Showing posts with label computing. Show all posts
Showing posts with label computing. Show all posts

Monday, March 30, 2009

The inhuman Flash vulnerability

A reliable security exploit for Flash is big news, or at least it should be big news, because Flash is on nearly every graphical browser on nearly every operating system, and there's only one supplier. (Sure, there's Gnash, but that's not yet ready for prime-time, and may never be.) A good exploit against Flash could allow Bad People to p0wn nearly every desktop everywhere. So even though this is a year old, this is still important.

Cyberdyne Systems, er, sorry, IBM researcher Mark Dowd demonstrated an incredible vulnerability that allows a single Trojan to exploit Flash in either IE or Firefox while leaving the Flash runtime operating normally. And it can bypass Vista security. Although Dowd doesn't explicitly mention other OSes, I see no reason to believe the same technique wouldn't work on Linux as well.

Start with the vulnerability.

It’s an integer overflow, but not a simple one.
...
The net result of this silliness is that it’s hard to do what attackers normally do with a write32 vulnerability, which is to clobber a function’s address with a pointer back to their buffer, so that their shellcode is called when the clobbered function is called. So Dowd’s exploit takes things in a different direction, and manipulates the ActionScript bytecode state.
...
Clobber the right value in the length table, and you can make an unused bytecode instruction that the verifier ignores seem much longer than it is. The “extra” bytes slip past the verifier. But they don’t slip past the executive, which has no idea that the unused bytecode has trailing bytes. If those trailing bytes are themselves valid bytecode, Flash will run them. Unverified. Giving them access to the whole system stack. Game over.

Security is hard.

Friday, June 20, 2008

The Internet is how old?

Bill Gates recently visited South Korea, where he declared that the Internet was ten years old. Richi Jennings commented:

Tell that to the National Science Foundation, who switched on the Internet as we know it today in 1983, migrating from the old ARPANET, which had been going since 1969.

He can’t possibly mean the Web, as that’s been going for over 15 years. He can’t even mean Internet Explorer — the first version of which was released in 1994.

Bill Gates was famously slow to notice the Internet. It barely got a mention in the first edition of his book The Road Ahead, although history was extensively revised in the second edition. But surely even Gates remembers Windows 95?

Saturday, March 08, 2008

Not your usual computer horror story

I found an old archive of emails involving computer horror stories: backups gone bad, deleting the wrong files, and so forth.

Somewhere along the line, somebody asked for the more Stephen King-ish style horror stories, about the system clock running backwards, files undeleting themselves, and so forth. That lead to this anecdote:

Many years ago a tiny little college in the middle of nowhere purchased an NCR tower, then a newfangled contraption. A half-dozen of us were using it for an assembly class. The prof should have made his warnings about TRAP a little more clear. One student runs his program and it suddenly begans spawning processes, rapidly filling the machine. The prof came in, amused, logged on as superuser, and killed a process. Another process was immediately spawned. The prof tried again. He was ignored. He was also no longer amused. After several minutes he gave up and turned off the box. The tower didn't even flinch. He pulled the plug. Nothing. He ripped the back off the box and dug around. Finally he found the fuse and pulled it, killing the machine.

Some of us later claimed we heard laughter as it went down.

(Many times since then I have wished other computers came with a backup battery as standard issue.)

Sunday, February 24, 2008

Another reason to hate Flash

There's a lot to hate about Flash video. And yes, I'm aware of the irony of saying this when I myself put Flash videos on my blog. If YouTube would use a decent format, I'd be onto it so fast your head would spin.

It's not a fully open standard, making it near impossible for anyone to create Flash applications that don't depend on Adobe. There are a zillion movie players for .avi, .mpg, and even a handful for .mov, there's only one player for Flash .swf applications. (In fairness, mplayer can, sometimes, play .flv videos. mplayer is awesome!) That's a warning sign of data obsolescence.

Specifications for the Flash formats are only released to developers on the condition that they don't create Flash players. Flash videos contain executable code, which is a serious security hole: it's only a matter of time before somebody creates a virus which runs through Flash, even on Linux. Most Flash applications are poorly written, with terrible user interfaces and buggy implementations: Flash sites frequently lock up my browser. You can't index or search Flash sites, or copy text out of them, and if you are blind and use a screen-reader, web designers who use Flash are giving you a big F-U. And if you're a movie creator, why on Earth would you be happy with the crappy, low resolution, compression-artifact-filled ugliness that is the typical .flv file?

