Showing posts with label cyb. Show all posts
Showing posts with label cyb. Show all posts

2013-12-15

you want my wot?!

11.4: pos.cyb/net.mywot/you want my wot?!
. after I found out I really need to
integrate mywot into chrome browser
in order to post reviews of sites;
I was not so sure I felt safe
having them read my every link;
and, with malware so good at cracking any site,
what is the purpose of a service like mywot
that pretends today's safe site
is likely to be tomorrow's safe site ?
12.15:
. simply trust who you have to;
and have separate virtual machines
for each level of trust;
eg, have at least these levels:
# banks,
# the pit for everyone else .
. when I want to use my bank,
I restart my chromebook
to have its verified boot flush the malware .

2013-12-14

brightness on ubuntu linux fujitsu laptop

10.10: web.cyb/xuw/brightness:
. ubuntu 12.04 LTS screen brightness?
adjust-the-screen-brightness-on-an-acer-aspire-one-d270
cant-adjust-screen-brightness-on-ubuntu-12-04lts
xbacklight
Install it by terminal:
sudo apt-get install xbacklight
Change brightness by xbacklight -set {20..50},
For example, to set medium brightness one would use
xbacklight -set 50

#nsa forces Torvalds' hand? #linux

12.14: intro:
see NSA backdoors all encryption software

12.12: news.cyb/sec/linux/nsa forces Torvalds' hand?:
rt.com:
. MIT-educated cryptographer and Linux developer
Theodore Ts'o stated publically that
he was happy with his decision to resist
earlier pleads from Intel engineers
to have that operating system commit entirely to
RDRAND [intel's on-chip routine] for encryption:
"Relying solely on the hardware random number generator
which is using an implementation sealed inside a chip
which is impossible to audit
is a BAD idea" . Now just three months later,
FreeBSD is rescinding their reliance on Intel and Via’s RNGs.
[by contrast:]
When a petition began circulating in mid-Sept
imploring Linux to stop relying on RDRAND,
one of the OS’s leading developers, Linus Torvalds,
called those who made those pleads "Ignorant" .

2013-12-13

reusing #Apple #iMac #superdrive dvd burner?

10.24: web.cyb/dvd burner enclosure:
. for reusing the mac's burner (or just player?)
I need a dvd enclosure ...
if this doesn't work out,
my mac replacement will have a dvd;
eg, one dell compatible with qubes os
comes with a dvd writer for $35 .
. the chromebook is no place to test the new dvd:
Chromebook can't play USB CD or DVD drives .

2013-12-07

Community-based internet with wireless_mesh_networks

12.5: news.cyb/net/Community-based internet with wireless mesh networks:
. there is software available
that allows our wifi routers to form meshes
with the wifi routers of our neighbors
so we can internet with them
and make use of their out-of-community connection .
... meshing makes a lot of noise
and is unreliable compared to;
better to plan point-to-point networks .

alternatives to wikipedia

12.4: web.cyb/net.wiki/alternatives to wikipedia:
. when considering alternatives to wikipedia
it is more than just a source of info,
it's something that can be edited by the public .
. we need a replacement for wikipedia
that doesn't shun conspiracy theorists;
and esp'ly the replacement must
allow mention of Dr. Judy Wood .
. the replacement should make categories per page,
according to what class of references are allowed:
# sources citable by academics,
# source trusted by the mainstream,
# sources considered to be on the fringe .

2013-11-30

#badBIOS @dragosr vs Mac, Linux and PC

4: cyb/sec/#badBIOS/ 
30: summary:
. malware that spreads via usb devices
can infect other usb devices,
and the problem is not the os;
it is the hardware and usb standards
which expose the os to malware infection .
. Dragos Ruiu talks about a mac infection
which sounds like the one I got;
it prevented me from reinstalling the os;
and it started infecting my chromebook,
but the chrome os was able to clean it up .
. my 2005 ubuntu laptop was not so lucky .
. a laptop in my future that will likely do well
is one running the xen hypervisor,
hardened with the Qubes OS .
(see #Qubes #Xen vs Dragos Ruiu's #badBIOS).

