Press "Enter" to skip to content

Posts published in “News”

Secure Linux Systems Require Savvy Users

Linux securityPatches are available to fix the bash vulnerability known as Shellshock, along with three additional security issues recently found in the bash shell. The patches are available for all major Linux distros as well as for Solaris, with the patches being distributed through the various distros.

After the patch is applied, there are a couple of commands that can be run from a terminal to ascertain that a system is no longer vulnerable. For details, see the article Steven J. Vaughan-Nichols has written for ZDNet. As yet, there is no patch available for OS X, although Apple says that one is on the way, while assuring its users that Mac systems aren’t vulnerable except for the most advanced users.

The good news about all this is that it demonstrates how quickly the Linux community can get the word out and then rally to engineer a solution when a security problem is discovered. The bad news is that not all Linux users listen. Too many users believe that the security features that are baked into Linux offer complete protection, no matter what. Unfortunately, that’s not the case. It never was, nor can it ever be.

My friend Andrew Wyatt, who spent time some years back as the founder and lead developer of the Fuduntu Linux distro, attempted to address this fact recently in a comment to an article on FOSS Force:

Hello World: Videos That Teach Linux To Kids

The Hello World Program needs a few bucks to buy some new equipment to enable them to continue to keep on doing what they do. What they do is make videos that teach Linux and other computer tech subjects to kids, using sock puppets, robots and animation — sort of Kukla, Fran and Ollie for the 21st century. Or Shari Lewis and Lamb Chop in color and high def.

They don’t need much. $2,048 by their estimation will do just fine — a mere drop in the bucket in the overall scheme of things. They’ve been on Indiegogo since last Wednesday, where they’re making their case.

Hello World Nielson
Jared (L) and JR (R) Nielson at work on a video project.
“We don’t have a proper studio to shoot video,” they wrote on their Indiegogo page, “the bulbs in our light kit are burned out, our cameras and lenses are dirty because we’ve been shooting in basements and (very cold) garages for the last year, our backdrop needs replacing, and our highly intelligent robot host requires an upgrade.”

They’re already a third of the way there, with $680 raised so far. But crowdfunding campaigns sometimes stall after getting off to a good start. It happens — ask Mark Shuttleworth. It’s not time to relax yet.

Jeff Hoogland Leaves Bodhi

Jeff Hoogland, the lead developer of Bodhi Linux, said in a blog post on Friday that “for a variety of reasons,” he is stepping down from the leadership of his “labor of love.”

Bodhi Linux, based on Ubuntu, is a lightweight distro leveraging the Enlightenment Desktop. A note on the Bodhi Linux web page says, “We regret to inform you Bodhi Linux is no longer being maintained,” and has a link to Hoogland’s blog page.

Bodhi Jeff Hoogland
Jeff Hoogland steps down from Bodhi Linux
“I have worked with dozens of different people over the course of the last few years. I have made friends and learned more than I could have ever imagined,” Hoogland said in his blog post.

Internet Slowdown Shifts Into High Gear

Internet users spoke loudly, firmly, and in no uncertain terms on Wednesday in sending a message of overwhelming support for net neutrality protections during the Internet Slowdown campaign.

Tech companies, websites, public interest organizations and more than a million users joined forces to bring the message of net neutrality forward by posting icons and links on their sites symbolically representing a slow-loading Internet, and by directing those clicking on the links to messages to Congress, the White House and the Federal Communications Commission.

“The numbers tell the story: People everywhere are using the Internet to save the Internet from phone and cable companies,” said Evan Greer, director of Fight for the Future. “We’ve shown that the best way to fight these powerful special interests in Washington is through mass action by people from outside Washington. The FCC and Congress can no longer dismiss the overwhelming consensus of public support for real Net Neutrality protections.”

Wednesday’s Internet Slowdown action generated just over 300,000 calls and nearly 2.2 million emails to Congress by Thursday afternoon. Facebook shares of the spinning “loading” icon topped 1.1 million. In addition, 722,364 filed comments Wednesday at the Federal Communications Commission, bringing the total number of comments since March 1 to 7.7 million.

Red Hat’s Brian Stevens Now At Google

Brian Stevens formerly of Red HatNow we know he walked and wasn’t pushed.

Back on August 27 when Red Hat announced that CTO Brian Stevens had left the building and was no longer in their employ, rumors began flying as people began to wonder what happened. His resignation came without warning and Red Hat wasn’t forthcoming with anything, other than a terse message wishing him well, so it’s only natural that some people began to suspect that some kind of shakeup was in play. Indeed, I was pretty sure that he hadn’t left voluntarily but had been pushed through the door.

