Home Blog Page 8922

U.S. broadband goes mass-market in next couple years

Author: JT Smith

The Register reports the prediction from Jupiter Media Metriz that broadband will become a mass-market product, with a quarter of U.S. homes having it by 2006.

DoD releases new GPS standard

Author: JT Smith

joabj writes, “The Defense Department just released the new civilian standards for GPS use, sharpening the horizontal accuracy from 100 meters to 36. Release here.”

LinuxCertified announces Linux Network Services Bootcamp

Author: JT Smith

LinuxCertified.com, a leading provider of Linux training, will
start offering the latest class in its portfolio, the Network
Services Bootcamp, on October 27-28, 2001 in San Francisco bay area (south bay). This workshop has been designed for network administrators in charge of providing key network services on
Linux servers.
This bootcamp is structured along the lines of the highly successful Linux System Administration bootcamp. Students get a powerful Linux laptop at the start of the class, along with other class materials. Their goal is to create a fully functional and secure Linux server. This server will provide the most important internet services such as Web, DNS, Mail, DHCP and File serving.

Students start by putting the system securely on an intranet. They
are then led by a team of network experts via carefully designed
lectures and labs to configure the network services mentioned above.
Students take this laptop with them as a fully configured network
server to further enhance their Linux expertise.

Linux and open source network applications such as Apache, BIND,
Sendmail, SAMBA etc. are the building blocks for most network
services being offered today within the organizations as well as on the internet. This bootcamp enables administrators to rapidly and securely provide these services to their clients. A detailed agenda for the bootcamp is available at:

http://www.linuxcertified.com/network_services.htm l

About LinuxCertified.com

The mission of LinuxCertified.com is to bring Linux to mainstream IT
usage. We firmly believe that Linux has an enormous potential, once it crosses over from the early adopters to the more mainstream users. Our goal is to help this transition by providing:

– Linux trained and certified professionals

– Linux certified products that cater to mainstream users rather than early adopters.

Contact:


info@linuxcertified.com
http://www.linuxcertified.com/

1-877-800-6873(Tel.)

Linux is a registered trademark of Linus Torvalds.

All other names and trademarks are the property of their respective owners.

Gnumeric 0.72 now available

Author: JT Smith

Posted at LWN.net: “This is primarily bug fixes as we prepare for a production ready release
before the end of the year. Graphs require Guppi 0.40.0. In addition to
the plethora of small improvements we threw in a few extras to make it fun.
Morten’s improved search console is very nice, and thanks to Andreas range
selection and non-modal dialogs are now outnumber the old ones. We now
support auto-scrolling during object creation which makes all mouse actions
auto-scrollable.

Chema and his army of evil monkeys have been kicking the tires trying to
make things fail. Please give him a hand. We always prefer to find the
bugs BEFORE we release :-)”

Japanese Linux iPAQ kit released

Author: JT Smith

Posted at LWN.net: 10art-ni Corporation, a Linux and Java system integrator in Japan,
announced their new product named “Melon.”

Melon is a Linux kit which provides Japanese Linux environment on
iPAQ, and is composed of Linux pre-installed 64MB Compact Flash and a
manual. It does not require to remove the default OS on the inside
flash ROM of iPAQ.

Fear led to anti-Microsoft-Passport alliance

Author: JT Smith

Agree or not, ZDNet’s AnchorDesk has commentary on the Liberty Alliance, which aims to compete with Microsoft’s Passport. “The two sides–plus America Online, which seems headed
its own way — need to sit down in a neutral forum and iron things out. We don’t need
competing — and confusing — schemes for a single log-on that would automatically enter user
names and passwords to access a variety of Web services and e-commerce sites.”

Security update to ptrace

Author: JT Smith

Posted at LWN.net: “Yet another ptrace race condition has been found which allows local
attackers to get access to the root account.

Also, a local attacker can use a recursive symlink structure setup
to effectively cause all filesystem actions to hang for an infinite
amount of time.

The IPTABLES implementation in the 2.4 kernel also had a problem in
the RELATED connection handling of the ip_conntrack_module which is
fixed by the supplied packages.”

Category:

  • Linux

SSSCA gets a hearing Oct. 25 — can it be stopped?

Author: JT Smith

by Tina Gasperson
Senator Fritz Hollings will testify about his proposed SSSCA legislation before the
Senate Commerce Committee on October 25. While the Open Source community is
acquainted with the potential effects of this bill on freedom from government
intrusion on our private activities, many businesses that use Open Source
software, government agencies who sponsor Open Source projects, and lawyers who
specialize in technology issues either have not heard of the bill, or do not
understand its implications.Eben Moglen, chief counsel for the Free Software
Foundation
, is succinct: “SSSCA is a deliberate attempt to destroy free
software.”

