Wednesday, 28 April 2021

The Puppy and the Dragon - week 13

Linus is something quite exotic for many and is often confused to be an operative system, it is actually a “kernel” around which many distributions are being developed. Those “distros” can be quite different one from the other, it definitely can generate a bit of confusion but also gives gigantic opportunities in terms of creating products that really fit the user’s needs.

Distros are designed to be optimized for specific tasks or different target users, they may have a small or big users base, and community, from which the maintenance and updates also depends, they all have a story, their specific origin, licensing choice, and business model (because yes also non-profits must have a business model).

Today I’m going to briefly introduce two different distros, Puppy and Kali.

Puppy Linux

Puppy Linux is a primary open-source distro belonging to the family of light-weight Linux based operating system, it is licensed GNU GPL.

The main target of Puppy is not a particular cluster of users, it is instead a particular class of machines. Puppy requires only about 600 MB (64-bit) or 300 MB (32-bit) to run and can be run directly from the RAM! Thus, making it a perfect choice for an old or slow machine. It can be used to revive legacy devices, avoiding waste.

The founder of the distro, Barry Kauler, released Puppy 01 in 2003, he retired in 2013 and since then the project has been followed by Larry Short, Mick Armando, and the Community in general. The last release is Puppy 9.5, September 2020.

In Barry Kauler's mind, Puppy Linux is a response to the trend of seeing Linux distros becoming more and more demanding in terms of system requirements.

Puppy Linux scores 19th in the DistroWatch “12 months” ranking. Not bad!

Kali Linux

Kali Linux is a Linux distribution, with more than 500 already installed penetration testing tools it is perfectly designed for “ethical hacking” activities such as digital forensics and penetration testing.

Kali was developed by Mati Aharoni and Devon Kearns with the first version “moto” released in March 2013, it is Debian-derived, maintained and funded by Offensive Security, the chosen license is GPLv3.

The original purpose of the distro was “Kernel Auditing”, which explains the name KALI (Kernel Auditing Linux), still the misconception it refers to Kali, the Hindu goddess increases the fascination of the brand.

Kali Linux increases its popularity also with users out of the security industry thanks to the TV series “Mr. Robot” where it appears many times.

Kali Linux scores 22th in the DistroWatch “12 months” ranking. So the Puppy won the day!

 

SOURCES:

DistroWatch

https://distrowatch.com/

It’s FOSS

https://itsfoss.com/best-linux-beginners/

How-To Geek

https://www.howtogeek.com/191207/10-of-the-most-popular-linux-distributions-compared/

Tuesday, 20 April 2021

H as in Heroes, who needs the Hackers? - week 12

Romantic and somehow postmodern, the Hacker figure, as emerged in this week reading topic, is a force for good. Those fascinating creatures, on one hand, are enormously narcissistic and in love whit themself and their life on the other hand they are not selfish or greedy for money.

The hacker’s suspicious attitude when comes to authority puts them on the frontline when comes to fight against powerful villains, and just as Robin Hood they do not seek enormous riches for themself; but don’t take this wrong, they don’t mind at all to be wealthy they just don’t have money as the main and final goal of their actions. This last aspect may cause them to not be understood by our economic-centric societies were the most skilled are supposed to mostly seek first for money, then for fame; real hackers may not care about the first and adverse the second.

In certain countries to be a hacker is a crime by itself, even for someone to claim himself to be one can put him in very serious trouble, this is not only because of the potential those people have to commit actual crimes, it comes from a widespread misunderstanding and a general ignorance of what genuine hackerdom really is.

Of course hackers are expert of their fields, coding, it, computer sciences and so on… and this in the new digital era makes them the fittest to be. Even more their approach to education and “professional recognition” is extremely meritocratic, disintermediated and non-discriminatory, this makes them very comfortable in a stage where concepts like “continuous learning”, “peer-recognition” and “hands-on experience” are becoming mainstream, challenging the more traditional and pyramidal tertiary educational models.

With the “all information should be free” dogma The hackers were the first to realize the importance of data in future (now present) societies, and economies; and while we are all adapting to it, they are data-minded native, a big advantage.

Much more than bits… Passion, Freedom, Caring, Creativity… Real hackers embrace life at its full, far from being monads in their shiny technical superiority they aim to be complete people whit an active role in the society, starting from sharing their knowledge (because we do have too many problems to waste time to find the same solution to one of them twice). This mentality is just what we need for the 3rd millennium citizen to have.