I could go on, but I'll just link to one more reason to avoid Flash if possible: Adobe is now adding Digital Restrictions Management software to the format.

Finally, there's a classic suite of arguments against DRM that will be as true for online video as they were for music. DRM doesn't move additional product. DRM is grief for honest end-users. And there's no reason to imagine that new DRM systems will stop copyright infringement any more effectively than previous systems.

Who owns data?

Ed Felten raises a very important point about many of the debates we have about data portability: we start off by making a poor assumption, and that closes off options.

An example is the Internet storm over Facebook canceling well-known blogger Robert Scoble's account. Scoble had amassed a vast amount of data in his account, and got caught using software tools to export it. Facebook has a vested interest in locking people into their service (more users = more advertising revenue), and the way they have chosen to do this is to give people free accounts, encourage them to invest a lot of time creating valuable (to the users, if not anyone else) data, but prohibit them from extracting that data elsewhere.

Hmmm... I must update my Blogger backup script. It hasn't worked well since Google made the upgrade from Blogger version 1 to version 2.

The poor assumption that we make is that data -- facts -- must be owned by somebody. As Felten says:

Where did we get this idea that facts about the world must be owned by somebody? Stop and consider that question for a minute, and you’ll see that ownership is a lousy way to think about this issue. In fact, much of the confusion we see stems from the unexamined assumption that the facts in question are owned.

Once we give up the idea that the fact of Robert Scoble’s friendship with (say) Lee Aase, or the fact that that friendship has been memorialized on Facebook, has to be somebody’s exclusive property, we can see things more clearly. Scoble and Aase both have an interest in the facts of their Facebook-friendship and their real friendship (if any). Facebook has an interest in how its computer systems are used, but Scoble and Aase also have an interest in being able to access Facebook’s systems. Even you and I have an interest here, though probably not so strong as the others, in knowing whether Scoble and Aase are Facebook-friends.

How can all of these interests best be balanced in principle? What rights do Scoble, Aase, and Facebook have under existing law? What should public policy says about data access? All of these are difficult questions whose answers we should debate. Declaring these facts to be property doesn’t resolve the debate — all it does is rule out solutions that might turn out to be the best.




UPDATE: Chris Finke has an innovative solution to the Facebook problem, one which could (in principle) be extended to all similar such websites. His Facebook Scavenger extension for Firefox lets you capture copies of the data once it's in your browser.

The downside of proprietary data

Mark Pilgrim is a published author, Google employee and long-time Apple Macintosh user and programmer. In the Macintosh universe, he's part of the pantheon: although never an Apple employee, and not quite up there with folks like Andy Hertzfeld, he's nevertheless one of the minor demi-gods of Apple mythology. He also helped create one of the few Mac viruses (the MBDF-A), but co-operated with police on his arrest and paid restitution for the damage done.

Putting aside his checked past, Pilgrim was considered one of the Mac power-user evangelists, so it came an unpleasant shock to the Mac community when he finally discarded his Mac in favour of Linux. There were tears and predictions of doom. Those predictions turned out to be wrong, and Pilgrim is predicting that 2008 will be the year of Linux on the Desktop. (With the sudden expansion of notebooks running Linux, like the EEE, I think those predictions will finally be right. And not before time.)

Not long after jumping ship to Linux, Pilgrim discussed his experiences with long-term data storage, and his frustration with the difficulty of keeping data accessible over a time frame measured in decades instead of months or years. The bottom line? Long-term storage of data is like a series of migrations from data format to data format. Anything which makes that migration harder is going to hurt you. Companies like Apple who don't grok openness are constantly trying to lock people into their products, then change the products. Every time they do that, there's pain and inconvenience for users, and usually the loss of data.

Pilgrim's conclusion is that using open source software and, more importantly, open formats, goes a long way to reducing this problem. You will still need to migrate data from computer to computer (anyone think that the computers of 2028 will still be running Windows Vista?) but the pain will be less.

There’s an important lesson in here somewhere. Long-term data preservation is like long-term backup: a series of short-term formats, punctuated by a series of migrations. But migrating between data formats is not like copying raw data from one medium to another. [...] But converting data into a different format is much trickier, and there’s the potential of data loss or data degradation at every turn.

Fidelity is not a binary thing. Data can gradually degrade with each conversion until you’re left with crap. People think this only affects the analog world, like copying cassette tapes for several generations. But I think digital preservation is actually much harder, in part because people don’t even realize that it has the same issues.

[...]

