<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
    <title>uncharted backwaters</title>
    <subtitle>The occasional rants and other miscellany of Francis Russell</subtitle>
    <link rel="self" type="application/atom+xml" href="https://www.unchartedbackwaters.co.uk/blog/posts/atom.xml"/>
    <link rel="alternate" type="text/html" href="https://www.unchartedbackwaters.co.uk/blog/posts/"/>
    <generator uri="https://www.getzola.org/">Zola</generator>
    <updated>2014-07-02T12:29:59+00:00</updated>
    <id>https://www.unchartedbackwaters.co.uk/blog/posts/atom.xml</id>
    <entry xml:lang="en">
        <title>Microsoft doesn&#x27;t understand DNS</title>
        <published>2014-07-02T12:29:59+00:00</published>
        <updated>2014-07-02T12:29:59+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://www.unchartedbackwaters.co.uk/blog/posts/microsoft_noip_dos/"/><id>tag:unchartedbackwaters.co.uk,2014-07:microsoft_noip_dos</id>
        
        <content type="html" xml:base="https://www.unchartedbackwaters.co.uk/blog/posts/microsoft_noip_dos/">&lt;p&gt;A few days ago, Microsoft &lt;a rel=&quot;external&quot; href=&quot;http:&#x2F;&#x2F;arstechnica.com&#x2F;security&#x2F;2014&#x2F;06&#x2F;millions-of-dymanic-dns-users-suffer-after-microsoft-seizes-no-ip-domains&#x2F;&quot;&gt;launched a DOS
attack&lt;&#x2F;a&gt;
against millions of users of the dynamic DNS service &lt;a rel=&quot;external&quot; href=&quot;http:&#x2F;&#x2F;www.noip.com&#x2F;&quot;&gt;NO-IP&lt;&#x2F;a&gt;. Microsoft&#x27;s aim
was to disrupt DNS entries used by the creators of malware, but had
the side effect of rendering the service effectively useless for
anyone using DDNS for resolving servers, home automation systems,
remote webcams etc.&lt;&#x2F;p&gt;
&lt;p&gt;Using a court order, Microsoft were able to replace the nameserver
records for 22 domain names used by NO-IP and pointed them to their own
nameservers.  Microsoft&#x27;s intent was presumably to answer legitimate DNS
queries by forwarding them to the original NO-IP nameservers and block
those from malicious entities, rather than completely crippling the
service.&lt;&#x2F;p&gt;
&lt;p&gt;Microsoft have since &lt;a rel=&quot;external&quot; href=&quot;http:&#x2F;&#x2F;arstechnica.com&#x2F;security&#x2F;2014&#x2F;07&#x2F;microsoft-issues-mea-culpa-to-no-ip-but-service-reportedly-remains-down-for-many&#x2F;&quot;&gt;claimed to have fixed the
problem&lt;&#x2F;a&gt;
yet for many users, myself included I can no longer find machines I use
dynamic DNS to resolve. Many are attributing this to DNS propagation
delay, but the actuality is that Microsoft seem to lack to lack the
technical competence to implement a such a filtering system.&lt;&#x2F;p&gt;
&lt;p&gt;As of writing (02&#x2F;07&#x2F;2014 11:38:25 BST 2014) cached DNS entries for NO-IP
domains are completely broken, so let&#x27;s use dig to directly query the
nameservers (and hence avoid any DNS caching issues):&lt;&#x2F;p&gt;
&lt;pre class=&quot;giallo z-code&quot;&gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;$ dig -tNS +trace no-ip.org&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;; &amp;lt;&amp;lt;&amp;gt;&amp;gt; DiG 9.9.2-P1 &amp;lt;&amp;lt;&amp;gt;&amp;gt; -tNS +trace no-ip.org&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;;; global options: +cmd&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;.                       163525  IN      NS      f.root-servers.net.&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;.                       163525  IN      NS      a.root-servers.net.&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;.                       163525  IN      NS      j.root-servers.net.&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;.                       163525  IN      NS      k.root-servers.net.&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;.                       163525  IN      NS      h.root-servers.net.&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;.                       163525  IN      NS      e.root-servers.net.&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;.                       163525  IN      NS      m.root-servers.net.&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;.                       163525  IN      NS      b.root-servers.net.&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;.                       163525  IN      NS      l.root-servers.net.&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;.                       163525  IN      NS      i.root-servers.net.&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;.                       163525  IN      NS      d.root-servers.net.&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;.                       163525  IN      NS      g.root-servers.net.&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;.                       163525  IN      NS      c.root-servers.net.&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;.                       515689  IN      RRSIG   NS 8 0 518400 20140709000000 20140701230000 8230 . p5nawXXuH07BoGUsETH3J3VEj7W6H6V1EzwfRIRkr5qepcJQoqyGuced WTeOWW4kZV8GfB0NPS4Rp8HBfNTR6CsxNf4da92kTtbJKh9P+xEtreyd z3RDMqKDDBHGEl2Taml6J5Yhy89gsbigAZKPammqKh2aZM9+Tz46OmPt GHg=&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;;; Received 913 bytes from 146.169.1.24#53(146.169.1.24) in 16 ms&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;org.                    172800  IN      NS      a0.org.afilias-nst.info.&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;org.                    172800  IN      NS      a2.org.afilias-nst.info.&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;org.                    172800  IN      NS      b0.org.afilias-nst.org.&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;org.                    172800  IN      NS      b2.org.afilias-nst.org.&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;org.                    172800  IN      NS      c0.org.afilias-nst.info.&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;org.                    172800  IN      NS      d0.org.afilias-nst.org.&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;org.                    86400   IN      DS      21366 7 1 E6C1716CFB6BDC84E84CE1AB5510DAC69173B5B2&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;org.                    86400   IN      DS      21366 7 2 96EEB2FFD9B00CD4694E78278B5EFDAB0A80446567B69F634DA078F0 D90F01BA&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;org.                    86400   IN      RRSIG   DS 8 1 86400 20140709000000 20140701230000 8230 . F7mv0vQZqoDHVnIGnms53kiVT4nEwfxPv7ebMixzb20tI&#x2F;FjH9nUrgvy PvrkzgXYV+HmO0Xzay&#x2F;bsdLLhE2nMpFY7aXhbmzav9C126UGEAaheUDB 4MuTltNzmpu01biTVxyfqr6ZueE7QMWaKia&#x2F;l29KdBab&#x2F;3UgN7M3UL5e wr0=&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;;; Received 683 bytes from 192.203.230.10#53(192.203.230.10) in 8 ms&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;no-ip.org.              86400   IN      NS      ns7.microsoftinternetsafety.net.&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;no-ip.org.              86400   IN      NS      ns8.microsoftinternetsafety.net.&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;h9p7u7tr2u91d0v0ljs9l1gidnp90u3h.org. 86400 IN NSEC3 1 1 1 D399EAAB H9PARR669T6U8O1GSG9E1LMITK4DEM0T NS SOA RRSIG DNSKEY NSEC3PARAM&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;h9p7u7tr2u91d0v0ljs9l1gidnp90u3h.org. 86400 IN RRSIG NSEC3 7 2 86400 20140723104131 20140702094131 21185 org. djVZn31Z2Fbpk8Wnj0QQ2HGfkZj&#x2F;tU9UWhJIEViDbvPaKHfqHRVYnBLc 0n+s04e1uuZJpxmGOjIw6+aTJrxP&#x2F;t4H525GtS5YLT&#x2F;TeMQyK5Tq8dKN fUq0lpUqz0fhz2H8QhfHPpZDBCy1Udh29gPmAbXWb84yhEgra7jFObK5 VGA=&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;vdarb7crtpe7mq8c176tsr178kc0put9.org. 86400 IN NSEC3 1 1 1 D399EAAB VDBA62E7405UOAVCP3IU953TNPO52T45 A RRSIG&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;vdarb7crtpe7mq8c176tsr178kc0put9.org. 86400 IN RRSIG NSEC3 7 2 86400 20140722155512 20140701145512 21185 org. UAsAW27kIw8XUKxtz1nD4tsjF2uSf8ERmgZS02s4fb0ATIXbDY95Az+u 3Ai&#x2F;iGDFjBxHJ1oJpEl8xat4IwHzx1&#x2F;JEgVIheoOd6lklZbXFQRi7RAu E75yYUnnRyVCk1tqGBT3QpgPAM3U6dBkji0UZ&#x2F;eAiL7CrTQk2Vzz3z8s cfY=&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;;; Received 594 bytes from 199.19.54.1#53(199.19.54.1) in 156 ms&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;no-ip.org.              119749  IN      NS      ns8.microsoftinternetsafety.net.&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;no-ip.org.              119749  IN      NS      ns7.microsoftinternetsafety.net.&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;;; Received 117 bytes from 157.56.78.73#53(157.56.78.73) in 142 ms&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;
&lt;p&gt;This shows that both the .org parent nameservers and the nameservers
Microsoft have introduced both agree that the current nameservers for
no-ip.org are located under microsoftinternetsafety.net. Their IPs
(157.56.78.93, 157.56.78.73) both belong to Microsoft. This means that
Microsoft&#x27;s “fix” must involve changes to their nameservers and &lt;em&gt;have not
returned nameserver control to NO-IP&lt;&#x2F;em&gt;.&lt;&#x2F;p&gt;
&lt;p&gt;Let&#x27;s lookup a DDNS host under the Microsoft nameserver, querying it
directly (replaced by asterisks for paranoia):&lt;&#x2F;p&gt;
&lt;pre class=&quot;giallo z-code&quot;&gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;$ dig -tA *****.no-ip.org @ns7.microsoftinternetsafety.net&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;; &amp;lt;&amp;lt;&amp;gt;&amp;gt; DiG 9.9.2-P1 &amp;lt;&amp;lt;&amp;gt;&amp;gt; -tA *****.no-ip.org @ns7.microsoftinternetsafety.net&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;;; global options: +cmd&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;;; Got answer:&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;;; -&amp;gt;&amp;gt;HEADER&amp;lt;&amp;lt;- opcode: QUERY, status: NOERROR, id: 20400&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;;; OPT PSEUDOSECTION:&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;; EDNS: version: 0, flags:; udp: 4000&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;;; QUESTION SECTION:&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;;*****.no-ip.org.               IN      A&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;;; ANSWER SECTION:&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;*****.no-ip.org.        60      IN      A       31.53.88.84&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;;; Query time: 217 msec&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;;; SERVER: 157.56.78.73#53(157.56.78.73)&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;;; WHEN: Wed Jul  2 11:49:05 2014&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;;; MSG SIZE  rcvd: 60&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;
