Why I hate Ubuntu: Reason #14

Published by manu
Updated
Tags:

You know how when you search for something within a search engine and the first results are adverts (sponsored links) ?

Now, you can get that feature right in your desktop environment ! Indeed Ubuntu has now added this thing, when you search for a program through the "lens" you get software results and right below "More Suggestions" which are products from your local Amazon online store.

Ubuntu and its followers defend this stating that Ubuntu needs to be funded somehow. It's a strange point of view that users of free email might understand as they already accept to have advertisements on their personal email pages (webmail). However I think both are perverse, we already are subject to so much consumer propaganda in public spaces as it is.

If Ubuntu is really in lack of money, they could have easily obtained funds by asking their users to donate. They already do that I heard, but I couldn't find where. Just put the link near the download link, or on the home page, or at least in the main menu. Offer services, like support, I don't know, maybe they should start a kickstarter page. Instead it looks like they are going in the direction of ChromeOS. I'll even predict that the next Ubuntu will be a just boot loader with the whole OS on their cloud.

Oh, I almost forgot, this probably means that whatever you type in the "Lens" thing is sent to Amazon.com with your IP (see update below).

Update: There is even a bug report about this. It seems the user's queries are not sent to Amazon directly but are sent to Ubuntu, the Ubuntu user's computer then gets a JSON formatted reply. That reply contains links to product informations and remote images that the user's computer will then request directly from Amazon.

This what a search like "games" looks like.

Mark Shuttleworth's honest response should make any Ubuntu user worried:

Why are you telling Amazon what I am searching for?

We are not telling Amazon what you are searching for. Your anonymity is preserved because we handle the query on your behalf. Don’t trust us? Erm, we have root. You do trust us with your data already.

No mister Shuttleworth, I don't trust you with my data, and this is just one of the reasons why.

Update 2: And so the bug reports are coming in, here are just a few.

Update 3: A post from the Free Software Foundation on Ubuntu, by RMS: Ubuntu Spyware: What to Do?

Update 4: The Ubuntu/Amazon parody logo is now under CC-BY-NC CC-BY-SA license thanks to Richard Stallman.

comments 8

Okular and "DRM"

Published by manu
Tags:
Copy forbidden by DRM

Today I wanted to copy paste something from a PDF file, because you know, technology and all that. To my surprise the option to copy as replaced with Copy forbidden by DRM message.

I found that Okular's obedience to DRM is an option that the user can uncheck.

All you need to do is uncheck "Obey DRM limitations"

All you need to do is uncheck "Obey DRM limitations"

What's also interesting is the thread okular: Arbitrarily enforces DRM on the debian-devel mailing list. I tend to agree that having this option active as a default makes no sense, actually, simply having such an option makes no sense.

Why would anyone want their computer to deny themselves the possibility to copy text from a file ? Is the goal to push people to develop faster and more precise typing skills or does someone actually think that such an option has an actual beneficial purpose to humanity ? Maybe right clicking is bad for your health and fake DRM wants to help ?

Some defend this saying that in a corporate environment blah blah blah... don't care. If you don't want your employees/co-workers or whatever to be able to copy paste text from a PDF don't send it to them.

comments 3

The Geniuses at Fox News "Circumvent" Wikipedia Blackout

Published by manu
Tags:

It's no news that Fox News is mostly made up of real geniuses who always deliver properly researched, reliable and fair information. Today they published an article on how"savvy moron surfers circumvent Wikipedia blackout.

The article goes on about how people have found ways of getting access to knowledge by using alternative sources (other websites!!) but the most striking part was that they announced how to get actual content from the Wikipedia itself.. ORLY!

For the diehard Wiki-fan who simply cannot do without Wikipedia, there is even a way to circumvent the blackout, using a system that relies on Google's cache of online sites.

This is how: Enter a search item in Google's search box, click on the double gray arrow that will appear when you hover your mouse on the right side of the search results. When a snapshot shows up on the right, click on "cache" ... and voila! ... you will be directed to the last snapshot of your search item in Wikipedia.

Of course, you could also click on the "Learn more" link provided by the blacked out Wikipedia page and find a simpler solution like:

During the blackout, Wikipedia is accessible on mobile devices and smart phones. You can also view Wikipedia normally by disabling JavaScript in your browser, as explained on this Technical FAQ page. Our purpose here isn't to make it completely impossible for people to read Wikipedia, and it's okay for you to circumvent the blackout. We just want to make sure you see our message.