#Qubes #Xen vs Dragos Ruiu's #badBIOS

6: co.cyb/sec/qubes/Xen vs Dragos Ruiu's #badBIOS:
me to qubes-devel 5:41am:
. reading about the #badBIOS infection,
blog.erratasec.com/2013/10/badbios-features-explained.html
I was surprised to learn that all computing accessories
(mouse, trackpad, hub, keyboard, and of course
 flash drives) could have a software-programmable firmware
and this could be infected with malware that could spread
to your next computer if attached to dom0 .
. I was also concerned that a new flash drive malware
-- Dragos Ruiu's #badBIOS --
could infect a next machine without even being mounted;
is this a new threat that xen has yet to adapt to?

2013-10-01

NSA backdoors all encryption software

9.18: news.cyb/sec/NSA backdoors all encryption software:
fierce government it`NSA backdoor:
. the NSA's SIGINT (signals intelligence) Enabling Project
covertly influences or overly leverages
the policies, standards and specifications
of the global cryptography marketplace
to make commercial public key technologies
more crackable by the cryptanalytic capabilities
being developed by the NSA and DOD's
Central Security Service.
. it has used a quarter billion dollars yearly
for at least the past 2 years .

2013-09-26

NSA's globalized internet security

9.26: news.cyb/sec/NSA's globalized internet security:
Sept. 25, 2013, Army Gen. Keith B. Alexander,
Cybercom commander, and director of NSA,
at the National Press Club
or 4th Annual Cybersecurity Summit .

. in the past year, we saw more than 300
distributed denial-of-service attacks
on Wall Street.
We saw destructive attacks against
Saudi Aramco and RasGas [Co. Ltd.],
and against South Korea .

. U.S. Cyber Command (Cybercom)
has activated the headquarters for
one of its 3 Cyber Force branches:
Cyber National Mission Force,
that defends the nation;
Cyber Protection Force
defends DOD's information environment.
and Cyber Combat Mission Force
will provide assistance to the military
to implement cyber counterattacks .
Cybercom teams are now fully operational
and working side by side with NSA
to defend the nation.
The Army, Navy and Marines
trained about a third of the force in 2013
and they will train a third in 2014
and another third in 2015.

2013-09-19

USA intel has SOA on High-Security Internet

9.11: news.cyb/sec/USA intel has SOA on High-Security Internet:
Sept. 11, 2013
Al Tarasiuk, intelligence community CIO
and assistant director of national intelligence .
. the IC ITE ( Intelligence Community
Information Technology Enterprise )
is a new IT environment that will
vastly improve information sharing
across the intelligence community .

. consolidating IT across the community
was driven by budget considerations.
But today,
it's more than an efficiency play on IT:
intelligence integration,
information sharing and safeguarding .
. that translates into 3 goals:
1: effectiveness,
2: security
3: efficiency .
"In the past, these were mutually exclusive,
but now we'll have more of all 3 goals
because of cloud technologies,
and a [SOA (service-oriented architecture)]
or "service-provider-based business architecture"
providing an IC cloud not on the Internet,
but privately hosted on TS|SCI networks
(top secret / Sensitive Compartmented Information)
[18:
. high-security wide-area networks are
connected by Tesla beam transmissions,
which unlike fiber optic cable,
can be transmitted wirelessly,
and are very difficult to intercept .
. the govt denies this technology even exists,
but they've used it to communicate with submarines,
and a chinese-american collaboration is developing it .]

2013-06-19

iMac Mountain Lion infected by Vmware Fusion Ubuntu

19: mis.cyb/mac.vmware/freeze with black screen:
. the usual:
I'm running vmware on a 2008 imac,
my virtual machine is running ubuntu;
I'm using firefox with noscript,
and my editor is komodo edit;
then a freeze requires a hard reset .
but this time,
I catch a keylogger or something ...
[@] mis.cyb/mac/fake log-in after crash

2013-02-26

optical backups are important #WWIII #EMP

2.26: co.cyb/xu/backup/optical media for EMP attacks:
linux/ Span DVD - backup software?/fisheater May 18th, 2012:
 I have 100GB of photos I would like to back up on to DVD
for remote (safety deposit box) backup.
I looked into brasero, but the documentation is lean.
I searched online and the forums with not much luck. 

optical backups are important

2012-10-30

crash predicted after election

8.5: news.cyb/pol/purges/reaganomics/
crash coming in after election:

. at coast to coast an astrologer Joni Patry
has predictions about this november;
she also predicted the japan erthquake in march 2011
and they were very thankful for the heads up .