&lt;p&gt;It works, that&#x27;s weird. This indicates that the Microsoft nameserver is
successfully forwarding requests to the underlying no-ip.org
nameservers. Now let&#x27;s make the same request to &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;developers.google.com&#x2F;speed&#x2F;public-dns&#x2F;&quot;&gt;Google&#x27;s public DNS
server&lt;&#x2F;a&gt;:&lt;&#x2F;p&gt;
&lt;pre class=&quot;giallo z-code&quot;&gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;$ dig -tA *****.no-ip.org @8.8.8.8&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;; &amp;lt;&amp;lt;&amp;gt;&amp;gt; DiG 9.9.2-P1 &amp;lt;&amp;lt;&amp;gt;&amp;gt; -tA *****.no-ip.org @8.8.8.8&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;;; global options: +cmd&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;;; Got answer:&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;;; -&amp;gt;&amp;gt;HEADER&amp;lt;&amp;lt;- opcode: QUERY, status: SERVFAIL, id: 60346&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 1&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;;; OPT PSEUDOSECTION:&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;; EDNS: version: 0, flags:; udp: 512&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;;; QUESTION SECTION:&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;;*****.no-ip.org.               IN      A&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;;; Query time: 297 msec&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;;; SERVER: 8.8.8.8#53(8.8.8.8)&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;;; WHEN: Wed Jul  2 11:52:09 2014&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;;; MSG SIZE  rcvd: 44&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;
&lt;p&gt;This fails with an error suggesting that the nameserver Google contacted
failed to answer. Checking the no-ip.org nameserver entries show that
the data is up-to-date, which means that Microsoft&#x27;s nameservers are
not replying to Google correctly.&lt;&#x2F;p&gt;
&lt;p&gt;My first thought was that this was some weird geographical issue, or
maybe Microsoft had mistakenly identified Google&#x27;s DNS requests as
malicious traffic. Instead the answer is much more simple, and
indicative of why Microsoft is simply incompetent.&lt;&#x2F;p&gt;
&lt;p&gt;There are two types of DNS server: recursive and non-recursive.
Recursive DNS servers are typically contacted by end-users&#x2F;clients, and
perform the sometimes complicated set of lookups required to resolve a
domain name. They almost always perform caching, in order to reduce load
on non-recursive nameservers.  Non-recursive name-servers serve only
local data, and don&#x27;t perform DNS lookups themselves. Organisations
wishing to make DNS entries visible set up non-recursive DNS servers
so that they can be contacted by recursive ones.&lt;&#x2F;p&gt;
&lt;p&gt;Within each DNS request, there is a &lt;a rel=&quot;external&quot; href=&quot;http:&#x2F;&#x2F;www.ietf.org&#x2F;rfc&#x2F;rfc1035.txt&quot;&gt;“recursion desired”
flag&lt;&#x2F;a&gt; (RD). This
tells the DNS server whether or not it should recursively perform the
query. A recursive DNS server will perform requests with this bit
&lt;em&gt;unset&lt;&#x2F;em&gt; since it&#x27;s performing the recursion itself and the target DNS
server ideally shouldn&#x27;t support it.&lt;&#x2F;p&gt;
&lt;p&gt;Unfortunately Microsoft&#x27;s DNS servers fail to deliver a useful reply if
this bit is unset. Consequently, &lt;a rel=&quot;external&quot; href=&quot;http:&#x2F;&#x2F;cr.yp.to&#x2F;djbdns.html&quot;&gt;djbdns&lt;&#x2F;a&gt;,
&lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;developers.google.com&#x2F;speed&#x2F;public-dns&#x2F;&quot;&gt;Google&#x27;s nameservers&lt;&#x2F;a&gt;
and many other recursive DNS servers will never get a useful response
from the nameservers Microsoft have inserted.&lt;&#x2F;p&gt;
&lt;p&gt;Let&#x27;s perform the same lookup directly to Microsoft&#x27;s nameservers again,
but this time disable recursion.&lt;&#x2F;p&gt;
&lt;pre class=&quot;giallo z-code&quot;&gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;$ dig -tA +norecurse *****.no-ip.org @ns7.microsoftinternetsafety.net&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;; &amp;lt;&amp;lt;&amp;gt;&amp;gt; DiG 9.9.2-P1 &amp;lt;&amp;lt;&amp;gt;&amp;gt; -tA +norecurse *****.no-ip.org @ns7.microsoftinternetsafety.net&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;;; global options: +cmd&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;;; Got answer:&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;;; -&amp;gt;&amp;gt;HEADER&amp;lt;&amp;lt;- opcode: QUERY, status: NOERROR, id: 9751&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;;; flags: qr ra ad; QUERY: 1, ANSWER: 0, AUTHORITY: 6, ADDITIONAL: 7&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;;; OPT PSEUDOSECTION:&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;; EDNS: version: 0, flags:; udp: 4000&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;;; QUESTION SECTION:&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;;*****.no-ip.org.               IN      A&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;;; AUTHORITY SECTION:&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;org.                    117492  IN      NS      c0.org.afilias-nst.info.&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;org.                    117492  IN      NS      a0.org.afilias-nst.info.&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;org.                    117492  IN      NS      a2.org.afilias-nst.info.&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;org.                    117492  IN      NS      b0.org.afilias-nst.org.&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;org.                    117492  IN      NS      b2.org.afilias-nst.org.&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;org.                    117492  IN      NS      d0.org.afilias-nst.org.&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;;; ADDITIONAL SECTION:&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;c0.org.afilias-nst.info. 117492 IN      A       199.19.53.1&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;a0.org.afilias-nst.info. 117492 IN      A       199.19.56.1&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;a2.org.afilias-nst.info. 117492 IN      A       199.249.112.1&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;b0.org.afilias-nst.org. 117492  IN      A       199.19.54.1&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;b2.org.afilias-nst.org. 117492  IN      A       199.249.120.1&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;d0.org.afilias-nst.org. 117492  IN      A       199.19.57.1&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;;; Query time: 149 msec&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;;; SERVER: 157.56.78.73#53(157.56.78.73)&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;;; WHEN: Wed Jul  2 12:15:05 2014&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;;; MSG SIZE  rcvd: 278&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;
&lt;p&gt;We do get a response, but it contains no useful information. This
demonstrates that Microsoft really has no idea what they&#x27;re doing.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>ICFP Competition 2013 Writeup</title>
        <published>2013-08-17T15:17:26+00:00</published>
        <updated>2013-08-17T15:17:26+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://www.unchartedbackwaters.co.uk/blog/posts/icfpc2013/"/><id>tag:unchartedbackwaters.co.uk,2013-08:icfpc2013</id>
        
        <content type="html" xml:base="https://www.unchartedbackwaters.co.uk/blog/posts/icfpc2013/">&lt;h2 id=&quot;introduction&quot;&gt;Introduction&lt;&#x2F;h2&gt;
&lt;p&gt;Having entered the International Conference on Functional Programming
Competition for the last six years under the team name “Hacking in the
Rain”, I thought it was about time I wrote about what I did.&lt;&#x2F;p&gt;
&lt;p&gt;&lt;a rel=&quot;external&quot; href=&quot;http:&#x2F;&#x2F;icfpc2013.cloudapp.net&#x2F;&quot;&gt;This year&#x27;s competition&lt;&#x2F;a&gt; could
effectively be summarised by the phrase “find the function” where the
function mapped 64-bit integer values to other 64-bit integer values. In
addition to the usual bitwise operators OR, AND, NOT, XOR, there was
also addition, fixed offset shifts, conditionals and folds over all the
bytes in a value with an arbitrary binary function.&lt;&#x2F;p&gt;
&lt;p&gt;As always, I chose to implement in C++, not because I dislike functional
languages, but because I&#x27;m somewhat more proficient in C++ than in
Haskell, and I prefer the control I get when needing to solve
efficiency-critical problems with limited computing resources.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;overall-strategy&quot;&gt;Overall Strategy&lt;&#x2F;h2&gt;
&lt;p&gt;The most obvious approach here would have been to try to enumerate all
programs of increasing size until finding one that matched all the given
input-output pairs, combined with some sort of pruning. I chose not to
do this because I was afraid that constructing and evaluating every
problem via this technique would be too slow, and never scale to the
larger problem sizes. I didn&#x27;t attempt to handle the “if0” or “fold”
operators in my initial solver.&lt;&#x2F;p&gt;
&lt;p&gt;My algorithm proceeded in two phases. In the first I computed metadata
about constructable expressions and their sizes:&lt;&#x2F;p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Choose an input-output pair provided by the server.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Build a set containing only the values of expressions of size one.