Did Red Hat’s CTO Walk – Or Was He Pushed?

Brian Stevens formerly of Red HatIt’s hard to believe the official story coming out of Raleigh, that CTO Brian Stevens abruptly resigned his position at Red Hat on Wednesday “to pursue another opportunity.” The company is being mainly mum on the subject, only offering a terse three sentence announcement on their website.

Red Hat seems to want us to believe Stevens left on his own in pursuit of the American dream. Maybe, maybe not. From the way the story has unfolded, it seems highly unlikely that Stevens’ decision to leave was entirely his.

ZDNet’s Steven J. Vaughan-Nichols is a North Carolina resident who usually has a pretty good idea of the happenings within Red Hat’s Raleigh headquarters. In his initial report on this story, he seems to have been as surprised by this move as anyone else.

Tux Paint: Doing FOSS Right

One could argue that the measure of how good software is, or what kind of effect it has on the wider world, can be based on the hard statistics of use, punctuated by glowing reviews, which add up to ongoing popularity and ubiquity. But the true impact of how software transcends mere popularity to positively change the world can be measured solely in how it affects people’s lives.

The journalist in me could give you just the specifics of the new Tux Paint release: Tux Paint 0.9.22 was released this week, thanks to the efforts of 170 contributors worldwide. This new version comes with a wide range of additions, like 14 new tools, 40 new template pictures, nearly 200 new stamps, SVG and KidPix support, an enhanced text tool, and accessibility improvements.

Tux Paint version 0.9.22, released last week, contains many improvements.
Tux Paint version 0.9.22, released last week, contains many improvements.
Or I could go into the expansion of 32 new languages featured in the latest release, including more than a dozen Indian subcontinental languages, including Nepali and Sanskrit; six European languages, including Bosnian and Valencian; nine new African languages, including Zulu and Sudanese; and the Canadian Inuit language of Inuktitut. This is 32 new languages atop the updates to the 90 current Tux Paint languages.

Of course, Tux Paint 0.9.22 also is available for multiple operating systems, including the usual suspects of Linux, MacOS, and Windows.

Ken Starks to Keynote At Ohio LinuxFest

Holy moley! Our Ken Starks is going to keynote at Ohio LinuxFest (OLF) and I almost forgot.

Ken had mentioned this in a email a few months back, I believe, but I’d put it on a back burner, where it fell off and landed hidden behind the stove. If Larry Cafiero, better known as the free software and CrunchBang guy, hadn’t made mention of the fact on Google+ the other day, I probably wouldn’t’ve remembered until it was way too late.

ken_starksAs most FOSS Force readers probably already know, Ken’s articles here and on his own Blog of Helios are only a small part of what he does. He’s one of those too rare people who works to make a difference in this world and he does so by leveraging the power of Linux and free and open source software for the greater good.

As the founder of the Reglue project (originally called Helios), he’s responsible for putting refurbished computers in the hands of financially challenged students in and around the Austin, Texas area where he resides. Over the years there have been thousands of these students and many of them, given Reglue computers while in middle or high school, have gone on to not only earn undergraduate degrees, but to attend graduate school as well — often studying computer science.

It’s his work at Reglue, of course, that’s responsible for Ken being invited to OLF. Wanting to know more, I fired off a list of questions in an email in the form of an interview. As usual, Ken was very giving of his time and put much thought into his answers.

USB Ports Are No Longer Your Friend (If They Ever Were)

Just because the good guys have discovered a new security risk doesn’t mean the bad guys haven’t known about it forever. The risk is only new to us. It’s actually been there for a long time, maybe forever. Who knows how long everyone from the black hats in Moscow to the NSA in bucolic Maryland have been taking advantage of what appears to us to be a “new” exploit?

The USB security hole recently unveiled by Berlin based Security Research Labs (SRL) seems to be of those that’s been around “forever.”

USB exploit infecting Linux
A slide used by Security Research Labs at the Black Hat USA security conference explaining how a USB device can be infected by a Windows computer in order to gain root access on Linux.
(click to enlarge)
While it shouldn’t be news to anybody that caution should be exercised when using USB devices, the new exploit would seem to indicate that even the most draconian security measures, short of doing away with USB devices entirely, might not be enough. The recently revealed problem has to do with the USB controller chip found in most, if not all, USB devices. The chip basically identifies the device type to the computer.

The trouble is, most of these chips are relatively easy to reprogram.

Latest Articles