FUG-BR / Grupo Brasileiro de Usuarios de FreeBSD - Todas Categorias
 
28.04  
Inicio arrow Todas Categorias
Principal
Inicio
Noticias
Artigos
Regras da Lista
Assinar a Lista
Histrico da Lista
Forum
Keyserver
PC-BSD: Artigos
PC-BSD: Notcias
Galeria de Imagens
Contador Usurios FUG
FUGs Estaduais
Downloads
Enquetes
FAQ
Resumo do Site
Links
Pesquisar
Contato
Sobre a FUG-BR
RSS / Twitter
-
DOC-BR (FUG BR)
Introduo
Projeto DOC-BR
Handbook
FAQ Oficial
-
+ Noticias
Alertas de Seguranca
Alertas em Ports
BSD em Geral
DaemonNews (Ingles)
MyFreeBSD
Todas Categorias
-
Login
Nome de Usurio

Senha

Lembrar login
Esqueceu sua senha?
Sem conta? Crie uma


Todas as Categorias de Noticas Externas
freebsd - Google Notcias
Google Notcias

freebsd - Google Notícias

FUG-BR - Espalhando BSD
Dicas Rpidas:

Dificuldades para imprimir aspas simples no awk(1)? escaping não ajuda né? Tente um escape no código de aspas simples (47): 

# echo a b | \
awk '{print "\47"$1"\47\t"$2}'

'a'     b

Para aspas duplas use \42

 

 






Wallpapers
Fontes Externas
FreeBSD Multimedia Resources List FreeBSD Multimedia Resources
bsdtalk - DragonFlyBSD 2.8 with Matthew Dillon - MP3 version

DragonFlyBSD 2.8 with Matthew Dillon - MP3 version
From: bsdtalk
Tags: bsdtalk, interview, meetbsd, meetbsd2010, dragonflybsd, matthew dillon, mp3
Interview from MeetBSD California 2010 with Matthew Dillon about the recent 2.8 release of DragonFlyBSD. More information at http://www.dragonflybsd.org/


bsdtalk - DragonFlyBSD 2.8 with Matthew Dillon - Ogg version

DragonFlyBSD 2.8 with Matthew Dillon - Ogg version
From: bsdtalk
Tags: bsdtalk, interview, meetbsd, meetbsd2010, dragonflybsd, matthew dillon, ogg
Interview from MeetBSD California 2010 with Matthew Dillon about the recent 2.8 release of DragonFlyBSD. More information at http://www.dragonflybsd.org/


bsdtalk - PC-BSD 9 Alpha with Kris Moore - MP3 version

PC-BSD 9 Alpha with Kris Moore - MP3 version
From: bsdtalk
Tags: bsdtalk, interview, pc-bsd, meetbsd, meetbsd2010, kris moore, mp3
Interview from MeetBSD California 2010 with Kris Moore. We talk about the new alpha snapshot of PC-BSD 9. More information at http://blog.pcbsd.org/


bsdtalk - PC-BSD 9 Alpha with Kris Moore - Ogg version

PC-BSD 9 Alpha with Kris Moore - Ogg version
From: bsdtalk
Tags: bsdtalk, interview, pc-bsd, meetbsd, meetbsd2010, kris moore, ogg
Interview from MeetBSD California 2010 with Kris Moore. We talk about the new alpha snapshot of PC-BSD 9. More information at http://blog.pcbsd.org/


bsdtalk - The mg text editor with Kjell Wooding - MP3 version

The mg text editor with Kjell Wooding - MP3 version
From: bsdtalk
Tags: bsdtalk, interview, mg, kjell wooding, mp3
Interivew with Kjell Wooding. We talk about the mg text editor. More information can be found in the OpenBSD man page: http://www.openbsd.org/cgi-bin/man.cgi?query=mg


bsdtalk - The mg text editor with Kjell Wooding - Ogg version

The mg text editor with Kjell Wooding - Ogg version
From: bsdtalk
Tags: bsdtalk, interview, mg, kjell wooding, ogg
Interivew with Kjell Wooding. We talk about the mg text editor. More information can be found in the OpenBSD man page: http://www.openbsd.org/cgi-bin/man.cgi?query=mg


bsdtalk - PC-Sysinstall with John Hixson - MP3 version

PC-Sysinstall with John Hixson - MP3 version
From: bsdtalk
Tags: bsdtalk, interview, pc-sysinstall, pc-bsd, john hixson, mp3
Interview with John Hixson. We talk about his work on PC-Sysinstall, the PC-BSD installer and possible alternative to the FreeBSD sysinstall.


bsdtalk - PC-Sysinstall with John Hixson - Ogg version

PC-Sysinstall with John Hixson - Ogg version
From: bsdtalk
Tags: bsdtalk, interview, pc-sysinstall, pc-bsd, john hixson, ogg
Interview with John Hixson. We talk about his work on PC-Sysinstall, the PC-BSD installer and possible alternative to the FreeBSD sysinstall.


bsdtalk - MeetBSD California 2010 - MP3 version

MeetBSD California 2010 - MP3 version
From: bsdtalk
Tags: bsdtalk, interview, meetbsd, meetbsd2010, matt olander, james nixon, mp3
Interview with Matt Olander and James T. Nixon. We talk about MeetBSD California 2010. More information at http://www.meetbsd.com/


bsdtalk - MeetBSD California 2010 - Ogg version

MeetBSD California 2010 - Ogg version
From: bsdtalk
Tags: bsdtalk, interview, meetbsd, meetbsd2010, matt olander, james nixon, ogg
Interview with Matt Olander and James T. Nixon. We talk about MeetBSD California 2010. More information at http://www.meetbsd.com/


TaoSecurity Richard Bejtlich's blog on digital security, concentrating on global challenges posed by China and other persistent adversaries.
Five Thoughts on New China Article

I just read a thoughtful article by Michael O'Hanlon and James Steinberg, posted at Brookings and Foreign Policy titled Don't Be a Menace to South (China Sea).

