Showing posts with label Offline. Show all posts
Showing posts with label Offline. Show all posts

Tuesday, 23 July 2013

Canonical takes Ubuntu forums offline in wake of password breach

Canonical, makers of the Ubuntu Linux distribution, recently announced that its Ubuntu help forums suffered a security breach over the weekend. Attackers were able to harvest an estimated 1.82 million user names, email addresses, and passwords from the site. Canonical says it isn’t sure how hackers were able to breach its systems and the company has taken the forums at Ubuntuforums.org offline as a precaution.

Canonical is warning anyone with an Ubuntu Forums account about the hack via email. The company is also advising users to change their security credentials on other sites, especially email, if they used the same password and username/email for other online services.

Ubuntu.com services such as Ubuntu One are not believed to be affected by the hack since they do not share the same login account as the Ubuntu forums.

Fans of the Ubuntu forums began reporting that the site had been defaced on Saturday. The hacker or group of hackers who breached the site posted an image of a penguin (the Linux mascot is a penguin) holding an AK-47.

The message underneath the image suggested the hackers were more interested in exposing a poorly secured site than anything else. “None of this ‘[you got hacked] by albani4 c3bir 4rmy’ stuff,” the message on Ubuntu’s forums site said. “Straight up, you dun goofed. It's as simple as that.”

It’s not clear if the hackers plan on exposing the database of user names and passwords online. Nevertheless, there is a definite possibility these account credentials could begin circulating around the less reputable areas of the Internet.


For now, the hack doesn't appear malicious, but users should take caution.
Canonical says forum user passwords were not stored in plain text and were hashed and salted. A hash uses a mathematical algorithm to convert plain text passwords into a series of numbers and letters. A specific hash will create the same string of letters and numbers each time for the same input (in this case a password). To make hashes more secure they are further obscured by “salting,” a process that inserts random bits into the hash making it harder to guess the original password.

Canonical had not returned our request for comment at this writing, so it’s not clear which hashing algorithm the company was using. However, a report from Ars Technica says Canonical was using the md5 hash. MD5 is a popular hashing algorithm that is often used by software companies as a security check to let users ensure downloaded executable files were not tampered with or corrupted. But md5 is not considered to be a secure choice for hashing passwords.

Reports of password breaches are always a good time to reevaluate your own online security practices. Always make sure you are using unique passwords for every site you visit online. For tips on generating your own passwords check out PCWorld’s “Learn to use strong passwords” or “Passwords: You're doing it wrong. Here's how to make them uncrackable.”

Use a password manager such as LastPass or Password Safe to store all your various passwords for different online sites. These programs can also create new passwords for you and can automatically fill out login forms for you.

Finally, activate two-factor authentication for any services that support this security measure such as Battle.net, Dropbox, Evernote, Facebook, Gmail, Twitter, and Outlook.com. Two-factor authentication requires you to enter a second, shorter temporary password that is usually generated by a smartphone application or small key fob.

Many services that offer two-factor authentication allow you to set trusted PCs so that you only have to enter your credentials once on new PCs or browsers.

Canonical has not said when Ubuntu forums will be back up. In the meantime, any Ubuntu user looking for support can check out sites such as Stack Exchange’s Ask Ubuntu or Ubuntu Discourse.

Friday, 19 July 2013

The new Chrome App Launcher: Google's backdoor into the offline world

On Friday, Google gave Windows users something that they’ve been pining for: A Start button. And even better than that, Google’s version keeps you on the desktop and actually opens a pop-up menu full of programs, unlike the nerfed Start button that’s slated to appear in the Windows 8.1 update.

No, Larry Page hasn’t decided to jump into the crowded Windows Start button replacement arena. Instead, Google’s engineers quietly dragged Chrome OS’s App Launcher—the Googlefied equivalent of a Start button—over to Chrome for Windows today. The seemingly simple addition is a major step in Google’s push to bring Web standards to walled gardens.

The Chrome App Launcher is exactly what you’d expect: A taskbar icon that lets you quick-launch Chrome browser apps, such as Gmail, the Play Store, Angry Birds, and yep, even Chrome itself. Simple, right? But the little launcher is a Trojan horse for much bigger ambitions—especially when paired with packaged Chrome apps.