So if you care about long-term data preservation, your #1 goal should be to reduce the number of times you convert your data from one format to another. You should also strive to increase the fidelity of each conversion, but you may not have any control over that when the time comes. Plus, you may not know in advance how faithful the conversion will be, so planning ahead to reduce the number of conversions is a better bet.

Open source software is not a panacea for this sort of data loss: as Pilgrim discusses, the open source photo-editing software Gimp uses a deliberately undocumented file format that no other application can fully read.

If you care about accessing your data in ten years time, then go read the rest of his conclusions. (And if you care about people accessing your data in 200 years time, print it out on good acid-free paper and deposit it somewhere dry and safe.)

Friday, January 18, 2008

More nonsense about Open Source vulnerabilities

Computer World is claiming that Red Hat Linux and Firefox are "more buggy" than Microsoft Windows.

That at least is the conclusion you are supposed to draw from the article's title, the summary and the opening paragraph:

Windows not that bad after all
By Matthew Broersma, Techworld


Secunia has found that the number of security bugs in the open source Red Hat Linux operating system and Firefox browsers far outstripped comparable products from Microsoft last year.

So they say. But if you read on to midway down the second page of the article, you get a very different picture:

Red Hat [Linux] was found to have by far the most vulnerabilities, at 633, with 99 percent found in third-party components. ...

Windows had only 123 bugs reported, but 96 percent of those were found in the operating system itself.

So let's see how that works. Red Hat Linux, which ships with multiple hundreds of third party applications, almost all of which are non-critical and don't even get installed, has about six vulnerabilities in the operating system. Windows, which ships with a handful of applications, has about 118 vulnerabilities in the OS. According to Computer World, an OS with six vulnerabilities is more buggy than one with 118 vulnerabilities.

Yeah, right. Sure it is. Just how much advertising does Microsoft do with Computer World?

The article goes on:

In the browser field, Firefox led the way with 64 bugs, compared to 43 for Internet Explorer, and 14 each for Opera and Safari.

However, in an examination of zero-day flaws - reported by third parties before a patch was available - Secunia found that Firefox tended to get more patches, sooner, compared to IE.

Out of eight zero-day bugs reported for Firefox in 2007, five have been patched, three of those in just over a week. Out of 10 zero-day IE bugs, only three were patched and the shortest patch time was 85 days.

You got that? The shortest time IE was vulnerable to known security bugs was nearly three months, compared to just over a week for Firefox.

But IE only looks as good as it does because ActiveX bugs are counted separately: IE had no fewer than 339 ActiveX bugs in 2007. If you include them in the count for IE, as you should, then you're comparing 382 for IE versus 64 for Firefox.

You almost -- almost -- have to admire the journalist's gall in trying to push a whopper of this size. Sadly, this sort of behaviour is very common: half-truths and deceptive statements in paragraph one, the actual facts buried deep in the article. That way you're not lying, because all the facts are there.

The people doing this know that there is a strong correlation between the number of readers and how close to the top of the article: for each extra paragraph you bury something under, you reduce the number of readers by a surprisingly large percentage.

I've written about the tendency of the IT press and security industry to make misleading if not dishonest comparisons between Linux and Windows before.

Thursday, January 17, 2008

Don't mess with the geeks

What happens when a clueless US senator pretending to run his own MySpace webpage hires clueless web developers to do the job for him?

In an attempt to prove how 21st century he is, 70-year-old Senator John McCain hired web developers to create his MySpace page. Unfortunately, they hotlinked to the wrong person's files.

When Mike Davidson learnt that McCain was "stealing" his bandwidth, he decided to play a little joke on the Republican senator:

'I think the idea of politicians setting up MySpace pages and pretending to actually use them is a bit disingenuous, so I figured it was time to play a little prank on Johnny Mac.'

Davidson replaced the image referred to in McCain's profile. However, the new image was a lot less prosaic: it described a political about-face by McCain on the subject of gay marriage and a penchant for partnerships between passionate females.

'The only thing necessary to effectively commandeer McCain's page with my own messaging was to simply replace my own sample image on my server with a newly created sample on my server. No server but my own was touched and no laws were broken. The immaculate hack.'

McCain should consider himself lucky that the image wasn't redirected to Goatse Man.

The article is a little sensational, describing it as "the perfect cybercrime" despite admitting that no laws were broken -- except possibly by McCain, who I'm sure had no authorization to use Davidson's computer resources.

