Showing posts with label system administration. Show all posts
Showing posts with label system administration. Show all posts

Friday, June 25, 2010

Windows 7: Byte Me

I've had to play with Windows 7 in the workplace lately.

It's been...interesting?

First of all, Microsoft did improve heavily from Vista. Vista was frustration wrapped in a pretty eye candy shell, and no matter what you did to try and enjoy the candy the frustration was just itching to burst through and make you gag.

At least now it doesn't nag you quite as much.

That said, I've still had issues with Windows 7.

I hate not being able to easily run something as administrator. I find that I have to type "cmd" into the search bar and then right click on the result to "run as administrator."

We use a VNC server to remotely work on many of the desktops in our organization. Windows XP? It wasn't a problem. Under 7 (and Vista when we tested that abomination) we needed to run something like UltraVNC, because the version we were running isn't compatible with the security model used in newer versions of Windows.

I also was more than a little irritated when I could no longer run XLiveCD, a CD disc that has a standalone set of Cygwin tools and X Windows client for Windows. Pop in the CD, run it, and it allows me to secure shell into a Linux system at the office and run my mail client or other tools on my office system. Exit out, and there's no trace of anything on the client computer. Really handy for getting some work done in the field. Windows 7 won't allow me to run it, no matter what I've tried (compatibility settings, permissions, running as administrator...) How annoying!

Another item; I had to change some permissions on icons placed on the desktop of a system. They were icons for everyone, but because of the way my boss made a batch file the icons were placed in a directory for everyone to use under Users but the permissions were set to just the administrative user running the batch file. I went into Users (since documents and settings is no more) and went into all users (after I finally found the setting for showing hidden files and folders, since the file menu is gone now from Explorer windows.) I went into All Users, but even as an administrative user I couldn't get into the "desktop" folder.

I swore a few times and my supervisor came over. "Oh no, it's not there. Go up one and go into Shared." (It may have been Public, I'm recalling this from memory and am too lazy to look it up.) Sure enough, that folder had the Desktop folder for all users who log into the machine.

"That's stupid! The folder sounds like one used as a common sharing area for any user to share documents with each other..."

"I know. But that's what it is now."

Bloody @#$.

Then I had to reset the permissions by selecting the folder containing the desktop files and resetting the files from there, since I couldn't just select the files and tell it to change permissions to those inherited by the parent folder as I could under XP.

Then today I had an application that is niche, used by only a few of our users but "vital" (due to more mandates from outside our control) for their job function. The program looks for "Windows NT 4.0 SP 6 or higher", and installed .NET runtime 1.1, if that tells you anything about the age of the program. It looks like something shoveled together at the last minute and shoved out the door, then as long as the #@#% thing ran the company never bothered to improve it (hey, they have a contract to supply it and we're mandated to use it! So why should they improve it?!)

Can you guess where this is going?

I contacted the company, saying that we have this program that apparently has problems with Windows 7. Is there an update or patch?

"Nope. The workaround is to use a Windows XP SP 3 system until we get a chance to test it with Windows 7, maybe sometime next month."

Um...you're aware the Windows 7 has been released, right? And if you actually developed the product, you should have had a copy of the betas of Win7 to...I don't know...test with several months ago, yeah?

Great. Another company producing shovelware.

And I can't get the "compatibility" mode of anything to work with this piece of crud. Then I saw something that gave me hope! Windows 7 XP mode!

Basically, it's a virtual machine running Windows XP for backwards compatibility!

I downloaded the 500 meg installer from microsoft, installed the virtual machine software, then installed the update patch (MS actually had a convenient web page with a "install this, then install this, then install this...set of instructions and download buttons.) I was getting irritated that I had to run some "Authentic windows" verification program, several times for reasons unknown to me other than probably clicking the link too many times while it was pausing to think about whether it actually wanted to do what I told it to do, and finally everything installed!

Then I created a new virtual machine. Oddly enough it said for memory I could allocate 4 to 511 meg. I skimmed the wizard's instructions (don't most people) and just clicked "next"; it beeped at me with an error. Apparently the default memory size in the box was 512, despite the warning that it could only go up to 511. My supervisor wondered what was going on when I blurted out, "How fucking retarded is this thing?!"

He just shrugged and went back to what he was doing once I explained what Windows was doing again. Because really, how hard is it to check that error condition?

Fixed it, created the VM, and double clicked it, giddy with excitement that I may have found the solution to our problem. The computer hesitated, gave a busy pointer for a moment, then *blip*...blue screen of death.

The machine rebooted, and I tried again. *blam.* Blue screen of death.

Yes, I found a great Windows simulator here.

I slammed the desk with a fist and moved on to Googling the error. So far I found griping about problems with XP Mode on Windows 7, but no solutions. The last thing I did before leaving was upgrade the BIOS since it was an older computer, but haven't tested it again.

So what do I think of Windows 7? It has potential. It looks nice, it has great features, it's leaps ahead of Windows Vista, but it's still frustrating as hell half the time and the rest of the time it's mildly irritating. It's broken a lot of software, and if you're using software by developers that played loose and wild with best practices you'll be lucky if your software works properly.

There are those that would say it's just because I'm used to "bad habits" from Windows XP. Perhaps they are right to some degree. On the other hand, every irritation is one more reminder why I have come to prefer the Mac as my computing platform. It's not fanboy fanaticism or a need to feel superior to Windows users. It's because I find it far less frustrating to use and it doesn't get in my way even half as much as Windows.

Thursday, May 6, 2010

Lower Merion School District Spying Report Issued

The findings of an independent consulting company (Ballard Spahr, LLP) were released recently regarding the remote monitoring of student laptop computers by the Lower Merion School District. Already it spurs an outpouring of vitriol in comments from the smart masses who think they understand anything that is going on here. Personally I think there's a huge disconnect between the peanut gallery and their perceived intelligence.

The report, an approximately 70 page outline of everything that was leaking into the press and then some, basically said what I originally thought. The school district has a lot of idiots running it. Not in so many words and perhaps not for the reasons people would think, but they did some pretty spectacularly stupid things.

The biggest problem, of course, was the IT department hiding the presence of the tracking software. It wasn't so much that I can't relate to their desire to hide it from people in case they try to circumvent the protection; I work in IT. I know people could do that. But anyone with half a brain in IT knows that security through obscurity won't work well. The laptops, if stolen, could easily be wiped and reinstalled with a clean OS image, and the tracking software would be useless. They not only hid it was there, but apparently they tried to obscure the fact that the software was there even when rumors were swirling about its existence. That is a blatant lack of respect for the students and faculty. Whether you regard them as little vengeful monsters or not they still deserve not to be lied to.

A very close second (okay, maybe it's a tie) was the lack of an updated usage policy for taking technology home. There were no documents to disclose modified acceptable use policies for using the laptops at home versus on the school network nor was there disclosure about potential security and privacy issues in the documentation given to parents.

Everything else in the report seems to nick the school for lax and ill-codified policies, and not being fully forthright with administrators and board members.

As someone who has to work in IT, I think the two biggest sins were the lack of properly documented procedures and the hiding of the ability to monitor the laptops. The fact that administrators and board members didn't know about these things, or didn't understand it, were not the IT department's fault, unless they went out of their way to hide it.

Really...there is a point where someone needs to take responsibility for themselves. The board didn't know about it because they didn't care. Neither did the administrators. They all had a vague idea of this ability, if they've seen evidence from the "anti theft" systems. What the hell did they think it did? That this stuff runs on unicorn farts and fairy dust?

I deal with users all the time. They care about how and why their systems work about as much as you care about how your car engine works. The IT department didn't explain it to them because it was a waste of time to do so! I've dealt with users to whom I've explained a simple (to me) concept several times and they simply don't listen. I can repeat it until I'm blue in the face and it doesn't matter. So why and how would this IT department telling their school board about activating timed snapshots from a webcam and screen capture utility while logging the remote system's IP address to a central server make any fucking difference to them?

And lack of following formal policies? In most smaller businesses and schools and, I'd venture, government agencies, following strict, codified policies is a luxury. We always hold up best practices as an ideal but more often than not they're aspired to, not followed. Departments like those in public schools are under immense pressures from the powers that be to just get a task done, and if it's held together with duct tape and broken pencils then so be it. Doing it "right" takes money and time. They don't want it done right. They want it done now.

While some would say that's an excuse, it's more of an explanation for the culture that this attitude has fostered. More often than not if something works, then it's good enough, and it saves money. If it's actually bad enough to bite you in the ass later then it will be fixed then. Otherwise, good enough is good enough.

What I find interesting is that lack of citing personal responsibility by the peanut gallery. These kids were using school property and apparently treated it like their own property. It wasn't. I was floored when this story broke and people were raving about how they'd format the computers if their kid had brought one of them home; yeah, right. You can't. It's not yours. The school was extending it as part of an experiment in technology-based curriculum. And it's their computer. Not yours. Not a handout. Not your property.

I'd have trusted the laptop about as far as I could throw it. Any organization that "lends" you a thousand dollar piece of equipment, would surely have the right to inspect it for activity; porn surfing, games, inappropriate use, anything of that nature. What universe would you live in where you go to school, can't browse the web the way you want, can't play the games you want, but expect them to just hand over a thousand dollar laptop so you could surf porn at home on their dime?

