source – Jupiter Broadcasting https://www.jupiterbroadcasting.com Open Source Entertainment, on Demand. Mon, 26 Dec 2016 16:45:20 +0000 en-US hourly 1 https://wordpress.org/?v=5.5.3 https://original.jupiterbroadcasting.net/wp-content/uploads/2019/04/cropped-favicon-32x32.png source – Jupiter Broadcasting https://www.jupiterbroadcasting.com 32 32 Forward Momentum | LAS 449 https://original.jupiterbroadcasting.net/105661/forward-momentum-las-449/ Sun, 25 Dec 2016 11:25:40 +0000 https://original.jupiterbroadcasting.net/?p=105661 RSS Feeds: HD Video Feed | Large Video Feed | Mobile Video Feed | MP3 Audio Feed | Ogg Audio Feed | iTunes Feed | Torrent Feed Become a supporter on Patreon: — Show Notes: — Brought to you by: Linux Academy Links Penguin Powered Production | LAS 417 The High Price of Purism | […]

The post Forward Momentum | LAS 449 first appeared on Jupiter Broadcasting.

]]>
RSS Feeds:

HD Video Feed | Large Video Feed | Mobile Video Feed | MP3 Audio Feed | Ogg Audio Feed | iTunes Feed | Torrent Feed

Become a supporter on Patreon:

Patreon

— Show Notes: —


LinuxAcad

Brought to you by: Linux Academy

Links

The post Forward Momentum | LAS 449 first appeared on Jupiter Broadcasting.

]]>
High on NextCloud | LAS 448 https://original.jupiterbroadcasting.net/105501/high-on-nextcloud-las-448/ Mon, 19 Dec 2016 03:50:20 +0000 https://original.jupiterbroadcasting.net/?p=105501 RSS Feeds: HD Video Feed | Large Video Feed | Mobile Video Feed | MP3 Audio Feed | Ogg Audio Feed | iTunes Feed | Torrent Feed Become a supporter on Patreon: — Show Notes: — Brought to you by: Linux Academy NextCloud 11 Nextcloud 11 sets new standard for security and scalability – Nextcloud […]

The post High on NextCloud | LAS 448 first appeared on Jupiter Broadcasting.

]]>
RSS Feeds:

HD Video Feed | Large Video Feed | Mobile Video Feed | MP3 Audio Feed | Ogg Audio Feed | iTunes Feed | Torrent Feed

Become a supporter on Patreon:

Patreon

— Show Notes: —


LinuxAcad

Brought to you by: Linux Academy

NextCloud 11

This release introduces significant security improvements, attested by NCC Group, a global expert in cyber security and risk mitigation to “complement the existing security architecture” and “enhance the general standing of the security working environment.

New security capabilities include:

  • Support for cutting edge browser security features CSP 3.0 and Same-site Cookies* Support for Kerberos authentication and Two-factor Authentication providers based on Universal 2nd Factor and Time-based One-Time Password* Expanded brute force protection to all API access points* More secure Federation through use of SSL/TLS* Our new app store automatically checks apps and enforces signatures

Scalability is a prime concern among our large enterprise customers. This release decreases database load by up to 80% and improves response time by up to 60% for common server operations. Combined with multi-bucket Object Store support, improved handling of previews and Collabora Online speed improvements Nextcloud 11 enables scaling to greater numbers of users and files, decreases the server load and improves the user experience.

Nextcloud 11 introduces Apache Solr powered Full Text Search, enabling users to find words or phrases in text, pdf and common office documents on internal, external, shared and encrypted storage. The next generation Federation technology introduces a central lookup server, enabling Nextcloud users to find each other irrespective of the server their account resides on. The experimental Spreed app integrates secure, peer to peer audio and video chat in Nextcloud.

How to Install from a SNAP

This Nextcloud snap is available in the store for release series 16 (e.g. Ubuntu 16.04).

$ sudo snap install nextcloud

$ sudo snap install –candidate nextcloud

Or if you already have it installed (not recommended for production systems):

$ sudo snap refresh –candidate nextcloud

— PICKS —

Runs Linux

Uber’s new Self Driving Cars, Run Linux

Uber is expanding its self-driving pilot to San Francisco, giving Bay Area residents the first taste of a driverless future. Anyone who hails an UberX could find themselves in the backseat of one of Uber’s self-driving Volvo XC90 SUVs.

Desktop App Pick

Hiri Email Client

Hiri is an email client that helps you master the art of email.

A complete replacement for Microsoft Outlook

Emails
Tasks
Calendars
Contacts

Collaborate with up to 10 members of your team for free. You can see our pricing here.
https://www.hiri.com/pricing/

Spotlight

Piler open source email archiving

Email archiving provides lots of benefits to your company. Piler is a feature rich open source email archiving solution, and a viable alternative to commercial email archiving products; check out the comparison with Mailarchiva.

Piler has a nice GUI written in PHP supporting several authentication methods (AD/LDAP, SSO, Google OAuth, 2 FA, IMAP, POP3). Be sure to try the online demo!

Piler supports

  • archiving and retention rules
  • legal hold
  • deduplication
  • digital fingerprinting and verification
  • full text search
  • tagging emails
  • view, export, restore emails
  • bulk import/export messages
  • audit logs
  • Google Apps
  • Office 365
  • and many more

Chris’ Personal YouTube Channel – MeetBSD and Behind the Scenes Noah Vist Videos Soon


— NEWS —

0-days hitting Fedora and Ubuntu open desktops to a world of hurt

The zero-day exploits, which Evans published on Tuesday, are the latest to challenge the popular conceit that Linux, at least in its desktop form

Ubuntu 17.04 Swaps Swap Partitions for Swap Files

Canonical’s Dimitri John Ledkov announced today that **Ubuntu 17.04 will use Swap files by default **on non-LVM installs (which if you just click through the installer, is the default setting).

Open-Source Warsow Game Development Appears To End

The Warsow video game was powered by the Qfusion engine, which they evolved into an advanced version of the open-source Quake II code. Thus it was a GPL game engine while their artwork ended up being under the Creative Commons. While it was one of the better open-source FPS video games and saw routine updates — along with passing Steam Greenlight a few years back — it looks like it’s now game over.

Microsoft Office Ribbon UI Is Coming to LibreOffice

LibreOffice 5.3 hides a hidden, Microsoft Office-style ‘Ribbon’ interface — but we’reg going to show you how to enable it.

Feedback:

Ask Noah

1-877-347-0011

Mail Bag
  • Name: Alex S.
  • Subject: School Presentation

  • Message:

Hey Noah and/or Chris,
So I have an anxiety disorder that make giving presentations a bit dangerous for me (think, passing out and bashing your face into things) so I get accommodations from my university’s RCPD that basically just add a little legal weight to any discussions I have with teachers to set up alternatives to giving presentations. This semester one of my teachers is allowing me to make a slide deck of the research I did and record me giving the presentation in audio only and turn that in rather than actually presenting in front of the class.
I wasn’t sure how I was going to manage the recording side of things since I run Linux exclusively so none of the teacher’s suggestions would work but then I remembered you guys talking about OBS and thought, since it’s in the AUR, I’d just install it and see if it could do what I needed.

AND IT DOES! It’s exactly what I need for my final presentation and I only knew it existed because you guys talked about it so I just wanted to say thanks! It’s not the first recommendation I’ve gotten from LAS but it is the first one that helps me with school work.
So, yeah, thanks again for the (indirect) help.


  • Name: Stefan R
  • Subject: Arch Help

  • Message:

Hey there Chris and Noah,

since I heard that Noah finally switched to Arch (Antergos) I decided it was time to ask this question.

How did you get hybrid graphics to work?

I have a nice 17,3″ ASUS Laptop (Intel i5-5200U, Nvidia 920M, Samsung SSD) which works just fine with every Linux-distro I’ve thrown at it so far, but the only thing that seems to work only on Ubuntu is the graphics switching.

Now don’t get me wrong, I love Ubuntu Mate (which it’s running now), but I’d rather have it run a rolling distro.

I simply cannot get it to work properly and trust me, I’ve tried everything:

  • Arch Wiki
  • Antergos Wiki
  • Ubuntu Wiki
  • forums

  • opensource drivers

  • proprietary drivers
  • bumblebee
  • prime
  • lts-kernel + lts-drivers
  • cutting edge kernel + cutting edge drivers

and ran into all sorts of problems:

  • bumblebee is working with os-drivers, but steam does not start
  • bumblebee is working with proprietary-drivers, but steam does not start
  • no drivers are working
  • steam does start, but only on Intel graphics

I’d like it to work like in Ubuntu where you choose the card in Nvidia-XServer-Settings, logout and log back in.

Thank you for your help and greetings from Austria (no Chris it’s not Australia)
thefenriswolf

Catch the show LIVE SUNDAY:

— CHRIS’ STASH —

Chris’s Twitter account has changed, you’ll need to follow!

Chris Fisher (@ChrisLAS) | Twitter

Hang in our chat room:

irc.geekshed.net #jupiterbroadcasting

— NOAH’S STASH —

Noah’s Day Job

Altispeed Technologies

Contact Noah

noah [at] jupiterbroadcasting.com

Find us on Twitter

The post High on NextCloud | LAS 448 first appeared on Jupiter Broadcasting.

]]>
Linux Shadow Force | LINUX Unplugged 168 https://original.jupiterbroadcasting.net/104201/linux-shadow-force-lup-168/ Tue, 25 Oct 2016 20:39:26 +0000 https://original.jupiterbroadcasting.net/?p=104201 RSS Feeds: MP3 Feed | OGG Feed | iTunes Feed | Video Feed | Torrent Feed | WebM Torrent Feed Become a supporter on Patreon: Show Notes: Follow Up / Catch Up Freeablo A work-in-progress free and open-source replacement for the Diablo I engine. Simply import the Diablo assets, and enjoy the same old game […]

The post Linux Shadow Force | LINUX Unplugged 168 first appeared on Jupiter Broadcasting.

]]>
RSS Feeds:

MP3 Feed | OGG Feed | iTunes Feed | Video Feed | Torrent Feed | WebM Torrent Feed

Become a supporter on Patreon:

Patreon

Show Notes:

Follow Up / Catch Up

Freeablo

A work-in-progress free and open-source replacement for the Diablo I engine. Simply import the Diablo assets, and enjoy the same old game with faster performance and modern resolutions, and first class support for mods.

