Archive for October 16th, 2012

B.C. to offer free textbooks online

“The B.C. government is offering free online textbooks for post-secondary students who are taking the 40 most popular courses.

Advanced Education Minister John Yap says up to 200,000 students could save money next year”.

see B.C. to offer free textbooks online – British Columbia – CBC News.

That’s a lot like the FLOSS (Free/Libre Open Source Software) ecosystem for software. Invest ~$1million per annum in generating on-line textbooks and save students ~$200 million per annum in expense. It lowers the cost of education. So does FLOSS. Invest a little in installing FLOSS and get all the benefits for very little. Organizations as large as governments could invest in generating FLOSS as well as free textbooks.

- Robert Pogson

Convenience, Features, Disaster

“I got tipped-off that the parts of the MSD network were completely exposed to the public. You could go into any WINZ office and use their self-service kiosks to access their corporate network.

These locked-down kiosks are provided so you could look for jobs online, send off CVs etc. They’ve had some basic features disabled, which supposedly meant that you couldn’t just open up File Manager and poke around the machine. However, by just using the Open File dialogue in Microsoft Office, you could map any unsecured computer on the network, and then open up any accessible file.”

via MSD's Leaky Servers • OnPoint • Public Address.

Well, it’s not exactly M$’s fault that they made their brand of networking so easy to set up but they also made it easy to neglect to lock it down and similarly easy to exploit. TFA is a rather boring thing except that I have seen similar situations several times. In one place where I worked the client machines were locked down pretty tightly so that I could not do stuff I needed to do for my job. Since technical help was weeks away, I hooked another client machine to the LAN and fired away. No one had bothered to lock down the DHCP server nor to define unknown machines as unprivileged on the network. I could do what I wanted… Of course, I did no harm, just setting up some GNU/Linux clients in my classroom but the methods, screens and simplicity of my “intrusion” were eerily similar to TFA. I was able to download FireFox onto the new client and then send it over to my “locked-down” XP machine totally bypassing restrictions which prevented browsing to any site not on a white list.

That event was in ~2003 and here we are in 2012 with the same sorts of issues.

I prefer GNU/Linux. A distro usually ships with NFS not sharing anything and privileges are a high priority. With that other OS, one can just “share” and be done with it. I’ve even been places where the system administrator shared “C:” to all and sundry from every machine to every machine. It was no wonder malware thrived quite unopposed for several years. Imagine just sprinkling malware hither and yon and waiting for someone to click on an icon to unleash the hounds.

I have no idea how the situation in New Zealand evolved. Probably someone added the kiosks without realizing they could access files all over (sad that was not checked…) or someone relaxed security not realizing the kiosks were around. Bad things happen when systems become more complex than one person knows. The right combination leads to disaster major or minor. One cannot regulate stupidity or ignorance but one can choose to use an OS like GNU/Linux where security is a higher priority than convenience.

- Robert Pogson



Archives by Month

My Mission

My observations and opinions about IT are based on 40 years of use in science and technology and lately, in education. I like IT that is fast, cost-effective and reliable. I do not care whether my solution is the same as yours. I like to think for myself.

My first use of GNU/Linux in 2001 was so remarkably better than what I had been using, I feel it is important work to share GNU/Linux with the world. I have been blessed by working in schools where students and school systems have benefited by good, modular software easily installed in most systems.

I have shown GNU/Linux to thousands of students and hundreds of teachers over the years and will continue in some way doing that until I die in spite of the opposition.

Posts

October 2012
S M T W T F S
« Sep   Nov »
 123456
78910111213
14151617181920
21222324252627
28293031  

    Writing

    3434 articles
    30663 comments

      Comments

      platforms
      linux 17507
      windows 12795
      macos 206
      sun 3
      wp 2

      browsers
      firefox 23959 
      safari 11878 
      chrome 11730 
      ie 4657 
      iceweasel 4280 
      opera 1643 
      konqueror 198 
      netnewswire 14 
      epiphany 2 
      flock 0 
      bonecho 0 
      lynx 0 

Bad Behavior has blocked 6356 access attempts in the last 7 days.