As a final note, hackers in my opinion have one merit, a big one, even despite the bad reputation, they managed to communicate, with their charisma and life example, a romantic and adventurous side of computer science, otherwise boring like a long string of zeros and ones.

Hackers as modern Heros can not only keep producing solutions for the digital era society problem, for everyone to benefit from, but they can also fascinate, educate and ultimately evangelize the masses whit their knowledge and values. They can be positive and inspiring role models.

So all things considered yes we need the hackers to be and stay whit us.

Wednesday, 14 April 2021

Two cases - week 11

One case about online censorship…

Online censorship is practised in every country in the world, such control, for example against paedophiliac pornographic contents or suicidal materials is not in contrast whit the values of a healthy democracy. When comes to online censorship on political matters you would expect it more from countries like Nord Korea or China, but that is not always the case… and today I’m pointing at you… Australia.

In the year 2006 Australian politics where still entrenched whit the political debate about the cursed war in Iraq, do not need to remember that Australia was a very active and loyal member of the “coalition of the willing” led by George W. Bush’s US, The back then Australian prime minister John Howard was under attack from the opposition and the general public about the decision of joining that war, which in the year 2006 was already evident to have been a very poor choice.

Richard Neville, an Australian futurist and social commentator made up a satiric web page, johnhowardpm.org, whit a fake apology from the prime mister about the Iraqi mistake, whit a layout somehow resembling Howard’s real website. The document reached 10,500 visits within 24 hours.

The spoof website was turned down by the web hosting company, Yahoo whit no notice. After request, it was told that decision has been made after a government “advice” to do so.

They used an accusation of fishing, due to the look of the page, to cover what in reality was an arbitrary and political act of censorship. 

 

…and one about privacy

This one is personal. Last year I took the questionable decision to go back to study, I got admitted at TalTech, an happy choice, and I started my journey in September a bit worry to failure, having no previous substantial experience as a computer scientist. Whith a lot of study, commitment, and a bit of luck I made my way until now, with great results, so great in fact my name got published on the institution’s official website in the Dean “Book of Honour”, so good so far, I have nothing to complain, but…

The publication of this list discloses a few personal information about me, that I’m studying, where I study, the specific course I’m taking and who are some of my classmates. None of the above information is present on my social network profiles, which is not a case, I wanted that way.

I wasn't asked if I wanted my name to be there, and I got only casually notified after the publication by a classmate. 

Privacy has to been handled carefully, also when is about “good things”, because all the data should belong to their owner and only to him.

 

SOURCES:

Government orders spoof site shut

https://www.smh.com.au/national/government-orders-spoof-site-shut-20060317-gdn6ag.html


THE BOOK OF HONOUR

https://taltech.ee/en/book-honour


Wednesday, 7 April 2021

Don’t try to steal in the thief’s house - week 10

 As a European person, I admire the American culture for two particular aspects, the first being that everyone has given a second chance (admitted is strong enough to survive after failure) and the second, being the great amount of pragmatism when comes to “use” people who can benefit the society, even if controversial. In Italy a person like Kevin Mitnick maybe would never have been jailed because of the lacklustre and slow judiciary system and probably would have never become an influencer for the good because of the hacker stigma.

Like many other great American stories Mr. Mitnick had a second chance in life and after paying his debt with the society he put his skills and his fame to work for the good. He entered the process to educate people on how to protect themselves from IT risks. Mitnick analysed what are the sources of security…   

…and he came with the three points formula:

·       Technology: networks, firewalls, antiviruses...

·       Training: awareness of different attacks

·       Policy: set procedures and requirements

Let us try to use this formula to analyse the situation in Italy.

When coming to technology and its networks Italy is quite advanced, as a dense populated first world country, the peninsula benefits of good It infrastructure network as highlighted in the NATO CDDCOE country report liked below. An ever-increasing focus is given to Network security.

Talking about policies and legal requirements for IT security the same report tells that Italy is also in good shape. The country has to complies whit the many European Union requirements both the legal and institutional framework and those requirements are increasing and improving year by year.

Perhaps looking at the Mitnick formula Italy’s Achilles’s heel is in training, there is no serious computer science education in the schools' curricula nor there are mainstream programs of public awareness to educate the general public, this leads to the common misconception that IT treats are all technical and can be simply stopped installing the best antivirus, the concept of “cyber engineering” is out of common sense and doesn’t translate in any Italian word.

