So I decided it was better to just deleted the account. With no idea if the hackers are still there, and what little benefit I personally get from it.. it is not worth keeping it open. If you are paying for a professional account etc it is a different matter, but for me I just can not trust a company that stores passwords in unsalted format. [Hopefully all the other sites, I trust but can't look at their source code don't.. *snort*.]
Anyway to delete your LinkedIn account. I pretty much followed the settings that LinkedIn's help page gave. Login, go to settings, go to account settings, and click close account. Tada, closed account... supposedly. The reason I say this is that I didn't receive any email telling me that the account has been closed. And there is no proof that someone who has my password can not just open it up again. Oh well. One step at a time.
2012-06-06
Why I am not immediately changing my LinkedIn password
So supposedly LinkedIn has had a massive breach, and 2->6 million password hashes have been harvested from some system. While this is bad, and most people watching it are urging people to go change their passwords on LinkedIn, I am waiting and will probably close my account if the problem is confirmed.
The passwords being found in this set look very corporate in how they are setup. People were using "good" password rules: mixing Uppercase, Punctuation, LowerCased, Number, longer than 10 characters, etc. These are probably the ones most likely used elsewhere.
If you used your LinkedIn password anywhere else, or you use a similar pattern (say your password was 123LinkedInQ@$ and you use that pattern elsewhere so your Fedora password was 123FedoraQ@$, please change your password at those other locations, and please please use a different pattern.
- There is no indication that the hacker is "out" of LinkedIn at the moment. So any passwords that are being changed currently could end up going to the hackers again. And with the fact that the most likely password a person is going to use is one they use elsewhere.. that means the hackers have a much larger set to use.
- The password hashes are stored in an Unsalted SHA1 format. This is criminally poor judgement of whoever implemented this part of the password system. The SHA1sum is a very very fast to match passwords to. This means that even 5 year old hardware can work through a terabyte dictionary in a day or so even with millions of hashes to check against. So most passwords less than 8 characters is going to be found within months and passwords longer than that but easily found via "rulesets" will be found in a similar timeframe.
The passwords being found in this set look very corporate in how they are setup. People were using "good" password rules: mixing Uppercase, Punctuation, LowerCased, Number, longer than 10 characters, etc. These are probably the ones most likely used elsewhere.
If you used your LinkedIn password anywhere else, or you use a similar pattern (say your password was 123LinkedInQ@$ and you use that pattern elsewhere so your Fedora password was 123FedoraQ@$, please change your password at those other locations, and please please use a different pattern.
2012-05-02
A History behind Code Names
Having kept a history of the Red Hat Linux code names a long time ago ... ** I wanted to remind people that they started off as an inside joke. Up until the late Red Hat Linux releases, most of the release names were done in a very closed mode. The release leads (Mark Ewing, Eric Troan, Preston Brown) might ask for a name (but you couldn't tell anyone except them what the link was) or a small cabal of people on a late night during the alpha process would choose a name.
The reasons for the names at that time was to a) blow off steam during long nights and little pay, and b) to get fans energized in trying to figure out what links they could come up with between releases. At some point the answer would be revealed and people got "points" on how close they were.. lots of little discussions on IRC, USEnet newsgroups, and mailing lists and it was free marketing. Looking at it this way, the original names were always an inside joke or puzzle.
After the puzzle was revealed, the names rarely were used by the community. Instead the people attracted to Red Hat Linux were more numbers versus names oriented. It is just how some people are.. the engineering types that who will call a CPU a 6500 Xeon versus a Beckton. They will know its die numbers and probably only remember Beckton from some joke about Intel marketing kicking cpus like Beckton to make it sound better. At its extremes, some people see codenames as meaningless marketing jingoism that hides the underneath true data from them.