Packaged apps are available now, but since Google has yet to highlight them in the Chrome Web Store, you might not be familiar with them. Packaged apps are programs built on the bones of the Chrome browser. They use traditional Web languages such as HTML5 and CSS, but they run as separate, standalone software that can also be used offline, unlike traditional browsers.

You could consider packaged apps to basically be desktop Web apps, as odd as that sounds.
“For quite some time, we’ve had a dichotomy between Web apps and native apps, and one of the things that sets them apart is the ability [for native apps] to be launched from the desktop and have a degree of persistence and independence from the browser,” says Ross Rubin, principal analyst at Reticle Research. “The availability of the Chrome App Launcher for Windows helps to further blur the line.”

Hey, who put Chrome OS’s Start button where my Windows Start button used to be? The apps without tiny arrows in their lower-left corner are all packaged apps.

  With the arrival of packaged apps and the Chrome App Launcher, no longer will you need to connect to the Internet, open the Chrome browser, and launch the Web app you want to use. Now, there’s a Web-app Start button right on your taskbar, and the packaged apps don’t even require an Internet connection.

“Clearly, one of the missions of the whole Chrome initiative is to serve as an incentive for people to adopt HTML5 and create cross-platform or Web applications,” says Rubin. “People want to interact with their Web apps as easily as they do with their desktop apps. Having the [Chrome App Launcher] available helps to ease the transition.”

Each packaged app runs as its own instance, not as part of the main Chrome browser, as this look at several packaged apps in the Windows fast-switch interface shows. (Click to enlarge.)

It’s made even easier by the App Launcher’s Chrome tie-in. All your Chrome apps seamlessly travel with you to any Windows PC on which you’ve installed the Chrome App Launcher, even the locally stored package apps (though those take a few moments to download to new installations). Download a Chrome app once, and it’s available anywhere.

What’s more, the Chrome App Launcher lets you pin shortcuts for specific apps to the Windows taskbar or the desktop—mimicking native software functionality even further. It doesn’t matter whether the app is packaged or a Web native, either. Blurring the lines, indeed.

As a Web-focused company, Google gains whenever more people start using the Web more often. But beyond generally coaxing the world to Web services, Google has a direct interest in getting people in front of Google’s Web services. That’s the reason the Chrome App Launcher comes chock full of links to YouTube, Chrome, Gmail, Google Drive, Google Search, and the Chrome Web Store (whose third-party apps often include Google Ads).

Monday, 15 July 2013

America Offline: Can the U.S. be disconnected from the Net?

Imagine a world with no tweets, no emails, no notifications pushed to your phone. A world without Candy Crush or indeed, even Facebook; a land without the Internet.

The thought may sound like heaven to minimalists, but in recent months, dictators around the world have been all too willing to transform the idea into a hellacious reality, flipping a switch and completely disconnecting whole nations from the Web: Syria. Egypt. Libya. All have been plunged into darkness during periods of civil unrest.

But is there any way the United States could be disconnected from the Internet? Could an act of terror, war, or simple governmental dictatorship snatch away our social feeds and online gaming? Curious, I reached out to several experts to examine all the potential doomsday scenarios.

They say the Internet is a series of tubes. One obvious way to disconnect the United States from the rest of the Net would be to cut, blow up, or otherwise destroy those tubes, right?

Not so fast. As it turns out, you'd need to cut a lot of tubes to completely disconnect the U.S. from the Internet. Check out the map below of all the undersea cables that connect the country to the outside world. Now, consider that TeleGeography's map lists only undersea cables (which you can peruse here), and doesn't include the legion of wires that connect the U.S. to Canada and Mexico over land. And what about wireless networks?
TeleGeographyThat's a lot of cables! (Click to enlarge.)
Yeah, you're starting to get the picture. Disconnecting all of America's tubes just isn't going to happen.

"It's close enough to impossible that in realistic terms, it's unlikely to the point of irrelevancy," says Patrick Gilmore, the chief network architect at Akamai, a content delivery network estimated to be responsible for up to 20 percent of all Web traffic. The good news doesn't end there.