It addresses thorny questions regarding China as President Obama visits South Korea, Japan, Malaysia, and the Philippines.

I wanted to share five quick thoughts on the article, fully appreciating I don't have all the answers to this complex strategic problem.

1. "Many in China see the U.S. rebalance as ill-disguised containment, while many in the United States see Chinese military modernization and territorial assertiveness as strong indications that Beijing seeks to undermine Washington's alliances and drive the United States from the Western Pacific."

I agree with these statements as being perceptions by both sides, but I also think they are closer to the truth than what the authors believe. I recommend Dr Ashley Tellis' monograph Balancing Without Containment: An American Strategy for Managing China as the best strategy I've seen for handling this aspect of the problem.

2. "Compounding this challenge, the long-term intentions of both sides are inherently unknowable. The inclination in the face of such uncertainty is to prepare for the worst -- which all too frequently becomes a self-fulfilling prophecy."

I disagree that long-term intentions are inherently unknowable. Building on the first point, the Chinese want to project regional power without US interference, and the US wants to maintain the ability to protect power globally. That means the two sides will be in conflict in the South China Sea and other regional Chinese waters.

3. "That does not mean Washington must immediately unsheathe the sword if tensions escalate over China's actions near the Senkakus or disputed islands in the South China Sea, but it must make clear that it is prepared to impose significant costs if red lines are crossed -- which is why the response to Russia's actions in Ukraine is so salient to the situation in East Asia."

I believe many commentators and policymakers cringe at the term "red lines" when applied to the current administration. The President's use of the term with respect to Syrian weapons of mass destruction has weakened his position. Perhaps more importantly, just what are the "red lines" in the South China Sea? The authors recommend meeting alliance commitments, but what does that mean?

4. "U.S. allies in Asia worry that China's ability to impose economic costs against the United States might deter Washington from acting -- a concern exacerbated by U.S. and European caution in imposing costs on Russia. The late March expansion of sanctions against Russia should help reassure U.S. allies of Washington's willingness to accept the risks of economic retaliation in order to impose costs on those who cross red lines."

There are few similarities between the US-Russia and US-China economic relationships. The risks of economic retaliation from Russia are far smaller than those that could be applied by China. US allies should worry about China's ability to impose economic costs against the US, but that is tempered somewhat by the effects those sanctions could have against China itself.

5. "The United States and its allies also have an interest in reassuring China that if Beijing acts responsibly, they will not seek to thwart its future prosperity and security... These might include "Open Skies" reconnaissance agreements, where both sides allow territorial overflights to reduce concerns about concealment...

Just as important as formal agreements is the willingness of both sides to exercise restraint in defensive actions that might appear threatening; to enhance transparency to dispel misunderstandings; and to reciprocate positive actions to stimulate a virtuous circle of enhanced confidence. This might mean Chinese willingness to slow the rate of its military buildup rather than race for parity." (emphasis added)

What does "act responsibly" mean? In US eyes, it probably means the Chinese allow the US to project power globally, including in the South China Sea. As I mentioned above, the Chinese don't want this to be the case in the medium and long term.

"Open skies" agreements and "enhanced transparency" are non-starters for China, just as they were non-starters for the Soviet Union in the 1950s. Strategic theory explains why. China is militarily weaker than the United States. They fear that the more the US learns about Chinese capabilities, the more accurately and effectively the US will be able to target and neutralize those capabilities. The Chinese follow this approach with nuclear weapons and cyber weapons, as we saw with the latter recently (see Adam Segal's What Briefing Chinese Officials On Cyber Really Accomplishes.)

I see few situations where China would slow its military buildup, with the exception of nuclear weapons. With nuclear weapons, the important feature is a first-strike-survivable retaliation capability. The Chinese don't need to match the US warhead-for-warhead if the US knows we can't get away with a first strike against China. (To learn more about this dynamic, see Strategic Stability: Contending Interpretations.)

On the conventional side, the Chinese are more likely to try to outbuild the US, because they still lack a qualitative advantage compared to US forces. Given declining US budgets, the Chinese should be able to out-spend and out-build the US Navy and Air Force, the two most critical services for a future US-China conflict.

Overall, this is a very tough problem, but I recommend reading the piece by Dr Tellis for the best answer I've read concerning strategic approaches to the US-China issue in the South China Sea.



Are Nation States Responsible for Evil Traffic Leaving Their Networks?

During recent talks to various audiences, I've mentioned discussions within the United Nations. One point from these discussions involved certain nation states agreeing to modes of behavior in cyber space. I found the document containing these recent statements: A/68/98, Group of Governmental Experts on Developments in the Field of Information and Telecommunications in the Context of International Security (pdf). This document is hosted within the United Nations Office for Disarmament Affairs, in the developments in the field of information and telecommunications section.

Fifteen countries were involved in producing this document: Argentina, Australia, Belarus, Canada, China, Egypt, Estonia, France, Germany, India, Indonesia, Japan, the Russian Federation, the United Kingdom of Great Britain and Northern Ireland and the United States of America.

Within the section titled "Recommendations on norms, rules and principles of responsible behaviour by States," I found the following noteworthy:

19. International law, and in particular the Charter of the United Nations, is applicable and is essential to maintaining peace and stability and promoting an open, secure, peaceful and accessible ICT environment...

23. States must meet their international obligations regarding internationally wrongful acts attributable to them. States must not use proxies to commit internationally wrongful acts. States should seek to ensure that their territories are not used by non-State actors for unlawful use of ICTs.

