Wednesday, March 03, 2021

Tip: Remote login to recover from missing display

No comments:

This morning, I found that my Mac’s screen wouldn’t wake up. The computer runs 24x7, with the screen blanking after a few hours of idle time. Nearly all of the time, I just tap a key on the keyboard to wake the screen when I want to use it.

This morning, that didn’t work. The screen remained asleep. I tried obvious things like hot-plugging the display and hot-plugging the keyboard, but no luck.

Wednesday, February 17, 2021

RIP, Rush Limbaugh

Rush Limbaugh, Radio Legend, Dies at 70.
The National Pulse, February 17, 2021

One of the world’s most studious and influential broadcast personalities that has ever lived – Rush Limbaugh – has passed away aged 70.

Love him or hate him, all can agree that Rush almost single-handedly defined modern conservative talk radio. My lunch-time radio listening will forever be less interesting without his voice giving me his opinions and analysis of current events.

Thursday, February 11, 2021

Bleeping Computer: Researcher hacks over 35 tech firms in novel supply chain attack

No comments:
Researcher hacks over 35 tech firms in novel supply chain attack
By Ax Sharma. February 9, 2021, 01:04 PM

A researcher managed to breach over 35 major companies' internal systems, including Microsoft, Apple, PayPal, Shopify, Netflix, Yelp, Tesla, and Uber, in a novel software supply chain attack.

The attack comprised uploading malware to open source repositories including PyPI, npm, and RubyGems, which then got distributed downstream automatically into the company's internal applications.

Unlike traditional typosquatting attacks that rely on social engineering tactics or the victim misspelling a package name, this particular supply chain attack is more sophisticated as it needed no action by the victim, who automatically received the malicious packages.

This is because the attack leveraged a unique design flaw of the open-source ecosystems called dependency confusion.

For his ethical research efforts, the researcher has earned well over $130,000 in bug bounties.

A remarkably simple attack revealing serious problems in corporations' open source package distribution systems.

Like most companies using open source software, they develop applications containing both public packages (which come from well-known and trusted Internet repositories) and private packages (developed in-house). In order to maximize reuse of private packages, they are deployed using an internal repository system, which automatically installs and an application's dependent packages, regardless of where they come from.

The problem happens because the internal repository system doesn't seem to distinguish between private and public packages. So if your application is using a private package, and later one a public repository adds a new package with the same name, the system may end up replacing your internal package with the one from the public server. And because automatic updates are common (in order to quickly incorporate bug fixes and security patches), these replacement packages may automatically get installed into publicly accessible applications.

Well that's not right.

Fortunately, this test was from a security researcher, who promptly reported the bugs, but this could just as easily been malware.

I don't think this should be hard to fix. Internal package management systems need to distinguish between public and private packages. When a given package name exists as both a public and a private package, the system *must* always give priority to the private package. It must also alert administrators and owners of affected applications to alert them to the conflics, so appropriate action may be taken. This action may be one or more of:

  • Block the public package
  • Rename the private package and update all applications using it so they use the renamed package
  • Allow application developers to explicitly state in their package manifests if they want to use the public or the private version

Thursday, January 28, 2021

Upgrading A Mac System, part 4: Peripheral Hardware

No comments:
Mac Mini (2018)
Photo credit: Derorgmas
Wikimedia Commons, CC BY-SA 4.0


The Upgrading A Mac System series:

In part 3 of this article series, I described my application migration story. In this part, I'm (finally) finishing up the tale by talking about my various pieces of hardware that either worked or needed to be replaced. All of the work I'm describing here was actually done in October and November, but I'm just getting around to writing about it now.

Ideally, I would like to just swap the computer and leave everything else unchanged. But life is not ideal. Over the years, Apple has changed the port configuration of the Mac mini, so not everything can just plug in. At least not without some adapters. And some devices that were perfectly great 9 years ago are old and slow by today's standards. So it's time to change up several peripherals.

Friday, December 18, 2020

The Federalist: Ring In Your Holidays By Buying All The Australian Wines The Chinese Won’t

No comments:
Ring In Your Holidays By Buying All The Australian Wines The Chinese Won’t
By Sumantra Maitra, December 18, 2020

In an escalating dispute, Australian Trade Minister Simon Birmingham is taking his nation’s quarrel with China to the World Trade Organization for its tariffs on Australian products.
...
Something else started it all. China, an imperial power throughout nearly its entire history, has finally realized that Australia is fit to be an outpost. The stubborn Aussie refusal to cave to China on all regional concerns eventually led to a crushing tariff over Australian wines.

I'm doing my part. My usual Shabbos wine is Teal Lake Shiraz.

Thursday, December 10, 2020

Upgrading A Mac System, part 3: Apps

1 comment:

In part 2 of this article series, I described the migration process to move all my stuff to the new computer. In this article, I want to share my experiences with application support. What just worked, what didn't work and what was easy and hard to make work.