Android phones rooted by “most serious” Linux escalation bug ever

I__ndependent security researcher David Manouchehri told Ars that this _proof-of-concept code that explo__its Dirty Cow on Android_gets devices close to root. With a few additional lines, Manouchehri’s code provides persistent root access on all five of the Android devices he has tested.

Dirty COW (which, naturally, has its own logo and web page, though this one is a
bit on the satirical side) is a race condition in the kernel’s memory-management
subsystem. By timing things right, a local attacker can exploit the
copy-on-write mechanism to turn a read-only mapping of a file into a
writable mapping; with that, a file that should not be writable can be
written to. It doesn’t take much imagination to see how the ability to
overwrite files could be used to escalate privileges in any of a number of
ways.

Using Rowhammer bitflips to root Android phones is now a thing | Ars Technica


TING

Xz format inadequate for long-term archiving

What’s your data archive strategy?

After Chris talked about wanting a Volt meter CPU monitor before LUP, so i made one

Loving deepin 15.3

Hi guys. Long term Linux user (+- 12 years), and huge openSuse and Arch Linux (Manjaro) fan. Been running Manjaro for the last couple of months. I’m always looking for a polished desktop experience. I installed the latest Deepin Linux version on my notebook. I’m blown away at how well polished this distro is.

The software store is amazing! Been running for two weeks, and loving it. I’ve never used WPS Office, always been Open Office user, and was blown away on how polished WPS Office were! Even the built in ‘guake’ like drop down terminal impressed me. I think I’ve found my new favorite distro. It almost feels ‘Apple’ like polished to me.

The one ‘niggle’ was that the default deepin file manager application is very basic. Probably the average user want’s it simple, but I quickly installed Nautilus from the app store, and replaced the dock on the bar.

Would be great if you guys did a review on Deepin 15.3. I’m stumped.

DigitalOcean

Coming around to home automation… On my terms.

Such a huge project cannot start without a good, long workshop about our needs and requirements. After a thorough workshop we decided to have the following features:

  • light control,
  • conference and call room occupancy signalization,
  • individual access codes for the main doors for each team member in a centralized database, * audio system with a wireless music streaming option,
  • separate, manageable audio experience in the restroom,
  • five TVs with the ability to manage the content displayed on them,
  • kitchen LED lamp color management,
  • ability to control everything via a web application (desktop, mobile, phone and panels mounted on the walls).

Linux Academy

Keyboardio: heirloom-grade keyboards for serious typists

The Model 01 is the best keyboard we can make. It’s not like other keyboards. We mill the Model 01’s enclosure from two blocks of solid maple that are a joy to rest your hands on. Instead of shallow, uncomfortable keyswitches, we use gloriously tactile mechanical keyswitches similar to those found in the original Apple II. We’ve custom-sculpted each of the 64 individual keycaps on the Model 01 to gently guide your fingers to the right keys. After putting it all together, the result is a keyboard that is a pleasure to type on all day and all night.

The post Linux Shadow Force | LINUX Unplugged 168 first appeared on Jupiter Broadcasting.

]]>
Get Swifty | CR 223 https://original.jupiterbroadcasting.net/103236/get-swifty-cr-223/ Mon, 19 Sep 2016 15:50:20 +0000 https://original.jupiterbroadcasting.net/?p=103236 RSS Feeds: MP3 Feed | OGG Feed | Video Feed | Torrent Feed | iTunes Audio | iTunes Video Become a supporter on Patreon: — Show Notes: — Hoopla: Microsoft is #1 on GitHub open source And Microsoft weighs in at #1, with 16,419 contributors, edging out Facebook with 15,682. GitHub Octoverse 2016 The Fall […]

The post Get Swifty | CR 223 first appeared on Jupiter Broadcasting.

]]>
RSS Feeds:

MP3 Feed | OGG Feed | Video Feed | Torrent Feed | iTunes Audio | iTunes Video

Become a supporter on Patreon:

Patreon

— Show Notes: —

Hoopla:

Microsoft is #1 on GitHub open source

And Microsoft weighs in at #1, with 16,419 contributors, edging out Facebook with 15,682.

The Fall of Eclipse

Eclipse felt less like an IDE and more like a collection of plugins you somehow hobble together to form your own.

Thimble by Mozilla – An online code editor for learners & educators.

Thimble is an online code editor that makes it easy to create and publish your own web pages while learning HTML, CSS & JavaScript.

[Vapor.codes] (https://vapor.codes)

Swift3

iPhone 7 Train Leaves the Station

  • iOS wide password manager
  • Intense App installation performance, literally unbelievable.
  • No headphone jack bites ironically.
  • Speaker(s) are a lot better. Much better for listening to Podcasts. (Nearly as good as Nexus 6p)
  • New sounds (lock, type, etc).
  • Widget Screen, like your own custom Google Now. Reminder widget, combined with Siri = win

The post Get Swifty | CR 223 first appeared on Jupiter Broadcasting.

]]>
A Real Pain in the Flash | LINUX Unplugged 161 https://original.jupiterbroadcasting.net/102836/a-real-pain-in-the-flash-lup-161/ Tue, 06 Sep 2016 18:03:31 +0000 https://original.jupiterbroadcasting.net/?p=102836 RSS Feeds: MP3 Feed | OGG Feed | iTunes Feed | Video Feed | Torrent Feed | WebM Torrent Feed Become a supporter on Patreon: Show Notes: Follow Up / Catch Up KDE Neon Developer OS Switches To Plasma Wayland By Default KDE developers have decided to switch to Wayland by default for KDE Neon’s […]

The post A Real Pain in the Flash | LINUX Unplugged 161 first appeared on Jupiter Broadcasting.

]]>
RSS Feeds:

MP3 Feed | OGG Feed | iTunes Feed | Video Feed | Torrent Feed | WebM Torrent Feed

Become a supporter on Patreon:

Patreon

Show Notes:

Follow Up / Catch Up

KDE Neon Developer OS Switches To Plasma Wayland By Default

KDE developers have decided to switch to Wayland by default for KDE Neon’s unstable/developer OS.

This authorization corrects a bureaucratic mistake: FESCo previously authorized the change for Fedora 24, but the Workstation working group decided to defer the change to Fedora 25, then forgot to request authorization again for Fedora 25 as required. An objection was raised on the grounds that the proper change procedure was not followed, so to sidestep this objection we decided to request permission again from FESCo, which granted the request. Authorization to proceed with the change does not mean the decision to proceed has been made; the change could still be deferred, just as it was for Fedora 24.

ext4 break with 32,000 Files

I ran into a bug with the ext4 filesystem that causes it to fail if there are more than about 32,000 files in a directory. The technical reasons for this are boring and I really don’t care why; I just want to trust that my filesystem will do the right thing.

How to flash Meizu Pro 5 to Ubuntu Touch From the start the Meizu Pro 5

I could have done with this last week 😃 Having gone through the process myself, this document is great and all you need


TING

Adobe Flash goes crawling back to Linux for some security

The official announcementsaid: “Today we are updating the beta channel with Linux NPAPI Flash Player by moving it forward and in sync with the modern release branch (currently version 23). We have done this significant change to improve security and provide additional mitigation to the Linux community.”_

FBI Announces Post-Election Attack on Encryption

Comey’s intention to renew the fight against encryption came about because the issue “has dipped below public consciousness now.” The wait to address encryption until 2017 comes because “next year we can have an adult conversation in this country” about it.

KDE Software Store to Soon Offer Downloads in Snap, Flatpak and AppImage Formats

Revealing the fact that users might be able to soon download their favorite open source applications in the new Snap, Flatpak, and AppImage binary formats, which allows you to use those apps on any distro that supports them.

elementary OS has a Countdown

DigitalOcean

FreeBSD Now Has A Port For CentOS 7 Binary Support

As of yesterday, linux_base-c7 landed in ports for installing the CentOS 7 base packages. This will allow running newer Linux binaries built for modern CentOS/RHEL 7 era systems on FreeBSD, assuming the source isn’t available or isn’t compatible natively with FreeBSD. Previously CentOS 6 was the default port used for this Linux binary compatibility with FreeBSD.

KaOS Brings Serious Relevance Back to KDE | Linux.com | The source for Linux information

If you’ve been looking for a distribution to sway you back to the KDE desktop, look no further than KaOS. It’s beautiful, runs with the snap of a much lighter desktop, and feels as reliable as any other option available for Linux. I

I haven’t been this impressed with KDE for a very, very long time.

Linux Academy

Multi-process Firefox brings 400-700% improvement in responsiveness

In the coming weeks, Mozilla will push multi-processing to 100 percent of their initial cohort of users. This group represents 40-50 percent of total users. Within the next six months, a majority of users can expect to have the capabilities. Here is a little cheat sheet of upcoming releases:

  • Firefox 49: Enabling for a set of add-ons that work well with multi-processing
  • Firefox 50 or 51: Sandboxing and enabling for more add ons
  • Firefox 52 or 53: Multiple content processes

Post-Show:

The post A Real Pain in the Flash | LINUX Unplugged 161 first appeared on Jupiter Broadcasting.

]]>
IoT and Chill | LAS 432 https://original.jupiterbroadcasting.net/102556/iot-and-chill-las-432/ Sun, 28 Aug 2016 17:51:22 +0000 https://original.jupiterbroadcasting.net/?p=102556 RSS Feeds: HD Video Feed | Large Video Feed | Mobile Video Feed | MP3 Audio Feed | Ogg Audio Feed | iTunes Feed | Torrent Feed Become a supporter on Patreon: — Show Notes: — Brought to you by: Linux Academy Internet of Linux? Can the Internet of Things really be under the control […]

The post IoT and Chill | LAS 432 first appeared on Jupiter Broadcasting.

]]>
RSS Feeds:

HD Video Feed | Large Video Feed | Mobile Video Feed | MP3 Audio Feed | Ogg Audio Feed | iTunes Feed | Torrent Feed

Become a supporter on Patreon:

Patreon

— Show Notes: —


System76

Brought to you by: Linux Academy

Internet of Linux?

Home Assistant is an open-source home automation platform running on Python 3. Track and control all devices at home and automate control. Installation in less than a minute.