All considered the situation in Italy in terms of Cybersecurity is not that bad, perfectly in line with most of the western countries, none the less, the country should implement programs to educate better on the topic the younger at school (hopefully, they may evangelize the older too!). Various programs can also be undertaken to educate the general public, the involvement of some testimonials, celebrities and respected people, can help to reach even the less tech-savvy ones. Definitely to have an Italian Kevin Mitnick, in his good-guy version, of course, may help.

 

Sources:

NATO-CCDCOE: National Cyber Security Organisation: Italy

https://ccdcoe.org/library/publications/national-cybersecurity-organisation-italy/

Wednesday, 31 March 2021

The mice and the 8 - week 9

Today I’m going to write about how ergonomics has affected the success or failure of IT products, I’m going to do it by two examples, a story of a well-designed product that revolutionized the IT industry forever and a poorly designed one that resulted in a disaster, a commercial disaster at least.

The Mouse

Very few things contributed to the commercial success of PCs and their operative systems as mice, both in business and domestic environment. Being a ''technical miracle'', the mouse allowed the user to move pointers on the desktop simply moving the device whit one hand, resulting in perfect coordination between the brain and the PC output on the monitor, something unseen before.   

After the first prototypes and milestones of mice development by Douglas Engelbart in 1964 (the “Wheels Mouse”) and Bill English in 1972 (the “Ball Mouse”), in 1973, PARC invented the very first desk-computer Alto and the potential for mice to be used in a commercial way. 

Since the 80’ mice imposed themselves on every computer and played a crucial role in making them ergonomic also for the common users who is usually reluctant at learning how to perform operations using command-line only OSs. 

Windows 8

An example of poor usability is Windows 8, it was a disaster, hopefully, no one died, but we can’t be sure about that. The problem wasn't that Microsoft's designers couldn't design a good operating system interface, it's that they designed two of them!

The designers of Windows 8 were probably thinking of doing a great thing engineering an OS with two separate environments/interfaces, one for keyboard/mouse and a second overlaid interface for touch screens. Windows 8 was meant to be a great tool to approach the coming (expected to come) transition to tablets so each of the two environments/interfaces had a separate Web browser, Control Panel, e-mail program and type of programs. It wasn’t possible to ignore either of the two, resulting in twice the learning, twice the confusion and halving the customer satisfaction.

Microsoft corrected the wrong approach with Windows 10 where the transition between traditional and touch environment is much better managed and ergonomic to use.

Sources:

Sutori: HISTORY OF COMPUTER MOUSE

https://www.sutori.com/story/history-of-computer-mouse--2yUFPn6vNQBstaaz2x4FTdsy

ZDNet: ​Saying goodbye to Windows 8: Where did it all go wrong?

https://www.zdnet.com/article/saying-goodbye-windows-8-where-did-it-all-go-wrong/

Wednesday, 24 March 2021

IT as in Italy, a trade in the darkness - week 8

Once my grandmother, class 1923, commenting on the job of the local car mechanic, told me: “you see my son, there are some trades that are in the dark, and those are the best to have”. What she meant was that while the performance of most of the professionals can be evaluated by most of the customers there are others where you can only trust their instructions and diagnosis. For example, everyone can rate the food made by a professional chef, can judge if the house has been nicely designed by the architect, complain about the details of the hairdresser job or even (!) not be happy with the doctor prescription because, well, a google search said differently, and who doesn’t know his own body right? In other words, my grandmother was appreciating how the mechanic was benefiting from a huge “information asymmetry” in his job, most of the customers can’t understand much about engines and could only trust him, and pay.

In an IT illiterate country, Italy, IT trades are definitely in the darkness in the above sense; writing a few lines of simple code or listing some directories using a command line is a sure way to astonish the most who are going to be impressed by the wizardry of such exotic skills.

Despite their rarity and importance for today economy, Italian IT professionals still don’t get the recognition, and the salary, they deserve or could have, at least if compared to colleagues in other European countries or other professions in Italy. A brain drain is happening of Italians IT professionals who, having the will and the knowledge of languages (non that common), decide to be expats.