As you probably know, the latest versions of macOS, starting from version 10.15 (Catalina), do not support 32-bit applications. No 32-bit application will work unless you run it on an older version of macOS (e.g. via a virtual machine). Apple has supported 64-bit applications for a very long time, and they have always been supported on Intel processors. Nevertheless, quite a lot of Mac apps in my possession were 32-bit. I'm not sure why, since 64-bit compilers were available on the Intel Mac platform since day-one.

Tuesday, November 10, 2020

Krebs on Security: Ransomware Group Turns to Facebook Ads

No comments:
Ransomware Group Turns to Facebook Ads
Brian Krebs. November 10, 2020

It’s bad enough that many ransomware gangs now have blogs where they publish data stolen from companies that refuse to make an extortion payment. Now, one crime group has started using hacked Facebook accounts to run ads publicly pressuring their ransomware victims into paying up.

Just when you thought Facebook had hit rock bottom. Now their adware network is being used for criminal extortion. And they're not even refunding the money to the victims who had their accounts hijacked in the process.

So glad I drop-kicked them to the curb many years ago.

Monday, November 02, 2020

Upgrading A Mac System, part 2: Migration

No comments:
Mac Mini (2018)
Photo credit: Derorgmas
Wikimedia Commons, CC BY-SA 4.0


The Upgrading A Mac System series:

In part 1 of this article series, I explained why I needed to upgrade my old Mac, what I bought, and the shipping process.

Now that the computer had arrived, the next step was to move all of my data from the old computer to the new one. In the past, I did this the hard way - I manually created user accounts (an administrator, my personal account, and accounts for my wife and daughter). I then copied all of our documents over the LAN, manually installed all the software I require, ending up with a working system. The whole process usually takes a week or two, plus all the time needed to configure my preferences in everything.

This time, I decided to use Apple's Migration Assistant utility to speed up the process. This, as it turns out, was a mixed bag. Some parts of the migration worked flawlessly, and other parts made a mess I had to clean up after.

Saturday, October 31, 2020

Upgrading A Mac System, part 1: Hardware Purchase

No comments:
Mac Mini (2018)
Photo credit: Derorgmas
Wikimedia Commons, CC BY-SA 4.0


The Upgrading A Mac System series:

For the past 9 years, I have been using the same computer for my main home system, a Mid-2011 Mac mini server. Equipped with two 750 GB hard drives and 16 GB of RAM (upgraded from its original 4GB), it has served me very well. Originally shipped with macOS version 10.7 ("Lion"), it has been upgraded several times through macOS 10.12 ("Sierra"). Although still working great today, it has become increasingly obvious that it needs to be replaced.

The main reason is that its system software is no longer supported by Apple. Although I could theoretically get a bit more support by upgrading to macOS 10.13 ("High Sierra"), that's still an old version and it has many known problems that I don't want to have to deal with. More recent versions of macOS are not compatible with this hardware and therefore can't be installed.

Another bigger problem is that some of my applications can't be upgraded. In particular, Microsoft Office dropped support for macOS 10.12. In order to get any new updates, including security updates, I need to move on to a newer version of macOS.

Finally, it's a bit slow. Modern versions of macOS make heavy use of the file system and a SATA hard drive, no matter how well it performs, just can't keep up these days. An SSD is really required for good performance. I could replace the hard drives with SSDs, of course, but that wouldn't solve the other two problems, so it became time to shop for a new Mac.

Thursday, September 24, 2020

Using a Raspberry Pi for basic network services, Part 4: DNS server

No comments:
Raspberry Pi 4 Model B from the side.
Photo credit: Michael Henzler
Wikimedia Commons, CC BY-SA 4.0


The Raspberry Pi for basic Networking services series:

In previous articles, I described how to set up a Raspberry Pi computer to act as a DHCP server and how to configure it to serve static IP addresses. But this is only half of the solution.

If all your computers are only used to access Internet sites, then you may not need anything more, but if you run any services on your LAN, you will want to access them as well as Internet services. Some examples of services I run on my LAN include:

  • Printer. My printer has a built-in Ethernet interface and acts as a print server for the entire LAN.
  • Web server. Two of my computers are running web server software. I use these for documents that I want to make available to all the computers in my home. In the past, when I ran an Internet-accessible web site, I used my local web servers as a staging area for changes before uploading them to the main server.
  • File servers. Several of my computers have file sharing enabled so I can copy files between my computers.
  • Remote access. Several computers run different remote access tools including SSH, VNC, X2Go and others. This lets me access everything from anywhere in the house.

When accessing a remote service, you need to provide the machine's name or IP address. If you've got a small LAN, you can just type in the address. Or you can set up hosts files on your computers to assign names to the addresses. But once you get more than a trivial number of devices on your network, those two solutions quickly become unmanageable. As I wrote in part 1, I've got 26 active devices on my LAN and many more that are rarely used. Using hosts files really doesn't work because every computer needs to be updated whenever the content changes and some devices (especially embedded devices like set-top boxes and mobile phones) don't even have a hosts file that can be managed.

But there is a well-established solution to the problem. The solution is to use the DNS protocol.