Use your damn brain!

There was one report of a girl who had taken the laptop into the bathroom to listen to music while she showered, and the parent was furious because the school may have seen his little high school princess naked. Huh?!

Damp, humid room...thousand dollar laptop...electronics...water. What the hell was it doing in that environment to begin with?!

To me, there were a number of failures here. From hiding the fact that this software existed to lack of formal CYA policies to cover proper usage of the laptops at home to a lack of common sense from the students and parents, there was a systematic failure that happened here.

The sadder part in my view is the ignorance of the peanut gallery. It's simply too easy to blame the evil school district and portray them as completely at fault while completely forgetting that there was also a bit of an attitude of entitlement, that reality has slammed down hard on the community realizing that these free toys weren't free. 

Tuesday, April 27, 2010

Microsoft Licensing: The Pain It Keeps On Rolling

I continued to set up the Dell machine from the other day. I started out my day at the office where I updated my supervisor on the installation, saying that the laptop couldn't be joined to the Active Directory domain because it was running Windows 7 Home, and apparently that ability is disabled in the home edition. I wasn't sure if he'd care because I thought the user was going to be using it primarily at home anyway.

"Nah," he said. "We have Windows 7 Professional and the licenses, just install that on it."

I sighed, packed up my shiny Windows 7 DVD (64 bit, since for some reason the home version of Windows 7 was 64 bit on that laptop with less than 4 gig of usable RAM...) and headed out to the office where I could work on that system.

I vaguely recall that Windows since Vista has been coming in a form where every version, and there are lots of them, of Windows is included on the install DVD. The different versions that cost you hundreds and hundreds of dollars between the lowliest, crappiest version to the least crippled version are all one in the same; they simply have functionality that is disabled or enabled depending on the license key you feed it.

Neat, eh?

Don't get me wrong with what I'm about to say. I personally hate using software that is crippled artificially. It was one of the reasons I initially moved to Linux; my desktop computer could act as a capable server, while Windows, despite being able to handle a modest workload, was throttled back in what it could handle simply because of a registry setting. Even though I never to my recollection was even maxing out the throttled limits I hated the idea that my system was crippled simply because of me not having more money.

At the same time, I understand and support that it is Microsoft's right to impose limits on their users, as we have to agree to the license in the first place and that license places these (irritatingly arbitrary) limits on the end user. That's why I moved to Linux instead of pirating Windows. It's their product. They dictate what can and can't be done with it.

That said, why is it that Microsoft seems to go out of their way to make a task as simple as installing our volume-licensed, legal copy of Windows 7 Professional over the default Windows 7 Home preinstalled on a Dell laptop?

Here's the thing; for the most part, choice is bad for ease of use. You give users choices, you make them think, you give them the opportunity to screw up. That counts against you in the ease of use department. Weird, isn't it?

Microsoft has outdone itself, going out of their way to make something as simple as licensing into a pain in the arse.

The DVD we have actually has two licenses printed on it. One is KMS and the other is MAK. KMS is their Key Management Service key, and MAK is their Multiple Activation Key. Two really long string of numbers and letters that belong to our business. The difference? The KMS key allows us to have an "in-house" server to handle activations more or less automatically, while the MAK key allows us to input the MAK key individually into systems that then call Microsoft over the Internet to activate. Both the MAK and KMS keys are types of Volume Keys.

Making sense so far?

The Dell laptop with Windows 7 Home apparently has a self-activated key already installed. I popped in the DVD with Windows 7 and told it to run Setup. Setup started chugging along, asking a couple questions, then  it got to the point where it asked if I wanted to upgrade or clean install. I said, upgrade! I already installed an antivirus and our full version of Office (after deleting some crappy trial version of Office that was on the system when we received it for configuration. Setup started looking at the drive and said, "Nope! We can't do that with this version of Windows! You have to run the Windows Anytime Upgrade from the start menu!"

Ah-ha! It does have all the versions of Windows, I just need to plug my key there!

I do a search, since the menu system in today's incarnations of Windows makes it damn near impossible to actually find anything now, for the Windows Anytime Upgrade utility. Run it, it asks for the key. I put in our MAK. It rejects it.

Apparently you need a special Windows Anytime Upgrade key in order to activate that function.

So now I have a licensed, pre-activated Home key, a MAK key, and a KMS key, and none of them do me a damn bit of good because I need a WAU key.

I swear, several times actually, and re-run the setup utility, this time telling it to nuke the C: drive and start over.

This time it worked. I had to spend most of the day reinstalling Windows (Professional, this time), reinstalling Office, reinstalling antivirus, and all the miscellaneous utilities that I had installed but wiped out in the full reinstall.

This wouldn't piss me off so much if I hadn't seen the alternative way to handle licensing. In Linux, there are no real restrictions. You may get a flash of the GPL license, but no key to enter, no restrictions on how you use the operating system (other than what the GPL enforces, which for most users is of no consequence).

On OS X, there are licensing restrictions, but Apple largely takes you at the honor system. Their attitude seems to be, if you put the operating system on hardware that's not ours and it doesn't work, you're screwed, buddy. Apple is largely a hardware company. They make money from their hardware and services. While they have restrictions on what you can and can't do with their software they don't go out of their way to make customers bend backwards while gargling Yankee Doodle Dandy on a unicycle in order to install their software on their hardware.

In the end it feels as if you buy their operating system just by having purchased the Mac. It doesn't bug you for software keys or activation. It just installs. The closest I've had to being locked out from an installer was trying to use a MacBook installer CD to reinstall OS X on an older system whose hard disk had failed. The install CD was keyed to work only with MacBooks, even though it was the version I had on the PowerMac before it died. I think I was still able to reinstall on the new hard disk by booting the Mac to Target Disk Mode and installing from there, as I recall.

No pestering. No nagging. Definitely no typing thirty-digit codes by hand. Maybe Apple just thinks it's not worth pissing off or frustrating customers for the possibility that someone will pirate their software. I had to take my mother-in-law's old G4 notebook in to an Apple store after the operating system became corrupt, and in the end they did a restore from a clean image. The guy at the Genius bar asked what version of OS X was on it.

How would I remember? I haven't looked at that system in probably two years. I can't remember what I wore two days ago, let alone what my mother in law had on her notebook. I guessed 10.4 judging from what I probably had on it when it became her system.

The Genius didn't ask for proof. Didn't hassle us at all. I think he was prepared to install whatever version I said (except Snow Leopard, since that didn't work on G4 Macs). Oh dear, they might lose $30 if I stole a newer version of their operating system! Instead, they made happy customers a priority over losing a drop in the bucket in change.

On the other hand I ended up losing most of a day of work because I needed to install from scratch Windows because I didn't have a particular type of key. Because the keys we paid lots of money for, legitimate keys, wouldn't work to do an in-place upgrade that would have taken ten minutes.

Thanks, Microsoft. One of the largest companies on the planet and you manage to make something as simple as installing your operating system a major hassle for a legitimate customer. Let me wave my "you're number one" sign at you without using my pointer finger. With both hands.

Saturday, February 27, 2010

Encrypting your Laptop: Summary Thoughts

The issue of encrypting your data is far more complicated that I'd like it to be. After doing this on my work laptop running OS X and my personal netbook that I'm using as a "portable computing experiment," I can say there is significant difference in the experience.

I used the "default" methods for encrypting these systems. There are many options if you research online; Truecrypt is popular and cross-platform, EncFS can be used on Linux and OS X but takes some Terminal Fu to accomplish, dm_crypt on Linux,...options abound.

But here's why I chose the "Default" methods; they work. They're supported (in this case by Apple and Canonical). When you upgrade the operating system, there's a far better chance that the encryption isn't going to break the new installation.

The problem is that these encryption techniques are still with trade-offs, partially because of the way these encryption techniques are implemented.

Both FileVault and EcryptFS as implemented here encrypt just the home directory. This means that anything in the temporary directory or in the log files are accessible, as is the swap partition, which can hold data that was in memory and could have sensitive information tucked among the crud. The good news is that odds are very good, since Linux and OS X are "UNIX-based" in design, that your personal data is contained within the home directory.

When you log in, the encrypted volumes are mounted so you can access the data. This means that when you're logged in malicious software can access your unencrypted data. In other words, encryption isn't a cure-all for security.

EcryptFS on Ubuntu stores your files as files on top of the filesystem. This means that if I were to look at my username's files when that username is logged off, say, by logging in as root, the files look like gobbledeygook. Each "real" file appears as a string of nonsense. There's a one to one correspondence...the encrypted file will still allow a nosebag to see when I created the file or last accessed the file, the approximate size of the file, basically they can get a lot of metadata without seeing the actual content or name of the file. This means that it's a lot easier to back up the files to another media.

FileVault is implemented using a "filesystem within a file". If I log in as my secondary user (more on that shortly) I see a huge number of files that comprise a sparse disk image. When I log in as my normal user, OS X takes the image files and combines them into one big container, and my files are contained within that container file. (To be more accurate, the many files are contained in a bundle, so within Finder you only see the top level bundle).