Ryan has a new job

Controlling IoT with Open Source:

— PICKS —

Runs Linux

Promethean

The ActivBoard Touch combines multi-touch functionality, a dry-erase surface and award-winning software to foster a truly interactive learning experience. It provides teachers with a wide range of tools to support their daily instruction while respecting tight budgets. – See more at:

https://support.prometheanworld.com/download/activinspire.html

Desktop App Pick

BleachBit

BleachBit quickly frees disk space and tirelessly guards your privacy. Free cache, delete cookies, clear Internet history, shred temporary files, delete logs, and discard junk you didn’t know was there. Designed for Linux and Windows systems, it wipes clean a thousand applications including Firefox, Internet Explorer, Adobe Flash, Google Chrome, Opera, Safari,and more.

Spotlight

KDE Connect 1.0 is here!

Today we are officially publishing the first stable release of KDE Connect. Hooray! This version is the most solid yet feature-packed version we ever released. It’s been in development for a year now and it took a lot of hard work, we hope you like it!

New Linux Show: User Error


— NEWS —

Having offended everyone else in the world, Linus Torvalds calls own lawyers a ‘nasty festering disease’

“I actually think we *should* talk about GPL enforcement at the kernel summit, because I think it’s an important issue,” Torvalds gently began, “but we should talk about it the way we talk about other issues: among kernel developers. No lawyers present unless they are in the capacity of a developer and maintainer of actual code, and in particular, absolutely not the Software Freedom Conservancy.”

“The GPL ensures that nobody is ever going to take advantage of your code. It will remain free and nobody can take that away from you. I think that’s a big deal for community management.”

Bytemark sponsor Ubuntu MATE

A couple of weeks ago the _Bytemark_Managing Director,
_Matthew Bloch
, contacted the Ubuntu
MATE team to offer free hosting for the project. As of August 18th 2016
all the Ubuntu MATE infrastructure is hosted on Bytemark Cloud Servers._

Secure, Monitor and Control your data with Nextcloud 10

Nextcloud 10 is now available with many new features for system administrators to control and direct the flow of data between users on a Nextcloud server. Rule based file tagging and responding to these tags as well as other triggers like physical location, user group, file properties and request type enables administrators to specifically deny access to, convert, delete or retain data following business or legal requirements. Monitoring, security, performance and usability improvements complement this release, enabling larger and more efficient Nextcloud installations. You can get it on our install page or read on for details.

Mail Bag

Call Box

Catch the show LIVE SUNDAY:

— CHRIS’ STASH —

Chris’s Twitter account has changed, you’ll need to follow!

Chris Fisher (@ChrisLAS) | Twitter

Hang in our chat room:

irc.geekshed.net #jupiterbroadcasting

— NOAH’S STASH —

Noah’s Day Job

Altispeed Technologies

Contact Noah

noah [at] jupiterbroadcasting.com

Find us on Google+

Find us on Twitter

Follow us on Facebook

The post IoT and Chill | LAS 432 first appeared on Jupiter Broadcasting.

]]>
Dollar Store Quality | CR 219 https://original.jupiterbroadcasting.net/102401/dollar-store-quality-cr-219/ Mon, 22 Aug 2016 14:36:54 +0000 https://original.jupiterbroadcasting.net/?p=102401 RSS Feeds: MP3 Feed | OGG Feed | Video Feed | Torrent Feed | iTunes Audio | iTunes Video Become a supporter on Patreon: — Show Notes: — 217 Coding Challenge Hoopla Google starts rolling out Android 7.0 Nougat to Nexus devices Microsoft open sources PowerShell, brings it to Linux and OS X Linux users […]

The post Dollar Store Quality | CR 219 first appeared on Jupiter Broadcasting.

]]>
RSS Feeds:

MP3 Feed | OGG Feed | Video Feed | Torrent Feed | iTunes Audio | iTunes Video

Become a supporter on Patreon:

Patreon

— Show Notes: —

217 Coding Challenge

Hoopla

Google starts rolling out Android 7.0 Nougat to Nexus devices

Microsoft open sources PowerShell, brings it to Linux and OS X

Linux users on Ubuntu, CentOS and Red Hat, as well as OS X users can now download the necessary bits to run PowerShell from the PowerShell GitHub repository.

3 Ways To Kill Your App Before It Launches

Feedback:

The post Dollar Store Quality | CR 219 first appeared on Jupiter Broadcasting.

]]>
Throwback Thursday… On Sunday! | LAS 431 https://original.jupiterbroadcasting.net/102381/throwback-thursday-on-sunday-las-431/ Sun, 21 Aug 2016 09:06:54 +0000 https://original.jupiterbroadcasting.net/?p=102381 RSS Feeds: HD Video Feed | Large Video Feed | Mobile Video Feed | MP3 Audio Feed | Ogg Audio Feed | iTunes Feed | Torrent Feed Become a supporter on Patreon: — Show Notes: — Brought to you by: Linux Academy Winning over at LA Following Up On Our Reviews OwnCloud Mint 18 Android […]

The post Throwback Thursday… On Sunday! | LAS 431 first appeared on Jupiter Broadcasting.

]]>
RSS Feeds:

HD Video Feed | Large Video Feed | Mobile Video Feed | MP3 Audio Feed | Ogg Audio Feed | iTunes Feed | Torrent Feed

Become a supporter on Patreon:

Patreon

— Show Notes: —


System76

Brought to you by: Linux Academy

Following Up On Our Reviews

— PICKS —

Runs Linux

Black Hole Laboratory at the University of Nottingham, Runs Linux

Desktop App Pick

Lsyncd (Live Syncing Daemon) synchronizes local directories with remote targets

Lsyncd watches a local directory trees event monitor interface (inotify or fsevents). It aggregates and combines events for a few seconds and then spawns one (or more) process(es) to synchronize the changes. By default this is rsync. Lsyncd is thus a light-weight live mirror solution that is comparatively easy to install not requiring new filesystems or block devices and does not hamper local filesystem performance.

Spotlight

CumulusClips | Free Video CMS, Video Sharing Script, Video Sharing Software, YouTube Clone

CumulusClips is a video sharing script that allows you to start your own video website. It’s free and easy to use. You can build a YouTube clone where users can upload videos, rate videos, comment on videos, and much more.


— NEWS —

Google Is Developing A New Open Source OS Named “Fuchsia”

Codenamed Fuchsia, one can spot the new platform existing in Google’s Git repositories. However, at the moment, the repository doesn’t include any source code. This project was originally spotted on Hacker News.

If you go ahead and dig a little deeper, you’ll come across a line on Google’s Git repo that reads — “Pink + Purple == Fuchsia (a new Operating System)”.

Upon further digging the GitHub repository, we came to know that Magenta is the new kernel that powers the Fushia OS. The kernel is designed to interact with the OS via object handles. The documentation from the same calls it an operating system targeting the modern phones and PCs.

Lithuanian police switched to LibreOffice

The police force in Lithuania have switched to using LibreOffice. This free and open source suite of office productivity tools is implemented on over 8000 workstations. The police has started to test the use of workstations running Ubuntu Linux.

Linux malware? That’ll never happen. Ok, just this once then

The good news is that while the Trojan targets Linux systems, it doesn’t rely on a Linux flaw to run.

Simplenote Now Open Source

we are announcing today that all of the official Simplenote client apps are now Open Source Software under the GPLv2 license. In addition to the previously open sourced Electron app, you’ll now find the source code for the iOS, Android, and macOS applications on our GitHub page.

Mail Bag

Call Box

Catch the show LIVE SUNDAY:

— CHRIS’ STASH —

Chris’s Twitter account has changed, you’ll need to follow!

Chris Fisher (@ChrisLAS) | Twitter

Hang in our chat room:

irc.geekshed.net #jupiterbroadcasting

— NOAH’S STASH —

Noah’s Day Job

Altispeed Technologies

Contact Noah

noah [at] jupiterbroadcasting.com

Find us on Google+

Find us on Twitter

Follow us on Facebook

The post Throwback Thursday… On Sunday! | LAS 431 first appeared on Jupiter Broadcasting.

]]>
Open Season on Swift | CR 182 https://original.jupiterbroadcasting.net/91246/open-season-on-swift-cr-182/ Mon, 07 Dec 2015 17:03:54 +0000 https://original.jupiterbroadcasting.net/?p=91246 Ballmer calls out Microsoft’s bogus revenue numbers over Azure, & we expand on his point to discuss an overall trend towards “hero CEOs”. But the majority of our discussion this week is around the open sourcing of Swift, what Apple got really right & what areas still really need improvement. Plus the real possibility of […]

The post Open Season on Swift | CR 182 first appeared on Jupiter Broadcasting.

]]>

post thumbnail

Ballmer calls out Microsoft’s bogus revenue numbers over Azure, & we expand on his point to discuss an overall trend towards “hero CEOs”.

But the majority of our discussion this week is around the open sourcing of Swift, what Apple got really right & what areas still really need improvement.

Plus the real possibility of replacing your laptop with a large tablet, starting your first app the “easy way” vs the “hard way” & more!

Thanks to:


Linux Academy


DigitalOcean

Direct Download:

MP3 Audio | OGG Audio | Video | Torrent | YouTube

RSS Feeds:

MP3 Feed | OGG Feed | Video Feed | Torrent Feed | iTunes Audio | iTunes Video

Become a supporter on Patreon:

Foo

Show Notes:

Hoopla:

Ballmer: Microsoft’s cloud revenue numbers are “bullshit”

_Rather than reporting these figures, Microsoft has reported its annualized revenue run rate—a hypothetical value that describes what the company’s revenue ___would___be if the current level of sales were sustained over the full year

Swift.org – Welcome to Swift.org

Swift goes Open Source Screenshot

We are excited by this new chapter in the story of Swift. After Apple unveiled the Swift programming language, it quickly became one of the fastest growing languages in history. Swift makes it easy to write software that is incredibly fast and safe by design. Now that Swift is open source, you can help make the best general purpose programming language available everywhere.

Not only is Swift on GitHub, but the Swift team will be working completely in the open. Apple did a spectacular job with the release. Not only do we have the source code, but we have the entire commit history for each project, a very detailed view into the Swift team’s development process, and access to the Swift evolution process. Everything you need to know is on Swift.org.

initial checkin, nothing much to see here.

