<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-2390611717677315220</id><updated>2011-11-18T21:30:32.864-08:00</updated><category term='ipod'/><category term='tips'/><category term='hardware'/><category term='apple'/><category term='security'/><category term='ubuntu-planet'/><title type='text'>mdeslaur</title><subtitle type='html'>Random ramblings of a shell junkie.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://mdeslaur.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2390611717677315220/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://mdeslaur.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>mdeslaur</name><uri>http://www.blogger.com/profile/05506714028603312467</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>20</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-2390611717677315220.post-7656969204703583571</id><published>2011-11-18T21:30:00.000-08:00</published><updated>2011-11-18T21:30:33.059-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ubuntu-planet'/><title type='text'>Where's Chuck 2</title><content type='html'>&lt;a href="http://farm7.staticflickr.com/6050/6361508901_7f126b18d7.jpg"&gt;&lt;img src="http://farm7.staticflickr.com/6050/6361508901_7f126b18d7.jpg" width="400"&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2390611717677315220-7656969204703583571?l=mdeslaur.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mdeslaur.blogspot.com/feeds/7656969204703583571/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2390611717677315220&amp;postID=7656969204703583571' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2390611717677315220/posts/default/7656969204703583571'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2390611717677315220/posts/default/7656969204703583571'/><link rel='alternate' type='text/html' href='http://mdeslaur.blogspot.com/2011/11/wheres-chuck-2.html' title='Where&apos;s Chuck 2'/><author><name>mdeslaur</name><uri>http://www.blogger.com/profile/05506714028603312467</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2390611717677315220.post-708950116884760918</id><published>2011-11-18T18:13:00.001-08:00</published><updated>2011-11-18T18:22:52.329-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ubuntu-planet'/><title type='text'>Where's Chuck?</title><content type='html'>&lt;a href="http://farm7.staticflickr.com/6038/6360846011_cbcb94a107_z.jpg"&gt;&lt;img src="http://farm7.staticflickr.com/6038/6360846011_cbcb94a107_z.jpg" width="400" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2390611717677315220-708950116884760918?l=mdeslaur.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mdeslaur.blogspot.com/feeds/708950116884760918/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2390611717677315220&amp;postID=708950116884760918' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2390611717677315220/posts/default/708950116884760918'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2390611717677315220/posts/default/708950116884760918'/><link rel='alternate' type='text/html' href='http://mdeslaur.blogspot.com/2011/11/wheres-chuck.html' title='Where&apos;s Chuck?'/><author><name>mdeslaur</name><uri>http://www.blogger.com/profile/05506714028603312467</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2390611717677315220.post-6515875247482205728</id><published>2011-10-17T08:43:00.000-07:00</published><updated>2011-10-17T08:43:25.882-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ubuntu-planet'/><category scheme='http://www.blogger.com/atom/ns#' term='tips'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><title type='text'>How to disable the guest account in Oneiric</title><content type='html'>Ubuntu 11.10 now ships with the guest account available at the LightDM login screen.&lt;br /&gt;&lt;br /&gt;This new feature isn't really a security issue, since by default using it requires physical access, and it is confined with an AppArmor profile. If an attacker has physical access to your laptop, all bets are off.&lt;br /&gt;&lt;br /&gt;The guest account can be disabled by editing /etc/lightdm/lightdm.conf and adding "allow-guest=false" to the "SeatDefaults" section.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2390611717677315220-6515875247482205728?l=mdeslaur.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mdeslaur.blogspot.com/feeds/6515875247482205728/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2390611717677315220&amp;postID=6515875247482205728' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2390611717677315220/posts/default/6515875247482205728'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2390611717677315220/posts/default/6515875247482205728'/><link rel='alternate' type='text/html' href='http://mdeslaur.blogspot.com/2011/10/how-to-disable-guest-account-in-oneiric.html' title='How to disable the guest account in Oneiric'/><author><name>mdeslaur</name><uri>http://www.blogger.com/profile/05506714028603312467</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2390611717677315220.post-2927229984946208885</id><published>2011-09-17T05:30:00.000-07:00</published><updated>2011-09-17T05:46:59.593-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ubuntu-planet'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><title type='text'>Introducing the Pasaffe password manager</title><content type='html'>For the past few years, I had been storing my passwords in an application called &lt;a href="http://projects.netlab.jp/gpass/"&gt;GPass&lt;/a&gt;. What I liked about it when I started using it at that time was its simplicity, and the fact that each entry in the database has a notes field that can be used for any additional information that the predetermined fields don't handle.&lt;br /&gt;&lt;br /&gt;Unfortunately, it doesn't seem to be actively developed anymore, and has been dropped from the &lt;a href="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=617590"&gt;Debian&lt;/a&gt; and Ubuntu archives. What's more, I've never looked closely at how secure the database format is, and there is no way to open the database it creates on other devices, such as my phone.&lt;br /&gt;&lt;br /&gt;I started looking for a replacement about six months ago, and I didn't like most of the ones I tried. Some of them used a &lt;a href="http://www.fpx.de/fp/Software/Gorilla/"&gt;cross-platform GUI toolkit&lt;/a&gt; which made the app cumbersome to use. Others were &lt;a href="http://www.keepassx.org/"&gt;too complex&lt;/a&gt;, didn't have a place to store notes, or were &lt;a href="http://oss.codepoet.no/revelation/wiki/Home"&gt;no longer actively maintained&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Since I've been wanting to learn GTK programming for a long time, this presented itself as a great opportunity. I started by looking at the popular password database formats, and the one that stood out was the one used by &lt;a href="http://www.blogger.com/blogger.g?blogID=2390611717677315220" ref="http://passwordsafe.sourceforge.net/"&gt;PasswordSafe&lt;/a&gt;. It is &lt;a href="http://passwordsafe.svn.sourceforge.net/viewvc/passwordsafe/trunk/pwsafe/pwsafe/docs/formatV3.txt?revision=4348&amp;amp;view=markup"&gt;well documented&lt;/a&gt;, well designed, and has implementations available on &lt;a href="http://passwordsafe.sourceforge.net/relatedprojects.shtml"&gt;numerous platforms&lt;/a&gt;. I implemented a Python library to read and write the database format, and then proceeded to use the excellent &lt;a href="https://wiki.ubuntu.com/Quickly"&gt;Quickly tool&lt;/a&gt; to create the initial GTK user interface. Since I want my app to run on the latest LTS release, Lucid, I decided to stick with &lt;a href="http://www.pygtk.org/"&gt;PyGTK&lt;/a&gt; for now instead of &lt;a href="http://live.gnome.org/PyGObject"&gt;PyGObject&lt;/a&gt;. I plan on converting it to PyGObject for the next LTS release. After having developed it for a while, I feel it's in a good enough state to be used.&lt;br /&gt;&lt;br /&gt;Introducing: &lt;a href="https://launchpad.net/pasaffe"&gt;Pasaffe!&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;You can find the upstream project page &lt;a href="https://launchpad.net/pasaffe"&gt;here.&lt;/a&gt;&lt;br /&gt;You can install it from a PPA &lt;a href="https://launchpad.net/%7Emdeslaur/+archive/pasaffe"&gt;here.&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;If anyone wants to contribute to it, there's a list of currently unimplemented features and other things that need to be done in the &lt;a href="http://bazaar.launchpad.net/%7Emdeslaur/pasaffe/trunk/view/head:/TODO"&gt;TODO file&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2390611717677315220-2927229984946208885?l=mdeslaur.