Of course, for Fox News it is much easier to relay the stupidest crap on earth then to go read 4 sentences.

comments

NameSecure - Killing in the DNS of

Published by manu
Tags:

I've been helping a friend with some projects of his, mostly websites and email. Very simply put, as I'm trying to host his stuff I need to set things up on my servers, this is supposed to be the "long" part, and then just edit a couple of DNS records... easy peasy.

The difficult part commenced when I tried to simply change an IP and perhaps add an MX record for one of his domains.. I logged in to NameSecure's crappy interface, I edited the record, again and again and nothing changes.. Well, maybe after about 10/15 minutes of trying it did, however the SOA was not aware of any modifications, even 3 days later !

Do this for 3 domains and you start to get a headache.

So I write to their support and ask them to apply the changes I need, to which they reply to my friend that it can take up to 96 hours... of course they are just brushing the ticket away and throwing words about propagation (of course I don't care about propagation, I ask the SOA directly when I'm checking this sort of thing). But still, nothing works anyway. A mess.

Namesecure sucks. You shouldn't take only my word, just search the Interweb and see for yourself. Or worse, register a domain that is critical to you with them.

Solution: Move to a real registrar. Your domain name is important, it should be registered with a real registrar made of real people who know how to actually do things.. One that gives you a real interface in which you can add records, press submit and magically it's there on the screen, it's like you didn't just waste your time. An example of a good company that can manage domain names properly is Gandi.net. It just works. It's quite amazing that there are so many "domain name companies", and I really mean MANY, that simply do not work and/or are totally crappy.

Anyway, the first and most important word on their website is "cheap", that means a lot.

comments

Broken Design - Sink

Published by manu
Tags:

This sink's design is broken in at least 2 ways.

Sink, or waterfall ?

This sink was installed only a few months ago in a high tech low spec building, yet the hot and cold water are distributed in 2 separate faucets. In the year 2011 you still have to chose between burning or freezing your hands every time you wash. Whoever designed this obviously isn't big on post-toilet hygiene.

The other issue, again if you use such a device, is the room left for you to maneuver your hands while washing.. . Actually, just trying to collect water is difficult, you find yourself constantly hitting the back of the sink with your hands.

Sink: Hot and cold water don't mix
comments 3

Black & Berg - Truth about TeamPoison and Lulzsec

Published by manu
Tags:

Black & Berg, a security company, has exposed the truth behind TeaMp0isoN and Lulzsec.. . it's all made up. .. ... . Or is it ? ... . ..... . Or, which part is actually made up ?

They seem to have two domain names/websites, blackandberg.com and blackbergsecurity.us but they are currently down (they redirect to google.com). you can see what their site used to look like via google.cache.

After reading a bit of their "Genuine" twitter account and some of Jo Black's twitter (and replies, those are the best), it' seems like this is a Ligattalike company. Their website is owned and they are tweeting about how they want to declare war on Anonymous, (something about an itchy finger). One word: Losers.

comments

Skype - The first MS effects

Published by manu
Tags:

Not even one month after Microsoft killed bought Skype bugs and such have started to pour all over their status site. People can't log in, problems with software that wont install/uninstall properly, can't call numbers in certain countries (depending on the weather), issues when trying to reset a password, etc etc...

You can check Skype's status on the site heartbeat.skype.com. I checked for each month over the last year, most of the issues they have had are related to payments and such, especially around December for some reason an issue with MasterCard... strange..

The past 2 months are really bad..

comments

Comodo SSL fail - part 2

Published by manu
Tags:

More on Comodo as it seems that there was another attempt to generate more SSL certs. Very interesting is that COMODOHACKER explains him/her.self via the copy pasting site. Some interesting details were shared like: I hacked Comodo from InstantSSL.it, their CEO's e-mail address mfpenco@mfpenco.com Their Comodo username/password was: user: gtadmin password: globaltrust Their DB name was: globaltrust and instantsslcms You have to admit that with a password like that... . you can be sure they mean business. (and by that I mean none of my business).