The Swift Package Manager is a tool for managing the distribution of Swift code.
It’s integrated with the Swift build system
to automate the process of downloading, compiling, and linking dependencies.

TL;DR: Apache 2.0 License + Full Standard and Core Libraries included + Compiler + copyright owned by the contributor (i.e. no assignment or CLA) + good community structure and documentation + code of conduct.

Saying goodbye to Carousel and Mailbox

We’re committed to making the transitions from these products as painless as possible. We’ve posted more information on the Carousel blog and the Mailbox blog, and we’ll be communicating details directly to users of both apps in the coming days. Mailbox will be shut down on February 26th, 2016, and Carousel will be shut down on March 31st, 2016.

The post-pivot startup cost the storage company “well over” $50 million, according to multiple sources. And we’ve heard that that the price was around $100 million in cash and stock.

Feedback:

The post Open Season on Swift | CR 182 first appeared on Jupiter Broadcasting.

]]>
Linux in Mint Condition | LAS 394 https://original.jupiterbroadcasting.net/91181/linux-in-mint-condition-las-394/ Sun, 06 Dec 2015 09:14:13 +0000 https://original.jupiterbroadcasting.net/?p=91181 Linux Mint 17.3 proves you can based a Linux desktop on a stable core (Ubuntu 14.04) & still deliver an innovative and polished desktop. We take back some of our concerns about Linux Mint & discuss the areas where they are pushing user experience forward. Plus Mozilla plans to dump Thunderbird, the big release that […]

The post Linux in Mint Condition | LAS 394 first appeared on Jupiter Broadcasting.

]]>

post thumbnail

Linux Mint 17.3 proves you can based a Linux desktop on a stable core (Ubuntu 14.04) & still deliver an innovative and polished desktop. We take back some of our concerns about Linux Mint & discuss the areas where they are pushing user experience forward.

Plus Mozilla plans to dump Thunderbird, the big release that completely ignores Windows & more!

Thanks to:


DigitalOcean


Ting


Linux Academy

Direct Download:

HD Video | Mobile Video | WebM Torrent | MP3 Audio | OGG Audio | YouTube | HD Torrent

RSS Feeds:

HD Video Feed | Large Video Feed | Mobile Video Feed | MP3 Audio Feed | Ogg Audio Feed | iTunes Feed | Torrent Feed

Become a supporter on Patreon:

Foo

— Show Notes: —


Linux Academy

Brought to you by: Linux Academy

New features in Linux Mint 17.3 Cinnamon

Linux Mint 17.3 Screenshot

Linux Mint 17.3 is a long term support release which will be supported until 2019. It comes with updated software and brings refinements and many new features to make your desktop experience more comfortable to use.

Linux Mint 17.3 available for download.

APT, the Advanced Package Tool from the Debian project, is for managing packages by using a lot of separate tools to accomplish various tasks. In the past, users needed to know multiple command structures like apt-get, apt-cache, apt-config, and many more to utilize the full feature-set of APT.

— PICKS —

Runs Linux

Race Cars Runs LINUX!

Sent in by: Nathan S.

Hi guys, I found a cool project run by castrol edge. They are racing two cars on a race track with the drivers wearing virtual reality helmets. Cameras and sensors on the cars feed information into an Ubuntu laptop inside the car and generate the VR display. Thanks for producing the great content that gets me through a 300 mile a week bus commute to school.

Desktop App Pick

Free Astronomical Observatory Software

Alexander Wolf has had the great pleasure of announcing the immediate availability for download of the first maintenance release of Stellarium 0.14, the best free and open-source astronomical observatory software.

According to the internal release notes, which we’ve attached at the end of the article for reference, Stellarium 0.14.1 is mostly a bugfix update that resolves some of the issues reported by users since the previous release of the software, Stellarium 0.14.

Weekly Spotlight

$276.00 worth of Raspberry Pi / Arduino

Humble Books Bundle: Learn Raspberry Pi and Arduino

Treat yourself to Raspberry Pi (and Arduino too)! Have an appetite for making? Satisfy your craving with these Make: books and magazines while serving up support for Maker Ed too!

Pay what you want for Make: Raspberry Pi and AVR Projects, MintDuino: Building an Arduino-compatible Breadboard Microcontroller, Make: Getting Started with Adafruit Trinket, Make: Getting Started with Adafruit FLORA, Make: Making Simple Robots, and Make: Arduino Bots and Gadgets.

Pay more than the average price to also receive Make: A Raspberry Pi-Controlled Robot; MAKE 38: High-Tech DIY; MAKE 36: Boards and Microcontrollers; Make: The Maker’s Manual; Make: JavaScript Robotics; Make: Getting Started with Sensors; Make: Getting Started with Arduino, 3rd Edition; Make: Getting Started with Raspberry Pi, 2nd Edition; and Make: AVR Programming.

Pay $15 or more for all of that plus Making Things Talk and Make: Sensors.

Plus, everyone who buys the bundle receives $10 off a print and $5 off a digital Make: Magazine subscription

Choose the price. Together, these books cost up to $276. Here at Humble Bundle, though, you choose the price!

Read them anywhere. These books are available in PDF, ePUB, and MOBI formats, meaning you can read them anywhere at anytime. Instructions and a list of recommended reading programs can be found here.

Sent in by Avatar C.

LAS Jacket Returns!

Celebrate your new year with Linux on your mind and on your body!

We are excited to offer this LAS zip up hooded jacket that will ship from the
EU!


— NEWS —

Mozilla Wants To Split Off Its Thunderbird Email/Chat Client, Says Mitchell Baker Memo

“I believe Thunderbird should would thrive best by separating itself from reliance on Mozilla development systems and in some cases, Mozilla technology,” Baker wrote in her open memo, posted on Mozilla’s public governance forum. “The current setting isn’t stable, and we should start actively looking into how we can transition in an orderly way to a future where Thunderbird and Firefox are un-coupled.”

Baker, who says she uses Thunderbird to organize vast parts of her life, now believes that the email client will thrive best if it does not rely on Mozilla for development resources and, in some cases, on Mozilla technology. “The current setting isn’t stable, and we should start actively looking into how we can transition in an orderly way to a future where Thunderbird and Firefox are un-coupled,” she wrote in Mozilla’s public governance forum on Monday.

Mozilla ends the advertisements in Firefox new tab tiles

Apple’s Swift programming language is now open source

As promised earlier in the year, Apple’s Swift team has now posted source code for the Swift compiler and standard library functions and objects.

Linux Mint 17.3 Screenshot

MATRIX – The World’s First Smart Home App Ecosystem by AdMobilize —Kickstarter

Feedback:


System76

Brought to you by: System76

I’ve recently came back to Ubuntu from Kubuntu, but I really like Dolphin. Is there any way how to set it up as default file manager?

Thank you to our sponsors, and our audience support!

Trine 3 Stream Giveaway

Rover Log Playlist

Watch the adventures, productions, road trips, trails, mistakes, and fun of the Jupiter Broadcasting mobile studio.

Chris’s Twitter account has changed, you’ll need to follow!

Chris Fisher (@ChrisLAS) | Twitter

— CHRIS’ STASH —

Hang in our chat room:

irc.geekshed.net #jupiterbroadcasting

— NOAH’S STASH —

Noah’s Day Job

Altispeed Technologies

Contact Noah

noah [at] jupiterbroadcasting.com

Find us on Google+

Find us on Twitter

Follow us on Facebook

Catch the show LIVE Friday:

The post Linux in Mint Condition | LAS 394 first appeared on Jupiter Broadcasting.

]]>
Better Open Source Options | LINUX Unplugged 97 https://original.jupiterbroadcasting.net/83782/better-open-source-options-lup-97/ Tue, 16 Jun 2015 20:56:18 +0000 https://original.jupiterbroadcasting.net/?p=83782 What makes the Linux awesome? Community. This week we’ve got exclusive clips from SouthEast LinuxFest 2015 & an on the ground report from OpenTech 2015. Plus why open source needs to follow the Apple model and get started with students, creating value around open source & how Red Hat stays connected to the community. Thanks […]

The post Better Open Source Options | LINUX Unplugged 97 first appeared on Jupiter Broadcasting.

]]>

post thumbnail

What makes the Linux awesome? Community. This week we’ve got exclusive clips from SouthEast LinuxFest 2015 & an on the ground report from OpenTech 2015.

Plus why open source needs to follow the Apple model and get started with students, creating value around open source & how Red Hat stays connected to the community.

Thanks to:

Ting


DigitalOcean


Linux Academy

Direct Download:

MP3 Audio | OGG Audio | Video | HD Video | Torrent | YouTube

RSS Feeds:

MP3 Feed | OGG Feed | iTunes Feed | Video Feed | Torrent Feed | WebM Torrent Feed

Become a supporter on Patreon:

Foo

Show Notes:

Catch Up:

Hack of cloud-based LastPass exposes hashed master passwords
Can we geat a review on NixOS? Pretty please.

Steam Summer Sale Day 6 – Linux Specific


Linux Academy


OpenTech 2015

The usual mix of technology, experience and everything else. Book your place now, while we firm up the schedule.


TING

Bryan Behrenshausen is semioticrobotic.

I’m Bryan Behrenshausen, a doctoral candidate in the Department of Communication Studies at the University of North Carolina, Chapel Hill, where I work on cultural studies of informatic technologies. I try to think conjuncturally about how the concept of information gets articulated differently across multiple discourses and domains.

DigitalOcean

Alan Hicks

One of the authors of The Revised Slackware Book Project, Senior Linux Systems Administrator at Intermedia Outdoors, long-time SELF contributor.

q5sys’ “Build Your Own Laptop” talk at the 2015 South East Linux Fest

Runs Linux from the people:

  • Send in a pic/video of your runs Linux.
  • Please upload videos to YouTube and submit a link via email or the subreddit.

Support Jupiter Broadcasting on Patreon

The post Better Open Source Options | LINUX Unplugged 97 first appeared on Jupiter Broadcasting.

]]>
The Open Pivot | CR 152 https://original.jupiterbroadcasting.net/81462/the-open-pivot-cr-152/ Mon, 04 May 2015 13:44:59 +0000 https://original.jupiterbroadcasting.net/?p=81462 Mike and Chris reflect on Microsoft’s Build 2015 conference & discuss the undeniable shift to open industry wide. Mike also announces his new business with a focus on open source. Plus we discuss Visual Studio Code a bit, bad app ports, new ways for developers to make money & more! Thanks to: Get Paid to […]

The post The Open Pivot | CR 152 first appeared on Jupiter Broadcasting.