"Even if you could do that, a lot of the reason things were done like that in Egypt and Syria were to keep people from posting to social networking sites," Gilmore continues. "Many of those social networking sites are hosted here in the United States. So if you could wave a magic wand and disconnect the United States, people would still see all those posts from each other inside the United States. It wouldn't stop that from happening."

Score one for free speech.


If the tubes are the veins of the Internet, the servers that power the Net are its brains. Could hackers use their botnets and evil geek powers to send America spiraling offline?

"That's actually much more likely than a physical attack, I think," says Dorian Kim, VP of IP engineering and network development for NTT Communications, the second-largest Internet backbone provider in the world. "…The entire wiring system relies a great deal on various systems of trust. It's possible for somebody—especially someone who is kind of an insider at an ISP or telco—to do things that would disrupt the infrastructure in a pretty widespread way."

There are several caveats to that, however. Any hack attack of that magnitude would very likely extend beyond U.S. shores, for one thing. It would be very difficult and take a high level of technical ability to accomplish. And it wouldn't last very long, either: Given the decentralized nature of the Net, Kim says the disruption would likely be limited to hours, or a day or two maximum.

Even if hackers managed to wreak havoc on the U.S. Internet, all the experts I spoke to expressed extreme doubt that an attack would be able to take out the entire country.


"Let's take the CloudFlare attack," says Gilmore, referring to a DDoS attack in Europe a few months ago that CloudFlare mitigated. "I was quoted in The New York Times as saying it was the largest publicly disclosed attack in the history of the Internet. That was 300 gigabits, or 300 billions. The total traffic on the Internet is measured in many, many terabits—trillions. And the U.S. is a large portion of that. A 500-gigabit attack—which again, would be the largest attack ever—would not be able to disrupt even a large portion of the United States.

"Some networks would go down," he continues. "You might be able to take out an ISP in a city, and have that ISP go offline, but to take 25 or 50 percent of the U.S. offline? It's not impossible to do, but it'd just be so ridiculously difficult."

Individual things—specific ISPs, websites, and so on—would be much easier to attack, says Gilmore. Kim agrees: The Internet's backbone carriers are just too strong to hack with any sort of effectiveness.

"[Hackers] would be much better off going for the softer underbellies of companies than going after core infrastructure," he says.
NSA headquarters.
So, widespread tube cutting and hack attacks would not only be incredibly difficult to pull off, but they would also be of questionable effectiveness. Now, let's explore the darkest of these dark options. The Middle Eastern countries mentioned above disappeared from the Net thanks to the heavy hands of iron-fisted dictators. Is there any way the U.S. government could possibly do the same? Does the Man have an Internet kill switch?

"No, there's no legal authority for it," says Dan Auerbach, a staff technologist with the Electronic Frontier Foundation. "Even if some were invented through creative lawyering, the practical reality is that it would just be too difficult to do in any sort of short time frame."

This circles back to the United States' dense web of tubes, and all three experts I spoke to touched on this point. Small countries like Syria have very few Internet access points, and very few service providers maintaining those access points, making it trivial for the government in such nations to shut down the hardware. That ain't so in this country.


"In the U.S., by contrast, we don't have that sort of monolithic ISP space," says Auerbach. "We have many different networks, and within those networks, there are many types of subnetworks operating. The amount of machinery you would need to shut down is enormous and controlled by lots of people. It'd be really hard to do that in any sort of quick way."

And again, the headaches double when you add wide area and cellular networks to the mix. Safe to say, in the States, The Man isn't going to shut us all down.

So, rule out the tubes, the hackers, and The Man. What might be the most effective way to wreak havoc on the country's infrastructure? NTT's Dorian Kim has an idea.

"Most of the networks—whether you're talking about networks like NTT, Level 3, AT&T, or content distribution people like Netflix or Akamai—all their traffic tends to get exchanged in a very small number of 'carrier hotels' in cities around the country," Kim says.


"The number of those concentration points of activity that you'd need to knock out to do serious damage to the Internet is actually smaller than the number of submarine cables," he continues. "If you ... take out, oh, half a dozen of these around the country, you'd actually do serious damage to the infrastructure. And if you double that and take out the dozen biggest carrier hotels, the impact will be very severe."

