Press "Enter" to skip to content

Posts published in “Security”

WordPress Upgraded to Fix Security Holes

Website publishers using the popular free and open source WordPress content management system (CMS) woke up this morning to find that their sites had been upgraded to version 4.2.2. Users who’s sites somehow missed being automatically upgraded are urged to update immediately, as this update addresses several important security issues. According to Wordfence, maintainers of a popular WordPress security plugin, this release fixes one recently discovered vulnerability and further hardens a security issue that was addressed in version 4.2.1.

Linux Chromebooks, Securing the Web & More…

FOSS Week in Review

Unfortunately, Larry’s a little under the weather today, so here I am…

Put that on your Chromebook and run it

We hear from Softpedia that Chromixium is just about ready for prime time. Well, that may be jumping the gun a little bit. What we really hear is that the distro has now gone from beta to release candidate, and that a honest-to-goodness 1.0 stable version is virtually just around the corner. Trouble is: we’re not sure yet just how far away we are from that corner. Shouldn’t be too far, however. The beta version was only released in February, so these developers aren’t wasting time.

Christine Hall

Christine Hall has been a journalist since 1971. In 2001, she began writing a weekly consumer computer column and started covering Linux and FOSS in 2002 after making the switch to GNU/Linux. Follow her on Twitter: @BrideOfLinux

Samsung’s Spying TVs, Ubuntu Phone Sells Out & More…

FOSS Week in Review

Larry Cafiero is busy working for SCALE (pun intended), so you’re stuck with me for another week. Sorry.

Ubuntu Phone sale is gone in a flash

The sale of the first ever Ubuntu phone through a European flash sale was evidently a success. Of course, we wouldn’t know as the phone isn’t available yet to those of us who live on this side of the pond, so it hasn’t been getting much press over here. However, EU sites are all atwitter with headlines like “Ubuntu Sells Out!”

Ubuntu phoneThat was referring to the first flash sale, held Wednesday morning EU time, in which all devices being made available were sold out in “just a few hours,” according to Softpedia. In fact, it sold so quickly that a decision was made to hold another flash sale that same afternoon. The original flash sale was supposed to last for nine hours. The number of devices sold hasn’t been released.

Christine Hall

Christine Hall has been a journalist since 1971. In 2001, she began writing a weekly consumer computer column and started covering Linux and FOSS in 2002 after making the switch to GNU/Linux. Follow her on Twitter: @BrideOfLinux

Google Fiber, Net Neutrality & More…

FOSS Week in Review

Larry Cafiero’s suffering through a power failure, so you’re stuck with me today.

The holiday fest is finally over for most — it should be for everyone by Monday morning — and it’s time for some normalcy to return to the world. Of course, these days what passes for normal is pretty damn weird, if you ask me, which you didn’t. News from the tech sector is pretty quiet, but should begin to pick-up as soon as managements’ hangovers clear and the suits get back to creating mayhem…

But here’s the best of the best (or the worst of the worst, depending on how you see it) from this weeks news.

Google Fiber & the FCC

Our favorite (or not so) search company on Tuesday filed a four-page public comment with the FCC, giving the august agency (or not so) yet another reason to reclassify ISPs under Title II of the Telecommunications Act. The reason would be access to telephone poles and other stuff.

It seems that Google hasn’t always been able to gain access to infrastructure such as utility poles, ducts, conduits and rights of way in its attempt to bring speed-of-light Internet access to the U.S. one city at a time. The company claims that reclassifying service providers as common carriers would open the door and give it access.

Christine Hall

Christine Hall has been a journalist since 1971. In 2001, she began writing a weekly consumer computer column and started covering Linux and FOSS in 2002 after making the switch to GNU/Linux. Follow her on Twitter: @BrideOfLinux

2014’s Five Biggest Stories Affecting FOSS

Another year has come and gone, and as you might have guessed, 2014 still wasn’t the year of the Linux desktop.