The first statement is important because it "imports" a large body of external law and agreements into the cyber field, for good or ill.

The second statement is important because, if States obey these principles, it has interesting effects upon malicious activity leaving State networks. Collectively these sentences imply that States are responsible for their networks. States can't claim that they are only innocent intrusion victims, and that any malicious activity leaving their State isn't their fault or problem.

Whether States try to meet these obligations, and whether others call them out for not meeting them, is another matter.



Five Thoughts from VADM Rogers Testimony

I had a chance to read Advance Questions for Vice Admiral Michael S. Rogers, USN (pdf) this weekend.

I wanted to share five thoughts based on excerpts from the VADM Rogers' answers to written questions posed by the Senate Armed Services Committee.

1. The Committee asked: Can deterrence be an effective strategy in the absence of reliable attribution?

VADM Rogers responded: Yes, I believe there can be effective levels of deterrence despite the challenges of attribution. Attribution has improved, but is still not timely in many circumstances...

Cyber presence, being forward deployed in cyberspace, and garnering the indications and warnings of our most likely adversaries can help (as we do with our forces dedicated to Defend the Nation). (emphasis added)

I wonder if "cyber presence" and "being forward deployed in cyberspace" means having access to adversary systems? There's little doubt as to the source of an attack if you are resident on the system launching the attack.

2. The Committee asked: Is it advisable to develop cyberspace officers as we do other combat arms or line officers? Why or why not?

VADM Rogers responded: ...We must find a way to simultaneously ensure combat arms and line officers are better prepared to contribute, and cyberspace officers are able to enjoy a long, meaningful career with upward mobility. A meaningful career should allow them to fully develop as specialized experts, mentor those around them, and truly influence how we ought to train and fight in this mission space. 

I am especially interested in the merit of how a visible commitment to valuing cyberspace officers in our ranks will affect recruitment and retention. I believe that many of today

Bejtlich Teaching at Black Hat USA 2014

I'm pleased to announce that I will be teaching one class at Black Hat USA 2014 2-3 and 4-5 August 2014 in Las Vegas, Nevada. The class in Network Security Monitoring 101. I've taught this class in Las Vegas in July 2013 and Seattle in December 2013. I posted Feedback from Network Security Monitoring 101 Classes last year as a sample of the student commentary I received.

This class is the perfect jumpstart for anyone who wants to begin a network security monitoring program at their organization. You may enter with no NSM knowledge, but when you leave you'll be able to understand, deploy, and use NSM to detect and respond to intruders, using open source software and repurposed hardware.

The first discounted registration deadline is 11:59 pm EDT June 2nd. The second discounted registration deadline (more expensive than the first but cheaper than later) ends 11:59 pm EDT July 26th. You can register here.

Please note: I have no plans to teach this class again in the United States. I haven't decided yet if I will not teach the class at Black Hat Europe 2014 in Amsterdam in October.

Since starting my current Black Hat teaching run in 2007, I've completely replaced each course every other year. In 2007-2008 I taught TCP/IP Weapons School version 1. In 2009-2010 I taught TCP/IP Weapons School version 2. In 2011-2012 I taught TCP/IP Weapons School version 3. In 2013-2014 I taught Network Security Monitoring 101. This fall I would need to design a brand new course to continue this trend.

I have no plans to design a new course for 2015 and beyond. If you want to see me teach Network Security Monitoring and related subjects, Black Hat USA is your best option.

Please sign up soon, for two reasons. First, if not enough people sign up early, Black Hat might cancel the class. Second, if many people sign up, you risk losing a seat. With so many classes taught in Las Vegas, the conference lacks the large rooms necessary to support big classes.

Several students asked for a more complete class outline. So, in addition to the outline posted currently by Black Hat, I present the following that shows what sort of material I cover in my new class.

OVERVIEW

Is your network safe from intruders? Do you know how to find out? Do you know what to do when you learn the truth? If you are a beginner, and need answers to these questions, Network Security Monitoring 101 (NSM101) is the newest Black Hat course for you. This vendor-neutral, open source software-friendly, reality-driven two-day event will teach students the investigative mindset not found in classes that focus solely on tools. NSM101 is hands-on, lab-centric, and grounded in the latest strategies and tactics that work against adversaries like organized criminals, opportunistic intruders, and advanced persistent threats. Best of all, this class is designed *for beginners*: all you need is a desire to learn and a laptop ready to run a virtual machine. Instructor Richard Bejtlich has taught over 1,000 Black Hat students since 2002, and this brand new, 101-level course will guide you into the world of Network Security Monitoring.

CLASS OUTLINE

Day One

0900-1030
         Introduction
         Enterprise Security Cycle
         State of South Carolina case study
         Difference between NSM and Continuous Monitoring
         Blocking, filtering, and denying mechanisms
         Why does NSM work?
         When NSM won

The Limits of Tool- and Tactics-Centric Thinking

Earlier today I read a post by Dave Aitel to his mailing list titled 
Drinking the Cool-aid. Because it includes a chart you should review, I included a screenshot of it in this blog, below. Basically Dave lists several gross categories of defensive digital security technology and tools, then lists what he perceives as deficiencies and benefits of each. Embedded in these pluses and minuses are several tactical elements as well. Please take a look at the original or my screenshot.



I had three reactions to this post.

First, I recognized that it's written by someone who is not responsible for defending any network of scale or significance. Network defense is more than tools and tactics. It's more often about people and processes. My initial response is unsatisfying and simplistic, however, even though I agree broadly with his critiques of anti-virus, firewalls, WAFs, and some traditional security technology.

