Wednesday, 28 April 2021

The Puppy and the Dragon - week 13

Linus is something quite exotic for many and is often confused to be an operative system, it is actually a “kernel” around which many distributions are being developed. Those “distros” can be quite different one from the other, it definitely can generate a bit of confusion but also gives gigantic opportunities in terms of creating products that really fit the user’s needs.

Distros are designed to be optimized for specific tasks or different target users, they may have a small or big users base, and community, from which the maintenance and updates also depends, they all have a story, their specific origin, licensing choice, and business model (because yes also non-profits must have a business model).

Today I’m going to briefly introduce two different distros, Puppy and Kali.

Puppy Linux

Puppy Linux is a primary open-source distro belonging to the family of light-weight Linux based operating system, it is licensed GNU GPL.

The main target of Puppy is not a particular cluster of users, it is instead a particular class of machines. Puppy requires only about 600 MB (64-bit) or 300 MB (32-bit) to run and can be run directly from the RAM! Thus, making it a perfect choice for an old or slow machine. It can be used to revive legacy devices, avoiding waste.

The founder of the distro, Barry Kauler, released Puppy 01 in 2003, he retired in 2013 and since then the project has been followed by Larry Short, Mick Armando, and the Community in general. The last release is Puppy 9.5, September 2020.

In Barry Kauler's mind, Puppy Linux is a response to the trend of seeing Linux distros becoming more and more demanding in terms of system requirements.

Puppy Linux scores 19th in the DistroWatch “12 months” ranking. Not bad!

Kali Linux

Kali Linux is a Linux distribution, with more than 500 already installed penetration testing tools it is perfectly designed for “ethical hacking” activities such as digital forensics and penetration testing.

Kali was developed by Mati Aharoni and Devon Kearns with the first version “moto” released in March 2013, it is Debian-derived, maintained and funded by Offensive Security, the chosen license is GPLv3.

The original purpose of the distro was “Kernel Auditing”, which explains the name KALI (Kernel Auditing Linux), still the misconception it refers to Kali, the Hindu goddess increases the fascination of the brand.

Kali Linux increases its popularity also with users out of the security industry thanks to the TV series “Mr. Robot” where it appears many times.

Kali Linux scores 22th in the DistroWatch “12 months” ranking. So the Puppy won the day!

 

SOURCES:

DistroWatch

https://distrowatch.com/

It’s FOSS

https://itsfoss.com/best-linux-beginners/

How-To Geek

https://www.howtogeek.com/191207/10-of-the-most-popular-linux-distributions-compared/

Tuesday, 20 April 2021

H as in Heroes, who needs the Hackers? - week 12

Romantic and somehow postmodern, the Hacker figure, as emerged in this week reading topic, is a force for good. Those fascinating creatures, on one hand, are enormously narcissistic and in love whit themself and their life on the other hand they are not selfish or greedy for money.

The hacker’s suspicious attitude when comes to authority puts them on the frontline when comes to fight against powerful villains, and just as Robin Hood they do not seek enormous riches for themself; but don’t take this wrong, they don’t mind at all to be wealthy they just don’t have money as the main and final goal of their actions. This last aspect may cause them to not be understood by our economic-centric societies were the most skilled are supposed to mostly seek first for money, then for fame; real hackers may not care about the first and adverse the second.

In certain countries to be a hacker is a crime by itself, even for someone to claim himself to be one can put him in very serious trouble, this is not only because of the potential those people have to commit actual crimes, it comes from a widespread misunderstanding and a general ignorance of what genuine hackerdom really is.

Of course hackers are expert of their fields, coding, it, computer sciences and so on… and this in the new digital era makes them the fittest to be. Even more their approach to education and “professional recognition” is extremely meritocratic, disintermediated and non-discriminatory, this makes them very comfortable in a stage where concepts like “continuous learning”, “peer-recognition” and “hands-on experience” are becoming mainstream, challenging the more traditional and pyramidal tertiary educational models.

With the “all information should be free” dogma The hackers were the first to realize the importance of data in future (now present) societies, and economies; and while we are all adapting to it, they are data-minded native, a big advantage.

Much more than bits… Passion, Freedom, Caring, Creativity… Real hackers embrace life at its full, far from being monads in their shiny technical superiority they aim to be complete people whit an active role in the society, starting from sharing their knowledge (because we do have too many problems to waste time to find the same solution to one of them twice). This mentality is just what we need for the 3rd millennium citizen to have.

As a final note, hackers in my opinion have one merit, a big one, even despite the bad reputation, they managed to communicate, with their charisma and life example, a romantic and adventurous side of computer science, otherwise boring like a long string of zeros and ones.

Hackers as modern Heros can not only keep producing solutions for the digital era society problem, for everyone to benefit from, but they can also fascinate, educate and ultimately evangelize the masses whit their knowledge and values. They can be positive and inspiring role models.