The reason the FileVault image was broken into many smaller files was because of an issue with Time Machine. Originally the encrypted volume was one giant file. If the user was logged in and then a backup was run, the backup will see that giant file has changed whenever even a tiny change was made in your home directory (since your home directory was actually contained in that giant container file). Apparently users got irritated at backups that took hours to complete when only a couple of documents changed.

Later versions of OS X changed the single giant volume into a number of smaller files. That way one small change doesn't trigger a backup of an entire multi-gigabyte file repeatedly but rather a single chunk of the volume.

In contrast, the EcryptFS method of using a one-to-one file encryption means that backups are simpler and faster. You alter one document, that file is the only one that changed and thus the nonsense-i-tized file will be backed up to your storage media.

It's also because of the OS X "container" approach that when using a utility like Carbon Copy Cloner for making images and backups of your computer that Bombich Software recommends you make sure you're logged out of any FileVaulted accounts. On the OS X system I had to create a second administrative user to do backups from.

Neither solution gives full-drive encryption, arguably the most secure. It is possible to configure a new Ubuntu system to encrypt an entire volume at installation time, but to do so means installing from the alternate installation CD. Not exactly user-friendly. So you balance security and convenience, accepting that anything in the temporary caches outside the home directory or anything in swap area could be recovered. On the other hand this means less of a performance penalty for accessing routine system files, since any encryption means having the CPU jump through more hurdles to decrypt information before you can access it.

Encryption adds a layer of security in case your notebook is stolen. The price is that it also adds a layer of complexity. Recovering your data in the event of drive corruption is far more difficult, and in the case of FileVault, if part of that container file is damaged you will most likely lose everything in your home directory. This makes having a backup even more important. Encryption adds processor overhead, so it slows the computer.

One last point I have is that these only encrypt the home directory. Since I'm using a netbook, my expansion storage area on the SD Card or USB drive is not encrypted. If I have that with my netbook case and they're both stolen, anything on those secondary drives is open to theft. I'm sure I could find a way to encrypt the data on those drives, but then if I needed to share data with another computer or use the drives with another computer, they couldn't use it since that system probably doesn't have the same encryption scheme installed. I also make heavy use of external drives at home for expanded space and backups, and they are not encrypted.

I do think that while FileVault has detractors...there are many on the Internet claiming that it will eventually destroy your data, and they decry the shortcomings of only encrypting the home directory...Apple has made the process braindead simple. When it comes to something like encryption, options are definitely a bad thing for end users. People want to accomplish a task. They don't want to have to weigh options and choose the "correct" answer among a sea of possibilities. With the Snow Leopard version, they get protection for the home directory, the protection is implemented in-place so they don't need to move their files around to a special encrypted directory or temporary holding area, the slack space can be securely wiped after the change is made, and they don't need to play with configuration files or the command line to set up details like automatically mounting the home directory, and since it's a standard OS X feature, chances are that new versions of OS X aren't going to render your home directory inaccessible.

The EcryptFS doesn't necessarily have detractors, but for a reason that is itself a criticism...it's not widely used. Linux has a small base of users compared to Windows (or Mac OS X), and an even smaller percent of those users are even aware of the existence of encrypted home directories. It's a feature that's probably not widely implemented in the wild.

I didn't talk about Windows encryption because I don't use it. Windows has had encryption support for some time now and third-party support is, predictably, even more mature (for example, TrueCrypt supports full-disk encryption for Windows, but not for Linux or OS X). But Windows is what I work with in my day job. And it drives me nuts. And one thing encryption will not protect you from is spying when you're already logged in with access to your encrypted volume, and the market for malware on Windows is more mature than the malware market for Linux and OS X as well.

What does that mean? It means that if spyware gets installed while you're logged in, the disk encryption can't prevent that spyware from uploading your documents or opening the machine to remote access to an attacker. The encryption only guards you from having your data stolen if your laptop is stolen; the attacker looks at your hard drive and finds nonsense instead of your banking information if they don't have your password.

It's all a balancing act. The two operating systems I am implementing encryption on stay true to their roots. OS X made it simple and painless. Linux makes it a hidden feature for people who dig under the surface to find the Easter eggs. Neither one is a panacea but are instead an added layer of security.

Thursday, February 25, 2010

Encrypting Your Laptop: EEE PC (Ubuntu Netbook Remix) Edition

Continuing from my previous post regarding encrypting my employer-issued Mac, here I describe the experience of encrypting my netbook running, as the title says, Ubuntu Netbook Remix.

OS X includes FileVault for encrypting your home directory and is braindead simple to implement. It allows for live home directory encryption; that is, if you have the space available on your laptop and turn on FileVault, you don't have to do anything to your directory that involves copying or manipulating your files in order to get protection. Most of the time was spent just sitting and waiting while the laptop went ahead and started altering my home directory for me.

Ubuntu...not quite so much.

It's not fair to say that Linux makes it completely difficult to implement encrypted home directories. The latest versions of Ubuntu supports eCryptfs, the encrypted filesystem. This is built on the FUSE filesystem which allows users to mount "plugin"-supported filesystems (FUSE is a topic all of its own; I can use FUSE to do neat things like mount a SSHFS filesystem, a mount over secure shell. I used to do this to gain access to my home computer's files as if they were mounted locally on my work computer's directory tree.)

The main problem I ran into was that Ubuntu's supported home directory encryption was meant for implementation when users are newly created or when the system is being set up. There is no "live migration" as of Ubuntu 9.10.

There were instructions that were supposed to support a manual move to an encrypted home directory. I had a second computer, so I logged off of my netbook and secure shelled into the system from another system (you can't have files being accessed while you're trying to move them from your home directory, and part of the instructions tells you to log off the graphical interface to minimize the risk of corruption.) I tried those directions twice, and both times failed miserably.

What I ended up doing was first disabling the automatic login to my administrative user by going to system->login screen and telling it to "show the screen for choosing who will log in".

Next I set about the task of creating a new user using the "adduser --encrypt-home tempusername" command, giving that user full sudo privileges by adding him to the admin group, then logging in as the new user. Next I synced my original user's files with the new user's directory (from secure shell, not the graphical login) using the command "sudo rsync -aP --exlude=.Private --exclude=Private --exclude=.ecryptfs /home/username/ /home/tempusername". This copied all the files from the original unencrypted directory to the encrypted new user's subdirectory.

Next I changed ownership to the new user. Probably unnecessary, but I did it for testing purposes; "sudo chown -R tempusername:tempusername *" from the new user's home directory. Then to copy the hidden files, "sudo chown -R tempusername:tempusername .*"

A quick "ls -al" told me that I had caught all the files in the new user's home directory in the net of ownership to the temporary user. I then logged in as the new user on the netbook and lo and behold, my customized color scheme, icons, configuration...all of it...popped up. I checked that my files were intact and happily found that they were.

Next I deleted the old home directory by changing to /home and running "sudo rm -fr username" as well as removing the user from the user management GUI (which just disables the user; home directory is left intact.)


Then I went back to the command line and ran "adduser --encrypt-home username" to create that username again. I verified that /home/.encryptfs now had a home directory for that user then reversed my sync of directories; "sudo rsync -aP --exclude=.Private --exclude=Private --exclude=.ecryptfs /home/tempusername/ /home/username", followed by a "sudo chown -R username:username *" and "sudo chown -R username:username .*" from within username's home directory.
 
Once the sync was complete I logged in on the netbook again and my desktop once again popped up to greet me! Yay!

I then deleted the tempusername from the Users and Groups utility and deleted the subdirectory for TempUsername from /home and /home/.encryptfs; the last one is the actual home directory, where the encrypted files are kept. The "home" directory directly under /home is a mountpoint.

To sum it up, what I ended up doing was creating a new user with an encrypted home directory, copying my data there, then deleting my username and username's home directory and rebuilding it by creating a new user with my old username's name and copying my home directory contents *back* over to the newer username that I just created.

Now when I log in it's using eCryptFS to protect my home directory. Is it particularly user friendly? Not in my opinion. No end user is going to want to sit down and create a "temporary user" to hold data, delete then recreate their username so it will be encrypted.

There was also no built-in way to scrub slack space; my files were deleted, but they're still recoverable to disk utilities. In order to truly delete that old data you need to overwrite the "cleared" space a few times with nonsense data. Over time those files will be naturally erased as I use the computer and other data is added and removed, and without a special utility I'll have to rely on that.

A second problem is that the EEE PC uses a form of flash for storage, like an internal USB thumb drive. From what I understand the cells used to hold the information have a limited "write" lifecycle. The more you write to them, the sooner they'll fail, so controllers use algorithms to write to random spots on the drive to minimise wear on the cells. Running a scrub operation to overwrite the disk spots (and thus make my old data irretrievable) can wear more on the drive and there's no guarantee it's going to actually write where it needs to write to hide old data. Then again, I'm not a storage technology expert, so I don't know if there's a different mechanism at work here or not.

Overall the netbook encryption was more manual and difficult a process than it was on the Mac. If it weren't for my own experience in using Linux, I'd not have been able to easily do it. Even the encrypted home directory feature is not fully advertised in the Ubuntu installer; it's more of a stealth feature being tested internally and by advanced users worried about privacy. This is evident in the fact that to even create the encrypted home directory you have to add the user via the command line since the GUI user manager doesn't have the option. No doubt the feature will appear in a later version of Ubuntu. It'll be interesting to see what the next netbook remix version will bring in options for data protection should my netbook get stolen...