. she says september is a high:
there will be a major crash in november;
when the election will be like Bush's
with much irate contention about the results .
[. how could that cause a crash?
# obama wins:
people wanting romney
will rage about unemployment endless
and taxes look relentless
this could cause the market to go into theatric lows .
# romney wins:
. people wanting obama
will see obamacare getting dismantled,
and there could be something like a 9-11
to greet a usa that is once again christian-headed . ]

says we should buy xmas gifts now
because the bottom falls out:

2012-09-26

.chm to .html conversion

7.14: news.cyb/xp/.chm to .html conversion:
you need a CHM decompiler
(You can use HTML Help Workshop)
[but it seems that is just a dev's api
not a command line tool ...]
counter-suggestion:
. decompile CHM using the built-in command line tool:
hh.exe . eg,
C:\>HH.EXE -decompile D:/output-folder D:/converted.chm
where "decompile-folder" could be simply "."
Decompiling the file produces a slew of
HTML and image files,
together with the table of contents (.hhc) file,
index (.hhk) file, and a few other supporting files.
The only decompiler with any additional features
is KeyTools,
as this can try to rebuild the project (.hhp) file.
You will need this file if you want to recompile the help project.
One thing to note is that the decompile/recompile
isn't a "round-trip" process.
Certain features that the help author added
to the original help file
can't be recovered when you decompile it,
so these may no longer work properly
after you've recompiled.
This is especially true in the area of
context-sensitive help,
which may be broken in the new version of the file.
7.14: cyb/fs/.chm to .html conversion:
web:
. the .chm file type is microsoft's compiled html
and I found there are decompilers for it
on both xp (built-in) and on ubuntu (openware).
proj: done on xp:
. I did it with hh! [@] see snapshot
. to use the terminal without the help of the
[open a terminal here] file menu item
-- where did that go?!
(I need to be in the admin acct) --
use the run box, and type in cmd.exe;
then try the command
(change directory to virtual drive E)
ie (cd E:)
which is really just link to a long pathname;
then in the hh command,
I'll need to mention the drive in the file paths,
and I'll rename the files
to make my command typing easier;
eg, rename "(programming python.chm) to pp.chm,
create a folder named pp,
and then run this command:
hh -decompile e:\pp e:\pp.chm .
. instantly it's filled with html files
-- data liberation !

mis:
. (cd E:) doesn't work?
likely because I don't own that space?

7.14: mis.cyb/xp/
virtual device has strange permissions:

. I have some ms programs that need their installer cd
to be in the cd drive at all times;
so, running these programs over-uses the cd drive,
and also the drive is slowing down these programs .
. the fix is to copy the cd to a folder,
and then use a command to
associate that folder with some spare drive letter .
. now I want to use that drive as a temp drive;
because when doing commands that use pathnames
it's easier to type in E:\
than C:\documents and settings\myacct\ .
. but I'm having trouble with the permissions,
and they are not found under properties?
I'll have to check a dos cookbook .
. I thought it was the admin's,
so the user would only allow reading not deleting;
but, xp is not letting the admin delete files either?
. so,
now nobody can delete anything from E:,
but anyone can add to it,
and move things within it;
eg, I created a trash folder,
and put all my done work into that folder .
todo:
. the next thing to try is removing the startup script
that creates the virtual device links .
. maybe it will have more permissions then .

mis.cyb/xp/
command line locks the current folder:

. it would not let me move one done folder to trash folder
because it's in use?
the command line's current folder was set to that,
so I moved it out of there (cd ..)
and then I could move it .

mis.cyb/xp/
command line output confused by virtual cd drive:

. I asked if I could (cd doneDir; rm *.*)
and it said it didn't recognized that command;
but it was supposed to remove files, and it did!
no it thought it did,
the finder shows it's still there .
. I can say (cd e:; del trash)
then I can reply sure to the "(are you sure?),
and it comes back having done nothing .

internet with both privacy and security

7.26: co.apt/cyb/sec/cloud computing is not easy:
. I thought cloud computing would be a breeze;
it was just like SOA, right?
only SOA is on a private network,
while cloud computing is using a public network .
. can that even be done securely?
[ it seems like shifting code tech should do it .
. being able to initialize the session
might be complicated .]