]]>

post thumbnail

Mike and Chris reflect on Microsoft’s Build 2015 conference & discuss the undeniable shift to open industry wide. Mike also announces his new business with a focus on open source.

Plus we discuss Visual Studio Code a bit, bad app ports, new ways for developers to make money & more!

Thanks to:


Linux Academy


DigitalOcean

Direct Download:

MP3 Audio | OGG Audio | Video | Torrent | YouTube

RSS Feeds:

MP3 Feed | OGG Feed | Video Feed | Torrent Feed | iTunes Audio | iTunes Video

Become a supporter on Patreon:

Foo

Show Notes:

Hoopla

What Microsoft didn’t say when announcing the new editor was how it built Visual Studio Code. In a move that might seem a little surprising, given the regular animosity between the two companies, the editor is built on top of Chromium, the open source version of Google’s Chrome browser.

The app is built using an open source desktop application framework developed by GitHub called Electron. Electron uses HTML5, JavaScript, and other Web technologies, using Chromium for presentation, and io.js (a fork of node.js) to tie it all together.

Continuum is a big deal for Windows Phone—both a technological advance and a means of escape from its lonely island of misfit apps. Microsoft’s plan to bring more Android and iOS apps to Windows 10 is another encouraging sign for the platform. It’s no fun for Windows Phone faithfuls to have to upgrade, but perhaps the right to brag about Continuum’s talents will be worth the expense.

Mike’s new company!
+ Microsoft Wants To Bring Azure To Your Data Center | TechCrunch

Azure Stack will bring Microsoft’s technologies for software-defined networking, pooling direct-attached storage, handling (and securing) virtual machines and monitoring this cloud to on-premise data centers. It’s essentially a new private cloud solution for IT pros and makes it easier for developers to scale their apps across their existing data centers and then boost to the cloud if they need more capacity on short notice.

  • Open source won.

Feedback:

The post The Open Pivot | CR 152 first appeared on Jupiter Broadcasting.

]]>
SMBTrapped in Microsoft | TechSNAP 210 https://original.jupiterbroadcasting.net/80632/smbtrapped-in-microsoft-techsnap-210/ Thu, 16 Apr 2015 19:01:23 +0000 https://original.jupiterbroadcasting.net/?p=80632 Researches find an 18 year old bug in Windows thats rather nasty, we’ve got the details. A new perspective on the bug bounty arms race & the security impact of Wifi on a plane. Plus great feedback, a bursting round up & much much more! Thanks to: Get Paid to Write for DigitalOcean Direct Download: […]

The post SMBTrapped in Microsoft | TechSNAP 210 first appeared on Jupiter Broadcasting.

]]>

post thumbnail

Researches find an 18 year old bug in Windows thats rather nasty, we’ve got the details. A new perspective on the bug bounty arms race & the security impact of Wifi on a plane.

Plus great feedback, a bursting round up & much much more!

Thanks to:


DigitalOcean


Ting


iXsystems

Direct Download:

HD Video | Mobile Video | MP3 Audio | OGG Audio | YouTube | HD Torrent | Mobile Torrent

RSS Feeds:

HD Video Feed | Mobile Video Feed | MP3 Audio Feed | Ogg Audio Feed | iTunes Feed | Torrent Feed

Become a supporter on Patreon:

Foo

— Show Notes: —

Cylance finds “SPEAR” a new spin on an 18 year old Windows vulnerability

  • In 1997 Aaron Spangler discovered a flaw in Windows
  • By causing a user to navigate to a file://1.2.3.4/ url in Internet Explorer, the user’s windows credentials would be sent to the remote server, to attempt to login to it
  • “Redirect to SMB is a way for attackers to steal valuable user credentials by hijacking communications with legitimate web servers via man-in-the-middle attacks, then sending them to malicious SMB (server message block) servers that force them to spit out the victim’s username, domain and hashed password”
  • “It’s a serious issue because stolen credentials can be used to break into private accounts, steal data, take control of PCs and establish a beachhead for moving deeper into a targeted network.”
  • “Software from at least 31 companies including Adobe, Apple, Box, Microsoft, Oracle and Symantec can be exploited using this vulnerability”
  • “Redirect to SMB is most likely to be used in targeted attacks by advanced actors because attackers must have control over some component of a victim’s network traffic.”
  • “Less sophisticated attackers could launch Redirect to SMB attacks on shared WiFi access points at locations such as coffee shops from any computer, including mobile devices. We successfully tested this attack on a home network using a Nexus 7 loaded with all required tools.”
  • “While the user credentials sent over SMB are commonly encrypted, the encryption method used was devised in 1998 and is weak by today’s standards. A stronger hashing algorithm being used on these credentials would decrease the impact of this issue, but not as much as disabling automatic authentication with untrusted SMB servers. With roughly $3,000 worth of GPUs, an attacker could crack any 8-character password consisting of letters (upper and lower case) as well as numbers in less than half a day.”
  • “Microsoft has yet to release a patch to fix the Redirect to SMB vulnerability. The simplest workaround is to block outbound traffic from TCP 139 and TCP 445 — either at the endpoint firewall or at the network gateway’s firewall (assuming you are on a trusted network). The former will block all SMB communication, which may disable other features that depend on SMB. If the block is done at the network gateway’s firewall, SMB features will still work inside the network, but prevent authentication attempts with destinations outside the network. See the white paper for other mitigation steps.”
  • “Microsoft did not resolve the issue reported by Aaron Spangler in 1997. We hope that our research will compel Microsoft to reconsider the vulnerabilities and disable authentication with untrusted SMB servers. That would block the attacks identified by Spangler as well as the new Redirect to SMB attack.”
  • Cylance Whitepaper (PDF)

Given enough money, all bugs are shallow

  • Eric Raymond, in The Cathedral and the Bazaar, famously wrote: “Given enough eyeballs, all bugs are shallow.”
  • “The idea is that open source software, by virtue of allowing anyone and everyone to view the source code, is inherently less buggy than closed source software. He dubbed this “Linus’s Law”.”
  • “However, the Heartbleed SSL vulnerability was a turning point for Linus’s Law, a catastrophic exploit based on a severe bug in open source software. How catastrophic? It affected about 18% of all the HTTPS websites in the world, and allowed attackers to view all traffic to these websites, unencrypted… for two years.”
  • “OpenSSL, the library with this bug, is one of the most critical bits of Internet infrastructure the world has – relied on by major companies to encrypt the private information of their customers as it travels across the Internet. OpenSSL was used on millions of servers and devices to protect the kind of important stuff you want encrypted, and hidden away from prying eyes, like passwords, bank accounts, and credit card information.”
  • “This should be some of the most well-reviewed code in the world. What happened to our eyeballs, man?”
  • “In reality, it’s generally very, very difficult to fix real bugs in anything but the most trivial Open Source software. I know that I have rarely done it, and I am an experienced developer. Most of the time, what really happens is that you tell the actual programmer about the problem and wait and see if he/she fixes it”
  • “Even if a brave hacker communities to read the code, they’re not terribly likely to spot one of the hard-to-spot problems. Why? Few open source hackers are security experts”
  • “There’s a big difference between usage eyeballs and development eyeballs.”
  • “Most eyeballs are looking at the outside of the code, not the inside. And while you can discover bugs, even important security bugs, through usage, the hairiest security bugs require inside knowledge of how the code works.”
  • Peer reviewing code is a lot harder than writing code.
  • “The amount of code being churned out today – even if you assume only a small fraction of it is “important” enough to require serious review – far outstrips the number of eyeballs available to look at the code”
  • “There are not enough qualified eyeballs to look at the code. Sure, the overall number of programmers is slowly growing, but what percent of those programmers are skilled enough, and have the right security background, to be able to audit someone else’s code effectively? A tiny fraction”
  • “But what’s the long term answer to the general problem of not enough eyeballs on open source code? It’s something that will sound very familiar to you, though I suspect Eric Raymond won’t be too happy about it.”
  • “Money. Lots and lots of money.”
  • “Increasingly, companies are turning to commercial bug bounty programs. Either ones they create themselves, or run through third party services like Bugcrowd, Synack, HackerOne, and Crowdcurity. This means you pay per bug, with a larger payout the bigger and badder the bug is.”
  • However, adding more money to the equation might actually make things worse
  • “There’s now a price associated with exploits, and the deeper the exploit and the lesser known it is, the more incentive there is to not tell anyone about it until you can collect a major payout. So you might wait up to a year to report anything, and meanwhile this security bug is out there in the wild – who knows who else might have discovered it by then?”
  • “If your focus is the payout, who is paying more? The good guys, or the bad guys? Should you hold out longer for a bigger payday, or build the exploit up into something even larger? I hope for our sake the good guys have the deeper pockets, otherwise we are all screwed.”
  • I like that Google addressed a few of these concerns by making Pwnium, their Chrome specific variant of Pwn2Own, a) no longer a yearly event but all day, every day and b) increasing the prize money to “infinite”. I don’t know if that’s enough, but it’s certainly going in the right direction.
  • “Money turns security into a “me” goal instead of an “us” goal“
  • “Am I now obligated, on top of providing a completely free open source project to the world, to pay people for contributing information about security bugs that make this open source project better? Believe me, I was very appreciative of the security bug reporting, and I sent them whatever I could, stickers, t-shirts, effusive thank you emails, callouts in the code and checkins. But open source isn’t supposed to be about the money… is it?”
  • “Easy money attracts all skill levels — The submitter doesn’t understand what is and isn’t an exploit, but knows there is value in anything resembling an exploit, so submits everything they can find.”
  • “But I have some advice for bug bounty programs, too”:
  • “You should have someone vetting these bug reports, and making sure they are credible, have clear reproduction steps, and are repeatable, before we ever see them.”
  • “You should build additional incentives in your community for some kind of collaborative work towards bigger, better exploits. These researchers need to be working together in public, not in secret against each other”.
  • “You should have a reputation system that builds up so that only the better, proven contributors are making it through and submitting reports”.
  • “Encourage larger orgs to fund bug bounties for common open source projects, not just their own closed source apps and websites. At Stack Exchange, we donated to open source projects we used every year. Donating a bug bounty could be a big bump in eyeballs on that code.”