Namely, 1, 0 and the input value.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;For increasing size, build sets containing all possible values of
expressions of that size (excluding “if0” and “fold”). This only
involves applying operators to elements of previously constructed
sets and doesn&#x27;t require any expression tree construction or
evaluation.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Terminate when one of the constructed sets contains the output value
we&#x27;re looking for.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ol&gt;
&lt;p&gt;As this point, I know the size of an expression tree that computes the
correct output for the input value I chose. However, I do not know what
the expression actually is.&lt;&#x2F;p&gt;
&lt;p&gt;The second phase builds the expression (or multiple expressions) that
compute the output value from the input in a top-down manner. Given the
desired output value and the size of the expression tree that computes
it, I now find the tree itself:&lt;&#x2F;p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;For every possible operator, determine if the value we want can be
computed using the values we know we can compute from expressions
with smaller sizes. We iterate over the sets we built in the
previous phase to determine this. If yes, we know that this operator
can form the topmost node in our tree.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;We now need to find expression trees of for any operands used by
the parent operator. We repeat step one for all subexpressions
required by the parent. Again, we already know their size and value.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;We terminate once we reach expressions of size 1.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ol&gt;
&lt;p&gt;Since there could be multiple expressions of the same size that evaluate
to the same value (and I wanted to keep all of them) it was necessary to
apply constructors across sets of values. I really missed being able to
work in Haskell&#x27;s list monad here which naturally handles Cartesian
product-like constructions needed for the binary operator case.&lt;&#x2F;p&gt;
&lt;p&gt;Armed with sets of expressions, it was a simple matter to evaluate them
on all other input-output pairs I had requested from the server to
validate. If no expressions turned out to be correct, I used the
remaining input-output pairs to generate more expressions.&lt;&#x2F;p&gt;
&lt;p&gt;This approach has the advantage that it only builds expression trees
which are known to produce a correct answer for at least one
input-output pair. In the event that no expressions were found that
matched all input-output pairs, I added the option to deliberately
construct oversized expressions. This was primarily used later for
inferring conditionals for ifs.&lt;&#x2F;p&gt;
&lt;p&gt;For many cases, this strategy allowed me to find correct expressions in
less than a second, especially with operator restrictions.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;handling-if0&quot;&gt;Handling “if0”&lt;&#x2F;h2&gt;
&lt;p&gt;Although “if0” could appear at arbitrary points in the expression tree,
I only looked at generating expressions with “if0” at the top. As ifs
(excluding those within folds) can always be lifted, this seemed
practical.&lt;&#x2F;p&gt;
&lt;p&gt;Though I could often find plausible expressions for sets of input-output
pairs, none of these involved “if0” since trees were constructed for
single input-output pair for which conditionals would always be
constant.&lt;&#x2F;p&gt;
&lt;p&gt;To solve this, I saved all programs that correctly evaluated a subset of
the input-output pairs. Once I had at least one valid program for every
input-output pair, I approximated a &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Set_cover_problem&quot;&gt;minimal
covering&lt;&#x2F;a&gt;  using a
greedy algorithm to map each input-output pair to a correct
program. I then used my existing code to infer the conditionals required
to choose the correct program for each input-output pair. Depending on
the number of programs used by the covering, this could involve a tree
of nested “if0”s.&lt;&#x2F;p&gt;
&lt;p&gt;This approach did work, however, it has a couple of subtle issues that
were difficult to debug:&lt;&#x2F;p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Any input-output pairs that were correctly computed by more than one
program used by the covering needed to be removed. Without doing
this, it was possible for ambiguous pairs to be assigned the wrong
program, and the if-condition would become impossible to derive.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;The order of if-construction was important. As an example, assuming
we were attempting to find this program:&lt;&#x2F;p&gt;
&lt;pre class=&quot;giallo z-code&quot;&gt;&lt;code data-lang=&quot;scheme&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;(&lt;&#x2F;span&gt;&lt;span class=&quot;z-keyword z-control&quot;&gt;lambda&lt;&#x2F;span&gt;&lt;span&gt; (&lt;&#x2F;span&gt;&lt;span class=&quot;z-variable&quot;&gt;id0&lt;&#x2F;span&gt;&lt;span&gt;) (if0 id0 &lt;&#x2F;span&gt;&lt;span class=&quot;z-constant z-numeric&quot;&gt;1&lt;&#x2F;span&gt;&lt;span&gt; id0))&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;
&lt;p&gt;The following program (using _ as a placeholder) covers both
sub-expressions, but it is extremely difficult to generate the condition
without using another if:&lt;&#x2F;p&gt;
&lt;pre class=&quot;giallo z-code&quot;&gt;&lt;code data-lang=&quot;scheme&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;(&lt;&#x2F;span&gt;&lt;span class=&quot;z-keyword z-control&quot;&gt;lambda&lt;&#x2F;span&gt;&lt;span&gt; (&lt;&#x2F;span&gt;&lt;span class=&quot;z-variable&quot;&gt;id0&lt;&#x2F;span&gt;&lt;span&gt;) (if0 _ id0 &lt;&#x2F;span&gt;&lt;span class=&quot;z-constant z-numeric&quot;&gt;1&lt;&#x2F;span&gt;&lt;span&gt;))&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;
&lt;p&gt;This is a consequence of only having a bitwise NOT, and not a
boolean NOT operator. To handle this I attempt to construct if
conditions in all possible orders.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ol&gt;
&lt;h2 id=&quot;results&quot;&gt;Results&lt;&#x2F;h2&gt;
&lt;p&gt;My final score was 701, which puts me at precisely 100th place. The
&lt;a rel=&quot;external&quot; href=&quot;http:&#x2F;&#x2F;labs.skbkontur.ru&#x2F;icfpc2013&#x2F;Stats&quot;&gt;unoffical scoreboard&lt;&#x2F;a&gt;  gives
a nice graphical representation of the &lt;a rel=&quot;external&quot; href=&quot;http:&#x2F;&#x2F;labs.skbkontur.ru&#x2F;icfpc2013&#x2F;Index&#x2F;____-851219916&quot;&gt;problems I managed to
solve&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;final-thoughts&quot;&gt;Final Thoughts&lt;&#x2F;h2&gt;
&lt;p&gt;Although I never got around to handling folds, the strategy I
implemented worked quite well for a number of problems. Far more than in
other years, the lack of algebraic data types in C++ was painful to work
around. I attribute this to both the number of possible node types in
the tree, and the number of operations that needed to be applied to
them. Of course, this is a good thing for a contest intended to
advocate functional programming.&lt;&#x2F;p&gt;
&lt;p&gt;I have mixed feelings over the decision to have the solver run on the
client side, rather than by the competition organisers after the
competition. I spent a lot of time trying to improve my solver before
letting it loose, and only did when there were around 8 hours left
before the competition ended. I suspect the scoreboard might look
somewhat different if myself and others had had the time to apply their
program to all the given problems.&lt;&#x2F;p&gt;
&lt;p&gt;&lt;strong&gt;Updated 18&#x2F;08&#x2F;2013:&lt;&#x2F;strong&gt; Revised main algorithm description after &lt;a rel=&quot;external&quot; href=&quot;http:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;icfpcontest&#x2F;comments&#x2F;1kjtrz&#x2F;hacking_in_the_rain_writeup_2013&#x2F;&quot;&gt;feedback on
reddit&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Another reason to ditch MythTV</title>
        <published>2013-01-13T21:05:45+00:00</published>
        <updated>2013-01-13T21:05:45+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://www.unchartedbackwaters.co.uk/blog/posts/another_reason_to_ditch_mythtv/"/><id>tag:unchartedbackwaters.co.uk,2013-01:another_reason_to_ditch_mythtv</id>
        
        <content type="html" xml:base="https://www.unchartedbackwaters.co.uk/blog/posts/another_reason_to_ditch_mythtv/">&lt;p&gt;MythTV is very pretty and featureful, but has always struck me as a
project that cares more about making it further so than trying to create
a robust, bug-free core. Today I came across the sort of bug that
exemplifies this.&lt;&#x2F;p&gt;
&lt;p&gt;I decided to record the film &lt;a rel=&quot;external&quot; href=&quot;http:&#x2F;&#x2F;www.imdb.com&#x2F;title&#x2F;tt1401152&#x2F;&quot;&gt;“Unknown”&lt;&#x2F;a&gt;,
starring Liam Neeson as a man who wakes from a coma to discover his life has
been stolen. Here we have the film in the programme listing view:&lt;&#x2F;p&gt;
&lt;p&gt;&lt;a href=&quot;&#x2F;files&#x2F;mythtv-unknown&#x2F;film.png&quot;&gt;&lt;img src=&quot;&#x2F;files&#x2F;mythtv-unknown&#x2F;film-small.png&quot; alt=&quot;MythTV programme listing&quot; &#x2F;&gt;&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;p&gt;Coincidentally, the MythTV front-end also lists time periods where it does not
have any listings data as “Unknown”. The MythTV frontend rightly prevents the
user from attempting to record these blocks.&lt;&#x2F;p&gt;
&lt;p&gt;&lt;a href=&quot;&#x2F;files&#x2F;mythtv-unknown&#x2F;nodata.png&quot;&gt;&lt;img src=&quot;&#x2F;files&#x2F;mythtv-unknown&#x2F;nodata-small.png&quot; alt=&quot;MythTV no data&quot; &#x2F;&gt;&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;p&gt;Why is this an issue? It turns out that the MythTV front-end prevents you from
recording &lt;em&gt;any&lt;&#x2F;em&gt; entry entitled “Unknown”, making it impossible to schedule
recording of the aforementioned film.  Clicking on the entry does nothing.