Other people store information by names and connotations. They know that a Beckton class system is part of the Nehalem family of CPUs and what relationship it is between previous and later CPUs. In this case, the name is a bond, a way to tell what the product is, why the person is linked to it, and how they will get others to use this. In its extreme, numbers are codes that obscure why something exists. ***
If there is any way I can tell "Debian/Ubuntu users" from "Red Hat/Mandrake/Suse" users it is not the .deb/.rpm rift. It is how they remember each OS and the relationship between them. One group is very name oriented and the others is very number oriented.
In the end, I am looking at our (Fedora's) naming "crisis" as partially release day jitters (ever notice before every release we have a OMG CAN YOU BELIEVE X?) we have always had (since RHL 4.2 at least) and partially a difference in how people remember and communicate. Trying to come up with a way to make sure we communicate between these two groups **** will be something for the next 6 months.
** I need to update my website. Dear lord that is so 1998 HTML3.
*** I am not going to say whether this is left brained/right brained/front brained/backbrained.. because god I don't know. Has anyone done real high def brainscans to see if there is any orientation. To me without that data it is like saying "Left handed people use Fedora and Right handed people use Ubuntu.. I know this because I am left handed." EG complete malarky.
**** Yes there are people who can think both ways. There are always people who never fit into the simple dichotomies we humans like to make up to simplify our Spherical Chickens.
The reasons for the names at that time was to a) blow off steam during long nights and little pay, and b) to get fans energized in trying to figure out what links they could come up with between releases. At some point the answer would be revealed and people got "points" on how close they were.. lots of little discussions on IRC, USEnet newsgroups, and mailing lists and it was free marketing. Looking at it this way, the original names were always an inside joke or puzzle.
After the puzzle was revealed, the names rarely were used by the community. Instead the people attracted to Red Hat Linux were more numbers versus names oriented. It is just how some people are.. the engineering types that who will call a CPU a 6500 Xeon versus a Beckton. They will know its die numbers and probably only remember Beckton from some joke about Intel marketing kicking cpus like Beckton to make it sound better. At its extremes, some people see codenames as meaningless marketing jingoism that hides the underneath true data from them.
Other people store information by names and connotations. They know that a Beckton class system is part of the Nehalem family of CPUs and what relationship it is between previous and later CPUs. In this case, the name is a bond, a way to tell what the product is, why the person is linked to it, and how they will get others to use this. In its extreme, numbers are codes that obscure why something exists. ***
If there is any way I can tell "Debian/Ubuntu users" from "Red Hat/Mandrake/Suse" users it is not the .deb/.rpm rift. It is how they remember each OS and the relationship between them. One group is very name oriented and the others is very number oriented.
In the end, I am looking at our (Fedora's) naming "crisis" as partially release day jitters (ever notice before every release we have a OMG CAN YOU BELIEVE X?) we have always had (since RHL 4.2 at least) and partially a difference in how people remember and communicate. Trying to come up with a way to make sure we communicate between these two groups **** will be something for the next 6 months.
** I need to update my website. Dear lord that is so 1998 HTML3.
*** I am not going to say whether this is left brained/right brained/front brained/backbrained.. because god I don't know. Has anyone done real high def brainscans to see if there is any orientation. To me without that data it is like saying "Left handed people use Fedora and Right handed people use Ubuntu.. I know this because I am left handed." EG complete malarky.
**** Yes there are people who can think both ways. There are always people who never fit into the simple dichotomies we humans like to make up to simplify our Spherical Chickens.
2012-05-01
Why I voted for Spherical Cow
OK I liked it because it was an old physics joke.. actually the version I had dealt with was Spherical Chickens, (the Big Bang Theory used chickens), but the canonical version is cows. The joke as it was told to me many years ago had to do with Centralized Soviet planning and putting physicists in charge of dealing with egg production. The punch line of course being "First we assume a spherical chicken..." at which point any one who has had to deal with Physics realizes how far away it is from the real world and engineering.