Second, staying within the realm of tools and tactics, Dave is just wrong on several counts:
  • He emphasizes the role of encryption to defeat many defensive tools, but ignores that security and information technology architects regularly make deployment decisions to provide visibility in the presence of encryption.
  • He ignores or is ignorant of technology to defeat obfuscation and encryption used by intruders.
  • He says "archiving large amounts of traffic is insanely expensive and requires massive analytics to process," which is wrong on both counts. On a shoestring budget my team deployed hundreds of open source NSM sensors across my previous employer to capture data on gateways of up to multi-Gbps bandwidth. Had we used commercial packet capture platforms we would have needed a much bigger budget, but open source software like Security Onion has put NSM in everyone's hands, cheaply. Regarding "massive analytics," it's easier all the time to get what you need for solid log technology. You can even buy awesome commercial technology to get the job done in ways you never imagined.
I could make other arguments regarding tactics and tools, but you get the idea from the three I listed.

Third, and this is really my biggest issue with Dave's post, is that he demonstrates the all-too-common tendency for security professionals to constrain their thinking to the levels of tactics and tools. What do I mean? Consider this diagram from my O'Reilly Webinar on my newest book:


A strategic security program doesn't start with tools and tactics. Instead, it starts with one or more overall program goals. The strategy-minded CISO gets executive buy-in to those goals; this works at a level understood by technicians and non-technicians alike. Next the CISO develops strategies to implement those goals, organizes and runs campaigns and operations to support the strategies, helps his team use tactics to realize the campaigns and operations, and procures tools and technology to equip his team.

Here is an example of one strategic security approach to minimize loss due to intrusions, using a strategy of rapid detection, response, and containment, and NSM-inspired operations/campaigns, tactics, and tools.




Now I don't want to seem too harsh, because tool- and tactics-centric thinking is not just endemic to the digital security world. I read how it played out during the planning and execution of the air campaign during the first Gulf War.

I read the wonderful John Warden and the Renaissance of American Air Power and learned how the US Air Force at the time suffered the same problems. The Air Force was very tactics- and technology-focused. They cared about how to defeat other aircraft in aerial combat and sought to keep the Army happy by making close air support their main contribution to the "joint" fight. The Air Force managed to quickly deploy planes to Saudi Arabia but had little idea how to use those forces in a campaign, let alone to achieve strategic or policy goals. It took visionaries like John Warden and David Deptula to make the air campaign a reality, and forever change the nature of air warfare.

I was a cadet when this all happened and remember my instructors exhibiting the contemporary obsession with tactics and tech we've seen in the security world for decades. Only later in my Air Force career did I see the strategic viewpoint gain acceptance.

Expect to hear more from me about the need for strategic thinking in digital security. I intend to apply to a PhD program this spring and begin research in the fall. I want to apply strategic thinking to private sector digital defense, because that is where a lot of the action is and where the need is greatest.

For now, I talked about the need for strategy in my O'Reilly Webinar.






More Russian Information Warfare

In all the hype about "cyberspace" and "cyberwar," it's easy to forget about information warfare. This term was in vogue in the military when I was an Air Force intelligence officer in the 1990s. The Russians were considered to be experts at using information to their advantage and they appear to continue to wield that expertise on a regular basis. The latest incarnation goes like this:

1. Unknown parties, probably Russian SIGINT operators, intercept and record a phone call between US Assistant Secretary of State Victoria Nuland and US Ambassador to Ukraine, Geoffrey Pyatt. In the phone call, the parties use language which could be considered inflammatory or insulting to EU politicians.

2. The interceptors pass the phone call recording to a private third party.

3. Either that third party, or some recipient down the line, posts the audio and a video overlay
on Youtube.



4. The third party Tweets about the video.



5. Russian-sponsored television begins broadcasting stories about the video.


6. Reputable news media begin broadcasting stories about the video.


7. The rift between American and European leaders widens (possibly).

I find several aspects of this story fascinating.

First, I am surprised that whomever intercepted the phone call decided it was worthwhile to probably burn an intelligence source. It's possible the Americans were using consumer cell phones, subject to monitoring by foreign intelligence services. If true, the Americans were not very OPSEC-aware. If the Americans were using a line which they thought was secure, then the interceptors just revealed they know how to access it.

Second, the use of third parties is characteristic of Russian activities. We are all familiar with the role of patriotic hackers, youth groups, etc. when doing normal "cyber" activities. This sort of propaganda activity, with direct ties to a probable SIGINT operation, is interesting.

Third, I wonder about the cost of this operation. In some ways it is very cheap -- Youtube, Twitter, etc. In other ways, it may be expensive -- interception and probable manual auditing of the audio to identify divisive and "offensive" content.

I don't pretend to be a Russian SIGINT expert, but I wanted to document this case in my blog. Constructive commentary is welcome but subject to moderation due to spam countermeasures. Incidentally, if I got the origin or order of any of these events wrong, I'm open to that too. I didn't ask my Russian-speaking friends to comment -- I'm just noting this story for future reference.

Update: I noticed that sources like Kyiv Post say:

Among the first to tweet the audio recording was an aide to Russian Deputy Prime Minister Dmitry Rogozin, named Dmitry Loskutov, who also wrote: "Sort of controversial judgment from Assistant Secretary of State Victoria Nuland speaking about the EU."

However, the timestamp on this Russian aide Tweet is "11:35 PM - 5 Feb 2014" whereas the private Tweet I mentioned earlier shows "9:36 pm - 4 Feb 2014" -- a day earlier.












Quick Thought on Internet Governance and Edward Snowden

I am neither an Internet governance expert nor am I personally consumed by the issue. However, I wanted to point out a possible rhetorical inconsistency involving the Internet governance debate and another hot topic, theft of secret documents by insiders, namely Edward Snowden.

Let me set the stage. First, Internet governance.