Bringing up the menu does give you the option to record, but fails to schedule
it.&lt;&#x2F;p&gt;
&lt;p&gt;&lt;a href=&quot;&#x2F;files&#x2F;mythtv-unknown&#x2F;record_attempt.png&quot;&gt;&lt;img src=&quot;&#x2F;files&#x2F;mythtv-unknown&#x2F;record_attempt-small.png&quot; alt=&quot;MythTV record attempt&quot; &#x2F;&gt;&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;p&gt;The only way I found to schedule the recording was to do it from the
HTML interface. Bad news for non-computer savvy Liam Neeson fans.&lt;&#x2F;p&gt;
&lt;p&gt;Just for the record, the front-end version was a 13&#x2F;01&#x2F;2013 build of the 0.26-fixes branch.&lt;&#x2F;p&gt;
&lt;p&gt;&lt;strong&gt;Updated 14&#x2F;01&#x2F;2013:&lt;&#x2F;strong&gt; Someone else &lt;a rel=&quot;external&quot; href=&quot;http:&#x2F;&#x2F;code.mythtv.org&#x2F;trac&#x2F;ticket&#x2F;11346&quot;&gt;apparently noticed around the same
time&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>The Amazon Kindle: wonderful device, shame about the books</title>
        <published>2011-07-02T20:08:49+00:00</published>
        <updated>2011-07-02T20:08:49+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://www.unchartedbackwaters.co.uk/blog/posts/kindle_first_impressions/"/><id>tag:unchartedbackwaters.co.uk,2011-07:kindle_first_impressions</id>
        
        <content type="html" xml:base="https://www.unchartedbackwaters.co.uk/blog/posts/kindle_first_impressions/">&lt;p&gt;The only time I tend to have to read is when I&#x27;m travelling to and from
work.  Unfortunately, it&#x27;s rather inconvenient for me to have to remove
and replace the book from and to my rucksack. This sometimes also leads
to me damaging the book in question. Hence, my decision to purchase an
Amazon Kindle.&lt;&#x2F;p&gt;
&lt;p&gt;The Kindle is certainly a nice device. It&#x27;s reasonably light, and despite
having a resolution of only 600x800, the properties of electronic ink and a
pixel density of 167 ppi result in an impressive display. The user-interface
can be a little clunky, but this is only an issue when you&#x27;re doing something
with the Kindle other than flipping the pages of a book.&lt;&#x2F;p&gt;
&lt;p&gt;For my first read, I decided I wanted a complete collection of all
Sherlock Holmes novels and short stories written by Sir Arthur Conan
Doyle. Surely, not an unreasonable request since &quot;The Adventures of
Sherlock Holmes&quot; (the first of four collections of stories) is
prominently featured by Amazon as one of the free classics available for
the Kindle.&lt;&#x2F;p&gt;
&lt;p&gt;My first choice was to download them from &lt;a rel=&quot;external&quot; href=&quot;http:&#x2F;&#x2F;www.gutenberg.org&quot;&gt;Project
Gutenberg&lt;&#x2F;a&gt; and avoid any DRM-related issues.  Alas,
none of these had any images (many stories were originally illustrated by
&lt;a rel=&quot;external&quot; href=&quot;http:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Sidney_Paget&quot;&gt;Sidney Paget&lt;&#x2F;a&gt; when first published
in &lt;em&gt;The Strand&lt;&#x2F;em&gt; magazine). Hence, I decided to purchase them from Amazon. I
expected that it would be trivial to find a complete collection including
original illustrations, ideally typeset for the Kindle, and not subject to
typographical errors. I couldn&#x27;t have been more wrong.&lt;&#x2F;p&gt;
&lt;p&gt;Finding such a book in paper form isn&#x27;t an issue. However, searching for an
equivalent ebook led me to reviews complaining about missing images, missing
contents pages, missing lines, poorly typeset conversations, poorly scanned
images and adverts for other books embedded within the text&lt;sup class=&quot;footnote-reference&quot;&gt;&lt;a href=&quot;#1&quot;&gt;1&lt;&#x2F;a&gt;&lt;&#x2F;sup&gt;. Note that most
of these editions were non-free and it would be necessary to buy the ebook
before spotting the issues, and again to get a revised version (if one was
produced in the future).&lt;&#x2F;p&gt;
&lt;p&gt;The first problem is that searching Amazon for Sherlock Holmes ebooks reveals
many, many, results and it&#x27;s extremely difficult to distinguish between them.
Amazon&#x27;s site aggregates the reviews of all editions of a book together,
regardless of publisher. As a result, it&#x27;s rather difficult to find reviews for
a specific Kindle edition of a book.  Multiple Amazon customers seemed
&lt;a rel=&quot;external&quot; href=&quot;http:&#x2F;&#x2F;www.amazon.co.uk&#x2F;product-reviews&#x2F;B003A03RRU&#x2F;&quot;&gt;confused&lt;&#x2F;a&gt; by which ebook
edition was being described by which review. Unfortunately, if the quality of
ebooks varies massively across editions, finding reviews for a specific edition
becomes altogether more important.&lt;&#x2F;p&gt;
&lt;p&gt;The next problem is the lack of trustworthy publishers. I had hoped that I
might be able to make a guess about the quality of the ebook based on its
publisher.  Publishers of physical books tend to have well defined reputations
but typing many of the ebook publishers into a search engine revealed no other
sign of their existence. Other books were simply listed as public domain or had
no publisher at all. &lt;a rel=&quot;external&quot; href=&quot;http:&#x2F;&#x2F;ignaciohillspress.com&quot;&gt;One publisher&#x27;s&lt;&#x2F;a&gt; website
had vanished entirely.  Of almost all the publishers I could find, there was no
indication that they&#x27;d existed for more than a year or two.&lt;&#x2F;p&gt;
&lt;p&gt;This is perhaps, hardly surprising. In the UK, all the Sherlock Holmes novels
and short stories have passed into the public domain. It doesn&#x27;t take much work
to imagine a business model to become an ebook publisher selling only classics.&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Download out of copyright works from Project Gutenberg or other public domain
resources.&lt;&#x2F;li&gt;
&lt;li&gt;Edit away undesired text and modify typography.&lt;&#x2F;li&gt;
&lt;li&gt;Create persuasive description and cover page, then sell on Amazon.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;The best part is that creating an ebook has no physical printing cost.  Of
course, I have no way to know whether this is happening. What I do know is that
the reviews suggest some extremely shoddy publishers. Given the difficulty of
checking for issues before purchase and no way to return or get refunded for an
ebook, it&#x27;s probably rather easy to make a pretty penny.&lt;&#x2F;p&gt;
&lt;p&gt;However, there is spark of hope. An &lt;a rel=&quot;external&quot; href=&quot;http:&#x2F;&#x2F;www.amazon.com&#x2F;Sherlock-Holmes-Illustrated-ebook&#x2F;dp&#x2F;B0052TAV12&quot;&gt;illustrated
edition&lt;&#x2F;a&gt;
by &lt;a rel=&quot;external&quot; href=&quot;http:&#x2F;&#x2F;www.theseashellpress.com&quot;&gt;Seashell Press&lt;&#x2F;a&gt; seems to have had
an unparalleled amount of effort placed into its creation and received
excellent reviews. It&#x27;s probably also worth noting that this is the only
publisher I&#x27;ve seen that also appears to produce physical books.&lt;&#x2F;p&gt;
&lt;p&gt;Alas, it looks like this collection was originally complete, but then was
revised to not contain &quot;The Case-book of Sherlock Holmes&quot; as it was still under
copyright in the US. This change was also applied to the version available in
the UK as well.  I&#x27;ve since emailed the publishers to see if it is possible to
get the original version distributed in the UK, where copyright of that
particular collection is not an issue.&lt;&#x2F;p&gt;
&lt;p&gt;Amazon&#x27;s use of DRM, &lt;a rel=&quot;external&quot; href=&quot;http:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Amazon_Kindle#Remote_content_removal&quot;&gt;remote content
removal&lt;&#x2F;a&gt; and
the choice not to support &lt;a rel=&quot;external&quot; href=&quot;http:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;EPUB&quot;&gt;EPUB&lt;&#x2F;a&gt; indicate
how much they wish to retain control of Kindle ebook distribution.  As such,
the quality of ebooks available from the Kindle store directly affects the
utility of the Kindle, and it&#x27;s sad to see issues like these that I never
anticipated.&lt;&#x2F;p&gt;
&lt;p&gt;These are simply first impressions, and I have no idea if the issues I&#x27;ve
described affect other books. If they do, they probably only exist for for
older, out of copyright works. However, one of Amazon&#x27;s main selling points for
the Kindle seems to be that it provides an acceptable experience for reading
classic literature. Just look at the Kindle&#x27;s display every time it&#x27;s switched