I actually hoped my suggestion of Pop Soda would win so that we could bring up Mr Hotdogs long lost friend.. but it would seem it was not to be. But I voted for Spherical Cow because I was worried I would end up with the "Sulphur" release again. I also voted that naming conventions need to be revisited. Out of the list (stolen from Mo):
I actually hoped my suggestion of Pop Soda would win so that we could bring up Mr Hotdogs long lost friend.. but it would seem it was not to be. But I voted for Spherical Cow because I was worried I would end up with the "Sulphur" release again. I also voted that naming conventions need to be revisited. Out of the list (stolen from Mo):
- Yarrow
- Tettnang
- Heidelberg
- Stentz
- Bordeaux
- Zod
- Moonshine
- Werewolf
- Sulphur
- Cambridge
- Leonidas
- Constantine
- Goddard
- Laughlin
- Lovelock
- Verne
- Beefy Miracle
- Spherical Cow
2012-04-22
Who is user jetty and why does he have an account on my machine?
As some people can tell, I have installed Fedora 17 on one of my systems at home.
The work laptop (a very nice IBM thinkpad T500) is about dead due to a TSA checkup from last FUDcon and has never been able to handle any of the GNOME-3 updates (I tried Fedora 15 and 16 for a short while but the system would auto-shutdown from heat overload after a bit.)
I had gotten an ASUS laptop for the Christmas of 2010 which had been used to deal with various "Windows" software that was needed for our neighborhood association and for me to play around with Cygwin. I finally decided I had done enough of that for a while, and it was time to play around with Fedora on it to see if how it would run. I had also tried Fedora 15 and Fedora 16 LIVE on the system, but had found it rather flakey in its graphics.. After reading Adam Jacksons and others updates to the X server I figured I should give 17 a go.
Install Trial #1. Since I have to keep the Windows side until my time on the association board is over.. I decided to resize the Windows partitions to fit Fedora on it. I had read that Fedora could do this but found out that this feature was no longer available, or that something with the laptops Windows 7 NTFS was not recognizable. Never fear, ask.fedoraproject.org had the answer I needed: reboot into Windows and use its built in tools.
Install Trial #2. Install the Beta from the DVD. The install went very well though I wish some of the pages could have been replaced with the ones that will show up in Fedora 18. I went through and customized the packages I had installed so that I would get my evil vice: emacs. Laptop rebooted and firstboot got all my information ready for me. Login showed up and there was user jetty (well actually I missed it at first, but realized it when I could not log in with my password.)
Finally log in as smooge, and tada! Look I have a GNOME3 desktop. System seems pretty zippy and windows are much smoother on this system than when I had used the LIVE images (either on USB or Cdrom).
So who is Jetty? The jetty user comes from my choosing eclipse to install. jetty is a java server that the eclipse-platform package requires. I am guessing there is a packaging bug somewhere that is causing the "user" to show up as a possible login. The reason is
A quick bugzilla 815177 and we have done our minimal testing duty. Now to start learning how to use the Fedora 17 desktop as a new Fedoran would.
The work laptop (a very nice IBM thinkpad T500) is about dead due to a TSA checkup from last FUDcon and has never been able to handle any of the GNOME-3 updates (I tried Fedora 15 and 16 for a short while but the system would auto-shutdown from heat overload after a bit.)
I had gotten an ASUS laptop for the Christmas of 2010 which had been used to deal with various "Windows" software that was needed for our neighborhood association and for me to play around with Cygwin. I finally decided I had done enough of that for a while, and it was time to play around with Fedora on it to see if how it would run. I had also tried Fedora 15 and Fedora 16 LIVE on the system, but had found it rather flakey in its graphics.. After reading Adam Jacksons and others updates to the X server I figured I should give 17 a go.
Install Trial #1. Since I have to keep the Windows side until my time on the association board is over.. I decided to resize the Windows partitions to fit Fedora on it. I had read that Fedora could do this but found out that this feature was no longer available, or that something with the laptops Windows 7 NTFS was not recognizable. Never fear, ask.fedoraproject.org had the answer I needed: reboot into Windows and use its built in tools.