And therein lies the Internet's biggest weakness. The great big Web's decentralized nature makes it incredibly resistant to attack, but when you get down to brass tacks, all the mininetworks that make the whole have to hook up somewhere.

"A lot of this comes down to the fact that there are economics behind how networks are built," Kim says. "You have to think about concentration points based on population, and with insulated networks, it makes sense for people who have to interconnect to be as close to each other as possible… Eventually, you wind up in a metro area with one or two gigantic carrier hotels where everybody's congregated."

But don't let that fool you: Pulling off an attack of that nature would be very difficult indeed, and its impact would be felt far and wide, not just in the United States. If—if—a large, well-informed, well-trained, and well-equipped team were able to pull off such a feat, it would be a direct attack against the entire world.
RenesysThe lighter the green, the more resistant the Net. (Click to enlarge.)
Let's pull it back a bit. Thanks to its central role on the Net and its decentralized network infrastructure, the odds of the U.S. pulling a Syria and disappearing from the face of the Web are effectively nil. In fact, when Renesys—a leading network research firm—examined how difficult it would be for countries all around the world to be disconnected from the Net, the U.S. was ranked "Resistant." Not Average. Not even Low Risk. Resistant. (See the map above.)

So breathe easy, folks. For all intents and purposes, if you're in the States, you've got mail—and nothing is ever going to take away the Internet in a flash. Unless, of course, you forget to pay your bill.

Thursday, 11 July 2013

Dropbox update eases worries over offline access to business data

As every hapless teenager stranded in a dank cabin in the psychopath-ridden woods can tell you, your cell phone is useless if you don't have a signal. For business users, the stakes are just as high: Travel to a farflung corner of the world to meet with clients and "zero bars" is a distinct possibility. And God help you if you have to take a plane ride anywhere and aren't lucky enough to get on the handful of jets with onboard Wi-Fi.

While being unable to make calls, send emails, or check the news is certainly an inconvenience, the problem is compounded if you rely on cloud services to actually get work done. Storing data online and running apps that rely on a live Internet connection mean you can abruptly turn into an unproductive layabout when wireless service isn't available.

Hybrid cloud services have started to address the issue, and Dropbox has been leading the charge. Files stored via Dropbox are automatically stored both in the cloud and on your local machine. Changes made to one file are copied in the background when a connection is available, and synced up with all devices running the Dropbox software. Google Drive, SugarSync, and many other cloud storage services work about the same way.


That's a start, but it only addresses the very beginning of the problem. A growing number of services are designed to work exclusively over the Web, and if you're not connected, they simply don't run at all. (Think Facebook.) Well then, why not enable these apps and services to work in offline, hybrid mode, the way Dropbox works? Evernote does it. So does Gmail; it doesn't include all its features from top to bottom, but what it offers is good enough for most users.

Offline support is uncommon because coding this kind of software isn't easy. There are myriad issues to consider: What happens if you change a file in two places before re-syncing? How do you manage the unavoidable data file differences between, say, an iPhone and a Windows 8 PC? And good luck when you bring multiple users into the mix. Imagine five offline users working on a single document simultaneously, then trying to sync en masse. Nightmare. Who wants to try to code all of this stuff themselves?

Well, with the new API releases the company put out this week as part of its DBX developers conference, Dropbox has told the developers of the world that they don't have to. Without getting too far into the weeds, the new APIs mean that third-party developers can now use Dropbox to store program data instead of having to stash it on the user's hard drive or build their own cloud service to store it. That means you'll be able to work on a spreadsheet, draw a picture, or play a game on one device… then pick right back up where you left off on another, whether you're online or off.

With 100,000 apps already supporting Dropbox in some fashion, this isn't a pipe dream. Universal access to data from any device and robust offline support have the potential not just to revolutionize the way we work but to become expected, almost required components of any piece of software we use. As Dropbox CEO Drew Houston told TechCrunch, "Every app is going to be designed this way in the future and we wanted to get started on that now.” I can't wait.