Moglen believes that the industries behind the drafting of the SSSCA want to
control information from the beginning to the end of every event chain. “The
content industries want to make a leakproof pipe that leads from their
production facility directly to the eyeball and eardrum of the consumer.”

That pipeline must not be broken apart by any technology that is under the
user’s control, he says. “If the computer closest to your eyeball and eardrum
has a free software operating system, the whole rest of the pipe doesn’t
matter: sound on its way to the sound card, or video on its way to the screen,
can be copied or sent anywhere by the OS kernel.

“So the content industries cannot — so long as they adhere to their present
obsolete business models — tolerate the existence of any user-modifiable
operating system for computers. Period.”

And that’s what’s behind Disney’s and other corporations’ campaign
contributions to Hollings and their subsequent “urging” that Hollings, the chairman of
the Senate Commerce Committee, draft the Security Systems
Standards and Certification bill
, which states in part that “it is unlawful to manufacture, import, offer to the public, provide or otherwise traffic in any interactive digital device that does not include and utilize certified security technologies.” And while Disney interests may
be completely aware of the subtleties behind the SSSCA, Hollings may be
unaware of the chain of effects this could set off. “Although I cannot comment
on the technical acuity of Senator Hollings,” says Pat Stakem, a NASA
consultant who works with FlightLinux,
a version of Linux that’s running on unmanned space flights, “there have been
problems in the past with oversight and unintended consequences when a highly
technical issue is legislated.”

This isn’t the first time that Hollings has sponsored highly technical
legislation and tried to rush it through Congress. It is ironic that it came
at a time when Hollings appeared to be on the other side of big business,
fighting for stricter Internet privacy laws. Back in July, Hollings was
testifying
at another Congressional hearing in favor of more privacy
legislation, as opposed to the self-regulation that the Information Technology
Industry Council (ITIC) favors. ITIC is populated by big tech companies that
normally are at odds with each other, like IBM, Microsoft, AOL, Amazon.com,
Compaq, and Dell. At that hearing, Hollings said, “Where did self-regulation
get us?” as he urged Congress to take swift action on new laws for privacy.
Now that draft bill has disappeared, and Hollings seems to have switched
sides, getting into bed with the anti-privacy, anti-freedom corporate
interests.

Hollings and company have turned deaf ears on requests for more information
from NewsForge
and from at least one lawyer we spoke to. A representative from
the office of Scott Draughon, an attorney who specializes in technology law and
policy, contacted Hollings office to request a draft of the bill and was
rebuffed by one of his staff, who told her, “attend the hearing.”

But according to a report at WebNoize,
that hearing may not be completely open. “Non-profit public interest groups
haven’t been invited to the hearing, which has motivated them to take action,”
the report written by Mark Lewis states. The Electronic Freedom Foundation issued an
alert
and is conducting a letter writing campaign to try to stop the
progress of the draft bill, calling it DMCA2, in a comparison to the
restrictive digital copyright legislation that landed Dmitry Sklyarov behind
bars earlier this year when he gave a presentation on e-Book unencryption techniques
at DefCon.

The Association for Computing Machinery’s (ACM) Public Policy Committee is
also trying to persuade Hollings and company of the dangers of the bill. “We
urge you to recognize that there are many legitimate uses of technology that
would be impaired by additional copyright-protection measures,” states a letter addressed to
Hollings
from Barbara Simons and Eugene Spafford of ACM. “Already, we have
seen an unintended chilling effect on computer security research by the DMCA.
Any law along the lines of the SSSCA might well have more far-reaching and
damaging effects, particularly as our nation attempts to enhance the security
of our infrastructure and prevent acts of terrorism.”

Simons and Spafford list some of their objections to the legislation:

  • Colleges, universities and trade schools throughout the United States would no
    longer be able to teach advanced computer science and computer engineering.

  • The acts of writing basic operating system software or assembling simple
    computer systems in classes or as assignments would be against the proposed
    law.

  • Research in computer security and protection would be further curtailed,
    as any such research would be required to be done on (and not interfere with)
    whatever technology is imposed by this law. However, malicious actors do not
    need to be so concerned. This has significant national security implications.

  • Researchers and hobbyists seeking new uses for innovative technology might
    well find their experimentation and prototypes to be criminal under this law.

  • Devices as disparate as electronic cameras, wrist watches, electric
    pianos, televisions, ATM machines, cell phones, home security systems, and
    medical equipment (among many examples) all process and display information
    electronically. Under the proposed legislation, all would be required to
    support anti-copying protocols. In most such cases, this is absurd and will
    raise costs unnecessarily.

