be easy. </p>
<p>Now this is more than just a little irritating. I have paid for a device with a &#8220;lifetime map update licence&#8221;. But I can&#8217;t update the maps without a PC running a particular OS. I&#8217;m pretty sure that garmin satnavs run a <a href="http://developer.garmin.com/linux/">version of embedded linux</a> so the company cannot pretend they have no linux expertise. Worse, they can produce a plugin for OSX machines (which is BSD based) but not something which is debian based.   </p>
<p>Garmin, I am disappointed. And annoyed as hell.</p>
]]></content:encoded>
			<wfw:commentRss>http://baldric.net/2012/05/13/disappointing-satnav/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>cheap?</title>
		<link>http://baldric.net/2012/04/24/cheap/</link>
		<comments>http://baldric.net/2012/04/24/cheap/#comments</comments>
		<pubDate>Tue, 24 Apr 2012 12:24:24 +0000</pubDate>
		<dc:creator>Mick</dc:creator>
				<category><![CDATA[network (in)security]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[trivial musing]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[network security]]></category>

		<guid isPermaLink="false">http://baldric.net/?p=1569</guid>
		<description><![CDATA[Michal Zalewski (aka lcamtuf) has just announced that google is changing the terms of its vulnerability purchase program. The google announcement says: Today, to celebrate the success of [the program] and to underscore our commitment to security, we are rolling out updated rules for our program — including new reward amounts for critical bugs: $20,000 &#8230; </p><p><a class="more-link block-button" href="http://baldric.net/2012/04/24/cheap/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<p>Michal Zalewski (aka lcamtuf) has just announced that google is changing the terms of <a href="http://googleonlinesecurity.blogspot.co.uk/2012/04/spurring-more-vulnerability-research.html">its vulnerability purchase program.</a> The google announcement says:</p>
<blockquote><p>Today, to celebrate the success of [the program] and to underscore our commitment to security, we are rolling out updated rules for our program — including new reward amounts for critical bugs:</p>
<ul>
<li>$20,000 for qualifying vulnerabilities that the reward panel determines will allow code execution on our production systems.</li>
<li>$10,000 for SQL injection and equivalent vulnerabilities; and for certain types of information disclosure, authentication, and authorization bypass bugs.</li>
<li>Up to $3,133.7 for many types of XSS, XSRF, and other high-impact flaws in highly sensitive applications.</li>
</ul>
</blockquote>
<p>Interestingly, the earlier part of the announcement says that the existing program resulted in:</p>
<blockquote><p>
&#8220;over 780 qualifying vulnerability reports that span across the hundreds of Google-developed services, as well as the software written by fifty or so companies that we have acquired. In just over a year, the program paid out around $460,000 to roughly 200 individuals.&#8221;
</p></blockquote>
<p>So, depending upon how you do the arithmetic, over the last year google paid out around $590 per vulnerability, or around $2300 per researcher. Whatever your views on the merits or otherwise of paying for vulnerabilities, that strikes me as pretty cheap, in all senses of the word.</p>
<p>As an aside, I found it amusing that the first commenter on the google posting was one Andrew Wallace, who styles himself an &#8220;Independent Consultant&#8221;. Wallace has been making a nuisance of himself around various security related mail lists and web fora for a while now. He used to post as &#8220;n3td3v&#8221; or latterly, as &#8220;Andrew from n3td3v&#8221;. Back in July 2010, <a href="http://www.wirelessforums.org/comp-security-misc/how-did-cyber-terrorist-tavis-ormandy-get-job-google-96726.html">Wallace labelled the google researcher Tavis Ormandy</a> a &#8220;cyber terrorist&#8221; following Ormandy&#8217;s rather public disclosure of a nasty vulnerability he believed Microsoft were trying to hide. Interested (or bored) readers are invited to search the &#8216;net for Andrew Wallace, n3td3v. </p>