Tuesday, February 23, 2010

Encrypting Your Laptop: Mac Edition

Here's another chapter in my ongoing experiment with the mobile lifestyle.

Periodically a story crops up about some poor sap having his or her laptop pilfered. The news I get has all sorts of cringe-worthy details...doctors losing their laptops with patient information, accountants, business people...even my own employer has departments with sensitive information going between work and home.

Every time I see the story and the concern of personal data being ripped from the drive and used for identity theft, I laugh and think, "You dolt! Why would  you carry sensitive information on a portable computer without encrypting it?!"

Then I stopped and remembered that I never got around to securing my own work laptop (or the EEE PC). It was always one of those things I "meant" to do but just hadn't bothered, and every time I thought of it I knew it was a bad thing because not only would my equipment be missing but they could get passwords, cached emails, etc. on the system. I'd make yet another mental note to take care of it and promptly procrastinate again.

Well, no longer.

My employer lets me use a MacBook. Here I'll outline how I used the default form of protection, called FileVault.

How do you use it? Open the security preference pane. Go to FileVault. Set the "master password" and turn on FileVault for your account. I strongly advise setting the "Secure delete" to wipe the drive of your unencrypted data after your directory is moved to the encrypted volume.

And that's about it.

FileVault creates an invisible encrypted disk file that is mounted as your home directory; it's a sparse image file that grows as you add more files. When you log in with your password, OS X mounts the image file to your home directory. Everything you save or alter goes into that file. When you log out, it's unmounted.

You can see this if you create another user and try viewing the home directory of your filevaulted user. It's just a bundle of encrypted files.

The secure delete takes care of another issue with deletion and security; when you delete a file, it's just removing a reference to the file. The disk still has the data on it so data recovery utilities will be able to retrieve the data you're trying to encrypt (well, the remnants of your previously unencrypted home directory would be recoverable until it is overwritten with other files in the course of just using the computer.)

The process of secure deleting the slack space of the drive and the moving of your data to the FileVault volume can take quite a bit of time; in my case, a couple hours. On the plus side, I put the computer to sleep when I had to leave the office, and as soon as I woke the computer back up it continued with the secure delete task.

There are some issues with encryption (why must everything be a pain in some way?) Apple has tried to address some of the issues, but it's never simple.

Time machine apparently doesn't like the FileVault. See, attempts to back up the system sees the volume files plus your mounted volume as separate files, confusing the backup system. Plus, since you have those files mounted, they show up as being constantly altered, so time machine will keep trying to copy the sparseimage files, which as soon as your home directory changes triggers a change on the image files which triggers confusion for the backup system again...meaning a simple differential backup can easily be corrupted or take hours when it should have taken minutes.

Apple tried to address this by turning the FileVault image into many smaller images. From what I found online, this helps, but still leaves room for complaints. Fortunately I don't use Time Machine so this didn't affect me.

What does affect me, though, is the use of Carbon Copy Cloner. This is one of the best (free!) utilities I've found for creating backup images of your Mac. The problem is that you confuse the @#$% out of it if you're FileVaulted and logged in. It's trying to copy your drive while you're altering the image files.

The solution is to have an administrative user that isn't FileVaulted, made just for administrative work, then image the drive. That way the FileVault image files are unmounted and untouched and you won't need to worry about corrupting your home directory.

I also need to remember to log off or turn off the laptop if I want data secured. When you're logged in, the volumes are mounted, and so anyone else logged into the computer can read your files. Only when you are logged off and the images are disconnected from the home directory mount point are the files "secured."

The only other complaint I've really run into is that logging off takes longer. Because FileVault uses a disk image, the image can't "shrink" just because you delete files. When you log off OS X will try to shrink slack space in the image and thus recover some space on the drive. If you deleted a lot of data, like gigs of photos, then log off it can take quite a while for the shrinking process to complete.

Overall Apple made it extremely simple to encrypt your home directory. It's all graphical, it's simple, and Apple takes the burden off the end user to figure out the technical workings of encryption. A few clicks, a few passwords, and the rest is largely invisible and "just works". The process took an hour and a half...but an hour and 25 minutes of it was just waiting for it to finish the background copy and scrub of data. OS X let me continue working as if nothing was happening (well, it slowed a little since the drive was given a workout, but I could keep working without issue.)

I can say that barring issues like having the image files become corrupt due to disk or power problems, encrypting your home directory on the Mac has been painless. I've been using it for a week or so without issues with any of my software, including virtualizing Windows in a Virtualbox session.

Next, I tackle encrypting my EEE PC with Ubuntu...

Wednesday, November 18, 2009

I Hate VISTA!

There are many things that factor into user-friendliness and it absolutely floors me that something like Vista was released so many years after Apple's OS X, an operating system that has been hailed as a shining example of user friendliness. I can understand many of the shortcomings of Linux in this area...it's largely developed by geeks that like to do what they can to prevent the average user from entering the sacred halls of geekdom, and creating pain among users is a secret handshake in our meritocracy.

But when you're the dominant operating system vendor with millions of users and millions and millions of dollars in R&D, what excuse do you really have for releasing something that is actually several times more frustrating than anything a bunch of geeks have (laughingly) "designed"?

I had to work on a laptop (yes, that I previously had worked on with Vista Home Edition) that was reported as saying that it "needed to update the antivirus but need administrator to do it."

Okay, shouldn't be hard. The antivirus is one that I'm not too crazy over because it, too, has in my opinion design flaws that drive me freakin' batty as well...Central Command's Vexira. However, I take the laptop and start to work.

I ended up having the laptop brought home. I spend some time trying to get Vista to find my wireless network (usually with XP it's a simple matter of clicking the wireless icon in the tool bar and selecting from a list, but this Vista laptops wouldn't show that to me). I eventually found in the networking control panel a line in English, in tiny print, telling me I can "find a network." Fair enough.

It found my (unsecured) wireless network. Join it. Warning: EVERYONE WILL SEE WHAT YOU'RE DOING!" Then it gave a button that didn't look like a button to continue on anyway. I thought it was a label of some sort...nope, just an awkwardly labeled button in the interface. I twitched a little.

It joined my wireless network, telling me the signal strength was excellent. I then right clicked on the Vexira system tray icon and told it to update. And waited. After a few moments I noticed a blinking task bar icon; click that, it tells me that there's a system notice. Click that, and the screen does the obligatory blanking-switch-to-system-screen. Told it to update, and it belches an error with the connection.

Huh?

Told it to "return to my desktop", leading to the laptop blinking a few times.

I was disconnected from the wireless. No reason why, just not connected.

I sigh and go through all the steps to reconnect and once again bring up the update interface on the "special annoy the hell out of the user" desktop.

SAME @#% ERROR. I returned to the regular interface and check the network connection. Disconnected.

I tell the bloody thing to reconnect, and this time "remember the network" and "connect automatically".  This time the notebook connected and stayed connected.

That wasn't the end of the problems, but my gripe here is about Vista, not Vexira. I don't understand why the connection was:
A) so awkward to connect to in the first place.
B) kept disconnecting without notice.
C) had so many @#% clicks to find, establish, and re-establish.

This was on top of the issue with having to switch desktop modes a few times and having the display click and clack as it changed back and forth (resetting video modes? Redetecting the display? I don't know; from the user perspective, all I know is that it ticked me off having to repeatedly go through that annoyance).

I'm a big believer in preventing friction in a user experience. I do what I can to minimize this friction; one thing I do to make it as least annoying as possible is to secure my systems from intrusion and monitor my network usage while removing encryption from my wireless network to make it friendly to the myriad devices we use. This should have made connecting to my wireless network a simple matter of "show available networks, select, connect." So why wouldn't this @#$% notebook connect and stay connected?

Once I told it to "remember the network" and "connect automatically", it stayed connected long enough for me to get a dose of hate for Vexira. The wireless network worked without issues for my wife's Mac. My own Mac hasn't had issues. My iPod hasn't had issues. So unless something is flaky with that notebook's hardware...which hasn't been reported (although possible)...it tells me that my headaches were Vista-related.

It's almost like Vista was going out of it's way to make this three times more difficult than it needed to be! Another checkmark on why I hate Vista. Supposedly Windows 7 improves this dramatically. Me, I'm not so sure I care. There's an Apple ad that pokes fun of the "it has none of the problems Vista had...it has none of the problems XP had...it has none of the problems Windows 2000 had..." There comes a point where I just don't care anymore. When the track record goes this far down, when the experience just fails so hard and far, when I've switched to another platform altogether and found it to be a huge improvement to my ulcers...

I. Just. Don't. Care.

Pay me to try Windows 7, and I might try it. If not then I'll wait until I absolutely need to deal with a new set of headaches.

Tuesday, November 10, 2009

Antivirus Programs vs. the Malware

AV-Comparatives, a name in online antivirus testing, has released the results of their 2009 malware removal tests pitting 16 antivirus programs against each other to test their ability to clean out malware from systems.

The results? None of the tested programs rated a "very good." The link above takes you to the full results of the test complete with a thorough description of the test methodology.