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mdeslaur.blogspot.com/feeds/2927229984946208885/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2390611717677315220&amp;postID=2927229984946208885' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2390611717677315220/posts/default/2927229984946208885'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2390611717677315220/posts/default/2927229984946208885'/><link rel='alternate' type='text/html' href='http://mdeslaur.blogspot.com/2011/09/introducing-pasaffe-password-manager.html' title='Introducing the Pasaffe password manager'/><author><name>mdeslaur</name><uri>http://www.blogger.com/profile/05506714028603312467</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2390611717677315220.post-799760277826952547</id><published>2011-05-31T14:38:00.001-07:00</published><updated>2011-05-31T14:50:22.316-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ubuntu-planet'/><title type='text'>Check your cron jobs...</title><content type='html'>Yesterday, a PAM security update was &lt;a href="http://www.ubuntu.com/usn/usn-1140-1/"&gt;released&lt;/a&gt;. Unfortunately, it introduced a regression which caused the cron daemon to stop working with a &lt;a href="https://launchpad.net/bugs/790538"&gt;"Module is unknown" error&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;The updates were quickly pulled from the archive, and a &lt;a href="http://www.ubuntu.com/usn/usn-1140-2/"&gt;regression fix has been released&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;If you have servers or desktops configured with unattended updates, they may have gotten updated with the broken release. If so, cron jobs will have stopped and updates will no longer be automatically installed.&lt;br /&gt;&lt;br /&gt;You may fix this problem by performing one of the following actions:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Rebooting your machine&lt;/li&gt;&lt;li&gt;Restarting your cron daemon ("sudo /etc/init.d/cron restart")&lt;/li&gt;&lt;li&gt;Updating to the latest PAM packages (with Update Manager, or apt-get)&lt;/li&gt;&lt;/ul&gt;This is a rather unfortunate situation, and steps have been implemented to make sure a similar issue doesn't happen with PAM updates in the future.&lt;br /&gt;&lt;br /&gt;We apologize for the inconvenience.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2390611717677315220-799760277826952547?l=mdeslaur.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mdeslaur.blogspot.com/feeds/799760277826952547/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2390611717677315220&amp;postID=799760277826952547' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2390611717677315220/posts/default/799760277826952547'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2390611717677315220/posts/default/799760277826952547'/><link rel='alternate' type='text/html' href='http://mdeslaur.blogspot.com/2011/05/check-your-cron-jobs.html' title='Check your cron jobs...'/><author><name>mdeslaur</name><uri>http://www.blogger.com/profile/05506714028603312467</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2390611717677315220.post-701141305894484455</id><published>2011-04-13T12:14:00.000-07:00</published><updated>2011-04-13T14:44:44.432-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ubuntu-planet'/><title type='text'>Self-Encrypting Hard Disks</title><content type='html'>I travel a lot with my laptop, and it can contain private information that shouldn't get disclosed if it's ever lost or stolen. For this reason, I've been using various types of disk encryption over the years, such as &lt;a href="https://help.ubuntu.com/community/EncryptedHome"&gt;Ubuntu's encrypted home directory&lt;/a&gt; feature, to reasonably assure that my data remains private.&lt;br /&gt;&lt;br /&gt;A few things have always bothered me with software encryption though. The first thing is the fact that software encryption is non-transparent. Although slight, there is a performance penalty in encrypting every read and write to your hard disk. Some people choose to only encrypt certain things to try and reduce that penalty. Do I only encrypt my home directory? What about my swap file or the /tmp directory? If I encrypt my swap file, do I give up hibernation, or do I make it ask me for a passphrase when I boot? What happens in case of disaster? Will I be able to boot a recovery cd and gain access to my data? Will I have saved the passphrase/encryption key somewhere safe in case an emergency arises?&lt;br /&gt;&lt;br /&gt;Another issue is the fact that the decryption key necessary to access my encrypted volumes is located somewhere in RAM. There are a bunch of reasons why this is worrisome, from &lt;a href="http://en.wikipedia.org/wiki/Cold_boot_attack"&gt;“Cold Boot”&lt;/a&gt; attacks, to hibernation, to simply having it leaked in some other way.&lt;br /&gt;&lt;br /&gt;But the biggest gripe I have with software encryption is the &lt;a href="http://www.schneier.com/blog/archives/2009/10/evil_maid_attac.html"&gt;“Evil Maid”&lt;/a&gt; scenario. Basically, every time I leave my laptop unattended, someone could boot off removable media, or physically plug my hard disk in another computer, and alter the software that is loaded before my encrypted volumes. The altered software could send them my encryption password as I type it, or could wait around for my volumes to be mounted before installing a back door. I need to stay physically present with my laptop at all times to make sure this scenario isn't possible, something I'm not always prepared to do. Although laptops are expensive, the loss or theft of an encrypted laptop is limited to the value of the hardware, not the incalculable value of its contents. Leaving my &lt;a href="http://www.dell.com/us/dfh/p/inspiron-mini9/pd"&gt;netbook&lt;/a&gt; in my hotel room is an easy choice to make if all I stand to lose is a couple of hundred dollars.&lt;br /&gt;&lt;br /&gt;Since the hard disk that came with my Lenovo Thinkpad was a little small for my taste, I decided to replace it with a bigger one. In doing so, I specifically paid $20 more to get a model with &lt;a href="http://www.hitachigst.com/internal-drives/self-encrypting-drives/"&gt;FIPS 197 certified hardware encryption&lt;/a&gt;. These hard disks will encrypt everything that is stored on the physical platters with &lt;a href="http://www.hitachigst.com/support/index-files/bulk-data-encryption-faq-index"&gt;AES 128bit encryption&lt;/a&gt;, and a random key. When the disk is powered on, a standard ATA password is required to access it, and the password cannot be reset; if it is lost, the disk is no longer usable. A master password can be set that can be used to reinitialize the random key, so the disk is usable, but the data contained is lost.&lt;br /&gt;&lt;br /&gt;Fortunately, most &lt;a href="http://www-307.ibm.com/pc/support/site.wss/MIGR-69621.html"&gt;ThinkPad models come with the required BIOS support&lt;/a&gt; for disk encryption, so simply swapping the hard disk and setting a password in the BIOS screen was enough to get it working. Not all computer manufacturers have implemented the ATA security set, so you need to check carefully. Apparently &lt;a href="http://www.hitachigst.com/support/index-files/bulk-data-encryption-faq-index"&gt;MacBooks&lt;/a&gt; &lt;a href="http://seagate.custkb.com/seagate/crm/selfservice/search.jsp?DocId=206011#4"&gt;don't have it&lt;/a&gt;, for instance.&lt;br /&gt;&lt;br /&gt;For under $100, I now have an encrypted 500GB hard disk in my laptop that asks for a passphrase when I boot. Is this solution perfect? No. But, it's better than what I had before, and is perfectly adequate for my piece of mind.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2390611717677315220-701141305894484455?l=mdeslaur.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mdeslaur.blogspot.com/feeds/701141305894484455/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2390611717677315220&amp;postID=701141305894484455' title='7 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2390611717677315220/posts/default/701141305894484455'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2390611717677315220/posts/default/701141305894484455'/><link rel='alternate' type='text/html' href='http://mdeslaur.blogspot.com/2011/04/i-travel-lot-with-my-laptop-and-it-can.html' title='Self-Encrypting Hard Disks'/><author><name>mdeslaur</name><uri>http://www.blogger.com/profile/05506714028603312467</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>7</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2390611717677315220.post-7188228424087126519</id><published>2010-11-07T11:08:00.000-08:00</published><updated>2010-11-07T11:28:21.762-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ubuntu-planet'/><category scheme='http://www.blogger.com/atom/ns#' term='tips'/><title type='text'>Netbook screen resolution</title><content type='html'>I love my &lt;a href="http://en.wikipedia.org/wiki/Dell_Mini_9#9_Series"&gt;Dell Mini 9&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;I'm back from UDS in Orlando, and have once again spent a whole week on my Mini 9. It's got a webcam so I can call home, and has bluetooth so I can use an external mouse without plugging in a dongle when the need arises. Although I've tried netbooks with 92% keyboards, I'm not ready to sacrifice portability by adding the extra 2 inches required to fit them. The keyboard on the Mini 9 has the perfect feel for such a small keyboard, and I've gotten quite used to it.