<p>It is also worth recording that as a result of Ormandy&#8217;s (some may say &#8220;premature&#8221;) disclosure in June 2010, after an initial furious response from Mike Reavey, Head of MSRC, Microsoft went on to devise and publish a new <a href="go.microsoft.com/?linkid=9770197"> &#8220;Coordinated Vulnerability Disclosure&#8221;</a> policy (warning, MS docx format document) covering the disclosure of &#8220;zero day&#8221; vulnerabilities in other vendor&#8217;s products.</p>
]]></content:encoded>
			<wfw:commentRss>http://baldric.net/2012/04/24/cheap/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>now switch it back on</title>
		<link>http://baldric.net/2012/04/18/now-switch-it-back-on/</link>
		<comments>http://baldric.net/2012/04/18/now-switch-it-back-on/#comments</comments>
		<pubDate>Wed, 18 Apr 2012 16:15:24 +0000</pubDate>
		<dc:creator>Mick</dc:creator>
				<category><![CDATA[network (in)security]]></category>
		<category><![CDATA[networks and networking]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[trivial musing]]></category>
		<category><![CDATA[network security]]></category>
		<category><![CDATA[networking]]></category>

		<guid isPermaLink="false">http://baldric.net/?p=1562</guid>
		<description><![CDATA[Bugtraq can be an interesting list. Back in June 2008 I noted that one Craig Wright had posted an advisory about a vulnerability in an Oral B toothbrush. Well, just over a week ago a chap called Gabriel Menezes Nunes posted a proof of concept remote denial of service attack on a Sony Bravia television &#8230; </p><p><a class="more-link block-button" href="http://baldric.net/2012/04/18/now-switch-it-back-on/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<p>Bugtraq can be an interesting list. Back in June 2008 I noted that one Craig Wright had posted an advisory about a <a href="http://baldric.net/2008/06/19/dental-dos/">vulnerability in an Oral B toothbrush</a>. Well, just over a week ago a chap called Gabriel Menezes Nunes posted a proof of concept remote denial of service attack on a Sony Bravia television set. He had discovered that a packet flood attack to any port on his TV using the tool <a href="http://www.hping.org/">&#8220;hping&#8221;</a> would cause a denial of service. In his post he says:</p>
<blockquote><p>
&#8220;After 35 seconds the TV stop working and back. This happens 3 times. At fourth time, the TV shuts down. In less than 3 minutes, the TV is off remotely. It is necessary to turn on the TV physically.&#8221;
</p></blockquote>
<p>I can&#8217;t help thinking that using the normal remote control would have been easier.</p>
]]></content:encoded>
			<wfw:commentRss>http://baldric.net/2012/04/18/now-switch-it-back-on/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>stallman likes sharing</title>
		<link>http://baldric.net/2012/04/18/stallman-likes-sharing/</link>
		<comments>http://baldric.net/2012/04/18/stallman-likes-sharing/#comments</comments>
		<pubDate>Wed, 18 Apr 2012 14:46:43 +0000</pubDate>
		<dc:creator>Mick</dc:creator>
				<category><![CDATA[free software]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[trivial musing]]></category>
		<category><![CDATA[anonymity]]></category>
		<category><![CDATA[e-book]]></category>
		<category><![CDATA[kindle]]></category>

		<guid isPermaLink="false">http://baldric.net/?p=1558</guid>
		<description><![CDATA[The guardian&#8217;s series on internet freedoms (or otherwise) continues today with an article by Richard Stallman on the kindle and ebook publishing. Stallman makes a point I&#8217;d missed in my own commentary on the kindle when he says: &#8220;Many other habits that readers are accustomed to are not allowed for ebooks. With the Amazon Kindle, &#8230; </p><p><a class="more-link block-button" href="http://baldric.net/2012/04/18/stallman-likes-sharing/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<p>The guardian&#8217;s series on internet freedoms (or otherwise) continues today with an article by Richard Stallman on the kindle and ebook publishing. Stallman makes a point I&#8217;d missed <a href="http://baldric.net/2011/08/14/in-praise-of-dead-trees/">in my own commentary on the kindle</a> when he says:</p>
<blockquote><p>
&#8220;Many other habits that readers are accustomed to are not allowed for ebooks. With the Amazon Kindle, for instance, you&#8217;re not allowed to buy a book anonymously. Kindle books are typically available from Amazon only, and Amazon doesn&#8217;t accept cash so users must identify themselves. Thus Amazon knows exactly which books each user has read. In a country like Britain, where you can be prosecuted for possessing a forbidden book, this is more than hypothetically Orwellian.&#8221;</p></blockquote>