FAA Needs a More Comprehensive Approach to Address Cybersecurity As Agency Transitions to NextGen

  • The Federal Aviation Administration (FAA) faces cybersecurity challenges in at least three areas:
  • (1) protecting air-traffic control (ATC) information systems,
  • (2) protecting aircraft avionics used to operate and guide aircraft
  • (3) clarifying cybersecurity roles and responsibilities among multiple FAA offices
  • “FAA has taken steps to protect its ATC systems from cyber-based threats; however, significant security-control weaknesses remain that threaten the agency’s ability to ensure the safe and uninterrupted operation of the national airspace systems”
  • “Modern aircraft are increasingly connected to the Internet. This interconnectedness can potentially provide unauthorized remote access to aircraft avionics systems. As part of the aircraft certification process, FAA’s Office of Safety (AVS) currently certifies new interconnected systems through rules for specific aircraft and has started reviewing rules for certifying the cybersecurity of all new aircraft systems.”
  • “FAA officials and experts we interviewed said that modern aircraft are also increasingly connected to the Internet, which also uses IP-networking technology and can potentially provide an attacker with remote access to aircraft information systems. According to cybersecurity experts we interviewed, Internet connectivity in the cabin should be considered a direct link between the aircraft and the outside world, which includes potential malicious actors. FAA officials and cybersecurity and aviation experts we spoke to said that increasingly passengers in the cabin can access the Internet via onboard wireless broadband systems.”
  • “Four cybersecurity experts with whom we spoke discussed firewall vulnerabilities, and all four said that because firewalls are software components, they could be hacked like any other software and circumvented. The experts said that if the cabin systems connect to the cockpit avionics systems (e.g., share the same physical wiring harness or router) and use the same networking platform, in this case IP, a user could subvert the firewall and access the cockpit avionics system from the cabin. The presence of personal smartphones and tablets in the cockpit increases the risk of a system’s being compromised by trusted insiders, both malicious and non-malicious, if these devices have the capability to transmit information to aircraft avionics systems”
  • One would hope that the cockpit avionics are separated from the onboard entertainment and wifi systems by more than just a firewall. Even if they are not, a properly configured firewall is very difficult to compromise.
  • Additional Coverage – BatBlue
  • It seems that the authors of this report were not experts on the subject, and when interviewing experts on the topic, they asked questions like “is there any way to get around a firewall”

Feedback:


Round Up:


The post SMBTrapped in Microsoft | TechSNAP 210 first appeared on Jupiter Broadcasting.

]]>
Open Source as a Trap | CR 146 https://original.jupiterbroadcasting.net/79347/open-source-as-a-trap-cr-146/ Mon, 23 Mar 2015 14:05:19 +0000 https://original.jupiterbroadcasting.net/?p=79347 It’s a special open mic edition of Coder Radio. We discuss the complex reasons behind Microsoft’s choice to open source MSBuild, the quest for the perfect Linux laptop continues & why, oh why, oh why HTML5 has a place. Plus emails & more! Thanks to: Get Paid to Write for DigitalOcean Direct Download: MP3 Audio […]

The post Open Source as a Trap | CR 146 first appeared on Jupiter Broadcasting.

]]>

post thumbnail

It’s a special open mic edition of Coder Radio. We discuss the complex reasons behind Microsoft’s choice to open source MSBuild, the quest for the perfect Linux laptop continues & why, oh why, oh why HTML5 has a place.

Plus emails & more!

Thanks to:


Linux Academy


DigitalOcean

Direct Download:

MP3 Audio | OGG Audio | Video | Torrent | YouTube

RSS Feeds:

MP3 Feed | OGG Feed | Video Feed | Torrent Feed | iTunes Audio | iTunes Video

Become a supporter on Patreon:

Foo

Show Notes:

Feedback

Dev World Hoopla

Commercial Dev on Linux?

  • Ubuntu Software Centre: Where is it now?

The post Open Source as a Trap | CR 146 first appeared on Jupiter Broadcasting.

]]>
How Non-Devs Can Help Linux | LAS 350 https://original.jupiterbroadcasting.net/76592/how-non-devs-can-help-linux-las-350/ Sun, 01 Feb 2015 19:20:50 +0000 https://original.jupiterbroadcasting.net/?p=76592 What are the best options for non-coders and developers to contribute to their favorite open source project? We’ll break down some of the barriers we’ve faced & approaches we like to help out in a non-development capacity. Plus the common ways the Ghost vulnerability is being exploited, how you can do your taxes under Linux […]

The post How Non-Devs Can Help Linux | LAS 350 first appeared on Jupiter Broadcasting.

]]>

post thumbnail

What are the best options for non-coders and developers to contribute to their favorite open source project? We’ll break down some of the barriers we’ve faced & approaches we like to help out in a non-development capacity.

Plus the common ways the Ghost vulnerability is being exploited, how you can do your taxes under Linux & a few surprises!

Thanks to:


DigitalOcean


Ting

Direct Download:

HD Video | Mobile Video | WebM Torrent | MP3 Audio | OGG Audio | YouTube | HD Torrent

RSS Feeds:

HD Video Feed | Large Video Feed | Mobile Video Feed | MP3 Audio Feed | Ogg Audio Feed | iTunes Feed | Torrent Feed

Become a supporter on Patreon:

Foo

— Show Notes: —

Contribution to open source when your not a developer


System76

Brought to you by: System76

Problems we’ve faced trying to help

  • Who could use the money the most ie: Mozilla vs Tox

  • Abandoned IRC, unclear if anyone still “owning” the project.

  • Mixed ways of funding. I want to contribute, but each project has their own payment system, and way of handling it.

Non-Monetary ways to help

  • Advocation for software,

  • Documentation

  • Community outreach

  • Bug Triage, find dupes, discover missing information developers would need to fully troubleshoot.


— PICKS —

Runs Linux

Samsung Smart Refrigerator

The Samsung 4-Door refrigerator with 8″ Wi-Fi Enabled LCD will allow you to browse the web, access apps and connect to other Samsung smart devices – opening up a world of interactive communication and entertainment.

Desktop App Pick

Gourmet Recipe Manager

Gourmet

Gourmet Recipe Manager is a recipe-organizer available for Windows, Linux, and other Unix systems.

Weekly Spotlight

BeansBooks

Easily create invoices and purchase orders, pay bills and track sales tax. Import and automatically categorize bank transactions.

Our Past Picks

These are the weekly picks provided by the Jupiter Broadcasting podcast, the Linux Action Show.

This site includes a separate picks lists for the “Runs Linux”, Desktop Apps, Spotlight Picks, Android Picks, and Distro Picks.


— NEWS —

WordPress, PHP Apps, Subject to Ghost glibc Attacks

“Less than 48 hours after the disclosure of the Ghost vulnerability in the GNU C library (glibc), researchers have uncovered that PHP applications, including the WordPress content management system, could be another weak spot and eventually in the crosshairs of attackers.

Ghost is a vulnerability in glibc that attackers can use against only a handful of applications right now to remotely run executable code and gain control of a Linux server. The vulnerability is a heap-based buffer overflow and affects all Linux systems, according to experts, and has been present in the glibc code since 2000. ???An example of where this could be a big issue is within WordPress itself: it uses a function named wp_http_validate_url() to validate every pingback???s post URL,??? wrote Sucuri research Marc-Alexandre Montpas in an advisory published Wednesday. ???And it does so by using gethostbyname(). So an attacker could leverage this vector to insert a malicious URL that would trigger a buffer overflow bug, server-side, potentially allowing him to gain privileges on the server.???”

LibreOffice gets a streamlined makeover, native alternatives for major Microsoft

The Document foundation announced availability of the latest version of LibreOffice on Thursday, which it says is the most beautiful version of the open source productivity suite yet. LibreOffice 4.4 also fixes some compatibility issues with files that are saved in Microsoft’s OOXML formats.

Official Google Drive Linux Client Screenshots Leaked

The screenshots above are bundled with the official Google Drive Mac client and they first appeared with version 1.18.7821.2489 (I checked the previous version and some random old versions and none contained these screenshots), released on October 30, 2014, which isn’t long ago and it most probably means that Google is testing Drive for Linux internally. So we might actually see an official release pretty soon.

Bill Gates Inadvertently Shows Off Ubuntu on His Facebook Page

The Internet is abuzz today after Bill Gates published an image on his Facebook page and a link towards his website with the text “15 years from now, most people in poor countries will be able to take classes online.” It’s a sound goal and it’s perfectly doable, but in the image posted on Facebook the operating system is Ubuntu.


— FEEDBACK —

— CHRIS’ STASH —

Hang in our chat room:

irc.geekshed.net #jupiterbroadcasting

— NOAH’S STASH —

Find us on Google+

Find us on Twitter

Follow the network on Facebook

Catch the show LIVE Sunday 10am Pacific / 1pm Eastern / 6pm UTC:

The post How Non-Devs Can Help Linux | LAS 350 first appeared on Jupiter Broadcasting.

]]>
Predicting 2015 | LINUX Unplugged 73 https://original.jupiterbroadcasting.net/74612/predicting-2015-lup-73/ Tue, 30 Dec 2014 19:09:35 +0000 https://original.jupiterbroadcasting.net/?p=74612 Our bold predictions for Linux & open source over 2015. Thought provoking, sometimes a bit inspired or maybe just plain wrong, this edition of Unplugged promises to entertain. Plus what goes into making a great & secure messaging system & more! Thanks to: Get Paid to Write for DigitalOcean Direct Download: MP3 Audio | OGG […]

The post Predicting 2015 | LINUX Unplugged 73 first appeared on Jupiter Broadcasting.

]]>

post thumbnail

Our bold predictions for Linux & open source over 2015. Thought provoking, sometimes a bit inspired or maybe just plain wrong, this edition of Unplugged promises to entertain.

Plus what goes into making a great & secure messaging system & more!