Italy, since middle ages at least, is a corporativist country whit long and well-established professions perfectly capable to enforce a long list of privileges, as an example right now in certain regions young lawyers and university professors have been prioritized on the COVID vaccination list over the elderly and the more vulnerable. As another example Bolt and Uber are not a thing because of the Taxi leagues.

For the Italian standards, where you need a bachelor degree and a state exam to be a tourist tour guide, the IT professionals being the last arrived are not recognized or protected at all and of course this is well reflected also in the salary level below the one of the above taxi drivers.

In Italy there are bachelor and Master degrees in informatics, but they are almost never taught in English resulting in none international recognition. Other than that we have the usual international private accreditation, among those the CISCOs are the most looked for in the job market.

There are only four professional figure object of government certification: Chief Information Officer (CIO), ICT Security Manager, ICT Security Specialist, ICT Trainer. Interestingly enough two of those are security focused.

As it often happened in the last years, positive improvements in Italy comes from European Union actions. The “Next Generation EU” program is delivering a lot of money to countries capable to invest in the IT sector with a focus on cybersecurity issues and formation, not only business opportunities but also a new need for standards and recognition may arise from that.

A long way has to come for the IT professionals to gain in Italy the social recognition they may deserve considering the important role they can have to “update” the country and the public administration in particular; hopefully, my generation will play a role.

Sources:

Competenze e professionalità nel settore informatico: pubblicata la EN 16234-1 – Competences and trades in the IT sector

https://www.uni.com/index.php?option=com_content&view=article&id=4831:competenze-e-professionalita-nel-settore-informatico-pubblicata-la-en-16234-1&catid=171&Itemid=2612

ISTAT – Italian National Statistics Institute

https://www.istat.it/en/

Wednesday, 17 March 2021

Real power doesn’t have to be exercised - week 7

There is very little to find online about Virginia Shea, Princeton alumna and “student of human nature all her life”. The “network manners guru” by the San Jose Mercury News has a husband, four cats but not a Wikipedia page on her name. Shea’s most important contribution to the conversation about the evolving cyberspace is the book “Netiquette”, 160 pages of length, published in May 1994, so well ahead of the social-media era but at a time when the human interaction on the web was already frequent enough to pose questions about to-dos and don’ts in the online communication; back then mostly via emails, mailing lists, newsgroups end so on.

The book Netiquette, featured in numerous publications, still actual in is purpose, is structured as a decalogue of “commandments” to follow for proper behaviour on the internet and, quite frankly, valid everywhere.

1.    Remember the Human

2.    Adhere to the same standards of behaviour online that you follow in real life

3.    Know where you are in cyberspace

4.    Respect other people's time and bandwidth

5.    Make yourself look good online

6.    Share expert knowledge

7.    Help keep flame wars under control

8.    Respect other people's privacy

9.    Don't abuse your power

10. Be forgiving of other people's mistakes

My favourite rule is “do not abuse your power”, being the “social power” dimension the one that in my opinion is among the ones to be most prone to be distorted in the cyberspace. That’s what the authoress as to say about the topic:

“Some people in cyberspace have more power than others. There are wizards in MUDs (multi-user dungeons), experts in every office, and system administrators in every system.”

“Knowing more than others, or having more power than they do, does not give you the right to take advantage of them. For example, sysadmins should never read private email.”

There is a peculiar figure in the cyberspace not present in the real world in the same fashion: the “forum moderator” or in its other declinations such as “Facebook group administrator” and so on… The human world is filled with people in charge of moderate and administrate others, but never like in the Net those figures had the power to annihilate others with a single click on the mouse.

Let’s think how easy can be for a moderator tho kick a “troll” out of a forum, how he can perform that without checks and balances, and then think of a bouncer job to take a dangerous intoxicated person out of a pub. How more difficult is the second task? How many things can get out of control and how easier the second action can evolve in legal litigation.

Group/forum moderator found for themselves to be much easier to abuse the use of authority over the healthy leadership of a group. This is clear seeing some once healthy forums destroyed by new “rulers” that overreaching with their will to impose themself actually destroyed the “vibes” and the functionality itself of the group.

All these issues can be trivial if we are talking about gaming forums but can become substantial if more important aspects of our social life are moving, and they are, online.

Source:

The core rules of netiquette, by Virginia Shea

http://albion.com/netiquette/

In the blink of an eye - week 14

  Technology has many effects on human societies, among the bests, is that it “enables people”. It makes it possible to do something that be...