<p>One obvious way around this is not to buy ebooks from Amazon (or anyone else). The only books on my kindle are those out of copyright which I have downloaded from sites such as <a href="http://www.gutenberg.org/wiki/Main_Page">project gutenberg</a> or other sites listed on portals such as <a href="http://ireaderreview.com/2008/01/19/free-books-for-the-amazon-kindle/">ireaderreview</a>. Of course you have to be careful that you do not add such books to your personal document archive or Amazon will helpfully copy and list them in your &#8220;kindle library&#8221;.</p>
<p>And I still haven&#8217;t really used my kindle except when on holiday.</p>
<p>(Note that Richard Stallman&#8217;s article is Copyright 2012 Richard Stallman under a Creative Commons Attribution Noderivatives 3.0 license)</p>
]]></content:encoded>
			<wfw:commentRss>http://baldric.net/2012/04/18/stallman-likes-sharing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>battle for the internet</title>
		<link>http://baldric.net/2012/04/17/battle-for-the-internet/</link>
		<comments>http://baldric.net/2012/04/17/battle-for-the-internet/#comments</comments>
		<pubDate>Tue, 17 Apr 2012 16:09:45 +0000</pubDate>
		<dc:creator>Mick</dc:creator>
				<category><![CDATA[privacy]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[trivial musing]]></category>
		<category><![CDATA[google]]></category>

		<guid isPermaLink="false">http://baldric.net/?p=1550</guid>
		<description><![CDATA[This week the guardian, my newspaper of choice, is running a week long series of articles under the theme &#8220;battle for the internet&#8220;. The reporting looks set to be interesting and is due to cover the following themes: &#8220;the militarisation of cyberspace&#8221;, &#8220;the new walled gardens&#8221;, &#8220;IP wars&#8221;, &#8220;civilising the web&#8221;, &#8220;open resistance&#8221;, and (doomladen &#8230; </p><p><a class="more-link block-button" href="http://baldric.net/2012/04/17/battle-for-the-internet/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<p>This week the guardian, my newspaper of choice, is running a week long series of articles under the theme &#8220;<a href="http://www.guardian.co.uk/technology/series/battle-for-the-internet">battle for the internet</a>&#8220;. The reporting looks set to be interesting and is due to cover the following themes: &#8220;the militarisation of cyberspace&#8221;, &#8220;the new walled gardens&#8221;, &#8220;IP wars&#8221;, &#8220;civilising the web&#8221;, &#8220;open resistance&#8221;, and (doomladen prophecy) &#8220;the end of privacy&#8221;. Personally I find the terms &#8220;cyberspace/cyberwar/cyberjihad/cyberwhatever&#8221; a horrible americanisation, but unfortunately the labels seem to have gained some traction even here in the UK. Whatever, it is at least refreshing that a mainstream newspaper (the guardian <em>is</em> mainstream, right?) should be taking a look at the issues rather than leaving it to the specialist press.</p>
<p>Yesterday&#8217;s reporting though was a hoot. The paper led with a <a href="http://www.guardian.co.uk/technology/2012/apr/15/web-freedom-threat-google-brin">front page article</a> reporting an interview with Sergey Brin. Brin is reported to have said:</p>
<blockquote><p>&#8220;there are very powerful forces that have lined up against the open internet on all sides and around the world&#8221;. and &#8220;I am more worried than I have been in the past, it&#8217;s scary.&#8221;</p></blockquote>
<p>OK &#8211; I can see how there could be a number of possible threats to the continued existence of the sort of open and collaborative &#8216;net that I so admire. But the guardian article went on to say: </p>
<blockquote><p>&#8220;The threat to the freedom of the internet comes, he claims, from a combination of governments increasingly trying to control access and communication by their citizens, the entertainment industry&#8217;s attempts to crack down on piracy, and the rise of &#8220;restrictive&#8221; walled gardens such as Facebook and Apple, which tightly control what software can be released on their platforms.&#8221;</p>