&lt;br /&gt;&lt;br /&gt;The only thing I can't quite get used to is the native screen resolution: &lt;a href="http://en.wikipedia.org/wiki/WSVGA#WSVGA_.28576p.29"&gt;1024x600&lt;/a&gt; is not a lot of screen real estate to work with.&lt;br /&gt;&lt;br /&gt;The other day I was looking at the &lt;a href="http://manpages.ubuntu.com/manpages/maverick/en/man1/xrandr.1.html"&gt;xrandr documentation&lt;/a&gt;, and I noticed it supports screen scaling. I now regularly use the following command:&lt;br /&gt;&lt;br /&gt;xrandr --output LVDS1 --scale 1.25x1.25&lt;br /&gt;&lt;br /&gt;This scales my 1024x600 netbook screen to 1280x750, which is really cool when trying to view &lt;a href="http://summit.ubuntu.com/"&gt;large web pages&lt;/a&gt;, or &lt;a href="http://projects.gnome.org/evolution/"&gt;any other application&lt;/a&gt; that uses a lot of screen space. The downside of this is a slight blurriness that is, in my opinion, an acceptable trade-off.&lt;br /&gt;&lt;br /&gt;Unfortunately it doesn't look like there's a way to set scaling in the &lt;a href="http://library.gnome.org/users/user-guide/stable/goscustdesk-70.html.en"&gt;GNOME Monitor Preferences&lt;/a&gt; tool.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2390611717677315220-7188228424087126519?l=mdeslaur.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mdeslaur.blogspot.com/feeds/7188228424087126519/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2390611717677315220&amp;postID=7188228424087126519' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2390611717677315220/posts/default/7188228424087126519'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2390611717677315220/posts/default/7188228424087126519'/><link rel='alternate' type='text/html' href='http://mdeslaur.blogspot.com/2010/11/netbook-screen-resolution.html' title='Netbook screen resolution'/><author><name>mdeslaur</name><uri>http://www.blogger.com/profile/05506714028603312467</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2390611717677315220.post-5059482103412907293</id><published>2010-10-07T06:43:00.000-07:00</published><updated>2010-10-22T05:44:05.992-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ubuntu-planet'/><category scheme='http://www.blogger.com/atom/ns#' term='tips'/><title type='text'>Stuck on dial-up (Updated)</title><content type='html'>My mother has been a happy Ubuntu user ever since I installed Dapper to solve the &lt;a href="http://support.microsoft.com/default.aspx?scid=gp;en-us;windowsmegeneralprotection"&gt;countless&lt;/a&gt; &lt;a href="http://www.pchell.com/support/tildefile.shtml"&gt;problems&lt;/a&gt; she was having with &lt;a href="http://www.pcworld.com/article/125772-2/the_25_worst_tech_products_of_all_time.html"&gt;Windows Me&lt;/a&gt;. Since her computer is starting to age, and she's a 5-hour drive away, I bought her a brand new computer for her birthday, which I've been installing with Lucid this week.&lt;br /&gt;&lt;br /&gt;Problem is, she is still &lt;a href="http://www.pcworld.com/article/136441/rural_us_doomed_to_dialup.html"&gt;stuck on Dial-Up internet access&lt;/a&gt; no matter how hard she's tried to get broadband from the local phone and cable companies.&lt;br /&gt;&lt;br /&gt;Unfortunately, &lt;a href="http://projects.gnome.org/NetworkManager/"&gt;NetworkManager&lt;/a&gt; still doesn't have 56K modem support, so a few steps are necessary to setup Ubuntu for dial-up.&lt;br /&gt;&lt;br /&gt;Since her phone line is noisy, I purchased a &lt;a href="http://www.usr.com/products/modem/modem-product.asp?sku=USR5686G"&gt;reliable modem&lt;/a&gt; that doesn't need special drivers to work in Linux, along with an appropriate USB-to-serial adaptor.&lt;br /&gt;&lt;br /&gt;Once I made sure the modem was visible by searching through dmesg for the right serial port, and testing it with minicom, I performed the following steps:&lt;br /&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Installed the gnome-ppp package&lt;/li&gt;&lt;li&gt;Added her user to the "dip" group so gnome-ppp could spawn the pppd daemon&lt;/li&gt;&lt;li&gt;Configured gnome-ppp with the phone number, username and password provided by her ISP&lt;/li&gt;&lt;/ol&gt;&lt;br /&gt;Once that was done, connecting to the Internet worked great, except for a single problem: Firefox would always start up in "Work Offline" mode. It turns out Firefox uses NetworkManager to figure out if an Internet connection is available when it starts. To fix this:&lt;br /&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Type "about:config" in the Firefox URL bar&lt;/li&gt;&lt;li&gt;Search for the "toolkit.networkmanager.disable" key&lt;/li&gt;&lt;li&gt;Switch it to "true"&lt;/li&gt;&lt;/ol&gt;&lt;br /&gt;I'm looking forward to seeing her go from Hardy to Lucid this weekend!&lt;br /&gt;&lt;br /&gt;Updated 2010-10-22:&lt;br /&gt;&lt;br /&gt;So, I ran into a couple of extra difficulties when I actually installed her new computer. It seems her ISP uses CHAP or PAP to authenticate which wasn't the case when I tried connecting with my ISP at home. Gnome-PPP uses WvDial to perform the actual dialing, and WvDial tries to add the necessary authentication information itself to the /etc/ppp/pap-secrets and /etc/ppp/chap-secrets files. Problem is, those files are owned by root and are 600 by default. The pppd man page states "this file should be owned by root and not readable or writable by any other user. Pppd will log a warning if this is not the case.", so this isn't an easy problem to solve. Since I didn't want her running gnome-ppp as root, I changed both files' ownership to root:dip and permissions to 660. This allowed gnome-ppp to authenticate to her ISP, even though pppd is logging a warning.&lt;br /&gt;&lt;br /&gt;The second problem I encountered was that Evolution would always come up as offline. Like Firefox, it integrates with NetworkManager to check if the computer is online. Unfortunately, unlike Firefox, Evolution doesn't seem to have a way to disable NetworkManager integration. Since time was limited, and I knew she wouldn't be using the Ethernet port on her computer, I simply disabled NetworkManager entirely by editing the /etc/init/network-manager.conf file.&lt;br /&gt;&lt;br /&gt;My stepfather owns a Dell Vostro laptop with Lucid on it, and uses it to connect to the high-speed wireless network at work. He asked me if I could get a modem for his laptop so he could use Dial-Up when at home. I'm not sure how I will be able to handle this for now, as disabling NetworkManager won't be an option in his case...&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2390611717677315220-5059482103412907293?l=mdeslaur.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mdeslaur.blogspot.com/feeds/5059482103412907293/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2390611717677315220&amp;postID=5059482103412907293' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2390611717677315220/posts/default/5059482103412907293'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2390611717677315220/posts/default/5059482103412907293'/><link rel='alternate' type='text/html' href='http://mdeslaur.blogspot.com/2010/10/stuck-on-dial-up.html' title='Stuck on dial-up (Updated)'/><author><name>mdeslaur</name><uri>http://www.blogger.com/profile/05506714028603312467</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2390611717677315220.post-6325381273465594920</id><published>2010-09-30T07:54:00.000-07:00</published><updated>2010-09-30T08:01:59.776-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ubuntu-planet'/><title type='text'>New GPG key!</title><content type='html'>In accordance to the Ubuntu Security team's &lt;a href="https://wiki.ubuntu.com/SecurityTeam/GPGMigration"&gt;GPG key transition plans&lt;/a&gt;, I now have a new GPG key capable of generating SHA-2 signatures.&lt;br /&gt;&lt;br /&gt;If you've signed my old key (40B8CCDA) in the past, I would appreciate it if you could take a look at my &lt;a href="http://people.canonical.com/%7Emdeslaur/key-transition-2010-09-30-mdeslaur.txt"&gt;transition statement&lt;/a&gt;, and sign my new key (A744BE93).&lt;br /&gt;&lt;br /&gt;Thanks!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2390611717677315220-6325381273465594920?l=mdeslaur.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mdeslaur.blogspot.com/feeds/6325381273465594920/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2390611717677315220&amp;postID=6325381273465594920' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2390611717677315220/posts/default/6325381273465594920'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2390611717677315220/posts/default/6325381273465594920'/><link rel='alternate' type='text/html' href='http://mdeslaur.blogspot.com/2010/09/new-gpg-key.html' title='New GPG key!'