off.&lt;&#x2F;p&gt;
&lt;div class=&quot;footnote-definition&quot; id=&quot;1&quot;&gt;&lt;sup class=&quot;footnote-definition-label&quot;&gt;1&lt;&#x2F;sup&gt;
&lt;p&gt;For example, &lt;a rel=&quot;external&quot; href=&quot;http:&#x2F;&#x2F;www.amazon.co.uk&#x2F;gp&#x2F;product&#x2F;B000JQU1VS&#x2F;&quot;&gt;this free
edition&lt;&#x2F;a&gt; of &lt;em&gt;The Adventures of
Sherlock Holmes&lt;&#x2F;em&gt;, currently at #3 in the  Free Kindle store, contains
character encoding errors. One such error is in the story &quot;Adventure II. The
Red-Headed League&quot; which contains the text &quot;there is now another vacancy open which
entitles a member of the League to a salary of ï¿½4 a week for purely
nominal services&quot;. The three strange characters should instead be a pound sign.&lt;&#x2F;p&gt;
&lt;p&gt;In &lt;a rel=&quot;external&quot; href=&quot;http:&#x2F;&#x2F;www.amazon.co.uk&#x2F;gp&#x2F;product&#x2F;B00495XR8E&#x2F;&quot;&gt;this non-free edition&lt;&#x2F;a&gt;
of &quot;The Complete Sherlock Holmes Collection&quot;, I found that the links in the
table of contents for the stories &quot;The Adventure of a Case of Identity&quot; and
&quot;The Adventure of the Read-Headed League&quot; pointed to each other&#x27;s stories
instead of their own. It seems free of more major issues though.&lt;&#x2F;p&gt;
&lt;&#x2F;div&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Random Slowness with Western Digital Caviar Green Hard Drives</title>
        <published>2010-10-14T02:28:55+00:00</published>
        <updated>2010-10-14T02:28:55+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://www.unchartedbackwaters.co.uk/blog/posts/western_digital_caviar_green_random_slowness/"/><id>tag:unchartedbackwaters.co.uk,2010-10:western_digital_caviar_green_random_slowness</id>
        
        <content type="html" xml:base="https://www.unchartedbackwaters.co.uk/blog/posts/western_digital_caviar_green_random_slowness/">&lt;p&gt;Several months ago, my &lt;a rel=&quot;external&quot; href=&quot;http:&#x2F;&#x2F;www.mythtv.org&#x2F;&quot;&gt;MythTV&lt;&#x2F;a&gt; server started acting
strangely. At seemingly random intervals, the system would experience high IO,
completely crippling the responsiveness of the system to the extent that it
would take minutes to even establish an SSH connection to the machine. There
appeared to be no way to trigger the problem and running my own high-IO tasks
showed no issues. The high-IO periods lasted for at least several minutes but
sometimes occurred days apart, and as they wrecked the machine&#x27;s responsiveness,
it was also practically impossible to monitor the system when the symptoms did
appear.&lt;&#x2F;p&gt;
&lt;p&gt;Over the months, I tried changing the root file-system, searching for known IO
issues with the Linux kernel, XFS or MythTV, checking fragmentation,
swap-utilisation, IO-priority settings and running a multitude of different
kernels including low-latency versions, all to no avail. The times I managed to
SSH into the machine during a high-IO attack, running top and latencytop were
equally unrevealing. It was only recently that I finally discovered the
culprit: the Western Digital Caviar Green 1.5TB hard drive.&lt;&#x2F;p&gt;
&lt;p&gt;It appears that the drive randomly enters periods where IO radically slows for
periods of minutes, then recovers and behaves normally until the next one. There
are no other signs that anything else is wrong with the drive such as strange
noises, bad sectors or SMART warnings. The drive model in question is a &#x27;WDC
WD15EADS-00P8B0&#x27; and is only just over a year old which means the symptoms must
have started manifesting not long after purchase.&lt;&#x2F;p&gt;
&lt;p&gt;As the problem isn&#x27;t reproducible on demand, I can&#x27;t give solid IO performance
figures. What I can state is that when the problem has manifested at boot time,
I&#x27;ve given up waiting after tens of minutes for a system that usually boots in
less that one. I can&#x27;t imagine that extensive amounts of data are read during
boot, which makes me wonder if the problem might be due to seeking rather than
actual read speeds. Either way, the result is an unusable system.&lt;&#x2F;p&gt;
&lt;p&gt;I&#x27;ve found postings on these issues
&lt;a rel=&quot;external&quot; href=&quot;http:&#x2F;&#x2F;www.paraesthesia.com&#x2F;archive&#x2F;2010&#x2F;06&#x2F;16&#x2F;beware-the-wd-green-drives.aspx&quot;&gt;here&lt;&#x2F;a&gt;,
&lt;a rel=&quot;external&quot; href=&quot;http:&#x2F;&#x2F;forum.synology.com&#x2F;enu&#x2F;viewforum.php?f=151&amp;amp;start=0&quot;&gt;here&lt;&#x2F;a&gt; and
&lt;a rel=&quot;external&quot; href=&quot;http:&#x2F;&#x2F;community.wdc.com&#x2F;t5&#x2F;Desktop&#x2F;WD15EADS-00P8B0-Really-slow-Or-am-I-just-crazy&#x2F;td-p&#x2F;1547&quot;&gt;here&lt;&#x2F;a&gt;
which indicate the issues affect only specific models. As far as I can tell,
Western Digital don&#x27;t seem to have acknowledged any issues with this drive, nor
provided any sort of firmware update that might fix it. As the symptoms don&#x27;t
match conventional signs of drive-failure (it&#x27;s unclear if the problem is even
physical), I can only imagine how many others are experiencing these issues
without realising the cause.&lt;&#x2F;p&gt;
&lt;p&gt;I&#x27;m not going to condemn Western Digital drives outright. The 2.5&quot; &#x27;WDC
WD3200BEVT-35ZCT1&#x27; SATA drive in my laptop has been absolutely fine and is also
the first laptop hard-drive I&#x27;ve owned that is so quiet that I actually need to
look at the activity LED to judge IO load. However, I find it disappointing
that Western Digital seems to have done so little to acknowledge what is
clearly an issue affecting a number of people.&lt;&#x2F;p&gt;
&lt;p&gt;Now let&#x27;s see if I can get Western Digital to give me a RMA code.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Debian OpenSSL Vulnerability Still Pains Two Years On</title>
        <published>2010-08-17T17:58:18+00:00</published>
        <updated>2010-08-17T17:58:18+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://www.unchartedbackwaters.co.uk/blog/posts/debian_openssl_vulnerability_still_pains/"/><id>tag:unchartedbackwaters.co.uk,2010-08:debian_openssl_vulnerability_still_pains</id>
        
        <content type="html" xml:base="https://www.unchartedbackwaters.co.uk/blog/posts/debian_openssl_vulnerability_still_pains/">&lt;p&gt;In April 2006, someone &lt;a rel=&quot;external&quot; href=&quot;http:&#x2F;&#x2F;bugs.debian.org&#x2F;cgi-bin&#x2F;bugreport.cgi?bug=363516&quot;&gt;filed a bug
report&lt;&#x2F;a&gt; with Debian
complaining that &lt;a rel=&quot;external&quot; href=&quot;http:&#x2F;&#x2F;www.openssl.org&quot;&gt;OpenSSL&lt;&#x2F;a&gt; (an open source SSL&#x2F;TLS
implementation) read data from an uninitialised buffer.  This was causing
&lt;a rel=&quot;external&quot; href=&quot;http:&#x2F;&#x2F;valgrind.org&#x2F;&quot;&gt;Valgrind&lt;&#x2F;a&gt; (a brilliant debugging tool) to report memory
usage warnings anywhere the OpenSSL random number generator was used. This was
actually the behaviour intended by the OpenSSL developers, as the uninitialised
buffer was being fed into an entropy pool used by the random number generator.&lt;&#x2F;p&gt;
&lt;p&gt;A fix was proposed that reset the uninitialised buffer to zero before first
use.  This would have had minimal security implications as OpenSSL used
multiple reliable entropy sources in addition to the buffer. However, the
initial patch to do this didn&#x27;t stop all the Valgrind warnings. Somehow the
proposed fix &lt;a rel=&quot;external&quot; href=&quot;http:&#x2F;&#x2F;svn.debian.org&#x2F;viewsvn&#x2F;pkg-openssl&#x2F;openssl&#x2F;trunk&#x2F;rand&#x2F;md_rand.c?rev=141&amp;amp;view=diff&amp;amp;r1=141&amp;amp;r2=140&amp;amp;p1=openssl&#x2F;trunk&#x2F;rand&#x2F;md_rand.c&amp;amp;p2=&#x2F;openssl&#x2F;trunk&#x2F;rand&#x2F;md_rand.c&quot;&gt;mutated into
one&lt;&#x2F;a&gt;
that caused almost no entropy to be added to the pool except for the process
ID, rendering the random number generator almost entirely useless. This in turn
led OpenSSL to create extremely vulnerable SSL certificates, SSH keys and a
bunch of other things. The broken OpenSSL version made it into Debian in
September 2006. It later propagated into Ubuntu.&lt;&#x2F;p&gt;
&lt;p&gt;Incredibly, no one &lt;a rel=&quot;external&quot; href=&quot;http:&#x2F;&#x2F;www.debian.org&#x2F;security&#x2F;2008&#x2F;dsa-1571&quot;&gt;noticed the
vulnerability&lt;&#x2F;a&gt; until 2008. By
then, a massive &lt;a rel=&quot;external&quot; href=&quot;http:&#x2F;&#x2F;wiki.debian.org&#x2F;SSLkeys#ApplicationDetails&quot;&gt;number of