<p>&#8220;He said he was most concerned by the efforts of countries such as China, Saudi Arabia and Iran to censor and restrict use of the internet, but warned that the rise of Facebook and Apple, which have their own proprietary platforms and control access to their users, risked stifling innovation and balkanising the web.&#8221;</p></blockquote>
<p>and moreover</p>
<blockquote><p>&#8220;There&#8217;s a lot to be lost,&#8221; he said. &#8220;For example, all the information in apps – that data is not crawlable by web crawlers. You can&#8217;t search it.&#8221;"</p></blockquote>
<p>So: along with restrictive regimes and an entertainment industry fighting to retain a lost business model, according to the world&#8217;s largest infringer of personal privacy, one of the biggest threats to the internet is the fact that apple and facebook won&#8217;t let google search the data they have gathered.</p>
<p>Is it just me? Or is this bonkers?</p>
]]></content:encoded>
			<wfw:commentRss>http://baldric.net/2012/04/17/battle-for-the-internet/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>this video is private</title>
		<link>http://baldric.net/2012/03/31/this-video-is-private/</link>
		<comments>http://baldric.net/2012/03/31/this-video-is-private/#comments</comments>
		<pubDate>Sat, 31 Mar 2012 20:20:53 +0000</pubDate>
		<dc:creator>Mick</dc:creator>
				<category><![CDATA[privacy]]></category>
		<category><![CDATA[trivial musing]]></category>
		<category><![CDATA[anonymity]]></category>
		<category><![CDATA[google]]></category>

		<guid isPermaLink="false">http://baldric.net/?p=1531</guid>
		<description><![CDATA[I have just tried to (re)view a youtube video I last looked at a couple of weeks ago from a link that a friend sent me in an email. On clicking the link I got the message: &#8220;This video is private. If the owner of this video has granted you access, please log in.&#8221; On &#8230; </p><p><a class="more-link block-button" href="http://baldric.net/2012/03/31/this-video-is-private/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<p>I have just tried to (re)view a youtube video I last looked at a couple of weeks ago from a link that a friend sent me in an email. On clicking the link I got the message: &#8220;This video is private. If the owner of this video has granted you access, please log in.&#8221; On clicking the link, I was taken to a google sign in page.</p>
<p>I suppose I shouldn&#8217;t be surprised at that. After all, the new google privacy policy, which covers all of its &#8220;services&#8221;, is now in place. But I must admit it did piss me off more than a little. What next? Must I sign in to watch pingu with my grandson?</p>
<p>No google, I won&#8217;t sign in just to view a youtube video. But walling off bits of the &#8216;net may yet be your downfall.</p>
]]></content:encoded>
			<wfw:commentRss>http://baldric.net/2012/03/31/this-video-is-private/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>that didn&#8217;t take long</title>
		<link>http://baldric.net/2012/03/29/that-didnt-take-long/</link>
		<comments>http://baldric.net/2012/03/29/that-didnt-take-long/#comments</comments>
		<pubDate>Thu, 29 Mar 2012 12:50:54 +0000</pubDate>
		<dc:creator>Mick</dc:creator>
				<category><![CDATA[mail and mail lists]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[trivial musing]]></category>
		<category><![CDATA[anonymity]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[spam]]></category>

		<guid isPermaLink="false">http://baldric.net/?p=1525</guid>
		<description><![CDATA[My last post contained two (non-existent) email addresses in my baldric domain in the extract from my postfix logs. As I said in the post, I had edited the log entry specifically to mask real details. Yesterday, only four days after that post, I received spam email attempts at those addresses. As I have said &#8230; </p><p><a class="more-link block-button" href="http://baldric.net/2012/03/29/that-didnt-take-long/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<p>My last post contained two (non-existent) email addresses in my baldric domain in the extract from my postfix logs. As I said in the post, I had edited the log entry specifically to mask real details. Yesterday, only four days after that post, I received spam email attempts at those addresses.</p>
<p>As I have said in the past, if you don&#8217;t want spam, don&#8217;t publish your email address.</p>