Install Trial #2. Install the Beta from the DVD. The install went very well though I wish some of the pages could have been replaced with the ones that will show up in Fedora 18. I went through and customized the packages I had installed so that I would get my evil vice: emacs. Laptop rebooted and firstboot got all my information ready for me. Login showed up and there was user jetty (well actually I missed it at first, but realized it when I could not log in with my password.)
Finally log in as smooge, and tada! Look I have a GNOME3 desktop. System seems pretty zippy and windows are much smoother on this system than when I had used the LIVE images (either on USB or Cdrom).
So who is Jetty? The jetty user comes from my choosing eclipse to install. jetty is a java server that the eclipse-platform package requires. I am guessing there is a packaging bug somewhere that is causing the "user" to show up as a possible login. The reason is
jetty:x:995:992::/usr/share/jetty:/bin/sh
A quick bugzilla 815177 and we have done our minimal testing duty. Now to start learning how to use the Fedora 17 desktop as a new Fedoran would.
2012-04-05
Mailman Passwords: How Fedora IT is dealing with them
Fedora uses Mailman software to run its mailing lists which for all its strengths is showing its age. One of its biggest irritants is its password system. Back in the stone age of the 1980's mailing list software was usually dealt with either by archaic email commands to some sort of list server software, or would have to have user changes done by a list administrator (mainly because it might take 8 or so emails to be able to get some versions of the mail software to put you on vacation or change your email to digest, UUCP or whatever.. and it only took 1 email to the list administrator to get it done.)
When the web came around in 1995 or so, various mailing lists added software to allow users to "self-service" themselves without having to try and reach the list administrator. This had great benefits but "griefers" also found it great to unsubscribe people, change their options, etc etc. So the creators of mailman put in passwords to stop this, and because they knew that the first thing people would do is forget the password they put in a monthly reminder email system.
These days those of us with many email subscriptions usually call the first of the month "Happy Mailman Day" as we get multiple emails telling us that we are subscribed to devel@lists.fedoraproject.org and we chose the password "spew-guts-twiggles" as our password in case we want to change some options. Now this is all fine if we don't use spew-guts-twiggles to password protect our bank.. but some people will use the same password in multiple places.
In order to combat this, most mailing lists have the following text:
Your email address:
Your name (optional):
You may enter a privacy password below. This provides only mild security, but should prevent others from messing with your subscription. Do not use a valuable password as it will occasionally be emailed back to you in cleartext.
If you choose not to enter a password, one will be automatically generated for you, and it will be sent to you once you've confirmed your subscription. You can always request a mail-back of your password when you edit your personal options. Once a month, your password will be emailed to you as a reminder.
However as one can guess, this isn't read by many people and password reuse becomes normal. After a bunch of work, Fedora Infrastructure has hopefully fixed it so that password reuse won't happen for mailing lists anymore.
When the web came around in 1995 or so, various mailing lists added software to allow users to "self-service" themselves without having to try and reach the list administrator. This had great benefits but "griefers" also found it great to unsubscribe people, change their options, etc etc. So the creators of mailman put in passwords to stop this, and because they knew that the first thing people would do is forget the password they put in a monthly reminder email system.
These days those of us with many email subscriptions usually call the first of the month "Happy Mailman Day" as we get multiple emails telling us that we are subscribed to devel@lists.fedoraproject.org and we chose the password "spew-guts-twiggles" as our password in case we want to change some options. Now this is all fine if we don't use spew-guts-twiggles to password protect our bank.. but some people will use the same password in multiple places.
In order to combat this, most mailing lists have the following text:
Your email address:
Your name (optional):
You may enter a privacy password below. This provides only mild security, but should prevent others from messing with your subscription. Do not use a valuable password as it will occasionally be emailed back to you in cleartext.
If you choose not to enter a password, one will be automatically generated for you, and it will be sent to you once you've confirmed your subscription. You can always request a mail-back of your password when you edit your personal options. Once a month, your password will be emailed to you as a reminder.