Too often the Internet governance debate is reduced to the following. One side is characterized as "multi-stakeholder," consisting of various nongovernmental parties with overlapping agendas, like ICANN, IANA, IETF, etc. This side is often referred to as "the West" (thanks to the US, Canada, Europe, etc. being on this side), and is considered a proponent of an "open" Internet. The other side aligns with state governments and made its presence felt at the monumental December 2012 ITU World Conference on International Telecommunications (WCIT) meeting. This side is often referred to as "the East" (thanks to Russia, China, the Middle East, etc.), and is considered a proponent of a "closed" or "controlled" Internet.

Continuing to set the stage, let me now mention theft of secret documents.

One of the critiques of Edward Snowden involves the following. He stole documents on his own accord, claiming he had the right to do so by the "egregious" nature of what he found (or was sent to find). Critics reply that "no one elected Edward Snowden," but that the programs he exposed were authorized by all three branches of the US government. Because that government is elected by the people, one could say the government is speaking on behalf of the people, while Snowden is acting only on his behalf.

Here's the problem.

If you believe that elected governments are the proper forum for expressing the wishes of their people, you should have a difficult time defending a "multi-stakeholder" model that puts groups like ICANN, IANA, IETF, etc. on equal footing (or even above) representatives of elected governments. If you believe in the primacy of the democratic system, you should also believe forums of elected representatives are the proper place to debate and decide Internet governance.

That chain of logic means Western democracies who support representative government should view government-centric bodies like the ITU in more favorable light than they do presently. After all, who created the UN? Where is the organizations headquarters? Who pays its bills?

You probably detect the "escape hatch" for the multi-stakeholder proponents: my use of the term "elected governments." If a regime was not properly elected by its people, it should not have the right to speak for them. This applies to governments such as those in the People's Republic of China. Depending on your view of the legitimacy of the Russian election process, it may or may not apply to Russia. You can extend the argument as necessary to other countries.

The bottom line is this: be careful promoting multi-stakeholder Internet governance at the expense of representation by elected governments, if you also feel that Edward Snowden has no right to contravene the decision of a properly elected American government.

PS: If you want to know more about WCIT, try reading Summary Report of the ITU-T World Conference on International Telecommunications by Robert Pepper and Chip Sharp.



Suricata 2.0beta2 as IPS on Ubuntu 12.04

Today I decided to install Suricata, the open source intrusion detection and prevention engine from the Open Information Security Foundation (OISF), as an IPS.

I've been running Suricata in IDS mode through Security Onion on and off for several years, but I never tried Suricata as an IPS.

I decided I wanted to run Suricata as a bridging IPS, such that it did not route traffic. In other words, I could place a Suricata IPS between, say, a router and a firewall, or between a router and a host, and neither endpoint would know the IPS was present.

Looking at available documentation across the Web, I did not see specific mention of this exact configuration. It's entirely possible I missed something useful, but most people running Linux as a bridge weren't using Suricata.

Those running Linux as a bridge sometimes enabled an IP address for the bridge, which is something I didn't want to do. (True bridges should be invisible to endpoints.)

Of course, to administer the bridge system itself, you ensure the box has a third interface and you assign that interface a management IP address.

I also noticed those using Suricata as an IPS tended to configure it as a router, giving IP addresses to the internal and external IP addresses. I wanted an invisible bridge, not a router.

The hardware I used for the bridge was a 2003-era Shuttle small form factor system with 512 MB RAM, two NICs (eth0 and eth1), and a wireless NIC (wlan0). I installed Ubuntu Server 12.04.3 LTS. I tried installing the 64 bit version but realized the box was too old for 64 bit. Once I tried a 32 bit installation I was working in no time.

The first step I took was to create the bridge. I wanted to deploy the system between a router and an endpoint with IP address 192.168.2.142, like this:



router <-> eth0/Linux bridge/eth1 <-> 192.168.2.142

These are the commands to create the bridge. This how-to was useful.


$ sudo apt-get install bridge-utils
$ sudo brctl addbr br0
$ sudo brctl addif br0 eth0
$ sudo brctl addif br0 eth1
$ sudo ifconfig eth0 0.0.0.0
$ sudo ifconfig eth1 0.0.0.0
$ sudo ifconfig br0 up

With the bridge working, I could reach 192.168.2.142, the endpoint host, through the Ubuntu Linux bridge system. If I wanted to, I could watch traffic with Tcpdump on br0, eth0, or eth1.

Next I needed to install Suricata. I decided to use the beta packages published by OISF as described here. I also had to install python-software-properties as shown in order to have add-apt-repository available.


$ sudo apt-get install python-software-properties

$ sudo add-apt-repository ppa:oisf/suricata-beta
You are about to add the following PPA to your system:
Suricata IDS/IPS/NSM beta packages

http://www.openinfosecfoundation.org/
http://planet.suricata-ids.org/
http://suricata-ids.org/

Suricata IDS/IPS/NSM - Suricata is a high performance Network IDS, IPS and Network Security Monitoring engine.

Open Source and owned by a community run non-profit foundation, the Open Information Security Foundation (OISF).
Suricata is developed by the OISF, its supporting vendors and the community.

This engine is not intended to just replace or emulate the existing tools in the industry, but will bring new ideas
and technologies to the field.