Covering FOSS and Linux isn’t nearly as exciting as it was a decade or so ago — but that’s a good thing. Back then, we were at war with nearly every proprietary software vendor on the planet and faced threats from all directions, including up and down. To be sure, we didn’t start the wars we were fighting, as PROFAL (the People’s Republic of FOSS and Linux) only wished for peaceful coexistence.

The dust settled long ago and it appears as if we won most of these wars we didn’t start. Even our old arch enemy Microsoft is now waving the flag of peace and is seeking to normalize relations with us. And our old arch-arch enemy, SCO, doesn’t even exist any more — at least not in any form that we would recognize as the SCO of old. May Caldera rest in peace.

That doesn’t mean there’s not still news to be covered in the FOSS world. There is — and plenty of it. But these days, it’s mostly about advancements in technology, new start-ups and new alliances. We still face threats, to be sure, from crackers, spooks, politicians, the RIAA and the MPAA, but these forces threaten all of computerdom, not just FOSS, so we’ve been able to nurture some new strange bedfellows to join us in our struggles.

As years go, 2014 wasn’t the most boring year in the history of the free software movement, but it also wasn’t overly exciting. Again, that’s a good thing as it means there was no battening down the hatches and stuff. Still, there were many trends in the news this year which directly affect the purveyors and users of FOSS.

Here’s my top five list:

Christine Hall

Christine Hall has been a journalist since 1971. In 2001, she began writing a weekly consumer computer column and started covering Linux and FOSS in 2002 after making the switch to GNU/Linux. Follow her on Twitter: @BrideOfLinux

Sony & North Korea: Dumb & Dumber

Hacking, hacking, everywhere hacking. And not the good kind either. We’re talking cracking hacking.

Take the Sony hack for instance. Bunches of movies set for Christmas release are now available online for free, for those willing to break the law and invoke the displeasure of the MPAA while firing up the ol’ BitTorrent. Worse than that: even more bunches of Sony employees have had their financial lives turned upside down, with all of their personal information leaked. Not so bad, however, is the news that “The Interview” won’t be making an appearance on a screen near you anytime soon.

Oddly, it’s that last tidbit that’s been getting the most press. That, and the ongoing argument on who’s to blame for the Sony crack hack.

At first, U.S. authorities said that the North Koreans didn’t do it. Then they said they did. The North Koreans countered with a “no-way-Jose” and offered to help in the hunt to find the real culprit, which elicited an adamant “no-way-back-atcha” from the U.S.

Christine Hall

Christine Hall has been a journalist since 1971. In 2001, she began writing a weekly consumer computer column and started covering Linux and FOSS in 2002 after making the switch to GNU/Linux. Follow her on Twitter: @BrideOfLinux

The Ongoing Wars Against Free Tech

After a few months of not hearing much from Microsoft, the company has been in the news a bit recently. First there was the brouhaha when it announced it was offering the .NET framework as open source. Then there were several big security problems with Windows, with one serious vulnerability going all the way back to Windows 95.

Although this would’ve been big news in the old days, the FOSS press has been relatively quiet about all this. There were a few articles about the .NET thing, with some writers pointing out that the MIT license which Redmond is using will offer no patent protection for Redmond owned .NET related patents, and the Windows security issues got next to no FOSS coverage at all.

My how times have changed.

A decade ago the open sourcing of any major program by Microsoft would have FOSS writers in a dither, even if released under the GPL. We would’ve been uber suspicious, certain that this was only the front end of a plan to end Linux and FOSS as we know it. As for the Windows security woes, we’d be rubbing our hands with glee, writing paragraph after paragraph on how much this proves the inferiority of Windows and the superiority of our beloved Linux. In those days, we had to take our good news wherever we could find it.