Thanks to:

Ting


DigitalOcean


Linux Academy

Direct Download:

MP3 Audio | OGG Audio | Video | HD Video | Torrent | YouTube

RSS Feeds:

MP3 Feed | OGG Feed | iTunes Feed | Video Feed | Torrent Feed | WebM Torrent Feed

Become a supporter on Patreon:

Foo

Show Notes:

Pre-Show:

FU:

Telegram

Being good at going full Salesman on things comes with a certain responsibility if you care about your audience. Touting the security of Telegram should be avoided. By all means, use it if it fits your needs but please don’t portrait Telegram as something vetted and secure, that’s doing the audience a disservice.

Only half of the equation (the client) is open source and the protocol is full of weirdness and outright flaws. I believe their crypto contest charade was even featured and scoffed at on one of the network’s channels a while ago.

Its encryption score in the following table should be taken with a grain of salt since it’s vulnerable to ‘hostile server’ attacks, which are sadly just a subpoena away:

https://www.eff.org/secure-messaging-scorecard

Why isn’t Debian as popular as Ubuntu on LAS

I have been loving LAS for some time now, but it always bothers me that Debian (the mother of so many great Linux distros) isn’t discussed as a primary Linux distro option as Arch/OpenSUSE/Ubuntu and so on. What is the deal with that? // Thanks for a great year, keep up the good work LAS!


2015 VLUG Linux Predictions

  • HighDPI
  • Secuirty? Audits? Shellshock 2.0?
  • Elementary OS Fork
  • The first batch of Steam Machines reach the general public?
  • Ubuntu Touch?
  • Firefox OS?

Runs Linux from the people:

  • Send in a pic/video of your runs Linux.
  • Please upload videos to YouTube and submit a link via email or the subreddit.

New Shows : Tech Talk Today (Mon – Thur)

Support Jupiter Broadcasting on Patreon

Post-Show

The post Predicting 2015 | LINUX Unplugged 73 first appeared on Jupiter Broadcasting.

]]>
Git your Pizza | CR 132 https://original.jupiterbroadcasting.net/73887/git-your-pizza-cr-132/ Mon, 15 Dec 2014 19:23:57 +0000 https://original.jupiterbroadcasting.net/?p=73887 It’s the birth of another open source project live on this week’s Coder Radio. Plus it’s an open mic edition & we discuss a wide range of topics from Microsoft’s big mobile strategy that nobody is noticing, the best Linux development environment, setting expectations, your feedback & more! Thanks to: Get Paid to Write for […]

The post Git your Pizza | CR 132 first appeared on Jupiter Broadcasting.

]]>

post thumbnail

It’s the birth of another open source project live on this week’s Coder Radio. Plus it’s an open mic edition & we discuss a wide range of topics from Microsoft’s big mobile strategy that nobody is noticing, the best Linux development environment, setting expectations, your feedback & more!

Thanks to:


Linux Academy


DigitalOcean

Direct Download:

MP3 Audio | OGG Audio | Video | Torrent | YouTube

RSS Feeds:

MP3 Feed | OGG Feed | Video Feed | Torrent Feed | iTunes Audio | iTunes Video

Become a supporter on Patreon:

Foo

— Show Notes: —

Feedback / Follow Up:

Content needed for the Best of Moments:

  • Episode Title:
  • Link to Episode:
  • Timecode:
  • What was the topic:

submit the content on the following form, https://goo.gl/forms/pK0zNG4F3i

OpenYourMouth

Dev Hoopla:

Microsoft today announced it had acquired HockeyApp, a crash analytics service for mobile apps. The company intends to integrate HockeyApp into Visual Studio Online to improve support for iOS and Android development in addition to Windows Phone.

HockeyApp provides a variety of tools for helping developers distribute and test mobile apps, including crash reporting, beta software distribution and feedback, and cross-platform support for iOS, Android and Windows Phone.

In the coming months, Microsoft will announce new iOS and Android SDKs for its Application Insights software to take advantage of the new tools. HockeyApp for its part says that nothing will change for its users at the moment; their apps and accounts will continue to work the same.

Today we announce Go 1.4, the fifth major stable release of Go, arriving six
months after our previous major release Go 1.3.
It contains a small language change, support for more operating systems
and processor architectures, and improvements to the tool chain and libraries.
As always, Go 1.4 keeps the promise of compatibility, and almost everything
will continue to compile and run without change when moved to 1.4.
For the full details, see the Go 1.4 release notes.

The most notable new feature in this release is official support for Android.
Using the support in the core and the libraries in the
golang.org/x/mobile repository,
it is now possible to write simple Android apps using only Go code.
At this stage, the support libraries are still nascent and under heavy development.
Early adopters should expect a bumpy ride, but we welcome the community to get involved.

The focus of Apple’s censorship lies in the full-body scanner introduced a few levels into the game that tasks the player with ensuring the person attempting to enter Arstotzka isn’t carrying any kind of contraband. The PC, Mac, and Linux versions of the game depicted fully nude (albeit in low resolution given the nature of the game’s graphics) versions of characters when put through this scanner, with an option to censor the nudity by including underwear on the characters.

Papers, Please for iPad, however, removes the choice from the equation, automatically covering the characters in underwear when scanned by the player.

The post Git your Pizza | CR 132 first appeared on Jupiter Broadcasting.

]]>
The COPPA Cabana | Tech Talk Today 101 https://original.jupiterbroadcasting.net/72997/the-coppa-cabana-tech-talk-today-101/ Thu, 04 Dec 2014 10:59:28 +0000 https://original.jupiterbroadcasting.net/?p=72997 Google is rebuilding some of its biggest products & services for kids under 13, Intel & Samsung feel the open source love. We’ll dig into major contributions both companies are making & their future commitments. Plus Dropbox makes a play for business lock-in & much more! Direct Download: MP3 Audio | OGG Audio | Video […]

The post The COPPA Cabana | Tech Talk Today 101 first appeared on Jupiter Broadcasting.

]]>

post thumbnail

Google is rebuilding some of its biggest products & services for kids under 13, Intel & Samsung feel the open source love. We’ll dig into major contributions both companies are making & their future commitments.

Plus Dropbox makes a play for business lock-in & much more!

Direct Download:

MP3 Audio | OGG Audio | Video | HD Video | Torrent | YouTube

RSS Feeds:

MP3 Feed | OGG Feed | iTunes Feed | Video Feed | Torrent Feed

Become a supporter on Patreon:

Foo

Show Notes:

Intel reinvents Stephen Hawking’s voice systems and will open source the software – IT News from V3.co.uk

Intel has reinvented the speech and text communication systems used by Professor Stephen Hawking, and plans to release the software as an open source project in 2015.

The Assistive Context Aware Toolkit has helped to double Hawking’s speech and text input times, and make it up to 10 times faster for him to open files, switch between applications and browse the web.

Hawking said at an event attended by V3 that the Intel developments are “life-changing” for him.

“The Intel team and I have been working for three years on upgrading my communication systems. My old system is more than 20 years old and I find it very difficult to communicative effectively and do the things I love to do.

“With the improvement I am now able to write much faster and I can continue to give lectures, write papers and books and speak with friends and family more easily.

“This new system is life-changing for me and I hope it will serve me well for the next 20 years.”

Intel began work on the project three years ago when Hawking contacted the firm’s founder, Gordon Moore, to ask for help in impro


One major improvement is a new system making it far easier for Hawking to access files, as ‎Lama Nachman, principal engineer and manager of the Anticipatory Computing Lab at Intel Labs, explained.


One aspect of the system that has not changed is the voice, which has become synonymous with Hawking. “He was actually adamant about us not changing his voice,” said Nachman.

The new software will be made open source next year, but Swiftkey said that its involvement in the project will not be included as the technology is too similar to its core product.

Google to launch kid-friendly versions of Chrome, YouTube, others in 2015 | Ars Technica

Google is currently working on versions of products like Chrome and YouTube tailored specifically for kids under the age of 13, according to a report from USA Today. Pavni Diwanji, a VP of engineering at Google, says that the new products are due at some point next year and that they are intended to help children “be more than just pure consumers of tech, but creators, too.”

It’s not clear how these under-13 products will work, but they may change the way they look or the kinds of data they present.

In the US, one of the biggest considerations when designing online products and services for kids is the Children’s Online Privacy Protection Act, or COPPA. It dictates how information can be collected from and presented to kids under the age of 13—changes to the law effective in July of 2013 include multiple stipulations related to privacy policies, parental oversight, and security requirements for data collected from young children. Since the vast majority of Google’s revenue comes from advertising and the value of the company’s ads is tied to its trove of user data, COPPA compliance will obviously be important to users and Google alike (Yelp was fined $450,000 earlier this year for COPPA violations).

Dropbox eyes Google and Box with launch of Business API- The Inquirer

**DROPBOX HAS ANNOUNCED **an API for third parties wishing to develop and integrate apps to work alongside its business service.

The move is designed to appeal to users of proprietary office systems.


The API launched with 20 partner organisations including Microsoft and IBM.

It will allow Dropbox for Business apps to use some of the more advanced features not available on the free service, and will also integrate with existing enterprise security systems.


But given Dropbox’s colourful history with regards to safety, what does the company which Edward Snowden described as “hostile to privacy” do to win hearts and minds?


George O’Brien, product manager for Dropbox for Business, told The INQUIRER: “Dropbox for Business is a security first product.”


Stop laughing and nobody mention Condeleezza.


He added: “We encrypt data as it travels through the API. Only a Dropbox for Business system administrator can install a Dropbox for Business API app. We’re very aggressive about who has control over the API and who has access to it.

Samsung’s Open Source Group Is Growing, Hiring Developers – Slashdot

Almost two years ago, Samsung’s open source team was just one person: Linux and FOSS advocate Ibrahim Haddad, head of the open source group at Samsung Research America. The new Open Source Innovation Group at Samsung is now 40 people strong, including 30 developers, devoted full-time to working on upstream projects and shepherding open source development into the company. The group is hiring aggressively and plans to double the size of the group in the coming years. Their first targets are project maintainers and key contributors to 23 open source projects that are integral to Samsung’s products, including Linux, Gstreamer, FFmpeg, Blink, Webkit, EFL, and Wayland. They plan to eventually start hiring more junior open source developers as well. Just about every Samsung product, from phones and tablets to home appliances, uses open source software, said Guy Martin, senior open source strategist at Samsung. Martin also mentions the importance of funding: “You already see this in the Linux kernel, where most people who contribute are paid to contribute. And you’ll see that more and more.”

