Wednesday, August 05, 2009

before renewing your cellphone ...

... fancy gadget or alike: please think twice.

Being a somewhat tech-savvy guy I am, I was scared to become aware of this _that_ late, evidently media companies are doing a very good job here also :P.

The mineral (Tantalum) inside the small capacitors used in these tiny electronic devices is fueling the worst contemporary humanitarian crisis in the world, with about 5.4 millon deaths so far.

No further presentation needed since you already have it in your pocket, meet "Coltan".

Wednesday, July 15, 2009

"En los países en serio ... ¡ Se fusila !"

¡ Quién puede ser sino el maeeeessstrooo Capusotto ! :)

Bastante tarde lo encontré, por cierto ... el loco tiene un programa de radio en Rock&Pop: "Lucy en el cielo con Capusottos".

Afortunadamente para los que no podemos escucharlo en vivo (zona horaria, en mi caso), un ilustre compatriota ha ido guardando los programas :)

Que lo disfruten ... , en mi caso tuve que parar el play, para contener el ataque de risa :-O

PD: el siguiente script resulta útil para taggear los archivos, de manera que queden amigables para tu PMP.

id3v2-lucy_con_capus.sh:



# ./id3v2-lucy_con_capus.sh:
# aplica id3v2 tag a todos los Lucy*.mp3 del directorio actual.
# ej:
# Lucy_en_el_cielo_con_Capusottos_1er_Programa_by_vamosmillo2.mp3
# , tomara el primer "conjunto" de numeros para usarlo como nro de track
album="Lucy en el cielo con Capusottos"
for i in Lucy*.mp3;do
track="$(echo "$i" | sed -n -r 's/^[^0-9]+([0-9]+).*/\1/p')"
track=$(printf "%02d" $track)
title="${i%%by*}"
title="${title/?con?Capusottos/...}"
title="${title//_/ }"
(set -x
id3v2 -y 2009 -t "$title" -A "$album" -a Capusotto -T $track "$i"
)
done

Friday, June 05, 2009

select chromium, chrome else firefox as default browser

Now that google-chrome requete-alpha build is published by Google [1], I have this
handy script as my default browser "selector":

#!/bin/bash
#
# $HOME/bin/browser.sh
# Author: JuanJo ( juanjosec O gmail o com )
#
# if running, try: chromium-browser, google-chrome
# else: firefox
#
case "$(ps -oargs= -C chrome)" in
/usr/lib/chromium-browser*)
exec /usr/bin/chromium-browser "$@";;
/opt/google/chrome*)
exec /opt/google/chrome/chrome "$@";;
esac
exec /usr/bin/firefox "$@"
exit $?

# Point2 me with the output from:
for p in /desktop/gnome/{applications/browser/exec,url-handlers/http{,s}/command}; do
echo gconftool-2 -s $p -t string "$HOME/bin/browser.sh \"%s\""
done



In a related note, you can see current milestone (LinuxDev [2]) and what to expect for the next one (LinuxBeta[3]).

[1] Danger: Mac and Linux builds available
[2] Chromium LinuxDev milestone
[3] Chromium LinuxBeta milestone

Monday, June 01, 2009

ads blocking in chromium-browser

ads blocking in chromium-browser

One key missing functionality in chromium is extensibility via browser extensions or user scripts, damn useful in particular for blocking ads.
Although the support is there in the dev channel, it had been not available in the ppa binary debs for a while, but about ~2days ago user scripts started working ... yAY!! \o/

To the point:

dpkg -l chromium-browser # version: 3.0.183.0~svn200905 Chromium browser
mkdir $HOME/.config/chromium/Default/User\ Scripts # yep, nasty white space :P
cd $HOME/.config/chromium/Default/User\ Scripts
wget http://www.adsweep.org/AdSweep.user.js # ala adblock

# ... and then start chromium as:
chromium-browser --enable-user-scripts


To confirm you have it enabled, visit http://www.adsweep.org/ && you'll see a red status line, up-right, with the adsweep script version.

Friday, May 29, 2009

chromium-browser with bookmark keywords

I've been enjoooying chromium-browser on */Linux since last ~3weeks, you'll find lotsa references out there on howto install it, in my ubuntu it boils down to:

echo deb http://ppa.launchpad.net/chromium-daily/ppa/ubuntu hardy main > /etc/apt/sources.list.d/chromium.list
#echo "Acquire::http::Proxy::ppa.launchpad.net DIRECT;" > /etc/apt/apt.conf.d/85launchpad
apt-key adv --recv-keys --keyserver keyserver.ubuntu.com 4E5E17B5
apt-get update
apt-get install chromium-browser

One important functionality I was missing was the ability to create "%s" bookmarks (ala firefox), the nice thing is that it's actually support, tho not "fancy" at the moment because of laking bookmark editor (May/09).
Good news is that you can actually ride it via sql:

#!/bin/bash
# Author: JuanJo
# License: GPLv2+
# Usage: (chromium-browser must not be running)
# ./chromium-browser_keywords.sh ## *see* it, then:
# ./chromium-browser_keywords.sh | sqlite3 $HOME/.config/chromium/Default/Web?Data
# Goodies:
# at the address bar type eg:
# yh tate
# wa theta
# rae teta
# bspot juanjosec

KEYWORDS="
yh http://search.yahoo.com/search?p=%s
wa http://www.wolframalpha.com/input/?i=%s
rae http://buscon.rae.es/draeI/SrvltConsulta?TIPO_BUS=3&LEMA=%s
bspot http://%s.blogspot.com
#foo http://%s.foo.com/
"
while read k url;do
case "$k" in ""|\#*) continue;;esac
echo -n "INSERT INTO keywords (short_name, keyword, favicon_url, url) "
echo "VALUES ('$k','$k','about:blank','$url');"
done < <(echo "$KEYWORDS"| sed 's/%s/{searchTerms}/')


Incidentally nuff, I'm now at a roaming session I need to last +4hs, so I closed my ff-3.1b3 cpu toaster and left riding entirely on chrome-browser (who needs flash after all ?).