Not that it's a big surprise. At least not to people that have to deal with this crap all the time.

The fact is that once a system is infected, there's no way to trust that it hasn't been modified in a way to prevent you from finding it. It could change operating system files so that utilities can't see the malware or see indications of the infection (like replacing netstat so that you can't see network activity linked to the malware). You don't know if it's hidden in the filesystem so it's invisible (see what NTFS filestreams are; oddly enough there aren't much for native tools with Windows to let you find the damn things but they are simple to access for hiding data and there are malware that can hide information using them.) You don't know if malware is downloading more in the background or working to create backdoor access to your system or if it's monitoring your keystrokes for passwords or uploading your documents to file sharing sites.

Many malware programs are made in a way to recognize attempts to detect them or remove them or know about popular antivirus programs so they work to cripple your ability to update your antivirus program or break the installation of your antivirus.

It's an arms race. The only way to be "safe" is to not get infected in the first place, since I've mentioned what they can do once in your system and the antivirus programs rely heavily on signatures for detecting malware.

But think about it.

You install antivirus with Monday's signatures.
Tuesday a malware author creates a new "virus" and releases it.
Tuesday night a honeypot used by your antivirus vendor detects the new malware.
Mid-wednesday the vendor has finished reverse engineering the malware and has created a new signature.
Wednesday afternoon the vendor has added the signature to their latest update list.
Hmm...when are you updating your signatures? Every hour? Once a day? Every night?

Even if you update every hour, that's an hour window where you were open to infection by that malware. There are hours and hours, at least, between a malware program's release and a vendor getting it, analyzing it, creating a signature, uploading that, then you downloading the "fix". On the Internet you can be infected by scanning worms and malware within minutes.

That means that for most users the topic of computers and viruses is a cat and mouse game, always playing catch-up. And that's if the user even bothers paying attention to the issue (judging from my web server logs, most don't).

Worse, it's not like you can install multiple antivirus programs and overlap protection. Nope. They will normally end up interfering with each other. You have to pick one and enjoy it. Plus they add overhead by scanning every file your system opens up as they work; there's a memory and CPU cycle cost to doing this.

And again. It's. Not. Completely. Effective.

You can minimize the risk by using "less popular" systems like Linux or OS X instead of Windows. That helps, but doesn't make you immune.

How do you stay safe?
Educate yourself about proper system maintanence.
Stay updated with your vendors bug fixes and patches.
Educate yourself about malware spreads; don't install programs from random websites, or give your information to websites that aren't encrypted and aren't reputable.
Pay attention to warnings about addons running in your web browser or programs trying to install or run.
Pay attention to your system so you can be aware of anomalies in behavior. If it's suddenly getting slower or starts acting weird those are red flags.
If you use an antivirus keep it up to date with the latest signatures.
Install specialized malware programs like Spybot Search-and-Destroy. Keep it updated.
Pay attention to security warnings.
Educate yourself on how to use Google to check into programs before you install them. A lot of sites have fake "virus detected!" popups with offers to clean it with a particular product, when the product is actually the malware.

All of these are good starts to keeping safer while using the Internet. Antivirus and anti-malware programs alone aren't 100% effective. Education is a wonderful way to help curb your personal information becoming public.

Sunday, November 8, 2009

System Administrators, Let's Hang Out

I found this question on one of my favorite tech help sites, serverfault.com. It's a wonderful wonderful resource for help (totally free!) for people who are system administrators by day and geeks by night. It's actually one of the "trilogy" of websites; there's serverfault for admins, stackoverflow.com for programmers, and superuser.com for "power users".

One of the things that seems to be underserved on the webbertubes is a good community for system administrators and geeks. The closest I've really found so far is serverfault, but really it's a help site; you have a question, you get answers from peers (that are vetted and voted up or down by peers as well). But a social site for geeks?

So someone asked where system admins go online to "hang out" and be geeky. There seem to be some good leads with that question, but still it's not flooded with answers. Weird...you'd think that the Internet would have some good sources of respite from neurotypicals online.

Part of me wonders if in general sysadmins are antisocial even in an environment as socially hostile as the Internet to the point where they can't even bother to show up at online hangouts made for them.

At any rate for now I get a good geek fix from Serverfault. If you're a programmer, check out Stackoverflow or if you're just a power user go to Superuser. If you have an interest in...just about anything else, check out the Stackexchange site, where there are sites using the Stackoverflow engine to run specialty sites for asking and getting advice on everything from parenting to World of Warcraft. Okay, maybe not tons of sites yet, and directories are being created but it is growing rapidly...check them out and let me know if you've found any gems in these sites! It would be great if I managed to give a reader something useful to work with.

Documenting Configurations

I had an incident that reminded me of an aspect to system administration that we as system administrators don't often address.

It's a "dirty thought", the thing that ends up being on our minds without usually being said. An elephant in the room, if you will.

That thought is just how much of our jobs is to protect users from themselves.

I had a user call up to say their program wasn't working. I'll call it Widgetapp. She is the only one that uses Widgetapp. It's an older program (not extremely old, but about five years in age or so), and it's used to track a vital bit of data on a couple thousand of our users for HR purposes.

Since she's the only user that uses Widgetapp she is the only one with a PC that has the application installed.

I viewed her desktop and found that the program was opening a "sample database" meant for training purposes. Oh...no problem. I use File->open to open the other database with our live data.

I couldn't find it on her PC.

Hmm...this could be bad.

Her desktop doesn't have a backup agent of any sort on it; users are instructed to save all data to their home directories and the servers are then backed up regularly (when the backup server is double checked that it is working properly, that is). I looked at what kind of file the database was and started searching her PC for similar files. Nothing.

At this point I was getting irritated; I couldn't imagine why, if I've worked with this application before (it rarely needed fixing or alterations made) and the application allows you to specify a location for the database file, I wouldn't have stuck it onto the server.

I started looking for a backup of the database on the server used for her department. I hoped that there would be a database that was at most a few weeks old.

Instead I found an oddly named folder that had an uncompressed database file. I created a new folder just above that with a more obvious name (Widgetapp_database) and copied the suspicious contents to that folder then pointed the program to that database and opened it and then had the user check the database; her most recent entries were there!

From what I could piece together my suspicion that I had pointed the program to a database on the server (where it would be backed up regularly) was indeed what I had done. At some point when the company made an upgrade to Widgetapp they moved the folder (still on the server) to another location.

The user probably had a network issue or some other problem where she ended up pointing the program to a default "training" database on her local hard disk. She had no idea that data was actually residing on a shared folder so it was up to us to know this...and we didn't.

Lessons?

A) Keep application data centralized. Programs that don't allow you to point to network shares or UNC's or IP's of application servers are crap. Centralizing the data allows you to centralize your backup management.
B) Document your applications. Document your changes. Document your configurations. Document everything.
C) Users won't have a freakin' clue what you're talking about.

Our organization doesn't do a lot of documentation. We don't have the manpower to properly handle it, and it's a situation that isn't going to change in the near future.

We expect users with specialized software needs to keep track of certain things with those applications. Again, we're extremely shorthanded in our duties and so we make an unreasonable assumption that the user will take responsibility for applications they insist they need. In the end they don't. I consider this another elephant in the room...we know we're doing wrong by it but do it anyway. What normally ends up happening is we end up spinning our wheels for a time because we're re-learning how to use the application or figuring out how something was configured instead of having an up to date reference that spells it out. Then we end up sometimes creating a new method to work around the issue or fix the problem that counters what one of our coworkers initially did. Hilarity ensues if that other coworker is the next one called in to fix the next mess.


I guess the biggest fail here is lack of documentation. We are shorthanded so we take shortcuts. This means we don't keep track of changes made to systems, we're just starting to document procedures, and no work has gone into properly making documentation available (not just available as in collected in some tome on a shelf; available means being able to actually find the information you need, and that means leveraging a wiki or issue tracking database for the troubleshooters to use for getting user and system history and tracking configuration issues).

In this case there was a happy ending. The user's database was found and the application worked once again. The user was happy. And I re-discovered how the application was set up, so I managed to solve my puzzle of the day. The next time I may not be so lucky.

Friday, November 6, 2009

A Video Game that Deletes Your Home Directory Files

Created as an art project, Lose/Lose is a Macintosh game that looks a bit like that 80's classic Space Invaders. The difference is, as is warned explicitly on the author's home page, each alien you kill will delete a file in your home directory.

The story made its way to AppleInsider.

I've already railed on users not bothering to read directions or popups and warnings. This program is clearly a joke on people who don't bother to do so.

However a second twist came up in that several antivirus firms are classifying it as malware and a trojan. They claim that other people may take the program and repackage it without the warnings of dire consquences so that people will delete their files

First, this is silly. The vast majority of malware authors out there are working to make money now. They do it by taking over the machines in order to blackmail other users (give us money or your drive is encrypted), commandeer user's computers to remote control them in order to blackmail other users (give us money or you will suffer a denial of service attack), and commandeer user's computers to remote control them in order to overwhelm anti-spam efforts (turn computers into zombies that send spam). Oh, and I'd be remiss if I didn't mention the take over the computer to record files and keystrokes so they get your login information to banks and corporate sites.