The post The COPPA Cabana | Tech Talk Today 101 first appeared on Jupiter Broadcasting.

]]>
Ever Shifting Google | Tech Talk Today 62 https://original.jupiterbroadcasting.net/67292/ever-shifting-google-tech-talk-today-62/ Mon, 22 Sep 2014 10:01:16 +0000 https://original.jupiterbroadcasting.net/?p=67292 The Oculus Platform has been announced, and promises to deliver an app store for VR games and experiences. But will this lead to watered down cheap VR games that doom the Oculus to triviality? And Our jury weighs if we are seeing another nail in the coffin for Google+ or just a new perspective from […]

The post Ever Shifting Google | Tech Talk Today 62 first appeared on Jupiter Broadcasting.

]]>

post thumbnail

The Oculus Platform has been announced, and promises to deliver an app store for VR games and experiences. But will this lead to watered down cheap VR games that doom the Oculus to triviality?

And Our jury weighs if we are seeing another nail in the coffin for Google+ or just a new perspective from Google.

Then DuckDuckGo gets a setback in China, Apple sells an unbelievable amount if iPhones over the weekend & much more!

Direct Download:

MP3 Audio | OGG Audio | Video | HD Video | Torrent | YouTube

RSS Feeds:

MP3 Feed | OGG Feed | iTunes Feed | Video Feed | Torrent Feed

Become a supporter on Patreon:

Foo

Show Notes:

The “Oculus Platform” Marketplace For Virtual Reality App Launches This Fall | TechCrunch

Oculus announced the “Oculus Platform” store for developers to distribute their virtual reality apps and experiences today at the Oculus Connect conference. Starting this fall on the Samsung Gear VR made by Oculus, this revamp of the Oculus Share marketplace will let users browse the Oculus Platform within virtual reality and download apps, games, and entertainment experiences.

Eventually, there will be versions of the Oculus Platform for the Rift, iOS, Android, Windows Phone, Chrome, Firefox, Safari, and Internet Explorer. Oculus Platform could become one of the first ways for developers to sell the VR experiences they build, and by creating this marketplace, Oculus could rally the ecosystem to its mobile and PC-based VR headsets.

Oculus open-sources original Rift developer kit’s firmware, schematics, and mechanics | PCWorld

Kicking off the Oculus Connect conference in Los Angeles this weekend, Oculus’s Nirav Patel announced that the original Oculus Rift developer kit (DK1) is now fully open-source, with the exception of the pieces that aren’t actually in production anymore—for instance, the display, which is no longer manufactured.

“We don’t want everyone to have to take the same risks we took. We just want to share the things we learned so you don’t have to do that. We’re all in this to build virtual reality together,” said Patel.

Mandatory Google+ Gmail Integration Quietly Shelved | WordStream

Google has gone to valiant lengths to convince us that rumors of Google+’s demise have been greatly exaggerated, but Google is no longer forcing new Gmail users to connect their account to a Google+ profile — yet another move that could signal the end for Google’s troubled social network.

DuckDuckGo joins Google in being blocked in China

Privacy-oriented search engine DuckDuckGo is now blocked in China. We noticed this over the weekend, and on Sunday DuckDuckGo founder and CEO Gabriel Weinberg confirmed to Tech in Asia that the team has noticed the blockage in China:

GreatFire index of blocked sites suggest that DuckDuckGo got whacked on September 4).

Apple Mac iOS Rumors and News You Care About

“Sales for iPhone 6 and iPhone 6 Plus exceeded our expectations for the launch weekend, and we couldn’t be happier,” said Tim Cook, Apple’s CEO. “We would like to thank all of our customers for making this our best launch ever, shattering all previous sell-through records by a large margin.


Currently, shipping estimates for new iPhone 6 orders remains at 7-10 business days, while the iPhone 6 Plus is still showing a shipping delay of 3-4 weeks.

The post Ever Shifting Google | Tech Talk Today 62 first appeared on Jupiter Broadcasting.

]]>
A BUG’s Life | BSD Now 38 https://original.jupiterbroadcasting.net/57997/a-bugs-life-bsd-now-38/ Thu, 22 May 2014 10:22:23 +0000 https://original.jupiterbroadcasting.net/?p=57997 We\’re back from BSDCan! This week on the show we\’ll be chatting with Brian Callahan and Aaron Bieber about forming a local BSD users group. We\’ll get to hear their experiences of running one and maybe encourage some of you to start your own! After that, we\’ve got a tutorial on the basics of NetBSD\’s […]

The post A BUG's Life | BSD Now 38 first appeared on Jupiter Broadcasting.

]]>

post thumbnail

We\’re back from BSDCan! This week on the show we\’ll be chatting with Brian Callahan and Aaron Bieber about forming a local BSD users group. We\’ll get to hear their experiences of running one and maybe encourage some of you to start your own!

After that, we\’ve got a tutorial on the basics of NetBSD\’s package manager, pkgsrc. Answers to your emails and the latest headlines, on BSD Now – the place to B.. SD.

Thanks to:


\"iXsystems\"


\"Tarsnap\"

Direct Download:

Video | HD Video | MP3 Audio | OGG Audio | Torrent | YouTube

RSS Feeds:

MP3 Feed | OGG Feed | iTunes Feed | Video Feed | HD Vid Feed | HD Torrent Feed

– Show Notes: –

Headlines

FreeBSD 11 goals and discussion

  • Something that actually happened at BSDCan this year…
  • During the FreeBSD devsummit, there was some discussion about what changes will be made in 11.0-RELEASE
  • Slides from Dev Summit
  • Some of MWL\’s notes include: the test suite will be merged to 10-STABLE, more work on the MIPS platforms, LLDB getting more attention, UEFI boot and install support
  • A large list of possibilities was also included and open for discussion, including AES-GCM in IPSEC, ASLR, OpenMP, ICC, in-place kernel upgrades, Capsicum improvements, TCP performance improvements and A LOT more
  • There\’s also some notes from the devsummit virtualization session, mostly talking about bhyve
  • Lastly, he also provides some notes about ports and packages and where they\’re going

An SSH honeypot with OpenBSD and Kippo

  • Everyone loves messing with script kiddies, right?
  • This blog post introduces Kippo, an SSH honeypot tool, and how to use it in combination with OpenBSD
  • It includes a step by step (or rather, command by command) guide and some tips for running a honeypot securely
  • You can use this to get new 0day exploits or find weaknesses in your systems
  • OpenBSD makes a great companion for security testing tools like this with all its exploit mitigation techniques that protect all running applications

NetBSD foundation financial report

  • The NetBSD foundation has posted their 2013 financial report
  • It\’s a very \”no nonsense\” page, pretty much only the hard numbers
  • In 2013, they got $26,000 of income in donations
  • The rest of the page shows all the details, how they spent it on hardware, consulting, conference fees, legal costs and everything else
  • Be sure to donate to whichever BSDs you like and use!

Building a fully-encrypted NAS with OpenBSD

  • Usually the popular choice for a NAS system is FreeNAS, or plain FreeBSD if you know what you\’re doing
  • This article takes a look at the OpenBSD side and explains how to build a NAS with security in mind
  • The NAS will be fully encrypted, no separate /boot partition like FreeBSD and FreeNAS require – this means the kernel itself is even protected
  • The obvious trade-off is the lack of ZFS support for storage, but this is an interesting idea that would fit most people\’s needs too
  • There\’s also a bit of background information on NAS systems in general, some NAS-specific security tips and even some nice graphs and pictures of the hardware – fantastic write up!

Interview – Brian Callahan & Aaron Bieber – admin@lists.nycbug.org & admin@cobug.org

Forming a local BSD Users Group


Tutorial

The basics of pkgsrc


News Roundup

FreeBSD periodic mails vs. monitoring

  • If you\’ve ever been an admin for a lot of FreeBSD boxes, you\’ve probably noticed that you get a lot of email
  • This page tells about all the different alert emails, cron emails and other reports you might end up getting, as well as how to manage them
  • From bad SSH logins to Zabbix alerts, it all adds up quickly
  • It highlights the periodic.conf file and FreeBSD\’s periodic daemon, as well as some third party monitoring tools you can use to keep track of your servers

Doing cool stuff with OpenBSD routing domains

  • A blog post from our viewer and regular emailer, Kjell-Aleksander!
  • He manages some internally-routed IP ranges at his work, but didn\’t want to have equipment for each separate project
  • This is where OpenBSD routing domains and pf come in to save the day
  • The blog post goes through the process with all the network details you could ever dream of
  • He even named his networking equipment… after us

LibreSSL, the good and the bad

  • We\’re all probably familiar with OpenBSD\’s fork of OpenSSL at this point
  • However, \”for those of you that don\’t know it, OpenSSL is at the same time the best and most popular SSL/TLS library available, and utter junk\”
  • This article talks about some of the cryptographic development challenges involved with maintaining such a massive project
  • You need cryptographers, software engineers, software optimization specialists – there are a lot of roles that need to be filled
  • It also mentions some OpenSSL alternatives and recent LibreSSL progress, as well as some downsides to the fork – the main one being their aim for backwards compatibility

PCBSD weekly digest

  • Lots going on in PCBSD land this week, AppCafe has been redesigned
  • The PBI system is being replaced with pkgng, PBIs will be automatically converted once you update
  • In the more recent post, there\’s some further explanation of the PBI system and the reason for the transition
  • It\’s got lots of details on the different ways to install software, so hopefully it will clear up any possible confusion
  • Working on adding support for FDE with GELI using GRUB for 10.0.2
  • Any devs who can grock the GRUB geli code are welcome to contact Kris

Feedback/Questions


  • All the tutorials are posted in their entirety at bsdnow.tv
  • Send questions, comments, show ideas/topics, or stories you want mentioned on the show to feedback@bsdnow.tv
  • If you\’ve got something cool to talk about and want to come on for an interview, shoot us an email
  • Michael Lucas will be giving a live presentation next Tuesday, \”Beyond Security: Getting to Know OpenBSD’s Real Purpose\” so be sure to catch that
  • Preorders for the book of PF\’s third edition are up
  • We got a picture of a bunch of old FreeBSD CDs
  • Watch live Wednesdays at 2:00PM Eastern (18:00 UTC)

The post A BUG's Life | BSD Now 38 first appeared on Jupiter Broadcasting.

]]>