7.8: sci.cyb/sec/how to get secure internet?:
. can there be secure communications networks
that are also self healing ?
how can we support openware and anonymity too?
to be anonymous you simply get another service to
send the message for you
but for openware that depends on
whether we need OS cooperation for the security .
[9.26:
. openware-based internet depends on
whether we need OS cooperation for the security?
I don't think the problem is software,
so, having openware wouldn't make the net more secure .
. there are 2 problems:
# denial of service:
. it's too easy for too many machines to be
owned by malware .
# id theft:
. it's too easy to spoof being someone else .
the solution?:
. there should be special hardware available
in order to authenticate your id;
if you don't have that box,
then you can't do banking, credit-card shopping,
and if there's a denial of service attack,
then you can't get through;
because, nodes stop forwarding your messages .]

7.10: news.cyb/sec/
DOD says we can have both privacy and security:
Cybersecurity and American power 7.9:
At an American Enterprise Institute (AEI) event
U.S. Army Gen. Keith B. Alexander
urged us to support cybersecurity legislation
being pushed through Congress .
. it asks internet service providers to
help federal anti-virus software,
by searching all emails for viral signatures,
and reporting malware event parameters
(malware signature, source address, destination address).
. when asked about china's role in the motivation
he reminded us that there is a high cost from malware
due to intellectual property loss via cyber espionage.
"Symantec placed the cost of IP theft
at $250 billion a year .

The director of the National Security Agency (NSA)
and chief at the Central Security Service (CSS)
reemphasized an immense problem the U.S. is facing:
cybercrime has been "the greatest
transfer of wealth in history,"
Alexander said in a statement.
global cybercrime is $114 billion annually
($388 billion when you factor in downtime),
and McAfee estimates that
$1 trillion was spent globally under remediation.
[ you might think the reason we are such targets
is that our foreign policy is so offensive
to so many bright communists and liberals
but, we'd be in the same danger anyway,
because there's so much money to be gained
from cracking our banks and intellectual property .
9.26:
. when they talk about remediation costs
they are referring to having their hands tied
by an internet that is inherently insecure;
I wonder what the cost would have been
if we had just rebuilt the internet from scratch
with security in mind .
. can the surveillance proposed by this legislation
make up for the lack of a dual system,
one that promotes anonymity,
and the other that promotes reliability? ]