So all things considered yes we need the hackers to be and stay whit us.

Wednesday, 14 April 2021

Two cases - week 11

One case about online censorship…

Online censorship is practised in every country in the world, such control, for example against paedophiliac pornographic contents or suicidal materials is not in contrast whit the values of a healthy democracy. When comes to online censorship on political matters you would expect it more from countries like Nord Korea or China, but that is not always the case… and today I’m pointing at you… Australia.

In the year 2006 Australian politics where still entrenched whit the political debate about the cursed war in Iraq, do not need to remember that Australia was a very active and loyal member of the “coalition of the willing” led by George W. Bush’s US, The back then Australian prime minister John Howard was under attack from the opposition and the general public about the decision of joining that war, which in the year 2006 was already evident to have been a very poor choice.

Richard Neville, an Australian futurist and social commentator made up a satiric web page, johnhowardpm.org, whit a fake apology from the prime mister about the Iraqi mistake, whit a layout somehow resembling Howard’s real website. The document reached 10,500 visits within 24 hours.

The spoof website was turned down by the web hosting company, Yahoo whit no notice. After request, it was told that decision has been made after a government “advice” to do so.

They used an accusation of fishing, due to the look of the page, to cover what in reality was an arbitrary and political act of censorship. 

 

…and one about privacy

This one is personal. Last year I took the questionable decision to go back to study, I got admitted at TalTech, an happy choice, and I started my journey in September a bit worry to failure, having no previous substantial experience as a computer scientist. Whith a lot of study, commitment, and a bit of luck I made my way until now, with great results, so great in fact my name got published on the institution’s official website in the Dean “Book of Honour”, so good so far, I have nothing to complain, but…

The publication of this list discloses a few personal information about me, that I’m studying, where I study, the specific course I’m taking and who are some of my classmates. None of the above information is present on my social network profiles, which is not a case, I wanted that way.

I wasn't asked if I wanted my name to be there, and I got only casually notified after the publication by a classmate. 

Privacy has to been handled carefully, also when is about “good things”, because all the data should belong to their owner and only to him.

 

SOURCES:

Government orders spoof site shut

https://www.smh.com.au/national/government-orders-spoof-site-shut-20060317-gdn6ag.html


THE BOOK OF HONOUR

https://taltech.ee/en/book-honour


Wednesday, 7 April 2021

Don’t try to steal in the thief’s house - week 10

 As a European person, I admire the American culture for two particular aspects, the first being that everyone has given a second chance (admitted is strong enough to survive after failure) and the second, being the great amount of pragmatism when comes to “use” people who can benefit the society, even if controversial. In Italy a person like Kevin Mitnick maybe would never have been jailed because of the lacklustre and slow judiciary system and probably would have never become an influencer for the good because of the hacker stigma.

Like many other great American stories Mr. Mitnick had a second chance in life and after paying his debt with the society he put his skills and his fame to work for the good. He entered the process to educate people on how to protect themselves from IT risks. Mitnick analysed what are the sources of security…   

…and he came with the three points formula:

·       Technology: networks, firewalls, antiviruses...

·       Training: awareness of different attacks

·       Policy: set procedures and requirements

Let us try to use this formula to analyse the situation in Italy.

When coming to technology and its networks Italy is quite advanced, as a dense populated first world country, the peninsula benefits of good It infrastructure network as highlighted in the NATO CDDCOE country report liked below. An ever-increasing focus is given to Network security.

Talking about policies and legal requirements for IT security the same report tells that Italy is also in good shape. The country has to complies whit the many European Union requirements both the legal and institutional framework and those requirements are increasing and improving year by year.

Perhaps looking at the Mitnick formula Italy’s Achilles’s heel is in training, there is no serious computer science education in the schools' curricula nor there are mainstream programs of public awareness to educate the general public, this leads to the common misconception that IT treats are all technical and can be simply stopped installing the best antivirus, the concept of “cyber engineering” is out of common sense and doesn’t translate in any Italian word.

All considered the situation in Italy in terms of Cybersecurity is not that bad, perfectly in line with most of the western countries, none the less, the country should implement programs to educate better on the topic the younger at school (hopefully, they may evangelize the older too!). Various programs can also be undertaken to educate the general public, the involvement of some testimonials, celebrities and respected people, can help to reach even the less tech-savvy ones. Definitely to have an Italian Kevin Mitnick, in his good-guy version, of course, may help.

 

Sources:

NATO-CCDCOE: National Cyber Security Organisation: Italy

https://ccdcoe.org/library/publications/national-cybersecurity-organisation-italy/

In the blink of an eye - week 14

  Technology has many effects on human societies, among the bests, is that it “enables people”. It makes it possible to do something that be...