Thursday, March 19, 2009

Copying isn't theft ...

Nina Paley, the talented cartoonist, sings the copyright song.

Hear it ... it's refreshing, and full of truth :-


Nina Sings "Copying Isn't Theft" from Reel 13 on Vimeo.

clapClapClapp....

Monday, February 16, 2009

conference: Security Clouds in the Horizons --by Adi Shamir

I had the invaluable chance to attend Adi Shamir [1]'s conference "Security Clouds in the Horizons" or "Why I'm skeptical about Cloud Computing", given at Google's offices.

Below are my ~raw notes (taken with Freemind[2], then exported to HTML), meaning: a GiAnT disclaimer about the possible inaccuracy of these, YHBW.
  • Cloud Computing
    • [def] from wikipedia (~fine)
      • dynamically scalable virtualised resources
      • as a service
      • over the Internet
    • "... not new to me" [sic]
      • 1960 -> John McCarthy : cimputation may someday be organized as a public utility
        eg. municipality -> computaion bureau
      • 1960: small number of large service centers
      • 1980: small companies with self managed DC (data center)

  • Q: Which type of system should be more secure in principle: Cloud or Self-managed ?
    • Cloud:
      • more experienced companies
      • -> more secure systems
      • -> BUT more attractive TARGETS for attacks
    • Computer insecurity
      • old problem, 1st recorded incident: RFC 602 (at ARPANET, aprox 100 computers)
  • Safety vs security [definition]
    • Safety
      • "YOU vs NATURE"
        • reliability issues, etc
      • difficult to achieve
        • eg. building a car which is perfectly safe to drive
          • very complicated
          • very expensive
          • very slow and cautious
    • Security
      • _MALICIOUS_
        • ++harder to deal
          • they know your defensive measures
          • they know your weaknesses
        • eg. design a car that resist eg
          • dropping sugar in the gas tank
          • putting explosives near the engine
  • Q: Is cloud computing more secure than company-centric computing?
    • 1: remote data storage
      • privacy
        • no problem iff KEY is *local* (send/store only encripted data)
      • reliability
        • much better for the cloud
    • 2: remote code execution
      • security of the data IN the hands of the provider (!)
      • diff. types of threats [classif]:
        • dishonest employees
          • a single "bad apple" can cause a LOT of damage
        • amateur hackers (script kiddies)
          • motivation proportional to SIZE
          • for recognition/ego
        • professional hackers (data thieves)
          • make money, spionage, etc
          • they carefully choose their target,
            they spend time and money for the attack, etc

          • ++attractive to break bigger systems
          • ++motivation: *high* reward/effort ratio
        • cyber terrorists using sophisticated cross border attacks
          • motivation: create *PANIC*
            • economic damage
            • make ppl to not trust
              • banks, govt, etc
        • discreet govt intervention
          • terrified by being discovered
            (political fallout of public disclosure)
            • ++risk if cloud (vs small DCs)
          • they ARE applying pressure (no doubt!)
      • Can cryptography solve the security issue ?
        • theoretical solutions
          • multiparty computation protocols
          • totally UNREALISTIC
          • VERY difficult
    • How do you BREAK the security of cloud computing ?
      • side channel attacks
        • use phyisics to overcome math
        • cryptanalytic attack: "cache attacks"
          • pure software attack
          • very efficient
          • full 128bit AES key extraction from Linux encrypted file system in 65ms
            • require only the ability to run code in parallel on the target physical location
          • can compromise eg VPN/aes =)
          • can be used to attack any Virtualization technique
            (jail, Xen, UML, Virtual PC , VMware)
          • very hard to protect against WITHOUT a major performance penalty
          • solution? turn off caching when encrypting ?
            • problem: @BIOS setup
            • speed (!)
          • HOW is the attack done:
            • look for the time delay in accessing mainmem vs cache while accessing the idx in the 1st table lookup, because:
            • for AES: finding the KEY == finding the INDEX of the 1st lookup table for a known plaintext *and* you can force the plaintext (eg encrypted harddisk, vpn).
        • another example: normal PC "noise"
          • signal processing of that noise, correlated to diff CPU ops, using FFT: patterns clearly shown, eg:
            • RSA key generation
            • HLT, MUL, ADD, etc
            • found: 2nd power supply capacitors
      • big problem with "virtualization":
        • the UNDERLYING physical CPU *is* the same
          • by stressing the "common" underlying resource
            another process @another VM can "discover"
            this sharing

        • using birthday paradox, you can reasonably "discover":
          • aprox number of physical processors in the network
          • aprox number of VMs
          • Virt-to-Phy processor allocation "spread" (eg for loadbalancing load/resources)
[1] http://en.wikipedia.org/wiki/Adi_Shamir
[2] http://freemind.sourceforge.net/