packages&lt;&#x2F;a&gt; and users had been
affected. Cue scrambling to fix the bug in Debian and Ubuntu, &lt;a rel=&quot;external&quot; href=&quot;http:&#x2F;&#x2F;digitaloffense.net&#x2F;tools&#x2F;debian-openssl&#x2F;&quot;&gt;creation of
blacklists and scanners&lt;&#x2F;a&gt; for
vulnerable OpenSSL and OpenSSH keys, arguments about who
&lt;a rel=&quot;external&quot; href=&quot;http:&#x2F;&#x2F;lwn.net&#x2F;Articles&#x2F;282230&#x2F;&quot;&gt;was&lt;&#x2F;a&gt; &lt;a rel=&quot;external&quot; href=&quot;http:&#x2F;&#x2F;lwn.net&#x2F;Articles&#x2F;282038&#x2F;&quot;&gt;to&lt;&#x2F;a&gt;
&lt;a rel=&quot;external&quot; href=&quot;http:&#x2F;&#x2F;www.links.org&#x2F;?p=327&quot;&gt;blame&lt;&#x2F;a&gt; and how open source practices could have
failed so badly. &lt;a rel=&quot;external&quot; href=&quot;http:&#x2F;&#x2F;xkcd.com&#x2F;424&#x2F;&quot;&gt;Also&lt;&#x2F;a&gt;,
&lt;a rel=&quot;external&quot; href=&quot;http:&#x2F;&#x2F;blog.dieweltistgarnichtso.net&#x2F;Caprica,-2-years-ago&quot;&gt;cartoons&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;p&gt;Yes, I did feel the need to reiterate the entire bug&#x27;s history. Reading the bug
report is like watching a slow-motion car crash. Even the &quot;fix&quot; for the initial
bug was applied incorrectly, which meant it appeared in Debian version 0.9.9c-1
of OpenSSL (released 17 September) instead of 0.9.8b-1 (released 4 May). I
suppose that was a good thing.&lt;&#x2F;p&gt;
&lt;p&gt;Even now, over two years after the bug was discovered and almost four years
after it was originally introduced, the damage it caused is still being
discovered. The &lt;a rel=&quot;external&quot; href=&quot;http:&#x2F;&#x2F;www.eff.org&#x2F;&quot;&gt;Electronic Frontier Foundation&lt;&#x2F;a&gt;,
&lt;a rel=&quot;external&quot; href=&quot;http:&#x2F;&#x2F;www.eff.org&#x2F;observatory&quot;&gt;launching a project&lt;&#x2F;a&gt; into all publicly used SSL
certificates has had to delay because they are disclosing vulnerabilities to
websites they found using weak private keys generated by the broken
Debian&#x2F;Ubuntu OpenSSL versions.&lt;&#x2F;p&gt;
&lt;p&gt;As the EFF SSL Observatory page will be updated at some point, it currently
reads:&lt;&#x2F;p&gt;
&lt;blockquote&gt;
&lt;p&gt;This project is not fully launched yet, because we are currently engaging in
vulnerability disclosure for around 28,000 websites that we observed to be using
extremely weak private keys generated by a &lt;a rel=&quot;external&quot; href=&quot;http:&#x2F;&#x2F;digitaloffense.net&#x2F;tools&#x2F;debian-openssl&#x2F;&quot;&gt;buggy version of
OpenSSL&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;&#x2F;blockquote&gt;
&lt;p&gt;Further information can be found in the &lt;a rel=&quot;external&quot; href=&quot;http:&#x2F;&#x2F;www.eff.org&#x2F;files&#x2F;DefconSSLiverse.pdf&quot;&gt;SSL Observatory DEFCON 18
slides&lt;&#x2F;a&gt;.  Of the 28K vulnerable
certificates seen, the 530 validating ones are the most interesting. The others
were either invalid or the 12K issued by private certificate authorities. Only
73 of the 530 valid certificates had been revoked. In particular none of the
140 valid certificates by Equifax had been revoked, and only 4 of the 125
issued by Cybertrust.&lt;&#x2F;p&gt;
&lt;p&gt;In conclusion, this all seems rather depressing. A bug in a patch to an
important open source security library went unnoticed for two years, despite
reducing of the effective security of the keys it generated to almost nothing
(15 bits).  Furthermore, a bunch of private &quot;trusted&quot; companies still haven&#x27;t
taken measures to ensure SSL certificates they generated using this library have
been marked invalid another two years after the bug was found.&lt;&#x2F;p&gt;
&lt;p&gt;On a positive note, I&#x27;m sure Debian has learnt from its mistakes by now, but it
would still be nice to find some policy document to show what has changed (I
failed to find one).  Rather unsettlingly it seems like this was the exact type
of bug the &lt;a rel=&quot;external&quot; href=&quot;http:&#x2F;&#x2F;www.debian.org&#x2F;security&#x2F;audit&#x2F;&quot;&gt;Debian Security Audit
Project&lt;&#x2F;a&gt; was set up to spot.&lt;&#x2F;p&gt;
&lt;p&gt;Unfortunately, nothing so positive can be said about the state of Certificate
Authorities. Until one is sued for not taking proper security precautions,
their behavior is unlikely to change. As for security, there&#x27;s nothing to stop
a CA from collaborating with a government or other entity that wants to
eavesdrop on communications (&lt;a rel=&quot;external&quot; href=&quot;http:&#x2F;&#x2F;www.eff.org&#x2F;deeplinks&#x2F;2010&#x2F;03&#x2F;researchers-reveal-likelihood-governments-fake-ssl&quot;&gt;as the EFF
warns&lt;&#x2F;a&gt;).
Also, no amount of money spent on an SSL certificate from even the most
trustworthy CA will protect against a rogue certificate created (or
successfully forged) from a different CA also trusted by the web browser. In
other words, SSL is nowhere near as trustworthy as you think.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Debian Packaging for TrueCrypt</title>
        <published>2009-11-20T23:45:50+00:00</published>
        <updated>2009-11-20T23:45:50+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://www.unchartedbackwaters.co.uk/blog/posts/truecrypt_debian_packaging/"/><id>tag:unchartedbackwaters.co.uk,2009-11:truecrypt_debian_packaging</id>
        
        <content type="html" xml:base="https://www.unchartedbackwaters.co.uk/blog/posts/truecrypt_debian_packaging/">&lt;p&gt;I like to be able to build Debian packages from source. Unfortunately,
the released &lt;a rel=&quot;external&quot; href=&quot;http:&#x2F;&#x2F;www.truecrypt.org&quot;&gt;TrueCrypt&lt;&#x2F;a&gt; sources don&#x27;t contain the
Debian&#x2F;Ubuntu packaging used to build their &lt;em&gt;.deb&lt;&#x2F;em&gt; files. As a result, I&#x27;ve created my
own Debian packaging, available
&lt;a href=&quot;&#x2F;truecrypt_debian_packaging&#x2F;&quot;&gt;here&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;p&gt;As the TrueCrypt license seems to have issues that stop TrueCrypt being
included in most distributions, the downloadable files only include the
&#x27;debian&#x27; folder.  You&#x27;ll still need to download the TrueCrypt sources from
&lt;a rel=&quot;external&quot; href=&quot;http:&#x2F;&#x2F;www.truecrypt.org&#x2F;downloads2&quot;&gt;here&lt;&#x2F;a&gt;. Advantages over the upstream
packaging include an init script to kill TrueCrypt device mappings on shutdown
and the generation of a reasonably well formatted man page from the output of
&#x27;truecrypt --help&#x27;.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>DNS resolution delays in Debian (and Ubuntu)</title>
        <published>2009-05-23T16:38:52+00:00</published>
        <updated>2009-05-23T16:38:52+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://www.unchartedbackwaters.co.uk/blog/posts/debian_ubuntu_dns_resolution_delays/"/><id>tag:unchartedbackwaters.co.uk,2009-05:debian_ubuntu_dns_resolution_delays</id>
        
        <content type="html" xml:base="https://www.unchartedbackwaters.co.uk/blog/posts/debian_ubuntu_dns_resolution_delays/">&lt;p&gt;Yesterday, I was pinging a server when I noticed that the output of ping seemed
to be rather slow. In fact, I&#x27;d noticed it before but never really thought about
it until I was pinging anther server at the same time and the saw the drastic
difference in output speeds.&lt;&#x2F;p&gt;
&lt;p&gt;Pinging google.co.uk, there was a ping every second:&lt;&#x2F;p&gt;
&lt;pre class=&quot;giallo z-code&quot;&gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;fpr@callisto:~$ ping google.co.uk | perl -ne &amp;#39;use Time::Format; print &amp;quot;$time{\&amp;quot;hh:mm:ss.mmm\&amp;quot;} - $_&amp;quot;&amp;#39;&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;14:44:34.898 - PING google.co.uk (74.125.77.104) 56(84) bytes of data.&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;14:44:34.915 - 64 bytes from ew-in-f104.google.com (74.125.77.104): icmp_seq=1 ttl=238 time=32.9 ms&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;14:44:35.883 - 64 bytes from ew-in-f104.google.com (74.125.77.104): icmp_seq=2 ttl=238 time=35.9 ms&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;14:44:36.882 - 64 bytes from ew-in-f104.google.com (74.125.77.104): icmp_seq=3 ttl=238 time=33.4 ms&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;
&lt;p&gt;On another server, it was closer to five:&lt;&#x2F;p&gt;