However as one can guess, this isn't read by many people and password reuse becomes normal. After a bunch of work, Fedora Infrastructure has hopefully fixed it so that password reuse won't happen for mailing lists anymore.
- We found all accounts whose mailman password matched their FAS password and we changed those passwords.
- We removed the options on the mailman servers to allow for passwords to be set in the first place. It turns out that if we remove those two fields in the file.. mailman will just create a password for you and email that to you instead. [Mailman 3.0 has this as the default and when it is in beta state we will look at upgrading to it. It will also have a some other work that Fedora is helping with but that should be covered by the people doing that work.]
tl;dr. Mailman passwords allowed for a place where passwords could be reused and stored in the clear. Fedora IT has reset passwords we knew were reused and turned off the ability for people to enter in bad passwords again. Further changes will be done as needed.
Steps to install Fedora Linux 17 on a Trim Slice Pro
So you have heard of this ARM thing, but can't wait to get a Raspberry pi to plug into your TV. There are various other models on the market.. and for my first one to try, I got a Trim Slice Pro. Here is a shortened, no frills setup instructions.
But wait.. what good is a box that has no monitor? Well not much for desktop people.. but for a server it is pretty darn useful. Future articles will show the following:
** I am assuming you have a local network plugin and a DHCP (most router/modems have this built in). I found that the trimslice built in wireless did not work as well as I hoped without an external antenae, and I also found that having a wired connection allowed for you to ssh into the box directly.
- Buy a Trim Slice Pro
- Wait two weeks for delivery.
- Get onto freenode IRC and join #fedora-arm. If things don't work this is where you will need to get help from.
- Acquire needed extra parts
- An external USB keyboard.
- An external USB mouse
- A serial crossover cable to another system.
- A network cable to plug into your local lan. **
- A SD card to do an initial install on. I bought a 32 GB. I recommend staying away from Kennsington
- Plug in the system and play around with Ubuntu Natty. For extra fun, do an OS upgrade to 11.10 and brick the system.
- Download blc (Brenden Conoboy)'s latest image for the OS.
- wget http://blc.fedorapeople.org/fedora-arm/f17/fedora-arm-17-latest-armhfp-trimslice-mmcblk0.img.xz
- unxz fedora-arm-17-latest-armhfp-trimslice-mmcblk0.img.xz
- Set up SD card (I have a 32 GB card so we will go with the following).
- insert card into system.
- dd if=fedora-arm-17-latest-armhfp-trimslice-mmcblk0.img of=/dev/mmcblk0
- sync; sync;
- remove card from system
- Power off the trimslice if you had it on before.
- Insert card into system and reboot trimslice. The card will need to be inserted upside down versus the way you expect :).
- Boot the box.. if you have plugged the disk into a monitor.. you can unplug it now. Currently the nvidia driver is propietary and Fedora does not support it. You will either ssh in or use a serial console.
- Look at your router to find out what DHCP and mac address came up. If you can, you can put this into your router for a more static setup later.
- either use the serial console or ssh into the box
ssh root@192.168.18.223 # found via router Password: fedoraarm - The system will have started the steps to resize the downloaded arm image to disk space. You should do the following and check to see if it worked.
fdisk -l
The size of /dev/mmcblk should show that the /dev/mmcblk0p2 is now the size of the disk, but a df will show it not the right size.Time to reboot. - After the 2nd reboot a resizefs should be running in the background and you should have a working system to start installing packages to.
But wait.. what good is a box that has no monitor? Well not much for desktop people.. but for a server it is pretty darn useful. Future articles will show the following:
- Setup of serial console (I didn't get my crossover cable yet).
- Setup of nvidia drivers for those who want a desktop more than purity.
- How to start a kickstarter to pay for a developer to port a free video driver
** I am assuming you have a local network plugin and a DHCP (most router/modems have this built in). I found that the trimslice built in wireless did not work as well as I hoped without an external antenae, and I also found that having a wired connection allowed for you to ssh into the box directly.
Subscribe to:
Posts (Atom)