Speaking of hotlinking from MySpace, those of you running your own Apache webserver might find this little rewrite rule handy:


RewriteCond %{HTTP_REFERER} ^http://([a-z0-9]+\.)?myspace\.com/ [NC]
RewriteRule (.*) http://collect.myspace.com/index.cfm?fuseaction=signout [redirect,last]


WARNING: I don't run my own webserver, and consequently I haven't actually tested this. No warranty is given. Use at your own risk. If it blows up your computer and eats your dog, don't come crying to me.

Tuesday, September 04, 2007

Information gathering for ATLAS

If the Internet itself was created by the US military to be a redundant, highly-resistant to damage information network, the World Wide Web was created to allow physicists to share data from experiments in subatomic partical physics.

CERN, the birthplace of the WWW, is about to start a series of experiments which will push the boundaries in information gathering, processing and sharing beyond anything ever attempted before. Three-Toed Sloth discuss the incredible engineering work needed for the ATLAS experiments on subatomic particles, and the vast amounts of data the experiments will collect: petabytes -- millions of gigabytes -- per second. Almost twenty years ago, CERN gave us the Web. What will we get in another twenty years?

Wednesday, August 08, 2007

Spell checkers

Why does Kmail's own spell checker not recognise its own name? Why doesn't it recognise offensive when it knows inoffensive?

Kmail spell checker

(Click image for full view.)


The second screen capture wasn't taken by me, it came from a Macintosh, so I can't entirely vouch that this is genuine. But it looks real:

Apple spellchecker
Suggesting "Windows" as a replacement for Linux surely has to be a joke by Apple's developers.

Friday, July 13, 2007

Deleting items from the Firefox address bar

I just discovered a neat trick in Firefox: you can delete items from the address bar without messing about with about:config or editing the history.dat file.

John Bokma's blog has the details. I couldn't get it to work just by pressing Delete, but Shift-Delete works fine for me. Possibly it is a minor difference due to version numbers or one of Firefox's bazillions of configuration settings.

Wednesday, July 04, 2007

This is how computers were meant to look

The steampunk desktop (sans mouse). So much better than beige plastic.

Steampunk desktop

Steampunk LCD monitor and keyboard

(Click images for larger view.)

Instructions for making the keyboard are here and for the LCD monitor here.

Wednesday, March 14, 2007

Bad code smells

This has been around for a few years now, but it is worth reading even if you aren't a C or C++ programmer. Joel Spolsky wrote an entertaining description of how programmers' intuition about bad code grows, and a number of conventions which help make dangerous code "smell bad".

Fifty most influential people on the Internet

PC World has published their list of the fifty most influential people on the Internet, starting with Google's executives, all the way down to "singer"/model Tila Tequila, who redefined "friend" to mean 1.6 million people she's never met.

(No, I'm not linking to her MySpace page. Trust me, you don't want to see it.)

Monday, March 12, 2007

Goodbye XP

After months of planning procrastination, Mrs. Impala's long-suffering Windows XP computer has been cured of atherosclerosis and Alzheimer's disease by an upgrade to Kubuntu.

I've got more experience with Red Hat and the Fedora Core series of distributions, and last time I played with vanilla Ubuntu, I was seriously unimpressed. But Kubuntu seems pretty impressive, and KDE doesn't dumb everything down like Gnome seems to do. And WINE installed flawlessly the first time, unlike my experiences under Fedora Core 5.

And naturally, there was no product activation and we didn't need to register the software. I can change hardware in the PC as often as I like with the operating system deciding that it has been installed on a different PC and refusing to run.

I'll report back after Mrs. Impala and I have had a chance to give it a solid workout.

Update Monday, 13/3/07: Seems I'm not the only one ditching Windows XP for Ubuntu (with or without the K). So is the French Parliament, which is purchasing 1,154 new PCs running Ubuntu.

Sunday, March 04, 2007

Eighty gigabytes

A few days ago, I bought an 80GB hard disk in a USB enclosure. When I plugged it in, I found it was preformatted to two 30GB partitions.

Hmmm. 30+30... carry the two... minus the number you first thought of... you do the maths.

Hard disk manufacturers are notorious for inflating the size of their disks (e.g. an 80GB disk using 1GB = 109 bytes is "really" only 74GB using the traditional 1GB = 230 bytes) but a discrepancy of 25% is ridiculous.

Tuesday, January 09, 2007

The Daily WTF

Thanks to The Daily WTF, we have two examples of corporate information technology gone mad, MAD I SAY, mwahahahahahah!

Security By Insanity:

"You altered ... The Contract!," he insisted.