Overall, the key to malware authors getting profits from ignorant users is to not get caught on the computer. If you disable the computer, they can't get money. They can't resend spam. They lose a zombie on their network of controlled machines. So unless it's a targeted attack, repackaging something that deletes home directory files is nothing more than digital vandalism (or a serious middle finger of misplaced anger at ignorant users to teach them a lesson).

In other words, it's a waste of time for malware authors.

On the other hand antivirus authors love this crap. "It's evil!" they laugh. "It'll destroy your computer! Plus it adds another signature to our database to increase the number we can post on our site so we look better than our competitors...

They know damn well it's not a serious threat.

Ken Thompson (if you don't know the name you're obviously not a computer person...just saying...) wrote a wonderful paper called Reflections on Trusting Trust wherein he described a compiler that was altered so it added a back door to the Unix Login program. He said that people normally audit the human-written source code to programs and trust the compiler, the program used to turn that source code into machine code. His alteration added a back door to the Login program and also had the ability to recognize when it was compiling a new version of the compiler, adding that backdoor-compilation-code to the new compiler as well.

In other words, this program questions trust. In order to install a program on the Mac (or Linux or Windows now) you have to authenticate as an administrative user. "Yes, I want to do this."

The problem is that you're normally installing programs from people you never met. You didn't write it. You didn't audit it. What's to stop the new trial software you downloaded from the webbertubes from uploading your financial information in the background while you're playing? If you granted it administrative access when installing the program, absolutely nothing will stop it.

Users simply trust that there's no chance (or a very slim chance) of that happening. They trust the authority of Those That Know More About This Shit Than I Do(tm).

Classifying Lose/Lose as malware (or potential malware) is silly and a waste of time. Any jackass that is worth their programming salt would come up with a better version than some retro 80's video game to attract more users rather than spend the time reverse engineering this little game, and even if they didn't, the time invested in removing the warnings would still probably not take much more to alter the compiled program so that it won't trip the signatures in the antivirus programs.

Hell...I could email a script to someone telling them to execute it and all it does is "rm -fr /". Got a signature for that, vendors?

The fact is that uneducated and ignorant users will always be a weakness in the system. There is no bringing them up to speed because they're not interested. See the number of cars that are on the streets in the US? How many of them don't know how to change a tire? Which, arguably, is one of the simplest tasks for car owners yet a rather important thing to know when they have a flat and are on their way somewhere. Lots of people have computers, they're ubiquitous, many people have come to rely on them for various tasks in their lives...yet they sure aren't flocking to the computer section of Barnes and Noble to learn how to properly maintain their system. Most of the time I'm lucky to find a user that even runs Windows Updates on their system.

So what's the summary here?
A) Users won't read warnings.
B) Antivirus vendors will do anything to look good.
C) If I can get you to install a program on your computer, you're not secure. You're probably fine. But you're not secure.

Tuesday, November 3, 2009

Security ID: NewSID is Retired?!

Mark Russinovich had this interesting blog article. He retired the NewSID utility.

If you didn't know, the NewSID utility was part of the Sysinternals suite of free Windows tools and was used to change the Security ID used on Windows NT based systems. The article explains more, but basically the SID identified certain accounts on the computer (the names associated with them are a friendly format for people to read, the SID was the machine version that actually mattered, similar to the userid in Unix systems mapping 0 to Root; anyone with userid 0 was considered Root).

Mark is a guru in the Windows world; he wrote NewSID, so when he posts his explanation that basically the SID is useless and doesn't need to be changed then questioning him is like questioning the Bible. It just isn't done.

The weird part is that I've had systems at work that acted very very strange on the Active Directory domain if it had a SID that matched another machine. Use NewSID, and suddenly issues went away. Coincidence?

Hmm...

Wednesday, October 28, 2009

The Abomination that is Windows Vista

I recently had cause to work on a system that another department had ordered a few years ago with Windows Vista Home Basic on it.

It reminded me all over again of all the things I hate so passionately about Windows Vista.

I recently blogged about my trials and tribulations involving the fact that there's no default administrator account while I had to reset the password for the default administrative user on the system in question. It was irritating, but followed the trend of other operating systems; "hide the administrative user behind another layer so people who don't think before hitting Enter will have another hurdle to cross before destroying their system."

The more I worked with this computer, though, the more agitated I became. The computer wasn't really a slouch. It was a core 2 duo with a gig of RAM. Yet I booted it, it would pop up with a welcome screen. Log in. Goes black. Comes back up. Flickers back out. Comes back up. I think at a couple points in the troubleshooting I turned off the computer accidentally, thinking that it had crashed when it went black for more than ten seconds.

My first computer ran DOS and Windows 3.1 on a 486SX-25 processor and 4 meg of RAM. That system even ran a beta of Windows 95. 4 meg of RAM. The is like comparing an 86' Chevy to the starship Enterprise. And Vista was killing it.

I had to reboot it several times over the course of upgrades. The upgrade mechanism was infuriating. There was very little feedback; it would sit at the prompt that it was checking for upgrades at 0% for ten or fifteen minutes at a time. When I thought it had crashed, it suddenly jumped to 40% complete.

Other times it would come up and say I had 4 optional addons (after several rounds of updates completed). Done? Nope. I clicked "check for updates" (again) and it suddenly found another couple of updates waiting.

I was even more agitated earlier when it installed a whole group of updates...twenty or thirty...then I attempted to install Internet Explorer 8. It wouldn't. The install program would just "disappear", no warning, no nothing. I downloaded it four or five times.

I broke down and downloaded the standalone installer to another folder and ran it from there. It failed, this time leaving a link on the desktop with a potential fix. Between that and checking my trusty friend Google, I was told to check Windows Updates first. Then there was a little note saying that Vista with SP1 didn't need this, and IE8 would install fine with Service Pack 1 installed.

No...service...pack...one?

I went to Microsoft's site and downloaded a FOUR HUNDRED MEGABYTE service pack. And installed it.

Then installed IE 8.

You can rightly assume there were three or four reboots involved.

And I nearly screamed when it said there was another 200 megabytes of updates waiting for me after those were installed.

I had to attempt to install those updates about four times. Each time, some installed, others failed due to some vague error. A reboot and retry would yield a little more progress.

You can rightly assume that I was getting more and more agitated at this.

After all these updates, Windows Updates decided that there was a service pack 2 waiting for me.

If you didn't know, most service packs roll previous fixes right in. So if you install service pack 2, you already have all the fixes that came before it. That way you don't have to install service pack 1then 2. You install 2 and get all the fixes since the operating system was released up to that point.

I was incensed and furious. What kind of braindead monkey designed this update system?

All this time I was working on getting the antivirus working. In the corporation we use Vexira antivirus from Command Central. It's not my favorite.

Vista doesn't seem to love it either. I right click on the tray icon and tell it to update itself. The update console doesn't come up. Instead some "interactive service dialog" pops up. Click it, and it takes me to some kind of privileged desktop that hides the things I was actually working on so I can see the antivirus update console.

With a heavy sigh I told it to start updating. It dutifully began downloading a new version of the antivirus. The computer sat for about a minute.

And went dark.

Another "flicker out"? WTF?

I moved the mouse and the login screen pops up. It said my administrative user was "already logged in", but...huh?

I couldn't find any way to shut that off. Unless I keep moving the mouse while in that "interactive desktop", the @#% thing would drop me to the login prompt after a minute or two.

This didn't happen at the regular desktop. Couldn't find a setting to stop this from happening in power settings or desktop settings or the user account.

I would have checked the local user policies, but because of Microsoft's crappy ranking system of their operating systems they don't include the policy editor with their home edition of Vista. Same operating system as their "business" operating system, but artificially crippled by cutting out utilities that could actually help the users in need of troubleshooting...another reason I moved to Linux in the first place. If your system couldn't act as a server it's because the hardware or software couldn't handle it, not because of someone's idea of a fair market or sales policy found posted in their colon or some other artificial limitation in the software.

Supposedly Windows 7 fixes a lot of the usability snafus and glitches. I hear lots of praises for it. The problem is, I don't care. I've had enough frustrations with Windows. I've spent years finding workarounds to various glitches in Windows 2000, then XP, and now I'm expected to leap again with Windows 7.

I'll do it because eventually I'll have to. But I can't enjoy it anymore. I used to be enamored by technology; I loved jumping into the theory behind multitasking operating systems and handles and filesystems. I used to devour articles in Byte magazine that compared various operating systems and how they worked and compared to each other in architecture. I think I still have magazines in storage that had information on the great OS/2 vs. NT debates.

But today it's no longer a question that interests me. The arguments don't focus on usability or architecture so much as how much the OS can be dumbed down for users; the Vista control panel tries to communicate in plain English concepts that for tech people would be much better served with straightforward checkboxes and text boxes for values. I don't need handholding and friendly web-like links asking if I'd like to change my password, thank you.

There aren't any companies really trying to innovate in operating systems. There are three; Apple's OS X, Microsoft's Windows, and Linux. That's it.

There is a convergence in features and eye candy that suck up resources like crazy. I remember my old computer was perfectly adequate for my tasks. Today you couldn't even get a common OS distribution to boot on a system with those specs.

