Author's posts
May 30 2014
a new app
My newspaper of choice, the Guardian, has for some time produced its own android (and iOS of course) app. I have often used the android app on my tablet to catch up on emerging news items at the end of the day. I also read the BBC news app for the same reason. Yesterday I …
Permanent link to this article: https://baldric.net/2014/05/30/a-new-app/
Apr 16 2014
nsa operation orchestra
In February of this year, Poul-Henning Kamp (a.k.a “PHK”) gave what now looks to be a peculiarly prescient presentation as the closing keynote to 2014’s FOSDEM. In the presentation (PDF), PHK posits an NSA operation called ORCHESTRA which is designed to undermine internet security through a series of “disinformation” or “misinformation”, or “misdirection” sub operations. …
Permanent link to this article: https://baldric.net/2014/04/16/nsa-operation-orchestra/
Apr 16 2014
more heartbleed
For any readers uncertain of exactly how the heartbleed vulberability in openssl might be exploitable, Sean Cassidy over at existential type has a good explanation. And if you find that difficult to follow, Randall Munroe over at xkcd covers it quite nicely. My thanks, and appreciation as always, to a great artist. Of course, Randall …
Permanent link to this article: https://baldric.net/2014/04/16/more-heartbleed/
Apr 16 2014
pulitzer guardian
The Guardian and the Washington Post have been jointly awarded the Pulitzer prize for public service for their reporting of Edward Snowden’s whistleblowing on the NSA’s surveillance activities. The Guardian reports: The Pulitzer committee praised the Guardian for its “revelation of widespread secret surveillance by the National Security Agency, helping through aggressive reporting to spark …
Permanent link to this article: https://baldric.net/2014/04/16/pulitzer-guardian/
Apr 15 2014
boot and nuke no more
I was contacted recently by a guy called Andy Beverley who wrote: Hope you don’t mind me contacting you about one of your old blog posts “what gives with dban”. Thought I’d let you know that I forked DBAN a while ago, and produced a standalone program (called nwipe) that will run on any Linux …
Permanent link to this article: https://baldric.net/2014/04/15/boot-and-nuke-no-more/
Apr 08 2014
heartbleed
This is nasty. There is a remotely exploitable bug in openssl which leads to the leak of memory contents from the server to the client and from the client to the server. In practice this means that an attacker can read 64K chunks of memory on a vulnerable service, thus potentially exposing security critical information. …
Permanent link to this article: https://baldric.net/2014/04/08/heartbleed/
Mar 31 2014
the netbook is not dead
I bought my first netbook, the Acer Aspire One, back in April 2009 – five years ago. That machine is still going strong and has seen umpteen different distros in its time. It currently runs Mint 16, and very happily too. The little Acer has nothing on it that I value over much, all my …
Permanent link to this article: https://baldric.net/2014/03/31/the-netbook-is-not-dead/
Feb 28 2014
the spy in your bathroom
Back in June 2008 I noted Craig Wright had posted to bugtraq reporting a “remote exploitation of an information disclosure vulnerability in Oral B’s SmartGuide management system”. I found it faintly amusing that a security researcher should have been looking for vulnerabities in a toothbrush. I should have known better. A report in wednesday’s on-line …
Permanent link to this article: https://baldric.net/2014/02/28/the-spy-in-your-bathroom/
Feb 12 2014
checking client-side ssl/tls
At the tail end of last year I mentioned a couple of tools I had used in my testing of SSL/TLS certificates used for trivia itself and my mail server. However, that post concentrated on the server side certificates and ignored the security, or otherwise, offered by the browser’s configuration. It is important to know …
Permanent link to this article: https://baldric.net/2014/02/12/checking-client-side-ssltls/
Feb 12 2014
policy update
An exchange of emails with Mark over at bsdbox.co a day or so ago made me realise that my privacy policy needed updating. Not, I hasten to add, for any fundamental reason, but simply because a couple of the references in that policy were out of date. I have therefore amended it and version 0.2.0 …
Permanent link to this article: https://baldric.net/2014/02/12/policy-update/
Feb 11 2014
privacy matters
The Open Rights Group here in the UK has been campaigning against mass, unwarranted surveillance by GCHQ since the Snowden revelations first emerged in summer of last year. Two of its current campaigns are: “don’t spy on us” and “the day we fight back“. I have signed both of them. I have also written to …
Permanent link to this article: https://baldric.net/2014/02/11/privacy-matters/
Feb 08 2014
compare and contrast
Foreign Secretary William Hague is apparently concerned about press restrictions in Egypt. He has reportedly urged the interim Egyptian government to demonstrate commitment to free expression. The press release on the gov.uk website says: Speaking today about increasing restrictions placed upon journalists and the media in Egypt, Foreign Secretary William Hague said: “I am very …
Permanent link to this article: https://baldric.net/2014/02/08/compare-and-contrast/