"Errm ... no," I didn't know how simplify it further him, "this is not a contract unless we both sign it. Nothing has been signed yet. You told me last week that this is just a review copy, and those pencil marks are just my comments about it."

The VP sat silent and confused. He flipped through my copy again, growing more and more disgusted at each pencil mark. He dashed out of the conference room in search of a pencil eraser. He returned moments later, exasperated and unable to find a pencil eraser anywhere in the building because, after all, erasers can be used to alter data and, therefore, were a security risk. Only pens were allowed in the building. Blue ink, to be exact.

He had no idea what to do; he had no access to the tools that could remove my offensive markings on The Contract. I offered this brilliant can-do solution instead: "You could just go back to your desk and print a new copy, right?"

That made no sense to him. No, can't do that. He shook his head. No. NO!!!

I calmly tried to explain it to him: "We don't have to sign this copy of The Contract. If we're going to sign anything, you'd print a fresh copy, and then we would sign that copy."

He couldn't hear me. There were pencil marks on The Contract! Pencil marks! He grabbed my pencil marked pages and bolted out the door again, leaving me alone in the conference room to contemplate the horrible things I had done. After about fifteen minutes, three people entered the conference room. They did not sit. They stood over me. The first speak was the President and Founder of the company.

"Did you ... do this?" she asked referring to pencil markings on The Contract.

Read the rest of the story here.

And then there is the sorry saga of Virtudyne:

The Savior was a self-made billionaire who struck it rich doing the type of business that makes unregulated industries regulated. He heard about Virtudyne's struggles and wanted to help out. He contacted the powers that be and offered some very reasonable terms. In exchange for investing $100M, he would take over operations and sit as chairman on the board of directors. It seemed to be a a win-win for everyone.

[...]

First and foremost, there was the new chief of operations, heralded as a "brilliant innovator" and "technological wizard." He was also The Savior's eldest son. Junior's grasp on technology is best illustrated with this simple anecdote: one day, Junior was walking past Rob Graves' office and saw a graph actively moving around on the screen. He got incredibly exited and wanted to know how he could get the cool looking monitoring software Rob was using to watch their World Wide Server. Rob just didn't have the heart to tell him it was the "Bars and Waves" visulization from Windows Media Player.

[...]

The sales and marketing department were desperate for ideas. They literally couldn't give their software away; anyone with even the most basic knowledge of Google could find out how well Virtudyne's first customer worked out. No one wanted to be their second.

But just then, it dawned on the sales team. They needed to find a market where the Internet had not yet reached. In such a market, their office suite would develop interest and that interest would lead right in to sales. One of the executives knew exactly how to find and penetrate such a market. They would use The Digital Donkey.

Read the rest of the story here.

Tuesday, September 05, 2006

IE website

Microsoft hasn't registered previous IE-related domain names, like ie.com or ie5.com, but then none of these have been used in quite the same way that ie7.com is being used.

ie7.com image
The question is, will Microsoft treat this as beneath their dignity to react to, or as a case of cyber-squatting?

Thursday, August 24, 2006

I'm shocked

You can knock me over with a feather.

As a Linux and former Macintosh user, I'm quite used to being sent proprietary, Windows-only file formats that can't be read except by specific, commercial software -- although it must be said that over the last few years, Linux software has become very good at coping with all sorts of secret file formats. It's been a while I've come across a file I wasn't able to open under Linux.

And then the other day, I received an email with an attached .mht file, and neither Kmail, Firefox, Konqueror or Mozilla seemed able to deal with it correctly.

That's not the shocking thing. The shocking thing is that .mht files are a standard, open file format, with a RFC from 1999 specifying the format: HTML plus external resources such as images, in a MIME encoding. It is simply a MHTML file. Essentially, it is a web page, plus all its images, sounds or other extras, in a single file.

Internet Explorer has supported MHTML in the form of .mht files for years; Opera has recently added support for it. Konquorer does something similar, except it puts the files in a compressed tar ball (.tar.gz or .tgz) and calls it a .war (Web ARchive) file.

As far as I can tell, this is a case where Microsoft has actually done the right thing, using a standard, open file format, and the Linux world is lagging behind. Shocking, but true.

Thursday, August 17, 2006

AOL digging for gold

You couldn't make this stuff up... AOL has got a court order allowing them to dig up a spammer's parents' yard looking for gold and platinum bars.

AOL believe, and have convinced a judge, that the spammer has converted his ill-gained fortune into bullion, which he then buried at his parents' farm.