This new Engine supports:

Multi-Threading - provides for extremely fast and flexible operation on multicore systems.
File Extraction, MD5 matching - over 4000 types of file recognition/extraction transmitted live over the wire.
TLS/SSL certificate matching/logging
Automatic Protocol Detection (IPv4/6, TCP, UDP, ICMP, HTTP, TLS, FTP, SMB )
Gzip Decompression
Fast IP Matching
Hardware acceleration on CUDA and GPU cards

and many more great features -
http://suricata-ids.org/features/all-features/
More info: https://launchpad.net/~oisf/+archive/suricata-beta
Press [ENTER] to continue or ctrl-c to cancel adding it

gpg: keyring `/tmp/tmpqk6Ubk/secring.gpg' created
gpg: keyring `/tmp/tmpqk6Ubk/pubring.gpg' created
gpg: requesting key 66EB736F from hkp server keyserver.ubuntu.com
gpg: /tmp/tmpqk6Ubk/trustdb.gpg: trustdb created
gpg: key 66EB736F: public key "Launchpad PPA for Peter Manev" imported
gpg: Total number processed: 1
gpg: imported: 1 (RSA: 1)
OK

$ sudo apt-get update
Now I was ready to install Suricata and Htp, a dependency.

$ sudo apt-get install suricata htp
Reading package lists... Done
Building dependency tree
Reading state information... Done
The following extra packages will be installed:
libhtp1 libnet1 libnetfilter-queue1 libnspr4 libnss3 libyaml-0-2
The following NEW packages will be installed:
htp libhtp1 libnet1 libnetfilter-queue1 libnspr4 libnss3 libyaml-0-2
suricata
0 upgraded, 8 newly installed, 0 to remove and 0 not upgraded.
Need to get 2,510 kB of archives.
After this operation, 8,394 kB of additional disk space will be used.
Do you want to continue [Y/n]?
...snip...
With this process done I added rules from Emerging Threats. I found Samiux's blog post helpful.

$ cd /etc/suricata
$ sudo wget https://rules.emergingthreatspro.com/open/suricata/emerging.rules.tar.gz
$ sudo tar -xzf emerging.rules.tar.gz
$ sudo mkdir /var/log/suricata
$ sudo touch /etc/suricata/threshold.config

Now I had to edit /etc/suricata/suricata.yaml. The following diff shows the changes I made to the original file.


$ diff -u /etc/suricata/suricata.yaml.orig /etc/suricata/suricata.yaml
--- /etc/suricata/suricata.yaml.orig 2014-01-25 21:39:57.542801685 -0500
+++ /etc/suricata/suricata.yaml 2014-01-25 21:41:31.530801055 -0500
@@ -46,7 +46,7 @@

# Default pid file.
# Will use this file if no --pidfile in command options.
-#pid-file: /var/run/suricata.pid
+pid-file: /var/run/suricata.pid

# Daemon working directory
# Suricata will change directory to this one if provided
@@ -208,7 +208,7 @@

# a line based information for dropped packets in IPS mode
- drop:
- enabled: no
+ enabled: yes
filename: drop.log
append: yes
#filetype: regular # 'regular', 'unix_stream' or 'unix_dgram'
@@ -337,7 +337,7 @@

# You can specify a threshold config file by setting "threshold-file"
# to the path of the threshold config file:
-# threshold-file: /etc/suricata/threshold.config
+threshold-file: /etc/suricata/threshold.config

# The detection engine builds internal groups of signatures. The engine
# allow us to specify the profile to use for them, to manage memory on an
@@ -373,7 +373,7 @@
- inspection-recursion-limit: 3000
# When rule-reload is enabled, sending a USR2 signal to the Suricata process
# will trigger a live rule reload. Experimental feature, use with care.
- #- rule-reload: true
+ - rule-reload: true
# If set to yes, the loading of signatures will be made after the capture
# is started. This will limit the downtime in IPS mode.
#- delayed-detect: yes
Next I added the following test rule to /etc/suricata/rules/drop.rules. The file location is arbitrary. I wrote a simple rule to alert on ICMP traffic from a test system, 192.168.2.126. All of the following is one line. I just broke it for readability.

alert icmp 192.168.2.126 any -> any any (msg:"ALERT test ICMP ping from 192.168.2.106";
icode:0; itype:8; classtype:trojan-activity; sid:99999998; rev:1;)

Notice I have no iptables rules loaded at this point:


$ sudo iptables -vnL
Chain INPUT (policy ACCEPT 5 packets, 392 bytes)
pkts bytes target prot opt in out source destination

Chain FORWARD (policy ACCEPT 4 packets, 240 bytes)
pkts bytes target prot opt in out source destination

Chain OUTPUT (policy ACCEPT 4 packets, 496 bytes)
pkts bytes target prot opt in out source destination

Now I was ready to see if Suricata would at least see and alert on traffic matching my ICMP test rule. First I started Suricata and told it to watch br0, the bridge interface.


$ sudo suricata -c /etc/suricata/suricata.yaml -i br0

25/1/2014 -- 22:44:13 - - This is Suricata version 2.0beta2 RELEASE
25/1/2014 -- 22:44:16 - - [ERRCODE: SC_ERR_NO_RULES(42)] - No rules loaded from /etc/suricata/rules/emerging-icmp.rules
25/1/2014 -- 22:44:33 - - [ERRCODE: SC_ERR_OPENING_RULE_FILE(41)] - opening rule file /etc/suricata/rules/dns-events.rules: No such file or directory.
25/1/2014 -- 22:44:51 - - [ERRCODE: SC_ERR_PCAP_CREATE(21)] - Using Pcap capture with GRO or LRO activated can lead to capture problems.
25/1/2014 -- 22:44:51 - - all 2 packet processing threads, 3 management threads initialized, engine started.
I don't care about the Warning or Error notices here. I could fix those but they are not germane to demonstrating the main point of this post.

On a separate system, 192.168.2.126, I pinged 192.168.2.142.