&lt;pre class=&quot;giallo z-code&quot;&gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;fpr@callisto:~$ ping server1.fsckvps.com | perl -ne &amp;#39;use Time::Format; print &amp;quot;$time{\&amp;quot;hh:mm:ss.mmm\&amp;quot;} - $_&amp;quot;&amp;#39;&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;14:49:42.389 - PING server1.fsckvps.com (66.71.248.146) 56(84) bytes of data.&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;14:49:42.408 - 64 bytes from 66.71.248.146: icmp_seq=1 ttl=45 time=122 ms&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;14:49:47.500 - 64 bytes from 66.71.248.146: icmp_seq=2 ttl=45 time=123 ms&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;14:49:52.625 - 64 bytes from 66.71.248.146: icmp_seq=3 ttl=45 time=122 ms&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;
&lt;p&gt;This didn&#x27;t make much sense since the round-trip times were small by comparison
and ping sends one request per second by default. A Google search indicated that
the problem might lie with my
&lt;a rel=&quot;external&quot; href=&quot;http:&#x2F;&#x2F;linux.die.net&#x2F;man&#x2F;5&#x2F;resolv.conf&quot;&gt;resolv.conf&lt;&#x2F;a&gt; file.  Unfortunately, mine
seemed to be fine and my local DNS server was completely responsive. However, if
I pinged the server by IP address instead of by hostname, the delay was gone.&lt;&#x2F;p&gt;
&lt;p&gt;To see what was blocking, I ran &lt;a rel=&quot;external&quot; href=&quot;http:&#x2F;&#x2F;linux.die.net&#x2F;man&#x2F;1&#x2F;strace&quot;&gt;strace&lt;&#x2F;a&gt; on
ping.&lt;&#x2F;p&gt;
&lt;pre class=&quot;giallo z-code&quot;&gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;15:04:26.789 - munmap(0x7f69ed319000, 129482)          = 0&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;15:04:26.790 - socket(PF_FILE, SOCK_STREAM, 0)         = 4&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;15:04:26.790 - fcntl(4, F_GETFD)                       = 0&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;15:04:26.790 - fcntl(4, F_SETFD, FD_CLOEXEC)           = 0&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;15:04:26.790 - connect(4, {sa_family=AF_FILE, path=&amp;quot;&#x2F;var&#x2F;run&#x2F;avahi-daemon&#x2F;socket&amp;quot;...}, 110) = 0&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;15:04:26.790 - fcntl(4, F_GETFL)                       = 0x2 (flags O_RDWR)&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;15:04:26.790 - fstat(4, {st_mode=S_IFSOCK|0777, st_size=0, ...}) = 0&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;15:04:26.790 - mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7f69ed359000&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;15:04:26.791 - lseek(4, 0, SEEK_CUR)                   = -1 ESPIPE (Illegal seek)&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;15:04:26.791 - write(4, &amp;quot;RESOLVE-ADDRESS 66.71.248.146\n&amp;quot;..., 30) = 30&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;15:04:31.789 - read(4, &amp;quot;-15 Timeout reached\n&amp;quot;..., 4096) = 20&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;15:04:31.789 - close(4)                                = 0&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;
&lt;p&gt;It was blocking each ping on a read from &#x2F;var&#x2F;run&#x2F;avahi-daemon&#x2F;socket, a socket
used by &lt;a rel=&quot;external&quot; href=&quot;http:&#x2F;&#x2F;avahi.org&#x2F;&quot;&gt;Avahi&lt;&#x2F;a&gt;, an implementation of the network
auto-configuration and service discovery mechanism
&lt;a rel=&quot;external&quot; href=&quot;http:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Zero_configuration_networking&quot;&gt;Zeroconf&lt;&#x2F;a&gt; that
augments DNS. Killing the Avahi daemon solved the problem, but I still wanted to
work out why ping was talking to Avahi and why it only occurred on certain
hosts, so I ran &lt;a rel=&quot;external&quot; href=&quot;http:&#x2F;&#x2F;linux.die.net&#x2F;man&#x2F;1&#x2F;ltrace&quot;&gt;ltrace&lt;&#x2F;a&gt;:&lt;&#x2F;p&gt;
&lt;pre class=&quot;giallo z-code&quot;&gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;15:14:33.062 - gettimeofday(0x7fff90ec0550, NULL)               = 0&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;15:14:33.062 - gettimeofday(0x7fff90ec0520, NULL)               = 0&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;15:14:33.062 - memcpy(0x00608988, &amp;quot;\311\004\030J&amp;quot;, 16)          = 0x00608988&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;15:14:33.062 - sendmsg(3, 0x6077c0, 2048, 2, 61091)             = 64&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;15:14:33.184 - recvmsg(3, 0x7fff90ec15f0, 0, 0, 61091)          = 84&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;15:14:38.193 - gethostbyaddr(&amp;quot;BG\370\222T\315(\002&amp;quot;, 4, 2)      = NULL&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;15:14:38.193 - inet_ntoa(0x92f84742)                            = &amp;quot;66.71.248.146&amp;quot;&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;15:14:38.194 - strcpy(0x006078e0, &amp;quot;66.71.248.146&amp;quot;)              = 0x006078e0&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;
&lt;p&gt;I then wrote a little test in C just to check that I could replicate the delay
with &lt;a rel=&quot;external&quot; href=&quot;http:&#x2F;&#x2F;linux.die.net&#x2F;man&#x2F;3&#x2F;gethostbyaddr&quot;&gt;gethostbyaddr()&lt;&#x2F;a&gt;. I could, and it
was then that I finally realised that the delay occurred when pinging hosts that had
no PTR record (reverse DNS). Slightly confusingly, ping performs a reverse DNS lookup
on the IP address when provided with a hostname, but not when given an IP address.&lt;&#x2F;p&gt;
&lt;p&gt;gethostbyaddr() was calling Avahi because it had plugged itself into the glibc
resolver using &lt;a rel=&quot;external&quot; href=&quot;http:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Name_Service_Switch&quot;&gt;NSS&lt;&#x2F;a&gt;. When an
attempt to resolve an IP address to a hostname failed, glibc would then call
Avahi to try to find it. For whatever reason, Avahi cannot answer this request
instantly and times out after 5 &lt;em&gt;long&lt;&#x2F;em&gt; seconds. Avahi also resolves host names
to IP addresses but the delay in looking up unresolvable host names only occurs
if the domain is under the &lt;a rel=&quot;external&quot; href=&quot;http:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;.local&quot;&gt;.local pseudo top-level
domain&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;p&gt;The Debian package dependencies make it a bit difficult to remove Avahi so the
easiest way to fix this is to remove references to mdns4 from
&lt;a rel=&quot;external&quot; href=&quot;http:&#x2F;&#x2F;linux.die.net&#x2F;man&#x2F;5&#x2F;nsswitch.conf&quot;&gt;&#x2F;etc&#x2F;nsswitch.conf&lt;&#x2F;a&gt;. If you want to
kill the daemon entirely then you can always disable its init script of course.&lt;&#x2F;p&gt;
&lt;p&gt;Amusingly (or tragically) this bug is listed in
&lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;bugs.launchpad.net&#x2F;ubuntu&#x2F;+source&#x2F;avahi&#x2F;+bug&#x2F;94940&quot;&gt;Ubuntu&lt;&#x2F;a&gt; and
&lt;a rel=&quot;external&quot; href=&quot;http:&#x2F;&#x2F;bugs.debian.org&#x2F;cgi-bin&#x2F;bugreport.cgi?bug=414569&quot;&gt;Debian&lt;&#x2F;a&gt; bug reports
which are both over two years old. At time time of writing, it still exists in
Ubuntu Jaunty and Debian testing. What makes me really angry is that somewhere,
someone decided that it would be a great idea to enable this daemon by default
on desktop installs and as a result, performance of applications is being
degraded.  Obviously ping doesn&#x27;t matter that much, but as mentioned in the bug
reports, this hits people using ssh and IMAP as well, causing anything from
mild delays to almost unusable systems. The worst part of this is that many
people (and there could be a lot) suffering these issues are probably
attributing them to a slow network, or packet loss, or ssh key verification  or
just about anything else other than a dubiously designed daemon running on
their own machine. The fact that it only occurs on certain hosts only
reinforces this and unless they suddenly realise that this delay &lt;em&gt;is&lt;&#x2F;em&gt; their
local machine&#x27;s fault and put &lt;em&gt;a lot&lt;&#x2F;em&gt; of effort into debugging, they&#x27;ll
probably never know.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Transport for London, spam and all that</title>
        <published>2009-01-22T01:51:40+00:00</published>