/><author><name>mdeslaur</name><uri>http://www.blogger.com/profile/05506714028603312467</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2390611717677315220.post-7398079244300505571</id><published>2010-04-23T05:29:00.000-07:00</published><updated>2010-04-23T09:20:13.400-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ubuntu-planet'/><title type='text'>Trying to switch to Empathy</title><content type='html'>I try to dogfood as much as possible. I try to use the actual applications Ubuntu ships by default for everyday things like web browsing, email and IM. I believe this is the best way for applications to get tested properly, fixed, and improved. If developers don't use the default applications because they are buggy, or don't contain necessary features, how can we expect them to be appropriate for regular users?&lt;br /&gt;&lt;br /&gt;I've been a &lt;a href="http://www.pidgin.im/"&gt;Pidgin&lt;/a&gt; user for years. It's a great, but now there's a new kid in town: &lt;a href="http://live.gnome.org/Empathy"&gt;Empathy&lt;/a&gt;, which is now the default IM client installed in Ubuntu and other distros. This week, I am attempting to switch from Pidgin to Empathy. So far so good. It's working pretty great, except for one thing: I keep missing the notifications when people send me messages.&lt;br /&gt;&lt;br /&gt;If I already have a chat window open with someone in Empathy, and the person sends me a new message, I get notified in three ways: I get a temporary notify-osd message, the Indicator Applet envelope turns green, and the window in my window list flashes for a few seconds and stays highlighted and bold.&lt;br /&gt;&lt;br /&gt;Most of the time, I miss the notify-osd popup, as I'm typing something, and tend to always finish before looking up at the alert. Once I do, I rarely have time to read the whole thing before it disappears. My Indicator Applet envelope is green most of the day as I almost always have unread messages in my Inbox. But as soon as I finish the task I'm doing and go to switch windows with the window list, I notice the highlighted and bold window demanding attention.&lt;br /&gt;&lt;br /&gt;The problem I have with Empathy is there is no way to tell it to open a new chat window automatically when a new message arrives and there isn't already a chat window open. When that happens, I don't have the highlighted window in the window list demanding attention, and often discover that I missed an IM an hour later when clicking on the green envelope to read my email.&lt;br /&gt;&lt;br /&gt;What am I doing wrong?&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2390611717677315220-7398079244300505571?l=mdeslaur.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mdeslaur.blogspot.com/feeds/7398079244300505571/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2390611717677315220&amp;postID=7398079244300505571' title='16 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2390611717677315220/posts/default/7398079244300505571'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2390611717677315220/posts/default/7398079244300505571'/><link rel='alternate' type='text/html' href='http://mdeslaur.blogspot.com/2010/04/trying-to-switch-to-empathy.html' title='Trying to switch to Empathy'/><author><name>mdeslaur</name><uri>http://www.blogger.com/profile/05506714028603312467</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>16</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2390611717677315220.post-258269198478308618</id><published>2010-02-26T05:51:00.000-08:00</published><updated>2010-02-26T06:37:13.468-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ubuntu-planet'/><category scheme='http://www.blogger.com/atom/ns#' term='tips'/><title type='text'>Canadian tax software and Linux</title><content type='html'>Well, it's tax time again!&lt;br /&gt;&lt;br /&gt;This used to be the part of the year I would dread. Not because I feared how much income tax I would need to pay, but because I knew I would have to get Windows running in a VM or on a spare computer in order to use &lt;a href="http://quicktax.intuit.ca/tax-software/quicktax-download-cd.jsp"&gt;tax preparation software&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;I would get &lt;a href="http://en.wikipedia.org/wiki/Heartburn"&gt;heartburn&lt;/a&gt; from wondering if the new &lt;a href="http://www.extremetech.com/article2/0,2845,815697,00.asp"&gt;flavour-of-the-day copy-protection &lt;/a&gt;mechanism the software used would actually work in a VM, and if it would let me open up my files again after &lt;a href="http://www.extremetech.com/article2/0,2845,834905,00.asp"&gt;reinstalling it&lt;/a&gt; if something went wrong. Top that off with the fact that trusting your important data to Windows is like locking your safe with duct tape, and I'd be popping &lt;a href="http://wesclark.com/am/rolaids.html"&gt;Rolaids&lt;/a&gt; like candy.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Are all the security updates installed?&lt;br /&gt;&lt;/span&gt;Every time I open "Windows update", it manages to &lt;a href="http://support.microsoft.com/kb/296861"&gt;find some more&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Is my antivirus software properly installed and working?&lt;/span&gt;&lt;br /&gt;What if I got &lt;a href="http://www.infopackets.com/news/security/2008/20081231_400000_pcs_infected_with_fake_antivirus_2009_software_says_microsoft.htm"&gt;malware&lt;/a&gt; while purchasing the antivirus software online, &lt;a href="http://esupport.trendmicro.com/Pages/The-error-%E2%80%9CInstallation-Interrupted-A-security-threat-prevented-the-in.aspx"&gt;before I installed it&lt;/a&gt;?&lt;span style="font-style: italic;"&gt; &lt;/span&gt;&lt;a href="http://shop.symantecstore.com/"&gt;Which one do I choose?&lt;br /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Oh great, the new version of the tax software uses Internet Explorer to update itself.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Luckily, a couple of years ago I discovered &lt;a href="http://www.ufile.ca/default.asp"&gt;UFile.ca&lt;/a&gt;, a web-based tax preparation application. They even &lt;a href="http://ufile.ca/Help/FAQ_tech.asp#11"&gt;officially support Linux&lt;/a&gt;! It's quite refreshing to see a Tux logo right next to the Windows and Mac logos. It's even easier to use than the software I was previously purchasing!&lt;br /&gt;&lt;br /&gt;Of course, it's web-based, so it's up to you to decide if you're willing to accept handing over your tax information to a third party. In my case, the decision was easy: I get to decide &lt;a href="http://www.ufile.ca/WhyUFile/OurHeritage.asp"&gt;&lt;span style="font-style: italic;"&gt;who&lt;/span&gt;&lt;/a&gt; can see my tax information, which is a lot better than &lt;a href="http://www.smh.com.au/news/technology/identity-theft-virus-infects-10000-computers/2006/08/02/1154198204613.html"&gt;&lt;span style="font-style: italic;"&gt;hoping&lt;/span&gt;&lt;/a&gt; no one could see it.&lt;br /&gt;&lt;br /&gt;Goodbye heartburn!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2390611717677315220-258269198478308618?l=mdeslaur.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mdeslaur.blogspot.com/feeds/258269198478308618/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2390611717677315220&amp;postID=258269198478308618' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2390611717677315220/posts/default/258269198478308618'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2390611717677315220/posts/default/258269198478308618'/><link rel='alternate' type='text/html' href='http://mdeslaur.blogspot.com/2010/02/canadian-tax-software-and-linux.html' title='Canadian tax software and Linux'/><author><name>mdeslaur</name><uri>http://www.blogger.com/profile/05506714028603312467</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2390611717677315220.post-3623485805931612329</id><published>2009-12-21T09:50:00.000-08:00</published><updated>2009-12-21T10:05:42.731-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ubuntu-planet'/><title type='text'>Ubuntu movie sighting</title><content type='html'>I was watching the &lt;a href="http://www.imdb.com/title/tt1132620/"&gt;Millenium movie&lt;/a&gt; last night, and spotted an Ubuntu desktop being used by the "Plague" character:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_fTkkvvK_Yr4/Sy-4wU02r5I/AAAAAAAAAAs/g2X_e1xUbYg/s1600-h/millenium2.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 186px;" src="http://1.bp.blogspot.com/_fTkkvvK_Yr4/Sy-4wU02r5I/AAAAAAAAAAs/g2X_e1xUbYg/s320/millenium2.jpg" alt="" id="BLOGGER_PHOTO_ID_5417752017113624466" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_fTkkvvK_Yr4/Sy-2i2eRClI/AAAAAAAAAAM/9UKKLo7SPOc/s1600-h/millenium1.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 186px;" src="http://2.bp.blogspot.com/_fTkkvvK_Yr4/Sy-2i2eRClI/AAAAAAAAAAM/9UKKLo7SPOc/s320/millenium1.jpg" alt="" id="BLOGGER_PHOTO_ID_5417749586604264018" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_fTkkvvK_Yr4/Sy-4B4tzhwI/AAAAAAAAAAc/CjcT3nSH4z4/s1600-h/millenium3.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 186px;" src="http://4.bp.blogspot.com/_fTkkvvK_Yr4/Sy-4B4tzhwI/AAAAAAAAAAc/CjcT3nSH4z4/s320/millenium3.jpg" alt="" id="BLOGGER_PHOTO_ID_5417751219293882114" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2390611717677315220-3623485805931612329?l=mdeslaur.