unhosted.org

7.10: news.cyb/net.unhosted.org:
@GoogleAppsDev
Tell us what it would take for you to
use "nothing but the web"
- google apps developer../2011/09/
. one reply was:
Unhosted.org-- to separate web apps from user data,
I must be in control of my data.
Once I put my data in the hands of a
third party web service or application,
I am no longer in control.
Unhosted.org ?
Unhosted.org is developing technology that will
put control of user data
back where it belongs: With the user.
Freedom from the web's monopolies
The web is not as open as it used to be:
monopoly platforms formed new proprietary layers on top of it.
But we create a better architecture for the web.
We break the package deal
»you get our app, we get your data«
with remoteStorage,
a cross-origin storage protocol
separating application servers from people's documents.
This enables everyone to use various web services
but keep their data in one place they choose and trust
– their remote storage,
their »home folder« for the web.
The applications will not run on servers you can't control,
but be pure Javascript which runs client-side, in your browser.
And app developers don't need to bother about
providing storage or managing user accounts.
Technically speaking, we define a protocol stack called remoteStorage.
A combination of WebFinger for discovery,
OAuth for authorization,
CORS (Cross-Origin Resource Sharing)
for cross-domain AJAX calls and GET, PUT, DELETE for synchronization.
We also work on its adoption through developing apps like
Libre Docs and Opentabs
as well as making existing apps and storage providers compatible.
If you speak French, there is also some info on Framablog en Français.
Unhosted is a movement by the people, for the people.
Everyone can participate, including you!
Libre Docs – liberate your ideas
libredocs.org
github.com/unhosted/libredocs
Remotestorage providers
github.com/unhosted/website/wiki/remoteStorage-providers
freemium providers:
    OwnCube recommended for end users!
    5apps recommended for javascript developers
domains that provide remoteStorage to their users:
    all Dutch universities
ways to run your own remoteStorage server:
    install pagekite on your computer
github.com/pagekite/plugins-pyUnhosted
    install ownCloud on a server
owncloud.org/
    coming soon: how to use your CouchDB instance as remoteStorage
pagekite
github.com/pagekite/plugins-pyUnhosted
. Unhosted.py is an HTTP server
implementing the bare minimum required for
the simple remoteStorage API from unhosted.org.
Hopefully this program will be useful for folks who want to
study how the remoteStorage protocol works
or as a development tool for people working on Unhosted apps.
As Unhosted matures,
Unhosted.py will hopefully also mature into a usable personal data-store
for people who want to store their Unhosted data on their own devices.
Getting started
Quick-start:
    Install pagekite.py
    In another console:
pagekite.py 6789 rs-YOURNAME.pagekite.me
You should now be able to use
whatever@rs-YOURNAME.pagekite.me
as a remoteStorage account.
If you prefer, you can also
use Unhosted.py without PageKite,
but you will need an SSL enabled
reverse HTTP proxy (such as Pound)
in order to comply with the protocol.
As far as I can tell,
hosting on http://localhost/ won't work.
Play!
5apps.com have written a nice Unhosted tutorial and test app
which works just fine with Unhosted.py.
Hacking
The file Unhosted.combined.py is combination of Unhosted.py
and the HttpdLite.py module it depends on.
For hacking, you'll want to check both out from github:
    Unhosted.py
    HttpdLite.py
The combined "binary" is generated using Breeder.
Where is my data?
Unhosted.py stores data in ~/.Unhosted.py/,
in a relatively intuitive directory structure:
~/.Unhosted.py/USER/CATEGORY/...
Each data folder will contain some regular files,
as well as a file named _RS_METADATA.js.
This meta-data file stores "real" names
for all keys, mime-types
and may store other meta-data in the future.
The meta-data file may also store key values as well,
if they are small and do not really "look like a file".
This is an optimization to reduce clutter and disk seeks
when working with small keys:
if the data is large or looks like an independent file,
it will be written as such to the filesystem,
although the name will probably be sanitized somewhat.
Note that changes to individual files of name:
_RS_METADATA.js
may be overwritten by Unhosted.py if it is running,
as it caches their contents in RAM.
Bugs
    Directory listings do not work yet.
    User names and passwords are ephemeral.
    _RS_METADATA.js could be overwritten by evil apps.
    Saving metadata fails sometimes due to a race condition.

hidden drive solved by permissions repair #mac

7.6: mis.cyb/mac.finder/
hiding the internal drive from user acct:

. my user acct's finder can't see anything on the internal drive
but on a visible external drive
there is a working link to a file on the internal drive,
so I know the files are there .
. the admin acct can see everything .
. there are no updates from Apple .
. use the disk utility app to verify and repair mac's permissions:
they are bad, but before fixing, verify disk is healthy .
web:
. others are seeing this last year,
and by 2 authors the terminal was suggested:
sudo chflags nohidden /
-- all but one mac user was not happy about that fix:
one just never came back to verify it worked;
and the other cracked jokes about
finding a fix by downloading xcode .
. I would find later that
Apple's diskUtility.permissionsFix
would fix my problem of finder hiding everything .

laptop suspended over recliner

7.6: proj.cyb/xuw/making it usable from easy chair:
. since my eyes can only see things a foot from my face,
I'm wondering how to make the laptop usable
while sitting in the easy chair:
. my first idea was to use it with glasses;
(I have some cheap prescription swimming goggles
to allow me to see things resting on my lap;
much cheaper than new scripts from the optometrist).
. I need a tray for another ergo kybd,
I'm using a spare 1ftx3ft plywood as tray
and resting it on arms of nearby chair when not in use ..
comfort keyboard

virginMobile's new outlook

7.9: aq.cell/Virgin Mobile/We Paid Your Monthly Charge
9.26: summary:
. I had to dump Virgin Mobile;
because, they kept double-billing me;
they used to have very high ratings
from Clark Howard
now I'm with tracfone.
. after I cut VM from my credit card
they sent me this piece of cheese ...