Tuesday, 25 June 2013

For Modern Jurors, Being On A Case Means Being Offline

More courts are asking jurors to avoid social media services and tools that have become an integral part of modern life, like Twitter, Facebook, email, texting, instant messaging and Internet research.
More courts are asking jurors to avoid social media services and tools that have become an integral part of modern life, like Twitter, Facebook, email, texting, instant messaging and Internet research.

In the Mercer County Courthouse in Trenton, N.J., John Saunders, a jury manager, spends his weekdays shepherding potential jurors. Much of what he tells them regards the paraphernalia of 21st century life: cellphones, tablets and laptops. These are OK to use in the waiting room, he tells them. "We realize life does not stop."

But in the courtroom, it's all phones off. Laptops and iPads stay with Saunders, and jurors are given a tag to reclaim their items. "Unlike the airport, when you return, your item will be there, and no baggage charge guaranteed," he says.

While jurors were once warned not to discuss with others the cases they were hearing, warnings to jurors in today's social media age have become much more explicit. Increasingly, jurors are hearing about what they should not
do with the devices that connect them to the world.
In New Jersey, judges like Travis Francis, the assignment judge in Middlesex County, have adopted model instructions to jurors that sound like something out of a Best Buy catalog.

"Do not use any electronic device," he tells them, "such as the telephone, cell or smartphone, BlackBerry, iPhone, PDA computer, the Internet, email, any text or instant message service, any Internet chat room, blog or website such as Facebook, MySpace, YouTube or Twitter to communicate to anyone any information about the case."

Doing any research or investigating of the case on your own is also forbidden here, as is "visiting the scene" virtually. "Jurors are specifically instructed not to use Google Earth or any other similar utility to visit the scene of an accident or crime," Francis says.

Putting Modern Communication On Hold

These lengthy lists of digital don'ts grow out of a conflict in modern life: Jury duty requires a juror to limit his or her communications with others. To many 21st century Americans, those limits might feel like solitary confinement.

Paula Hannaford-Agor, who directs of the Center for Jury Studies in Williamsburg, Va., says that in an age when everyone's used to instant digital information — finding a restaurant, paying a bill, checking a bank balance — "it's very difficult and really counterintuitive for many jurors" to be told they must refrain from using the Internet to research a case.

But how often does a juror actually visit a crime scene on Google Earth, tweet about the case she's on or look up the filings? Hannaford-Agor says a 2010 Reuters study found that only 90 verdicts were challenged on the basis of juror digital disobedience between 1999 and 2010. But, she notes, those are the only reported cases or instances that were admitted to. Now, Hannaford-Agor says she typically hears about one case a week in which jurors looked up legal terms on the Web or shared their jury duty experience on social media.

Those kinds of communications have sparked various new rules and procedures across the country. In New Jersey, one case involving jury deliberations in a 2011 Bergen County drug trial made a big impact on judges all over the state, including Superior Court Judge Robert Billmeier, who hears criminal cases in Trenton.

"It was actually the foreperson of the jury who got on the Internet despite the judge's instructions not to," Billmeier says. He found information about a minimum prison term that he thought would pertain to the defendant if he was found guilty. "As it turned out, his research was inaccurate," Billmeier says, but that information led to a deadlocked jury and a mistrial. The juror was fined $500.

Where's The Line?

Billmeier has since adopted a juror pledge. Jurors must agree to not engage in any online research or communication pertaining to their trial — and jurors must sign under penalty of perjury. That, he says, "brings home to them how important this instruction is not to get on the Internet, not to use social media, to follow the court's instructions — or there could be adverse consequences."

But what about a tweet that reveals nothing more than what one might tell a spouse, like, "I'm on a jury in a drug case," for example?

The problem, Billmeier says, is that a tweet is an invitation to a conversation. And while such a tweet may not necessarily get someone dismissed or get a verdict overturned, the lines between unacceptable and acceptable tweets are likely to get less clear, says Hannaford-Agor.

"We're starting to hear, begrudgingly, a lot more discussion about under what circumstances is a juror's conduct of going online or posting something actually harmful error," she says.

Meaning that, with social media so integral to our lives, there are some circumstances of jurors going digital that society may simply have to accept as harmless.