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mdeslaur.blogspot.com/feeds/3623485805931612329/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2390611717677315220&amp;postID=3623485805931612329' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2390611717677315220/posts/default/3623485805931612329'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2390611717677315220/posts/default/3623485805931612329'/><link rel='alternate' type='text/html' href='http://mdeslaur.blogspot.com/2009/12/ubuntu-movie-sighting.html' title='Ubuntu movie sighting'/><author><name>mdeslaur</name><uri>http://www.blogger.com/profile/05506714028603312467</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_fTkkvvK_Yr4/Sy-4wU02r5I/AAAAAAAAAAs/g2X_e1xUbYg/s72-c/millenium2.jpg' height='72' width='72'/><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2390611717677315220.post-3819083241861987102</id><published>2009-11-04T05:09:00.000-08:00</published><updated>2009-11-04T05:56:49.222-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ubuntu-planet'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><title type='text'>GNOME Keyring</title><content type='html'>For the past week or so, people have been &lt;a href="http://ubuntuforums.org/showthread.php?t=1302342"&gt;talking&lt;/a&gt; about a “security issue” in Seahorse. This sums up my opinion on the matter:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic; font-weight: bold;"&gt;This isn't a security issue, and there is no good way to fix it.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;There, I've said it. Now, here's some background:&lt;br /&gt;&lt;br /&gt;Although people are talking about Seahorse, the actual application that manages passwords is called &lt;a href="http://live.gnome.org/GnomeKeyring"&gt;GNOME Keyring&lt;/a&gt;. GNOME Keyring is an application that manages a user's authentication information, such as user names and passwords. It stores the authentication information in one or more encrypted databases, called &lt;span style="font-style: italic;"&gt;keyrings&lt;/span&gt;. A password, supplied by the user, is required to unlock a keyring, at which point all the information contained within is decrypted and is made available to applications via the libgnome-keyring library. It is similar to the &lt;a href="http://en.wikipedia.org/wiki/Keychain_%28Mac_OS%29"&gt;Keychain&lt;/a&gt; in Mac OS X, and Protected Storage in Microsoft Windows.&lt;br /&gt;&lt;br /&gt;Traditionally, a desktop application that needed to remember a user's password, such as an email or an instant messaging program, would store the password in a hidden &lt;a href="https://bugs.launchpad.net/ubuntu/+source/pidgin/+bug/226974"&gt;config&lt;/a&gt; &lt;a href="https://bugs.launchpad.net/ubuntu/+source/tsclient/+bug/296682"&gt;file&lt;/a&gt; in the user's home directory. Appropriate permissions would be set on the file to make sure other local users can't read it.&lt;br /&gt;&lt;br /&gt;Sometimes, passwords stored in this manner would be obfuscated using a &lt;a href="http://www.oxid.it/ca_um/topics/vnc_password_decoder.htm"&gt;reversible scheme&lt;/a&gt;, as the password needs to be converted back to plain text in order to be used. This would provide a false sense of security. Users inspecting the file would think the passwords were encrypted, but a myriad of &lt;a href="http://www.oxid.it/creddump.html"&gt;little&lt;/a&gt; &lt;a href="http://www.nirsoft.net/utils/pspv.html"&gt;recovery&lt;/a&gt; &lt;a href="http://www.forensicideas.com/tools.html"&gt;scripts&lt;/a&gt; and on-line converters were available to anyone who knows how to perform a &lt;a href="http://www.google.ca/search?q=password+recovery"&gt;Google search&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;A password managing daemon, such as GNOME Keyring, increases the security of stored passwords for the following reasons:&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Passwords are stored in a database that uses &lt;span style="font-style: italic;"&gt;real encryption&lt;/span&gt;, not just an obfuscation scheme&lt;/li&gt;&lt;li&gt;A single code base needs to be audited to make sure no vulnerabilities exist in the encryption algorithms that are being used&lt;/li&gt;&lt;li&gt;The database is protected by a password that is known only to the user who unlocks it&lt;/li&gt;&lt;li&gt;Since the database is encrypted, no other user or bootable CD can recover the stored passwords if the unlock password is not known&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;So, if GNOME Keyring increases the security of user credentials, why can you see your passwords exposed in plain text when you open Seahorse? &lt;span style="font-style: italic;"&gt;Because you've unlocked the keyring using your login password.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Although GNOME Keyring supports multiple keyrings, there is only one by default, called “login”. This keyring is automatically unlocked by a PAM module when logging into a GNOME desktop. When the desktop session is closed, the keyring is locked. When the keyring is in an “unlocked” state, the database files are decrypted using the decryption password and all the contents are in memory for gnome-keyring-daemon to access.&lt;br /&gt;&lt;br /&gt;Now, the attack scenario that has been talked about this past week has been leaving your computer unattended, and an attacker using Seahorse to access your clear text passwords. This has been criticized as being a security issue, and a few “solutions” have been suggested to “fix” the issue. Here are some of the scenarios proposed:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;font-size:130%;" &gt;Scenario 1: Ask for the user's password before displaying the clear text keyring contents.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;This scenario doesn't work in practice. Once the keyring is unlocked, the contents are available under the user's security context. Since the GNOME Keyring daemon is under the user's security context, the intruder has every privilege necessary to simply bypass the authentication step and directly read the unencrypted keyring from memory. Even if Seahorse asked for a user password, nothing could prevent the intruder from simply downloading a “reveal passwords” application from the Internet or a USB key. There is no difference in time or skill required to open Seahorse and display passwords, or to type “gnome password revealer” in Google and execute the first application available for download. The GNOME Keyring project has a &lt;a href="http://live.gnome.org/GnomeKeyring/SecurityPhilosophy"&gt;web page to explain this&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Even worse, the fact that a password would be required in Seahorse would make the user &lt;span style="font-style: italic;"&gt;think&lt;/span&gt; that a password is required to see the clear text information. This would give the user a &lt;span style="font-style: italic;"&gt;false sense of security&lt;/span&gt;. If Seahorse asks for a password, but a five line python script can bypass the password, bug reports would change from “Seahorse displays clear text passwords” to “Seahorse authentication can be easily bypassed”. This scenario doesn't solve the problem.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;font-size:130%;" &gt;Scenario 2: Make keyring session expire automatically after a certain time.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;If the keyring session expires automatically, such as every 15 minutes, it becomes useless. The purpose of the keyring is to store passwords that are needed by applications. With keyring session expiration, Evolution can't automatically check for new mail, Empathy can't auto-reconnect to instant messaging networks, the wireless connection can't re-authenticate to access points.&lt;br /&gt;&lt;br /&gt;If you expire the keyring session every 15 minutes, you will probably need to type in your password every 15 minutes. Besides, if you leave your computer unattended, 15 minutes is long enough for an intruder to steal your passwords. This scenario doesn't solve the problem.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;font-size:130%;" &gt;Scenario 3: Make the keyring daemon run as root or as a dedicated user.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;The idea behind this is to have a central daemon that would authenticate users and applications before giving out passwords. Since the daemon doesn't run under the user's security context, no amount of hacking by an intruder in an unlocked desktop session would result in gaining access to the unlocked password database.