Anyway, it has been confirmed that this person is indeed responsible (at least partially) for this nice demonstration by errata security.

I'll just say it again, when will we all agree that the business of signing SSL certificates is just a bunch of bullshit ?

comments 1

Comodo SSL fail

Published by manu
Tags:

We [should] all know that trusting third party SSL roots is bad, but if you are still not convinced then read how Comodo's SSL service was compromised. In short a reseller account was broken into and from there the attacker requested certificates for 7 domain names.

What this means is that certificates are issued without being verified. Whether it is the reseller or an attacker that is trying to generate certificates, they are not really verified, they are simply issued. Again, why do people trust ANY of these Certificate Authorities ?

Maybe time to think more about Monkeysphere and/or an SSL verified over DNS system.

comments

Nominet, Learn me the Internet

Published by manu
Tags:

I noticed that Nominet has set up a website to educate people about how the Internets works. It's called knowtheinternet.org.uk. Thing is, after 1 click I started to wonder if this was a lolsite or they were actually trying to educate people, I say this because I agree people should know a few theoretical things to get a better understanding of this thing we call the "Internet". But worse than ignorance is false knowledge. Examples.

Web Server

A web server distributes the load over a number of computer servers. If a site you look at is very slow its usually because its not got a web server, therefore the load cannot be shared. Source: Web Server

Website

A computer connected to the internet that maintains a collection of related web pages, images of videos on the World Wide Web. A website is typically accessible from the same URL. Source Website

Data Protection

A description for the data protection glossary term. Source Data Protection (they removed this word since)

There are a few other gems out there. The idea is cool, but, I mean. Hmmm. : ]

comments

Ligatt Security (Hole)

Published by manu
Tags:

After seeing this guy, Gregory D. Evans talk last year about Wikileaks, the Anon people, Mastercard and all that I seriously felt this guy was a bit of a phony. It turns out, his emails where got to and twitter accounts, personal and professional where broken into.

Gregory D. Evans Twitter page - Feb 8 2011

It only seems logic that a firm (Liggat) that boasts they can teach how to become a hacker in 15 minutes cannot realistically know anything about security. Anyway, links with more info here:

Bonus image of Gregory D. Evans.

comments

Reporting Spam to hotmail

Published by manu
Updated
Tags:

I have been receiving some spam from authenticated hotmail users lately, so I thought it could be useful to report it to them. Remembering some of the Microsoft logic I decided to use the Bing search engine to find out what kind of process they may have set up for the common people to use. Of course I did this because they do not respond to the recommended "abuse@domain.tld" addresses, they are above that sort of thing anyway.

I finally found this very informative page on how to report spam to hotmail and I think "what if I click the link titled How to report abusive e-mail with full headers to MSN?". So I do just that, and guess what, it's a link to a a page titled Dealing with Pornography Online, and the page does not even contain any information on how to deal with porn online... . It's the same for the link to the page that is supposed to explain how to identify if the mail has been sent using their systems. It's hopeless.

Update

It seems I spoke to soon, they have taken note of my email, however their auto replies have been blocked because the ACK emails are sent from misconfigured SMTP servers:

NOQUEUE: reject: RCPT from bay0-xmr-009.hotmail.com[65.54.241.58]: 450 4.7.1 <BAY0-XMR-009.phx.gbl>: Helo command rejected: Host not found; from=<abuse@msn.com> to=<ME> proto=ESMTP helo=<BAY0-XMR-009.phx.gbl>

I of course set up some stuff to at least be able to see where this goes.. .. I will update this article when they send the actual response.

comments 2

WTUnderground

Published by manu
Tags:

I have found a public transportation system worse than the Parisian RATP. In total there are more lines affected than non affected.. : ]. It's totally out of control this Underground.

These are photos of the Transport for London website..

So, what's left of the underground ?
The colored lines are those that are closed

(to get from here to there I might just book a flight.. .... euh, that is if the travel agency doesn't go bankrupt and BAA doesn't go on strike* at the same time (as another volcano ash rainfall ?). ... .. gosh it's not easy getting around in this country.)

* just to be clear, I am NOT against the BAA strike. :]
comments 2

just in case

Published by manu
Tags:

LOLOMG !FAIL.. I'm sure this door was put there because it was cheaper than a window...

door with something missing
comments 1