]]></content:encoded>
			<wfw:commentRss>http://baldric.net/2012/03/29/that-didnt-take-long/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>android mail client is broken</title>
		<link>http://baldric.net/2012/03/24/android-mail-client-is-broken/</link>
		<comments>http://baldric.net/2012/03/24/android-mail-client-is-broken/#comments</comments>
		<pubDate>Sat, 24 Mar 2012 22:03:12 +0000</pubDate>
		<dc:creator>Mick</dc:creator>
				<category><![CDATA[mail and mail lists]]></category>
		<category><![CDATA[networks and networking]]></category>
		<category><![CDATA[tips, tricks and howtos]]></category>
		<category><![CDATA[trivial musing]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[mobile phone]]></category>
		<category><![CDATA[networking]]></category>
		<category><![CDATA[postfix]]></category>
		<category><![CDATA[system administration]]></category>

		<guid isPermaLink="false">http://baldric.net/?p=1494</guid>
		<description><![CDATA[In January of this year I wrote about t-mobile&#8217;s apparent policy of actively looking for and blocking any TLS-secured SMTP sessions over their network. At the time I believed this to be a cockup rather than a deliberate policy. I still prefer to believe that, but the episode left a rather sour taste in my &#8230; </p><p><a class="more-link block-button" href="http://baldric.net/2012/03/24/android-mail-client-is-broken/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<p>In January of this year I wrote about<a href="http://baldric.net/2012/01/12/t-mobile-resets-its-policy/"> t-mobile&#8217;s apparent policy</a> of actively looking for and blocking any TLS-secured SMTP sessions over their network. At the time I believed this to be a cockup rather than a deliberate policy. I still prefer to believe that, but the episode left a rather sour taste in my mouth. So this month I took the opportunity presented by the end of my contract to shift to another provider. Of course, in doing so I gained a nice shiny new &#8216;phone which meant that I could spend a fun few hours setting it up the way I wanted it and nailing it down as much as possible so that it didn&#8217;t leak <strong>all</strong> my data to google. This is unnecessarily difficult, and much harder than it should be (and I know that people like Peter H will simply tell me that I shouldn&#8217;t be using an android &#8216;phone in the first place). But that is not the point of this post.</p>
<p>Like most people these days, I use my &#8216;phone to pick up email. The standard email client on my last &#8216;phone was pretty uninspiring so I used <a href="https://github.com/k9mail/k-9/wiki">K-9 mail</a> in its place. K-9 is a pretty good application, but it has a <a href="http://code.google.com/p/k9mail/issues/detail?id=350&amp;can=1&amp;q=CertPathValidatorException&amp;colspec=ID%20Product%20Type%20Status%20Priority%20Milestone%20Owner%20Summary">silly little bug</a> in it which is still not sorted properly. This bug manifests itself in a rather odd, and unpredictable way &#8211; K-9 seems to &#8220;forget&#8221; the X509 certificate used to protect the authentication process if that certificate is self-signed, or otherwise not verifiable by an external CA. The cure, such as it is, is to simply refresh the certificate by reloading the account settings and accepting the cert when K-9 warns you that &#8220;TrustAnchor found but validation failed&#8221;. The length of time between accepting the cert and K-9 &#8220;forgetting&#8221; it again seemed random to me, so I got into the habit of refreshing my account settings whenever I noticed that I hadn&#8217;t received any mail for a while. Annoying, but not ultimately a deal breaker for using what was otherwise a pretty good application.</p>
<p>So, the first application I looked at on my new mobile was, of course, email. The default mail client on this new phone looks a lot slicker than the old one on my previous phone, but then it is a much newer &#8216;phone, from a different manufacturer and the android version is much newer too, so no real surprise there. The setup seemed to have no problem with my self signed certs so I thought I might stay with the default to see if it would solve my annoying little problem with K-9.</p>
<p>Unfortunately not.</p>