&lt;br /&gt;&lt;br /&gt;Although this scenario may seem appealing, it would probably be &lt;span style="font-style: italic;"&gt;less secure&lt;/span&gt; than the current approach. If we have a central daemon that serves all users, a programming vulnerability could result in other users gaining access to your confidential information. Besides, if your desktop applications, under your security context, can gain access to the passwords they need, so can an intruder in your security context. The intruder's script can simply spoof the desktop applications themselves to get the passwords, or get them out of the application's memory. This scenario doesn't solve the problem.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;font-size:130%;" &gt;Scenario 4: Stop using GNOME Keyring.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Well, GNOME Keyring was created to solve the problem of people writing down their passwords everywhere, including text files or their computer, and the problem of applications storing passwords in text files. Removing GNOME Keyring would decrease security to the state it was before. This scenario doesn't solve the problem.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;font-size:130%;" &gt;Scenario 5: Locking the desktop session when stepping away from the keyboard.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Now we're getting somewhere!&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Since the attack vector that's being discussed is an intruder gaining physical access to an unlocked desktop, the simplest way to prevent this from happening is to &lt;span style="font-weight: bold;"&gt;lock the desktop when you leave it unattended&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;If someone gains access to your desktop, your passwords are not the only thing they can access. Who needs your email password, when they have access to your whole mail file?&lt;br /&gt;&lt;br /&gt;Even if we assume GNOME Keyring could be made attacker proof, we would need to do the same for every desktop application. An intruder could, in a few seconds, install a &lt;a href="http://en.wikipedia.org/wiki/Trojan_horse_%28computing%29"&gt;Trojan horse&lt;/a&gt; downloaded off the Internet that runs in the background and emails him your passwords as soon as your desktop applications use them. The same application could intercept your sudo password, and become root to access the GNOME Keyring data. &lt;span style="font-style: italic;"&gt;Absolutely no technical skill is required to do this.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Leaving your desktop unattended exposes all your confidential data to an attacker, not just your passwords.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Game Over.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Recommendations:&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Always lock your screen when you leave your computer unattended. This is akin to locking your front door when leaving the house. Hit Ctrl-Alt-L, select “Lock Screen” from the user switch applet, or put the “Lock Screen” applet somewhere in your panel for easy access.&lt;/li&gt;&lt;li&gt;Set a low screen-saver idle timeout, for example, 5 minutes. If you forget to lock your session, it will do so automatically after a couple of minutes, reducing the time your confidential data is exposed.&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;And remember: &lt;span style="font-style: italic;"&gt;This isn't a security issue, and there is no good way to fix it.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2390611717677315220-3819083241861987102?l=mdeslaur.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mdeslaur.blogspot.com/feeds/3819083241861987102/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2390611717677315220&amp;postID=3819083241861987102' title='27 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2390611717677315220/posts/default/3819083241861987102'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2390611717677315220/posts/default/3819083241861987102'/><link rel='alternate' type='text/html' href='http://mdeslaur.blogspot.com/2009/11/gnome-keyring.html' title='GNOME Keyring'/><author><name>mdeslaur</name><uri>http://www.blogger.com/profile/05506714028603312467</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>27</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2390611717677315220.post-8400803429027301541</id><published>2009-08-30T11:25:00.000-07:00</published><updated>2009-08-30T11:48:07.225-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ubuntu-planet'/><category scheme='http://www.blogger.com/atom/ns#' term='hardware'/><category scheme='http://www.blogger.com/atom/ns#' term='ipod'/><category scheme='http://www.blogger.com/atom/ns#' term='apple'/><title type='text'>The ideal portable media player</title><content type='html'>After the overwhelming response to my &lt;a href="http://mdeslaur.blogspot.com/2009/07/goodbye-apple.html"&gt;Goodbye Apple blog post&lt;/a&gt;, I have compiled a list of criteria I would like to see in a portable music player:&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;Linux compatibility&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;This is a deal-breaker for me, as I only use &lt;a href="http://www.ubuntu.com/"&gt;Ubuntu&lt;/a&gt;. The next mp3 player should be manageable from a Ubuntu desktop. In order of preference:&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Manufacturer lists Linux support or compatibility on the box&lt;/li&gt;&lt;li&gt;Manufacturer lists Linux support or compatibility on their website&lt;/li&gt;&lt;li&gt;Device is known to work with Linux&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;Of course, I would also need to be able to update the device's firmware, but this isn't a must. I can probably find someone with a Windows box to do a one-time firmware update.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;font-size:130%;" &gt;Video support&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;I spend a lot of time in airports and planes. This is where I use my player the most. I like watching videos and movies while on the move. I want at least a 2.5 inch screen, but it still needs to be light and small enough to fit in my shirt pocket. It's what I had on my 5G iPod Video, and it's the minimum I would tolerate.&lt;br /&gt;&lt;br /&gt;Video conversion should be easy, and should not require Windows-only software. I should be able to encode video from DVDs I own, and from video podcasts I download from the Internet.&lt;br /&gt;&lt;br /&gt;Bonus points if the manufacturer gives some example &lt;a href="http://ffmpeg.org/"&gt;ffmpeg&lt;/a&gt; or &lt;a href="http://www.mplayerhq.hu"&gt;mencoder&lt;/a&gt; command-lines in a wiki somewhere, or submits presets for their device to encoding software such as &lt;a href="http://handbrake.fr/"&gt;Handbrake&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Podcast support&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;I listen to a lot of &lt;a href="http://www.twit.tv/FLOSS"&gt;podcasts&lt;/a&gt;. Since a lot of podcasts are available encoded in mp3 format, most people think they work on any mp3 player. Fact is, I want the player to be able to recognize podcasts and apply special logic to them the way iPods do. They need to:&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Have a “completed” flag to be able to easily spot the ones I've listened to already&lt;/li&gt;&lt;li&gt;Automatically resume from where they were left off (without having to manually set a “bookmark”)&lt;/li&gt;&lt;li&gt;Be in a separate list from regular music files&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;The most important criteria for me is the automatic resume one, and is the one most media players are lacking. I don't enjoy losing my place in a podcast when I get interrupted, or want to listen to some music. Trying to locate where you were in an hour-long podcast with a fast-forward button is painful.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Standard USB port&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;I want a media player with a standard &lt;a href="http://en.wikipedia.org/wiki/Mini_usb#Mini_and_Micro"&gt;mini or micro USB port&lt;/a&gt; for syncing and charging. I hate having to spend extra on spare proprietary cables. I hate having to lug ten different proprietary cables in my laptop bag when I travel. And most of all: I hate forgetting the proprietary cable at home when I leave on a trip. Even though the iPod has a proprietary connector, at least you can purchase a spare cable pretty much anywhere.&lt;br /&gt;&lt;br /&gt;Of course, most devices come with proprietary ports because a standard USB port can't offer all the extra features that a portable media device needs, such as TV Out, Audio Out, Line in, etc. How about this for an idea, folks: USB for syncing/charging, and proprietary port for all the rest.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;User-friendly interface&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;My dad came over the other day with a &lt;a href="http://www.youtube.com/watch?v=d5BajfRaz9Y"&gt;cheap no-name 3rd generation iPod Nano knockoff&lt;/a&gt; he bought at an electronics store. He was raving about how inexpensive it was.