        <updated>2009-01-22T01:51:40+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://www.unchartedbackwaters.co.uk/blog/posts/tfl_spam/"/><id>tag:unchartedbackwaters.co.uk,2009-01:tfl_spam</id>
        
        <content type="html" xml:base="https://www.unchartedbackwaters.co.uk/blog/posts/tfl_spam/">&lt;p&gt;I never realised this before, but &lt;a rel=&quot;external&quot; href=&quot;http:&#x2F;&#x2F;www.tfl.gov.uk&quot;&gt;Transport for London&lt;&#x2F;a&gt;
have been spamming me for at least three years. Despite never having
subscribed, I receive a &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.tfl.gov.uk&#x2F;tfl&#x2F;livetravelnews&#x2F;plannedworks&#x2F;default.aspx&quot;&gt;weekly
email&lt;&#x2F;a&gt;
detailing weekend closures to various TfL services. I&#x27;ve happily ignored this
abuse of my email address because unlike most spam, or more specifically in
this case, Unsolicited Bulk Email, it came from a legitimate company, I knew
how they got my email address (card application) and the messages contained
genuinely useful information.  Furthermore, I only want to unsubscribe as part
of the process of moving to a new email address. Having said that, I&#x27;m &lt;a rel=&quot;external&quot; href=&quot;http:&#x2F;&#x2F;dizzythinks.net&#x2F;2008&#x2F;03&#x2F;livingstones-transport-for-london.html&quot;&gt;not the
only one who&#x27;s noticed this
abuse&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;p&gt;It turns out that getting off the mailing list is harder than it looks. The
message contains no unsubscribe links. Neither does the TfL website. However,
on the subscribe form, they do offer to stop duplicate emails if you give them
your &lt;a rel=&quot;external&quot; href=&quot;http:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Oyster_card&quot;&gt;Oyster Card&lt;&#x2F;a&gt; number and your
address.  Well, &lt;em&gt;that&lt;&#x2F;em&gt; doesn&#x27;t make me too paranoid about a giant government
database.&lt;&#x2F;p&gt;
&lt;p&gt;Examining the email&#x27;s headers, they appear to be sent from the domain
&lt;a rel=&quot;external&quot; href=&quot;http:&#x2F;&#x2F;c-f-1.com&quot;&gt;c-f-1.com&lt;&#x2F;a&gt;. Go to this domain and you&#x27;ll get a PDF in which
the company &lt;a rel=&quot;external&quot; href=&quot;http:&#x2F;&#x2F;www.communicatorcorp.com&quot;&gt;Communicator Corp&lt;&#x2F;a&gt; explain how
they&#x27;re not spammers and how every email sent though their system contains &quot;an
easy and automated way for you to unsubscribe&quot; (they don&#x27;t) and how they
&quot;promise to keep your email address secure and private&quot; (also untrue). I&#x27;d have
found a link to an unsubscribe form far more convincing.&lt;&#x2F;p&gt;
&lt;p&gt;However, using Google, I was able to locate &lt;a rel=&quot;external&quot; href=&quot;http:&#x2F;&#x2F;www.google.co.uk&#x2F;search?hl=en&amp;amp;q=site%3Ac-f-1.com+unsubscribe&quot;&gt;unsubscription
forms&lt;&#x2F;a&gt; for
other email sent from c-f-1.com. From this, I constructed a URL of the form:&lt;&#x2F;p&gt;
&lt;p&gt;http:&#x2F;&#x2F;www.c-f-1.com&#x2F;Unsubscribe.aspx?emailid={emailid}&lt;&#x2F;p&gt;
&lt;p&gt;where {emailid} was the value of the &#x27;X-UEmailID&#x27; header of the TfL message.
Imagine my geekish glee when I was presented with an unsubscribe page containing
my old email address. I still received an email the following week, but now it seems
they&#x27;ve finally stopped sending messages to that address.&lt;&#x2F;p&gt;
&lt;p&gt;What&#x27;s rather disturbing is that those unsubscribe pages were even on Google in
the first place. Looking at the email IDs, they appear to be nothing more than
&lt;a rel=&quot;external&quot; href=&quot;http:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Base64&quot;&gt;Base64&lt;&#x2F;a&gt; encoded integers. Whilst they
don&#x27;t seem to start from 0, they don&#x27;t appear to be random either. Also, even
after unsubscribing, these pages seem to remain. Yes, it seems Communicator
Corp is leaking their their entire list of email addresses onto the World Wide
Web. If that isn&#x27;t a breach of privacy, not to mention the &lt;a rel=&quot;external&quot; href=&quot;http:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Data_protection_act&quot;&gt;Data Protection
Act&lt;&#x2F;a&gt;, I don&#x27;t know what is.
All that&#x27;s needed now is for an enterprising spammer to write a script to
collect them all.&lt;&#x2F;p&gt;
&lt;p&gt;&lt;strong&gt;Update 26&#x2F;04&#x2F;2009:&lt;&#x2F;strong&gt; For the first couple of months after writing this, I
noticed a number of hits to this page from what appeared to be Communicator
Corp&#x27;s Internet gateway. I can&#x27;t be certain that it&#x27;s connected, but I notice
that the mailing list unsubscribe form now no longer leaks email address
information and requires that the email address be entered as confirmation
which is a definite improvement. If Communicator Corp are reading this, I&#x27;d
also like to take this opportunity to ask them to ensure that all messages sent
do actually have a link to the corresponding unsubscribe form.&lt;&#x2F;p&gt;
&lt;p&gt;&lt;strong&gt;Update 02&#x2F;10&#x2F;2009:&lt;&#x2F;strong&gt; I notice that the weekly TfL emails now have both
subscribe and unsubscribe links although I&#x27;m unsure when they appeared.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>MD5 collision used to create rogue certificate authority</title>
        <published>2009-01-01T13:48:04+00:00</published>
        <updated>2009-01-01T13:48:04+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://www.unchartedbackwaters.co.uk/blog/posts/md5_collision_rogue_ca/"/><id>tag:unchartedbackwaters.co.uk,2009-01:md5_collision_rogue_ca</id>
        
        <content type="html" xml:base="https://www.unchartedbackwaters.co.uk/blog/posts/md5_collision_rogue_ca/">&lt;p&gt;&lt;a rel=&quot;external&quot; href=&quot;http:&#x2F;&#x2F;www.win.tue.nl&#x2F;hashclash&#x2F;rogue-ca&#x2F;&quot;&gt;This&lt;&#x2F;a&gt; really is quite nice.
Researchers used collisions in the MD5 hash algorithm to create a rogue CA
(Certification Authority) certificate signed by
&lt;a rel=&quot;external&quot; href=&quot;http:&#x2F;&#x2F;www.rapidssl.com&quot;&gt;RapidSSL&lt;&#x2F;a&gt;.  RapidSSL is apparently trusted by the
majority of web browsers.&lt;&#x2F;p&gt;
&lt;p&gt;It was &lt;a rel=&quot;external&quot; href=&quot;http:&#x2F;&#x2F;eprint.iacr.org&#x2F;2004&#x2F;199.pdf&quot;&gt;demonstrated&lt;&#x2F;a&gt; years
ago that MD5 collisions could be generated relatively easily, but that hasn&#x27;t
stopped MD5 being used in a number of contexts where cryptographically secure hash
functions are  required. The attack involves getting a CA that uses MD5 for
hashing to provide a legitimate website certificate. The attacker then generates
their own CA certificate which has the same hash as the legitimate one. It is
now possible for the attacker to generate SSL certificates for arbitrary
websites, signed by their rogue CA certificate. As the rogue CA certificate has
the same hash as a legitimate one signed by the CA, browsers that trust the CA
will accept the fraudulent site&#x27;s identity.&lt;&#x2F;p&gt;
&lt;p&gt;What I really like about this work is that the authors have managed to
bridge the gap between a result primarily of interest to security researchers
and an issue which could affect the average web user. Quite often, when
cryptographic research results get publicity, the implications are so obscure to
anyone without a knowledge of cryptography that the reporting soon becomes badly
distorted. Hopefully, this example of how MD5&#x27;s unsuitability as a cryptographic
hash can lead to such an easily comprehensible real-world vulnerability might
make people take notice of the danger in using broken hashing and encryption
algorithms. Well, one can hope.&lt;&#x2F;p&gt;
&lt;p&gt;As Bruce Schneier &lt;a rel=&quot;external&quot; href=&quot;http:&#x2F;&#x2F;www.schneier.com&#x2F;blog&#x2F;archives&#x2F;2008&#x2F;12&#x2F;forging_ssl_cer.html&quot;&gt;points
out&lt;&#x2F;a&gt;, the
plethora of valid sites with broken certificates have trained users to ignore
SSL warnings so the ability to spoof SSL certificates doesn&#x27;t really add that
much. Having said that, Firefox 3 goes out of its way to make it difficult to
access web-sites with invalid SSL certificates. Still, given the multitude
of far simpler methods criminals have for acquiring sensitive information, it&#x27;s
unlikely this attack will ever be seen in the wild.&lt;&#x2F;p&gt;
</content>
        
    </entry>
</feed>