I've played with BeOS, AmigaOS, Linux, MacOS, OS X, DOS (MS, IBM, Novell), Windows from 3.0 to 98 (we don't speak of ME), NT from 3.1 to Vista, Netware, and several small and hobby OS's like QNX and ReactOS and others too small to name here. Today most of the projects are gone. Except, of course, for Windows, Linux, and OS X.

Vista was a reminder of what I hated about this trend. Technology is exciting today with new devices; the Kindle. The Nook. The iPod and iPhone. The web. Operating systems are so bland and commodity that they're not really even worth looking at anymore.

When operating systems frustrated me before it was because of my own limitations and lack of knowledge. I had to expand my understanding of how the system worked in order to bend it to my will. Today the frustration is being designed into the operating system. "Are you sure you want to run this?" "Do you really want this program to run?"

Or all the times I'm searching for a function that disappeared from the previous version of Windows. It's infuriating when I know what I'm looking to do and can't because I have to interpret the "natural language" version of the interface.

Or I have to click to open the C: drive, then confirm that yes I want to see this files, then click on Program Files, and again confirm that I wanted to see the contents of the folder.

At that point I really can't help but re-examine my job duties. It's one thing when I can't get something to work because I'm lacking information. Learn more about LDAP. Learn more about TCP/IP. Learn about priorities and file handles and applications to monitor I/O. Read read read. But to have an operating system act like it knows more than I do, and actively get into my way when I'm trying to configure it or set something up?

I'm tired of it.

And now Microsoft is promising, just as they did with Vista, that Windows 7 is better than anything they've released before.

Yeah, right. I'm going to go back to my corner and browse the web with my iPod.

Tuesday, October 27, 2009

Windows XP SP3 v. 3264 (Or, "The pre-release version of Remote Desktop Connection has expired...")

Here was an interesting problem today.

I was working on an "import" for a client. By import, I mean this computer technically belonged to another agency that is working within our network because of a leasing arrangement; we didn't set up the machine, but it was on our domain, authenticated to our domain servers, and ran some software we run because it's expected that we babysit the system and maintain it while on our property, but the computer itself isn't owned by us. Clear as mud?

The machine itself was somewhat decent. One of those budget E-Machines, 2.x Ghz with a gig of RAM. Decent enough for most users online chores, running Windows XP. I was annoyed at it since it won't run X on a RIP Linux CD (just keeps stuttering to the command prompt, and xsetup doesn't seem to like the video chipset).

The user ended up needing a home directory set up so they'd not be tranferring a 400 meg profile with them (who's the genius at MS that designed it so that "my documents" was part of the profile? If a home directory is defined, why not make it *automatically* point to that location instead of forcing admins to hack away at settings to redirect it? Stupid stupid stupid...)

No problem. Just open up the RDP client...start,...programs...accessories...click on the client. Voila! What the hell?

"The pre-release version of Remote Desktop Connection has expired. To download teh full version of Remote Desktop Connection, go to Windows Update or contact your system administrator."

Um...okay. Run Windows Update. Nope...no update available there.

Wait, did it say pre-release? I checked the version of Windows. It was Windows XP Pro SP3 v. 3264. I did a double take at that...what's the v. 3264?

Google. It's running a release candidate for service pack 3? Who's the chucklehead that did that? And inflicted it on a technology illiterate user? These are wedgie-deserving offences. Worse, if this draws into a problem where I'm going to go all Hulk on someone.

Google for a fix to the terminal issue. @#%...replace  a couple files under Windows' System32 directory. Didn't work. Replace two .mui files under en-us in the system32 directory. Still no joy.

Weird...

I pulled a copy of the ginormous service pack off our network share and run the setup. Goody. Takes forever, but it actually ran without complaint, and in the process fixed the RDP client. Know what else it fixed? A small flood of back hotfixes and security updates labelled for service-pack-3-no-freakin'-RC-version.

I don't know if the company behind those Walmart special E-machines installed a @#$% release candidate service pack or if their "tech person" did it, but anyone that installs a BETA of a SERVICE PACK on a user's system that is then turned out into the world to fend for themselves should be stabbed with shards from broken DVD's.

If you encounter that weirdo message about the RDP client expiring, try reinstalling SP3. The full version. Not some crippled beta.

Monday, October 26, 2009

Windows Vista and the Administrator

Well, I'm typing this on the eve of Windows 7's release and by the time you read it it will have been out for a month. Nearly.

It's being hailed as the next big thing, perhaps even big enough to erase that abomination that was Windows Vista.

I had occasion recently to have to work on a laptop running Vista Home. Most of the systems where I work are still running Windows XP for two reasons; it works (relatively) well on the cruddy hardware we have, and it is nowhere near as infuriating as Windows Vista.

My task was to clear a password for an administrative user on the laptop because the admin password had been lost.

Believe it or not, this is normally ridiculously simple. I boot with my trust RIP Linux CD, mount the hard disk, and then run chntpw to wipe the password. Reboot to Windows, log in. Done this hundreds of times with XP and have had no problems. Easy peasy.

Given that Vista is largely XP with more hassles layered on...well, okay, given that Vista is still the same basic code base as XP, it still uses the SAM portion of the registry to save password data. Shouldn't be any issue with wiping the password.

I booted, mounted the drive, checked for a /mnt/sda3/windows/system32/config/SAM file, and ran chntpw. Rebooted.

Um...where's the administrator?

Turns out...THERE ISN'T ONE! Surprise! On me!

By default the administrator account is turned off. Instead there's an administrative user account used by the system. Otherwise you have to go and enable it on Vista Home using a boot disk and command prompt. Check it out here.

So apparently I cleared a password for a user that doesn't work. @#$%

I was irritated. This was one of the few constants I have counted on in my administrative duties, having an administrator account available. Systems fall off the domain, systems have issues that necessitate a login to the local machine, now it doesn't work quite right.

I shouldn't be quite so irritated. Many Linux distros have started moving away from having the root user enabled, forcing you to instead use sudo to gain privileges. Ubuntu does it and OS X does it, both of which I use constantly.

I guess my main peeve is that those are systems I use. I know them. I generally can find my way around under the hood. When your job means having a system dumped on you with no back history available and the directive to get it working, though, this adds another layer of frustration since now I have to figure out another piece of the puzzle just to log into the damn thing.

It goes back to usability. One of the strengths of the Mac was that Apple was the most anal retentive companies about how their system appears and how your application looks and behaves. If you ask the user what word is in the upper left corner, it's going to be the active application. In Windows you have to guide the user ever so gently into figuring out which menu bar is highlighted to figure out the current window that is active. Menus may or may not follow the same order (you can imagine the calls and hair loss after Office 2007 was released with their wonderful redesigned ribbon bar for a menu...)

The ability to have a quick and easy way to log in was something I took for granted. No matter which head twitch configured the system or what knob had screwed it up, I could use administrator on the local machine to log in. No more.

I read that windows 7 continued the new tradition. Just another reason to want to cry some days in the tech pits, I suppose. It would be different if more people were knowledgeable about the tools they're misusing, but such is life.

In case you're curious, which you might not be, I did get into that system. I figured out which user from the menu was the admin user and then booted back to rip, and this time used chntpw with the -u parameter to specify the username whose password I wanted to erase. Voila. Worked.

*sigh*

Friday, September 11, 2009

What Is That Program Doing? Or, Why Is This System Using So Much Memory!?

First, let's get a quick concept out of the way. When dealing with computers, new sysadmins have to understand that when it comes to a system compromise (a computer gets hacked), the system cannot be trusted. It's like asking a person to objectively assess their mental state; when you ask a person's brain to evaluate itself, it's going to be biased and distorted. Similarly, when a person cracks a computer system, they can alter the programs and filesystem so that if you run utilities to show network connections, running programs, etc., the altered files will hide the unauthorized activity.

Pretty simple, yeah?

So how do you see unauthorized activity? If your computer was hacked and is now sending spam email...which is network activity...but if you run utilities everything is showing up as normal (because the altered files are hiding the unauthorized network activity), the computer can hide what's going on, but a second system on the network that is monitoring network activity will see all the activity. In other words, your hacked computer may have its fingers in its ears yelling, "LA LA LA LA LA" but a third party system will still see what that computer is doing.

You add a layer of abstraction to watch what's going on, and in the process you can learn a bit about what is actually going on with your computer.

Now...the topic of of the post.

I have been working with a technology called virtualization for some projects at work. It's really great stuff...it lets you create computers that exist only in software, letting you install and configure multiple computers that run on just one system. Schizophrenic, but very very handy for people like me that have to run print servers, web servers, and file sharing servers in an organization among other things because I can consolidate those systems onto one or two actual physical systems (with tons of RAM and disk space).

In the process of running tests to migrate some of our physical systems to virtual software systems we moved a printer server. This is a Windows computer whose entire job on our network is to spool print jobs and dole them out to our many many printers scattered around several buildings. Not uncommon in businesses to have printer servers configured in their network for easier management.

Normally we'd think that this isn't a huge task, either. Most of the time a server like this would sit largely unused; I mean, it just sits waiting for someone to send a print job, render it then send it to the appropriate printer. It's not crunching numbers to predict the weather.