Jan 22 2014
dis-unity
The “cloud” is achingly trendy at the moment and new companies offering some-bollocks-as-a-service (SBaaS) keep popping up all over the ‘net. Personally I am extremely unlikely to use any of the services I have seen, I just don’t trust that particular business model. I checked out the website for one of these companies today following …
Permanent link to this article: https://baldric.net/2014/01/22/dis-unity-2/
Jan 21 2014
backblaze back seagate
In October last year I noted that the Western Digital “Green” drives in my desktop and a new RAID server build looked to be in imminent danger of early failure. That conclusion was based on a worryingly high load-cycle count which a series of posts around the net all attributed to the aggressive head parking …
Permanent link to this article: https://baldric.net/2014/01/21/backblaze-back-seagate/
Jan 20 2014
thrust update
I have just run a search for further evidence of the possible compromise at thrustvps and found threads on webhostingtalk, vpsboard, freevps.us and habboxforum amongst others. All of those comments are from people (many, like me, ex-customers) who have received emails like the one I referred to below. So, I guess thrust /do/ have a …
Permanent link to this article: https://baldric.net/2014/01/20/thrust-update/
Jan 19 2014
rage against the machine
I know it is futile to rant about banks. I know also that I should not really expect anything other than crap service from an industry that treats its customers as useful idiots. But yesterday I met with such appalling and unforgiveable stupidity and intransigence that I feel the need to rant here. I have …
Permanent link to this article: https://baldric.net/2014/01/19/rage-against-the-machine/
Jan 18 2014
thrustvps compromised?
I have not used thrust since my last contract expired. I left them because of their appalling actions at around this time last year. However, today I received the following email from them: From: Admin To: xxx@yyy Subject: Damn::VPS aka Thrust::VPS Date: Sat, 18 Jan 2014 03:28:06 +0000 This is a notification to let you …
Permanent link to this article: https://baldric.net/2014/01/18/thrustvps-compromised/
Jan 11 2014
strip exif data
I have a large collection of photographs on my computer. And each Christmas the collection grows ever larger. I use digiKam to manage that collection, but as I have mentioned before, storing family photographs as a collection of jpeg files seems counter intuitive to me. Photographs should be on display, or at least stored in …
Permanent link to this article: https://baldric.net/2014/01/11/strip-exif-data/
Dec 30 2013
http compression in lighttpd
Today I had occasion to test trivia’s page load times. I used the (admittedly fairly dated) website optimization test tool and was surprised to find that it reported that parts of the pages I tested were not compressed before delivery. I have the default compression options set in my lighty configuration file as below: compress.cache-dir …
Permanent link to this article: https://baldric.net/2013/12/30/http-compression-in-lighttpd/
Dec 26 2013
getting close to the nsa
Since my last post there have been a couple more entrants to the Tor logo competition. Neither, strictly speaking, meets the original requested criterion that they be suitable for inclusion in Tor Project team presentations, but each has its merits. The first image below was posted by “David”. I think it captures rather nicely the …
Permanent link to this article: https://baldric.net/2013/12/26/getting-close-to-the-nsa/
Dec 24 2013
merry christmas
As I have noted before, 24 December is trivia’s birthday. My first post dates from 24 December 2006 so trivia is seven years old today. As is now becoming traditional I therefore post again today. And as a reflection of the story which has come to dominate trivia over the latter half of this year …
Permanent link to this article: https://baldric.net/2013/12/24/merry-christmas/
Dec 14 2013
tor boost
Moritz Bartl has just posted some good news. Torservers.net, a volunteer run organisation spread across eight countries which provides high bandwidth Tor servers to the network, has just been awarded $250.000 over two years by the Digital Defenders Partnership. According to Bartl’s press release, with this additional funding: participating Torservers organizations will be able to …
Permanent link to this article: https://baldric.net/2013/12/14/tor-boost/
Dec 12 2013
you choose
A letter in today’s Guardian, signed by someone called Paul Brannen, touched a chord. Brannen commented that it was difficut to find anyone today who did not, apparently, support Mandela’s release from Robben Island. Putting that in perspective, he noted that UK membership of the anti-apartheid movement in the 1980s averaged only 8,500. Brannen concludes …
Permanent link to this article: https://baldric.net/2013/12/12/you-choose/
Dec 10 2013
caption needed
This picture, from the french news agency AFP taken at the memorial service for Nelson Mandela, just cries out for a speech or thought bubble caption (or two). Just what is the First Lady thinking whilst her husband poses with Denmark’s Helle Thorning-Schmidt (with our own dear PM trying desperately to get in on the …
Permanent link to this article: https://baldric.net/2013/12/10/caption-needed/