Christine Hall

Christine Hall has been a journalist since 1971. In 2001, she began writing a weekly consumer computer column and started covering Linux and FOSS in 2002 after making the switch to GNU/Linux. Follow her on Twitter: @BrideOfLinux

Facial Recognition: It’s Hide Your Face Time

Do you have any traffic tickets you neglected to pay? You know, the kind that eventually turn into bench warrants and cause you to be super careful when you drive, lest you get pulled over for yet another minor infraction and end up handcuffed in the back of a squad car, on your way to spend a few hours in the local hoosegow until your significant other shows up with bail? If so, don’t worry. As long as you manage to not get pulled over, you’re still reasonably safe. But the time is rapidly coming when just walking down the street minding your own business might cause a squad car to be dispatched to pick you up to make sure you pay your fine, thanks to our old buddy, facial recognition.

facial recognition - surveillance camerasI know this is old news and it seems like implementation of the technology in such manner is years away — but I think it’s coming quicker than we think. Some may even think this to be no big deal. After all, what’s wrong with the fuzz having the ability to pick lawbreakers out of downtown pedestrian traffic or while on a jaunt across the parking lot to Office Depot at a local strip mall? Wouldn’t that include the ability to get dangerous violent criminals off the street?

Well, yes. But this old hippie still doesn’t like it. During my life I’ve seen too many instances where the police overzealously abuse a new technology they’ve embraced. Think tasers or pepper spray — or swat teams for that matter. Do a Google to get an idea of how many unarmed citizens have been dispatched to their graves through the wrongful use of tasers or pepper spray — although the investigation of these incidents rarely find fault with the officer who did the dispatching.

Christine Hall

Christine Hall has been a journalist since 1971. In 2001, she began writing a weekly consumer computer column and started covering Linux and FOSS in 2002 after making the switch to GNU/Linux. Follow her on Twitter: @BrideOfLinux

Drupal Hack & WordPress Users

It’s not a good day for Drupal users, with the security folks at the CMS platform telling all users to consider themselves compromised if they didn’t install a security patch within seven hours of its release on October 15th.

Fixing the infected sites will require a bit of work. Sites will need to be taken offline, and the current install of Drupal blown-up and replaced with a backup from before October 15th. Any changes made made to a site since that date will have to be redone. Site owners will also need to notify their hosting companies of the situation, since the Drupal exploit could also be used to hack into other sites on a host’s server. Hosts will not be happy to hear this.

Users of other CMS platforms can give a sigh of relief — after all, they’ve dodged a bullet — but they’d be well advised to pay attention; a similar scenario could play out on any platform at any time.

Christine Hall

Christine Hall has been a journalist since 1971. In 2001, she began writing a weekly consumer computer column and started covering Linux and FOSS in 2002 after making the switch to GNU/Linux. Follow her on Twitter: @BrideOfLinux

Should Everything in the World Be Facing the Internet?

From its inception, we knew the Internet to be an unsafe place. Before the first server was cracked by an online hacker, we knew that was bound to happen sooner or later. We knew because people were already breaking into computers, even without the Internet offering 24/7 cracker/hacker convenience.

Back in the early 90s, when I was living in the college town of Chapel Hill, I shelled-out five bucks or so at the local Egghead Software store for a shrink wrapped floppy disk loaded with “shareware” utilities for MS-DOS. Twenty years have passed, so I don’t remember what tool I needed, but I’d gone there specifically looking for something or another and had been directed to that particular product by a clerk at the store. Once I got home, I stuck the disk into the drive, looked over its contents and installed a couple of the apps.

securityThat was the end of it, or so I thought.

Several months later a biology major friend of mine with no computer skills — yes, in those days it was possible to earn an undergraduate science degree without knowing how to use a computer — dropped by to use my computer, a 486 with a whopping 4 megs of RAM. She was set to graduate soon and needed to use my machine to prepare a resume. I opened WordPerfect and set her loose to type away, answering any questions she had as she worked — such as how to remove a formatting code or preview how the document would look when printed.

An hour or so later, when she finished, I saved her work to a new blank floppy and sent her to see our mutual friend, Tony, to print it, as all I had was an old, noisy and beat-up Epson dot matrix printer and he had a fancy daisy wheel job. Two days later, she was back at my door, mad as hell.

Christine Hall

Christine Hall has been a journalist since 1971. In 2001, she began writing a weekly consumer computer column and started covering Linux and FOSS in 2002 after making the switch to GNU/Linux. Follow her on Twitter: @BrideOfLinux

Latest Articles