&lt;br /&gt;&lt;br /&gt;The user interface was the most horrible thing I have ever encountered. It was so complicated to simply get a song to play that I would have paid double the price difference to never see it again.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;On-demand playlist support&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Although this isn't something that's absolutely necessary, I really enjoy listening to music while &lt;a href="http://ipod.about.com/od/introductiontotheipod/ht/otg_playlist_ip.htm"&gt;creating a playlist on the device itself&lt;/a&gt;.&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Adequate volume&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;The volume needs to be loud enough to listen to music and movies while on a plane. My Sony PSP isn't loud enough for me to listen to movies on a plane.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Open multimedia format support&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;It would be great if the device supported open multimedia formats and codecs, such as &lt;a href="http://en.wikipedia.org/wiki/Ogg"&gt;Ogg&lt;/a&gt;, &lt;a href="http://en.wikipedia.org/wiki/Flac"&gt;FLAC&lt;/a&gt; and &lt;a href="http://en.wikipedia.org/wiki/Theora"&gt;Theora&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Well, that's all I can think of for now. Based on recommendations in my blog comments, I have purchased a &lt;a href="http://www.cowonamerica.com/products/cowon/s9/"&gt;Cowon S9&lt;/a&gt;. Also, I have received a &lt;a href="http://us.creative.com/products/product.asp?category=213&amp;amp;subcategory=214&amp;amp;product=18615"&gt;Creative Zen MX&lt;/a&gt;, and will be receiving a &lt;a href="http://www.sansa.com/players/sansa_fuze"&gt;Sansa Fuse&lt;/a&gt; shortly. In the coming weeks, I'll be reviewing each of these (and maybe others) to try and find the ideal portable media player for Linux users.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2390611717677315220-8400803429027301541?l=mdeslaur.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mdeslaur.blogspot.com/feeds/8400803429027301541/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2390611717677315220&amp;postID=8400803429027301541' title='10 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2390611717677315220/posts/default/8400803429027301541'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2390611717677315220/posts/default/8400803429027301541'/><link rel='alternate' type='text/html' href='http://mdeslaur.blogspot.com/2009/08/ideal-portable-media-player.html' title='The ideal portable media player'/><author><name>mdeslaur</name><uri>http://www.blogger.com/profile/05506714028603312467</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>10</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2390611717677315220.post-3305488122997490144</id><published>2009-08-18T14:30:00.000-07:00</published><updated>2009-08-18T14:44:45.457-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ubuntu-planet'/><category scheme='http://www.blogger.com/atom/ns#' term='tips'/><title type='text'>My God! It's full of stars!</title><content type='html'>Ever try hooking up a server or firewall with multiple network cards? You stand in back of it wondering which RJ45 port is eth0, which one is eth1...&lt;br /&gt;&lt;br /&gt;Here's a little tip: you can make network card lights blink with the ethtool command:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;ethtool -p eth0&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;You can make each card blink for 30 seconds in order with something like:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;for net in eth0 eth1 eth2; do ethtool -p $net 30; done&lt;br /&gt;&lt;/blockquote&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2390611717677315220-3305488122997490144?l=mdeslaur.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mdeslaur.blogspot.com/feeds/3305488122997490144/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2390611717677315220&amp;postID=3305488122997490144' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2390611717677315220/posts/default/3305488122997490144'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2390611717677315220/posts/default/3305488122997490144'/><link rel='alternate' type='text/html' href='http://mdeslaur.blogspot.com/2009/08/my-god-its-full-of-stars.html' title='My God! It&apos;s full of stars!'/><author><name>mdeslaur</name><uri>http://www.blogger.com/profile/05506714028603312467</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2390611717677315220.post-6079221251668964759</id><published>2009-08-15T10:21:00.000-07:00</published><updated>2009-08-15T12:39:27.874-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ubuntu-planet'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><title type='text'>Aide (Advanced Intrusion Detection Environment) improvements</title><content type='html'>At the Karmic Ubuntu developer summit, we had a session on filesystem integrity checkers. The main purpose of the session was to see what the current state of them was, and if we needed to replace &lt;a href="http://sourceforge.net/projects/aide/"&gt;Aide&lt;/a&gt; in main with a newer alternative.&lt;br /&gt;&lt;br /&gt;I don't traditionally like filesystem checkers. While they are very useful to detect files that get modified during an intrusion, an administrator needs to invest an incredible amount of time in analyzing the log files that they produce every day. This is compounded by the fact that servers don't remain static: they get security and stability software updates installed. The more that servers get updated, the more they divert from the original database that was generated by the integrity checker, and the more false positives get reported in the log.&lt;br /&gt;&lt;br /&gt;Wouldn't it be great if the integrity checker was smart enough not to report on files that were changed by operating system updates?&lt;br /&gt;&lt;br /&gt;I introduced this very feature in the Aide package in Karmic Koala. It is disabled by default. To activate it, simply modify the /etc/default/aide configuration file and set “FILTERUPDATES” to “yes”. I also recommend changing “COPYNEWDB” to “yes” in order to get changes reported only once.&lt;br /&gt;&lt;br /&gt;This new configuration option will filter out files that were modified by operating system updates from the daily email sent to the administrator. It will not filter them out from the main log file.&lt;br /&gt;&lt;br /&gt;Of course, overwriting the pristine database every day and filtering out the files changed by system updates may slightly reduce Aide's effectiveness, but I think it's a compromise worth having if the alternative is to not use Aide at all because of administrative overhead.&lt;br /&gt;&lt;br /&gt;If you've never used Aide before on your Ubuntu server, and would like to give it a try on Karmic, here are the steps necessary to get started:&lt;br /&gt;&lt;br /&gt;1- Install aide:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;apt-get install aide&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;2- Create the initial database (this may take a while):&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;aideinit&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;3- Customize the MAILTO, COPYNEWDB and FILTERUPDATES parameters in /etc/default/aide&lt;br /&gt;&lt;br /&gt;4- You should now get a daily email report on filesystem changes!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2390611717677315220-6079221251668964759?l=mdeslaur.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mdeslaur.blogspot.com/feeds/6079221251668964759/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2390611717677315220&amp;postID=6079221251668964759' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2390611717677315220/posts/default/6079221251668964759'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2390611717677315220/posts/default/6079221251668964759'/><link rel='alternate' type='text/html' href='http://mdeslaur.blogspot.com/2009/08/aide-advanced-intrusion-detection.html' title='Aide (Advanced Intrusion Detection Environment) improvements'/><author><name>mdeslaur</name><uri>http://www.blogger.com/profile/05506714028603312467</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2390611717677315220.post-2083066115212472694</id><published>2009-07-23T05:20:00.000-07:00</published><updated>2009-07-23T14:49:56.753-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ubuntu-planet'/><category scheme='http://www.blogger.com/atom/ns#' term='hardware'/><category scheme='http://www.blogger.com/atom/ns#' term='ipod'/><category scheme='http://www.blogger.com/atom/ns#' term='apple'/><title type='text'>Goodbye Apple</title><content type='html'>I've owned a lot of iPods. My wife has owned a lot of iPods.&lt;br /&gt;&lt;br /&gt;Not anymore.