  • Inclusion of anti-copying technology in general purpose equipment —
    including real-time computing devices used in traffic control, air flight
    control, medical equipment, and manufacturing — adds to their complexity and
    potential for failure. Unexpected interactions with other code, and accidental
    activation of protection protocols cannot be ruled out in every case, and in
    many venues the potential for damage is extreme.

  • Photocopy machines, telephones and VCRs are now digital in form and can
    copy information. Forcing adoption of anti-copying protocols on those machines
    will change accepted modes of use, at best, and may render them unusable for
    their intended purposes.

  • Other countries will not have similar requirements in their laws and may
    actively fear the imposition of anti-copy technologies; this will put U.S.
    products at a competitive disadvantage with other products manufactured
    elsewhere in the world. At a time when electronics manufacturers in other
    countries are seeking an advantage over U.S. firms, this could be catastrophic
    for the U.S. electronics industry.

  • In addition, the draft version of SSSCA would have significant negative
    impacts on foreign technology imports, such as the Linux operating system, in
    direct violation of our obligations as a participating member of the World
    Trade Organization.

Spafford
testified
before the House Committee on October 10 at the Full Committee
Hearing on Cyber Security, saying, “Legislation that is scheduled to be
introduced into the Senate, the Security Systems Standards and
Certification Act (SSSCA), may further restrict what research is conducted in
information security. Legislation against technology instead of against
infringing behavior can only hurt our progress in securing the
infrastructure.”

Though Spafford, Simon, and FSF lawyer Moglen are well aware of the dangers of
SSSCA, other key elements may only now be waking up to the potential
consequences of such broad legislation. Draughon, who specializes in D.C.
doings in technology, was unaware of the draft and requested a copy from me
when I contacted his office. Government agencies that use Linux and other Open
Source software are also largely ignorant of SSSCA, including the Army, Navy,
and the NSA, and have not been prepared to discuss the issue with NewsForge.

FlightLinux’s Stakem was willing to take a look at the draft and share his
initial impressions. “If the legislation, which appears to be driven and
influenced by big content-providers, does affect Open Source distribution,
then we need to take a long hard look.” But Stakem is not overly concerned
about potential danger to Open Source. “We have to make it [the source code]
freely available, but [the GPL] doesn’t say it can’t be encrypted.

“There is a need to reform intellectual property laws to bring them more into
sync with new, unforeseen realities. Unfortunately, those who can affect those
changes don’t necessarily understand the issues.”

The Navy is preparing to experiment with Open Source software, “particularly
Linux,” and has signed a Cooperative Research and Development agreement with
the Open Source Software Institute (OSSI). But are they aware of the dark
clouds gathering around that scenario? John Weathersby, the director of the
OSSI says, “SSSCA is typical of a reactionary bill proposal. It is stimulated
from one side of the spectrum. But it represents a work in progress.”

Weathersby believes that the Open Source community has to take the saying
“eternal vigilance is the price of freedom” to heart. “I see issues like SSSCA
as growing pains that we must wrestle with as we outgrow our protective shell
and realize that we are part of a larger more complex economic picture.

“I don’t see how it can be adequately enforced. It’s like trying to hold back
the tide; you can do it for a while, but then the open market, like Open
Source software, will find its equilibrium.”

Stakem thinks that perhaps the SSSCA will exempt government usage from its
restrictions, but Moglen says there is no such exemption in the current text
of the bill. “But it’s not only about specific applications government might
write. If SSSCA prohibits the Linux kernel, prohibits the Hurd kernel,
prohibits any system with enough openness to permit users to modify its basic
behavior, the ability of one federal agency to publish one applications
program more or less wouldn’t make the slightest difference.

“The software monopolist and the entertainment oligopolist are discovering
that this can be the beginning of a beautiful, but socially obnoxious and
oppressive friendship.”

NetRadio.com dies

Author: JT Smith

Anonymous Reader writes, “Net radio.com has has shut down its site. One of the leading Internet radio stations, the site has entered dot.com Valhalla as another casualty in the war for online music distribution.

http://www.mp3newswire.net/stories/2001/netradio.html.”

Severe Linux kernel bugs show up

Author: JT Smith

From Slashdot.org:
“According to this mail from Rafal Wojtczuk and a german article on Heise Online, there’s a new severe bug in all Linux Kernels, from 2.2.0 up to
2.4.10, which allows users to become root on your system. Kernel 2.4.12 fixes this problem, and RedHat, Caldera and other distributors already supply patches for
their Kernels. See Bugtraq for more information.” Important notes for anyone running a multi-user system.”