<p>Whilst I had no problem with incoming mail over my IMAPS connection, all attempts to send mail failed. On checking my server logs I found the following (real details changed or obfuscated):</p>
<blockquote><p>Mar 20 20:45:57 pipe postfix/smtpd[7594]: NOQUEUE: reject: RCPT from home.baldric.net[12.34.56.78]: 504 5.5.2 &#60;localhost&#62;: Helo command rejected: need fully-qualified hostname; from=&#60;null@baldric.net&#62; to=&#60;noone@baldric.net&#62; proto=ESMTP helo=&#60;localhost&#62;
</p></blockquote>
<p>Aha! My postfix configuration is set up to reject hosts which do not have valid hostnames or do not announce themselves with fully qualified domain names (i.e. names of the form &#8220;host.domain&#8221;). Now since I use SASL authentication in my postfix configuration the fix is relatively easy; just ensure that the stanza &#8220;permit_sasl_authenticated&#8221; appears in both &#8220;smtpd_sender_restrictions&#8221; and &#8220;smtpd_helo_restrictions&#8221; <strong>before</strong> &#8220;reject_non_fqdn_hostname&#8221; &#8211; thusly:</p>
<blockquote><p>smtpd_helo_required = yes<br />
smtpd_helo_restrictions = permit_sasl_authenticated, permit_mynetworks, reject_non_fqdn_hostname, reject_invalid_hostname<br />
smtpd_sender_restrictions = permit_sasl_authenticated, permit_mynetworks, reject_non_fqdn_sender, reject_unknown_sender_domain</p></blockquote>
<p>(In fact, this episode highlighted an error in my postfx configuration because my helo restriction was inadequate. By now checking the authentication before the helo restriction kicks in I am still well protected, but mail from valid authenticated users is permitted.)</p>
<p>I am in that (very) small minority of people who run their own mail servers and are able to change server side configurations. But, and this is a big but. I should <strong>not have to change the server side configuration to accommodate a broken client</strong> and the vast majority of people will not be able to do so anyway. Almost all well set up mail servers will reject mail where the client connection announces itself in the helo exchange as &#8220;localhost&#8221;. That is normally an indication of a spammer, indeed spamassassin will allocate a high score to any mail which is so flagged. This means that there will be a huge, and growing, number of people who cannot send mail from their android &#8216;phones.</p>
<p>If this is the default android mail behaviour, then google need to fix it now. Meanwhile, K-9 is looking attractive again.</p>
]]></content:encoded>
			<wfw:commentRss>http://baldric.net/2012/03/24/android-mail-client-is-broken/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
		<item>
		<title>unlinked</title>
		<link>http://baldric.net/2012/03/19/unlinked/</link>
		<comments>http://baldric.net/2012/03/19/unlinked/#comments</comments>
		<pubDate>Mon, 19 Mar 2012 14:39:33 +0000</pubDate>
		<dc:creator>Mick</dc:creator>
				<category><![CDATA[mail and mail lists]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[trivial musing]]></category>
		<category><![CDATA[spam]]></category>

		<guid isPermaLink="false">http://baldric.net/?p=1488</guid>
		<description><![CDATA[Today I received two (make that four now &#8211; must sort out my spam filters) phishing emails from a source new to me. Each email purported to come from &#8220;linkedin&#8221; and each invited me to login to respond to &#8220;invitations from your work colleague&#8221;. Since a) I have never been a member of linkedin, and &#8230; </p><p><a class="more-link block-button" href="http://baldric.net/2012/03/19/unlinked/">Continue reading &#187;</a>]]></description>
			<content:encoded><![CDATA[<p>Today I received two (make that four now &#8211; must sort out my spam filters) phishing emails from a source new to me. Each email purported to come from &#8220;<a href="http://www.linkedin.com/">linkedin</a>&#8221; and each invited me to login to respond to &#8220;invitations from your work colleague&#8221;. Since a) I have never been a member of linkedin, and b) am retired, the invitations immediately looked suspect, but the return address looked real at first sight. That is, until I looked more closely. The actual address used was linkedln.com (with a second letter &#8220;l&#8221;) rather than the correct linkedin.com. </p>
<p>Nice try.</p>
]]></content:encoded>
			<wfw:commentRss>http://baldric.net/2012/03/19/unlinked/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