"But Barry," you ask, "What does this have to do with hackers and second computers to watch what a system is doing?" Glad you asked. See, when you run a full-on virtual server system...in this case what's called a type 1 hypervisor...you get an abstracted view of a computer; memory use, disk use, network use...and so you can get a quick overview of what the computer is doing that ordinarily you wouldn't get to see with a physical computer.

What I saw was that out of (more than five, fewer than ten systems) on our virtualization server the printer server was taking up nearly 800 meg of memory and shooting between first and second place for CPU usage and network usage, depending on what the other systems virtualized on the testbed were doing at that point. What in blazes is it doing?

I logged into the machine and ran a wonderful tool from the sysinternals suite called Process Explorer (free download...I highly recommend the sysinternals suite of software to ANY system administrator or troubleshooter). From there I could monitor process (program) names, the command line from which they were running, memory and CPU usage, etc.

I found a couple things of note. First, the converter program I used to automagically convert the physical machine to a virtual machine runs a service that carries a large footprint of memory; now that the system was virtual, the converter program isn't needed. So I removed that program from add/remove programs and memory use for that virtual image dropped over 100 megabytes.

Second, the computer is running a database program as well as a Bash shell spawning Java. Huh?

In case you didn't know, Bash is a shell program that runs normally under a Unix system (like Linux), not Windows.

Process Explorer told me that both the database and the Bash shell (and in turn the Java system) was tied to a Dell utility tied to Openmanage. Many mental scars remind me that OpenManage is a set of utilities made by Dell for managing their servers...usually it has functions for things like monitoring fans and CPU temps, rebuilding RAID arrays, etc. etc...generally a headache to sort everything out and get working in the proper combination for your system. At least, that's my experience with it.

So I go into add/remove programs to remove the OpenManage software, since now that the system is virtual there really wasn't any Dell hardware for it to manage.

Surprise! I was wrong. Apparently at some point someone installed an OpenManage component for managing printers! It wasn't small either. In the add/remove programs there was a listing for "Dell Printer Software" and for "OpenManage Printer Manager", each of which was taking 1.6 gigabytes in storage space on the hard disk. Each. Not both together.

But since some departments wanted Dell multifunction printers on the network and I didn't install it I don't know if these software packages are something that are needed so I can't really just tear through and uninstall those programs without dealing with the possibility of Nasty Consequences(tm).

Apparently Dell tries to cut some corners to make their software more portable between Linux and Windows by using Java (I'm speculating since I'm not too thrilled with OpenManage software, so I don't install it on my Linux systems on Dell hardware). Part of their software workflow involves using a program called Cygwin to do something with logging or some management task; Cygwin is a port of Unix utilities to run on Windows (that's why I saw Bash running). You can run tools like Secure Shell or awk or sed or ls...many many many scripting and administration utilities...on Windows that normally you'd only see on Linux. Process Explorer popped up lines in the process list as some of these scheduled tasks were periodically popping up thn disappearing, no doubt adding to the memory and resource use of the virtual machine. To be clear, Cygwin has it's place and I think it's great when properly used. I've also seen it installed on systems that suddenly start spiking CPU usage because of one of the programs using Cygwin libraries (in that case, SSHD running on Windows as a service).

What lessons can we learn from this little educational field trip?
  • Generic is good. Addon software is bad. Backed up by anecdotes on the StackOverflow podcast, that CD that came with your camera/printer/device should not be installed unless you have no other choice but to use it to get the device to work. Many modern operating systems include drivers to work various media devices, or for devices like HP printers, you often can go right to the website and download just the driver, without all the addon crap that will bog down your computer with extra programs that you don't need (or know what they're really doing).
  • Virtualization can give you tools that will both teach you about using your system and open your eyes to some things your computer(s) may be doing in the background without your knowledge. There's no reason that a printer server should be sucking down resources like this one was except that it had some poorly optimized software installed that it probably doesn't need.
  • Third party utilities like the Sysinternals Suite can help you track down oddball activity on your system (or insights on how things work) for free. There are tools that tell you what's connected to the system over the network, which program is writing and reading the hard disk, which program is hitting what part of the registry, and many other useful tools. Try it out if you run Windows.
  • Audit your system once in awhile to see what's actually installed and what it's doing. If it's not needed, free up the drive space by uninstalling that program. Use Google to figure out what the programs are. Part of what contributes to your computer slowing down over time is having programs running in the background that take up space in memory and access the network and you probably don't need them. Become familiar with your system and it can help save you aggravation down the road...also it'll help you later on when you notice something that should not be in that process list running, so you can tell when something is out of the ordinary on your computer. Process Explorer even includes tools for you to Google process names from a menu, making it even easier to learn about what your system is doing!
Windows isn't the only platform to suffer from bloated, inefficient and/or poorly designed software, but since Windows has the majority of users who are non-technical in interest and nature it is the platform with developers who get away with creating shovelware much more often. Fight it by not using it. I'm not referring specifically to Windows, although I encourage not using that too...but rather don't use the bloated crap that comes as trinkets and addons that only serve to bog down your computer. Don't install software from CD's that came with your new tech toys unless you must; try plugging it into the computer first to see if Windows or Linux or the Mac recognizes the hardware and installs the necessary drivers for you first. Then you're using native tools and not someone else's idea of how you should use their tools (and sometimes screw up your system in the process). Check your computer and screen it for odd behavior and find out what those processes in the background of your system are doing so you can get rid of software that is slowing your computer without justified cause.

Anyone have any stories they'd like to share?

Friday, August 21, 2009

Windows 2008: I Hate You

I recently had the joy of installing Windows 2008 Server at work in preparation to migrate an older server application to it. I put off moving to or using the latest versions of Windows because I read of many of the headaches for sysadmins that lay in store (in case you want to relate a little, ever use Vista? Well, 2008 is Vista with server capabilities, and a few consumer interface items stripped out...but keeping most of the security problems).

In my two days using it, I ran into this short list of things that truly annoyed the bejebus out of me.

I ran a chkdsk (check disk) on the drives to repair any potential damage after a power outage that outlasted the UPS (I know, what were the odds?). Ordinarily, you run chkdsk at bootup, you can check the results by looking in the logs for messages from WinLogon. I searched for five minutes through the list without finding it...because now it was under something called WinInit. In a way this was funny, since I wondered "Wininit gonna work right for a change??"...say it out loud if you don't get it.
Almost every site, including Windows Updates, including innocuous sites that I've visited for years, including common sites for additional software...required me to add it to a "trusted sites" list. Sometimes it wouldn't even tell me it needed it, some redirect or addon simply wouldn't work. It's an additional step that I don't need when I'm under pressure to get the server working and get things configured.
VNC doesn't work. It's a neat program from www.realvnc.com (which has a free edition) that allows you to remotely view and control your desktop console. It's a convenient way to get to the console, whoever's logged in...we often use it for remote troubleshooting. It has its own password mechanism so it's not reliant on the password for a particular Windows user. "But Barry, why use that when you can use Remote Desktop? You get two client licenses included!"-easy. If Administrator is logged into the console downloading something, and then I RDP in and log in administrator, due to idiot licensing restrictions my login will kill the other session. So if something is being worked on at the same time...poof! Gone. VNC just brings up the remote console because it's remote control, not remote access. Anyway, VNC comes up with an error that Windows won't allow it to run because it's an interactive process. Nice. Really nice.
They changed the Management Console. I used to be able to right click on "my computer", go to manage, then from the top of the tree right click on the "local computer" and from there enter the address of another Windows system on our network so I could view services, system logs, etc...well, no more! Windows 2008 uses the "Server Management Console". And I can't connect to other systems from it! How handy is that?! Well, it's not. Thanks to some other people who were annoyed at this they already solved the problem...I just created a batch file on the desktop that contains the line, "start compmgmt.msc", launching the old fashioned management console from which I can actually manage other systems.
The system logs on the server like logging a message about licenses being validated by WinLogon. Um...who or what is it validating against? Why...? I'm always a bit skittish about software "phoning home". We are using a server, with potentially sensitive data on it. Maybe it's just validating against something on itself, maybe to one of our Active Directory servers, I don't know. But it's annoying me.
Creating a share seems to get more of a burden with each release of Windows. I had to use a wizard now to create a simple share; Wizards are supposed to be a good idea for helping new users with tasks that may be unfamiliar. But wow..."provision share"? I wasn't sure what it wanted me to do with that at first. The familiar route...right click the folder I want to share and select sharing...now takes you to a mini-wizard that would not let me change the name of the share, which I needed to do. I believe I ended up going through a submenu in the server manager to create the share I wanted...through a bigger wizard. All I would like is to right click the folder, have a list of tabbed options, and go from there. Why is that so !@#% difficult? This is Windows Server, sharing is a very basic and common task for server admins. Why must it be a topic for a wizard, without a choice to not suffer through a @#$$ wizard interface? Or worse, an inconsistent interface, since there is more than one wizard to go through for sharing?

Maybe these are just initial impressions and I have to adjust to it. But my first impression was that it was a pain in the arse. VNC didn't work on it. Security notifications keep popping up, even for Windows Update! And common tasks have to be relearned. This is progress? You must seriously have to love the Microsoft Kool-Aid to embrace newer versions of Windows. I find it to be an giant pain to deal with...

Anyone else have similar experiences? Or reasons I should love this version of Windows? Please?