&lt;br /&gt;&lt;br /&gt;For the longest time, I could use &lt;a href="http://www.gtkpod.org/"&gt;gtkpod&lt;/a&gt; to seamlessly access my iPods from my Ubuntu desktop. It initially took some reverse-engineering effort to understand the iPod's data format to be able to access it from non-iTunes software, but it was possible. All of a sudden, Apple is trying everything they can to prohibit interopability.&lt;br /&gt;&lt;br /&gt;First, they &lt;a href="http://home.gna.org/linux4nano/"&gt;encrypted the firmware&lt;/a&gt;, blocking the use of third-party firmware like &lt;a href="http://www.rockbox.org/"&gt;Rockbox&lt;/a&gt; and &lt;a href="http://www.ipodlinux.org/"&gt;iPod Linux&lt;/a&gt;. This doesn't bother me much, as I always prefered the original Apple firmware anyway.&lt;br /&gt;&lt;br /&gt;Then, in August 2007, they added a new &lt;a href="http://gorkworld.wordpress.com/2007/09/17/ipod-hash-defeated/"&gt;hash&lt;/a&gt; to the database to block non-iTunes software. This was quicky reverse-engineered and support was added to gtkpod once again.&lt;br /&gt;&lt;br /&gt;In November 2008, they changed the hash again. This time, Apple used code-obfuscation software on iTunes in an effort to complicate reverse-engineering a second time. When a &lt;a href="http://bluwiki.com/go/Ipodhash"&gt;wiki&lt;/a&gt; was put up to start documenting the new hash, Apple &lt;a href="http://bluwiki.com/go/Ipodhash/Takedown"&gt;sent a takedown notice.&lt;/a&gt; Fortunately, some people found an ugly &lt;a href="http://marcansoft.com/blog/2009/01/using-amarok-and-other-itunesdb-compatible-software-with-the-iphone-2x/"&gt;workaround&lt;/a&gt; to get gtkpod working again.&lt;br /&gt;&lt;br /&gt;In 2009, Palm released the Palm Pre. It supported &lt;a href="http://gizmodo.com/5271917/palm-pre-to-sync-directly-with-itunes"&gt;syncing with iTunes.&lt;/a&gt; Apple retaliated by updating iTunes specifically to block &lt;a href="http://www.informationweek.com/news/personal_tech/smartphones/showArticle.jhtml?articleID=218500862"&gt;Palm Pre interopability.&lt;/a&gt; Unfortunately, this changed the iPod database structure, and the workaround for gtkpod &lt;a href="http://marcansoft.com/blog/2009/06/iphone-os-30-music-totally-incompatible/"&gt;no longer works.&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;While I can understand Apple not wanting the Palm Pre to be able to sync with iTunes, as iTunes integration is one of the main selling points for the iPod, I can't understand why they would actively block third party software from accessing the iPod.&lt;br /&gt;&lt;br /&gt;Everyone is now selling &lt;a href="http://en.wikipedia.org/wiki/Amazon_mp3"&gt;DRM-free mp3 music&lt;/a&gt;, so it's not a question of protecting DRM. You'd think they would &lt;span style="font-weight:bold;"&gt;want&lt;/span&gt; to sell more iPods, not block a certain percentage of their market out.&lt;br /&gt;&lt;br /&gt;My 5G iPod broke today. Dear Apple, the replacement I purchase won't be from you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2390611717677315220-2083066115212472694?l=mdeslaur.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mdeslaur.blogspot.com/feeds/2083066115212472694/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2390611717677315220&amp;postID=2083066115212472694' title='91 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2390611717677315220/posts/default/2083066115212472694'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2390611717677315220/posts/default/2083066115212472694'/><link rel='alternate' type='text/html' href='http://mdeslaur.blogspot.com/2009/07/goodbye-apple.html' title='Goodbye Apple'/><author><name>mdeslaur</name><uri>http://www.blogger.com/profile/05506714028603312467</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>91</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2390611717677315220.post-2914259732634749636</id><published>2008-11-02T06:03:00.000-08:00</published><updated>2009-07-23T14:50:19.578-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ubuntu-planet'/><category scheme='http://www.blogger.com/atom/ns#' term='tips'/><title type='text'>Launchpad search plugins for Firefox</title><content type='html'>If you work a lot with &lt;a href="http://www.launchpad.net/"&gt;Launchpad&lt;/a&gt;, there is a package in the Ubuntu repos that adds Launchpad integration into the Firefox search box. The package is called "firefox-launchpad-plugin":&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;span style="font-weight: bold;"&gt;Launchpad firefox integration&lt;/span&gt;&lt;br /&gt;Mozilla Firefox Launchpad integration add quick search for:&lt;br /&gt;- Ubuntu bugs on Launchpad&lt;br /&gt;- Ubuntu specifications on Launchpad&lt;br /&gt;- Ubuntu packages on Launchpad&lt;br /&gt;- Ubuntu support tickets on Launchpad&lt;br /&gt;- People and team on Launchpad&lt;/blockquote&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2390611717677315220-2914259732634749636?l=mdeslaur.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mdeslaur.blogspot.com/feeds/2914259732634749636/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2390611717677315220&amp;postID=2914259732634749636' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2390611717677315220/posts/default/2914259732634749636'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2390611717677315220/posts/default/2914259732634749636'/><link rel='alternate' type='text/html' href='http://mdeslaur.blogspot.com/2008/11/launchpad-search-plugins-for-firefox.html' title='Launchpad search plugins for Firefox'/><author><name>mdeslaur</name><uri>http://www.blogger.com/profile/05506714028603312467</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2390611717677315220.post-2381920600194621572</id><published>2008-10-26T17:52:00.000-07:00</published><updated>2009-07-23T14:50:34.864-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ubuntu-planet'/><category scheme='http://www.blogger.com/atom/ns#' term='tips'/><title type='text'>Adobe Reader fonts</title><content type='html'>Here's another PDF tip while I'm at it: how to fix broken fonts in Adobe Reader in Ubuntu Hardy and Intrepid.&lt;br /&gt;&lt;br /&gt;It seems Adobe Reader doesn't use font-config by default. If you open a pdf file that uses Arial or some other font that is installed in font-config, Reader will still replace it with a generic Adobe Sans font. To turn on font-config support, modify the /usr/bin/acroread launcher script and uncomment the following two lines:&lt;br /&gt;&lt;br /&gt;ACRO_ENABLE_FONT_CONFIG=1&lt;br /&gt;export ACRO_ENABLE_FONT_CONFIG&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2390611717677315220-2381920600194621572?l=mdeslaur.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mdeslaur.blogspot.com/feeds/2381920600194621572/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2390611717677315220&amp;postID=2381920600194621572' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2390611717677315220/posts/default/2381920600194621572'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2390611717677315220/posts/default/2381920600194621572'/><link rel='alternate' type='text/html' href='http://mdeslaur.blogspot.com/2008/10/adobe-reader-fonts.html' title='Adobe Reader fonts'/><author><name>mdeslaur</name><uri>http://www.blogger.com/profile/05506714028603312467</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2390611717677315220.post-7198076536013986331</id><published>2008-10-26T15:39:00.001-07:00</published><updated>2009-07-23T14:50:47.974-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ubuntu-planet'/><category scheme='http://www.blogger.com/atom/ns#' term='tips'/><title type='text'>Discovering QPDF</title><content type='html'>A friend of mine asked for help removing the restrictions on a PDF file he made a while ago. It seems he misplaced his original source file because of disk bloat and all that was left was a PDF file he created for the print shop. Of course, he couldn't remember the password he had used when he created the file.&lt;br /&gt;&lt;br /&gt;A quick look through google came up with a simple solution: qpdf, available in universe:&lt;br /&gt;&lt;br /&gt;QPDF is a program that can be used to linearize (web-optimize),&lt;br /&gt;encrypt (password-protect), decrypt, and inspect PDF files from&lt;br /&gt;the command-line.&lt;br /&gt;&lt;br /&gt;Here's the command line that removed the PDF restrictions:&lt;br /&gt;&lt;br /&gt;qpdf --decrypt infile.pdf outfile.pdf&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2390611717677315220-7198076536013986331?l=mdeslaur.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mdeslaur.blogspot.com/feeds/7198076536013986331/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2390611717677315220&amp;postID=7198076536013986331' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2390611717677315220/posts/default/7198076536013986331'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2390611717677315220/posts/default/7198076536013986331'/><link rel='alternate' type='text/html' href='http://mdeslaur.blogspot.com/2008/10/unknown-apps.html' title='Discovering QPDF'/><author><name>mdeslaur</name><uri>http://www.blogger.com/profile/05506714028603312467</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