$ ping -c 2 192.168.2.142
PING 192.168.2.142 (192.168.2.142) 56(84) bytes of data.
64 bytes from 192.168.2.142: icmp_req=1 ttl=64 time=5.29 ms
64 bytes from 192.168.2.142: icmp_req=2 ttl=64 time=4.03 ms

--- 192.168.2.142 ping statistics ---
2 packets transmitted, 2 received, 0% packet loss, time 1001ms
rtt min/avg/max/mdev = 4.030/4.663/5.297/0.637 ms
Then I checked my Suricata logs:

$ ls -al /var/log/suricata/
total 88
drwxr-xr-x 3 root root 4096 Jan 25 22:50 .
drwxr-xr-x 11 root root 4096 Jan 25 21:38 ..
-rw-r--r-- 1 root root 0 Jan 25 22:15 drop.log
-rw-r--r-- 1 root root 392 Jan 25 22:50 fast.log
-rw-r--r-- 1 root root 0 Jan 25 21:42 http.log
-rw-r--r-- 1 root root 66008 Jan 25 22:50 stats.log
drwxr-xr-x 2 root root 4096 Jan 25 22:15 .tmp
-rw-r--r-- 1 root root 388 Jan 25 22:50 unified2.alert.1390708237

$ cat /var/log/suricata/fast.log
01/25/2014-22:50:40.510124 [**] [1:99999998:1] ALERT test ICMP ping from 192.168.2.106 [**] [Classification: A Network Trojan was detected] [Priority: 1] {ICMP} 192.168.2.126:8 -> 192.168.2.142:0
01/25/2014-22:50:41.510464 [**] [1:99999998:1] ALERT test ICMP ping from 192.168.2.106 [**] [Classification: A Network Trojan was detected] [Priority: 1] {ICMP} 192.168.2.126:8 -> 192.168.2.142:0
That worked as expected. I got alerts on the ICMP traffic matching the test ALERT rule.

Now it was time to drop traffic!

I added a new rule to drop.rules, again broken only for readability here:


drop icmp 192.168.2.126 any -> any any (msg:"DROP test ICMP ping from 192.168.2.106";
icode:0; itype:8; classtype:trojan-activity; sid:99999999; rev:1;)
I also disabled the previous ALERT rule by commenting it out.

Next I added iptables rules for the FORWARD chain, for traffic traversing the bridge. This Documentation was helpful.


$ sudo iptables -I FORWARD -j NFQUEUE

$ sudo iptables -vnL
Chain INPUT (policy ACCEPT 32 packets, 2752 bytes)
pkts bytes target prot opt in out source destination

Chain FORWARD (policy ACCEPT 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
0 0 NFQUEUE all -- * * 0.0.0.0/0 0.0.0.0/0 NFQUEUE num 0

Chain OUTPUT (policy ACCEPT 25 packets, 2600 bytes)
pkts bytes target prot opt in out source destination
Finally I restarted Suricata, this time telling it to use queue 0, where NFQUEUE was waiting for packets for Suricata.

$ sudo suricata -c /etc/suricata/suricata.yaml -q 0
25/1/2014 -- 22:54:49 - - This is Suricata version 2.0beta2 RELEASE
25/1/2014 -- 22:54:52 - - [ERRCODE: SC_ERR_NO_RULES(42)] - No rules loaded from /etc/suricata/rules/emerging-icmp.rules
25/1/2014 -- 22:55:08 - - [ERRCODE: SC_ERR_OPENING_RULE_FILE(41)] - opening rule file /etc/suricata/rules/dns-events.rules: No such file or directory.
25/1/2014 -- 22:55:26 - - all 3 packet processing threads, 3 management threads initialized, engine started.
With Suricata running in IPS mode, I tried pinging 192.168.2.142 from 192.168.2.126 as I did earlier.

$ ping -c 2 192.168.2.142
PING 192.168.2.142 (192.168.2.142) 56(84) bytes of data.

--- 192.168.2.142 ping statistics ---
2 packets transmitted, 0 received, 100% packet loss, time 1006ms
Nothing got through! I confirmed that I could ping the same box from another source IP address. In other words, only ICMP from 192.168.2.126 was blocked. Now check the Suricata logs:

$ ls -al /var/log/suricata/
total 152
drwxr-xr-x 3 root root 4096 Jan 25 22:57 .
drwxr-xr-x 11 root root 4096 Jan 25 21:38 ..
-rw-r--r-- 1 root root 294 Jan 25 22:57 drop.log
-rw-r--r-- 1 root root 798 Jan 25 22:57 fast.log
-rw-r--r-- 1 root root 0 Jan 25 21:42 http.log
-rw-r--r-- 1 root root 125812 Jan 25 22:57 stats.log
drwxr-xr-x 2 root root 4096 Jan 25 22:15 .tmp
-rw-r--r-- 1 root root 388 Jan 25 22:50 unified2.alert.1390708237
-rw-r--r-- 1 root root 0 Jan 25 22:55 unified2.alert.1390708526
-rw-r--r-- 1 root root 360 Jan 25 22:57 unified2.alert.1390708633

$ cat drop.log
01/25/2014-22:57:17.031400: IN= OUT= SRC=192.168.2.126 DST=192.168.2.142 LEN=84 TOS=0x00 TTL=64 ID=36055 PROTO=ICMP TYPE=8 CODE=0 ID=59729 SEQ=256
01/25/2014-22:57:18.038179: IN= OUT= SRC=192.168.2.126 DST=192.168.2.142 LEN=84 TOS=0x00 TTL=64 ID=36056 PROTO=ICMP TYPE=8 CODE=0 ID=59729 SEQ=512
Cool, those are our dropped ICMP packets. Checking fast.log we'll see the original two ALERT test messages, but check out the new DROP test messages too:

$ cat /var/log/suricata/fast.log
01/25/2014-22:50:40.510124 [**] [1:99999998:1] ALERT test ICMP ping from 192.168.2.106 [**] [Classification: A Network Trojan was detected] [Priority: 1] {ICMP} 192.168.2.126:8 -> 192.168.2.142:0
01/25/2014-22:50:41.510464 [**] [1:99999998:1] ALERT test ICMP ping from 192.168.2.106 [**] [Classification: A Network Trojan was detected] [Priority: 1] {ICMP} 192.168.2.126:8 -> 192.168.2.142:0
01/25/2014-22:57:17.031400 [Drop] [**] [1:99999999:1] DROP test ICMP ping from 192.168.2.106 [**] [Classification: A Network Trojan was detected] [Priority: 1] {ICMP} 192.168.2.126:8 -> 192.168.2.142:0
01/25/2014-22:57:18.038179 [Drop] [**] [1:99999999:1] DROP test ICMP ping from 192.168.2.106 [**] [Classification: A Network Trojan was detected] [Priority: 1] {ICMP} 192.168.2.126:8 -> 192.168.2.142:0
So that's it.

Note that with this configuration, if you stop Suricata then the host it's "protecting" is totally unreachable. You can restore connectivity by flushing the iptables rules via this command:


$ sudo iptables -F
Now the endpoint is reachable while Suricata is not running. To re-enable the IPS, you have to set up the NFQUEUE via iptables again as shown previously.

Following these directions you have the foundation for building a bridged IPS using Suricata on Ubuntu Server 12.04. The next step would be to fix the configuration issues causing the start-up error messages, make the bridge, firewall, and Suricata components available at start-up, and then build your own set of DROP rules. There are probably also optimizations for PF_RING and other performance features. Good luck!

Do you run Suricata as an IPS? How do you do it? Have you tried the new 2.x beta?



What Does "One Hour" Mean for Incident Response?

Yesterday, 8 January 2014, was the 11th birthday of TaoSecurity Blog. Please check out my happy 10th birthday post if you want to know why I don't blog much! In brief: Twitter.

I just read a story which I thought required more than 140 characters of attention: OMB revising data breach reporting requirements by Jason Miller. It says in part:

GAO found OMB's requirement to submit information about data breaches to the DHS U.S. Computer Emergency Readiness Team (US-CERT) within an hour after discovering the breach is of little value...

"Officials at agencies and US-CERT generally agreed that the current requirement that PII-related incidents be reported within one hour may be difficult to meet and may not provide US-CERT with the best information," auditors wrote.

"Specifically, officials at the Army, FDIC, FRB, FRTIB, and SEC indicated that it was difficult to prepare a meaningful report on a PII incident to US-CERT within the one-hour time frame required by OMB. The officials stated that meaningful information on an incident is often not available in that time frame, and reporting an incident to US-CERT without all relevant details would likely be of limited value. While VA officials stated that most of their incidents are reported in less than an hour, they do not believe the time frame is consistent with other US-CERT reporting guidelines and that the majority of the incidents would more appropriately be reported on a weekly basis."

US-CERT told GAO that the one-hour time frame doesn't give a clear picture of the reported incident and the information isn't used to help remediate incidents or provide technical support to agencies.

"Further, US-CERT's Chief of Performance Metrics confirmed that the vast majority of PII-related data breaches are not cybersecurity-related," the report stated. "Specifically, the official estimated that seven of every eight reported breaches do not involve attacks on or threats to government systems or networks...

Additionally, OMB staff said that they were unaware of the rationale for the one-hour time frame, other than a general concern that agencies report PII incidents promptly.

I'm not quite sure if OMB required reporting all incidents within an hour, or just "PII-related incidents." The latter seems true, but the article mentions reporting other incidents within an hour.

If you've heard me speak or read my fourth book, The Practice of Network Security Monitoring, you will recall me mentioning "one hour." The one hour in my context is time from detection to containment. There is no explicit time reporting requirement. There is a difference between notification to implement containment and writing a thorough investigative report.

Furthermore, my one hour recommendation is a requirement for high severity intrusions, not every incident. (The meanings of all these words matter, hence the bold and underline formatting.) Not all incidents are intrusions. Please see my 2009 post on intrusion ratings for examples of different severities.

The reason to strive for one hour from detection to containment is to implement the strategy of limiting the intruder's time of maneuver. If you can stop an intruder from accomplishing his ultimate objective, the fact that he penetrated your resistance systems is less important. What's important is that the intruder didn't complete his mission.

The fact that "OMB staff said... they were unaware of the rationale for the one-hour time frame" shows that requirement was divorced from an articulated, thoughtful, grounded defensive strategy. There is nothing magic about one hour, although I believe it represents an aggressive yet realistic containment requirement for organizations willing to invest in thorough and comprehensive detection, response, and containment processes and technology staffed by motivated CIRT members.

Ideally you implement one hour from intrusion to recovery, but let's save that even more aggressive goal for a time when you can implement one hour from detection to containment!

If you want to read more, chapter 9 of my book explains these ideas. Use code NSM101 to save 30% off when ordering from No Starch.



Linux Covert Channel Explains Why NSM Matters

I just read a post by Symantec titled Linux Back Door Uses Covert Communication Protocol. It describes a new covert channel on Linux systems. A relevant excerpt follows:

[T]he attackers devised their own stealthy Linux back door to camouflage itself within the Secure Shell (SSH) and other server processes. This back door allowed an attacker to perform the usual functionality

Daemonic Dispatches Musings from Colin Percival
Tarsnap: No heartbleed here

By now I assume everyone is aware of the "
Heartbleed" bug in OpenSSL. I wasn't planning on commenting on this, but considering how many emails I've received about this I've decided that I need to make a public statement: Tarsnap is not affected by this vulnerability.



Tarsnap price cut

On Tuesday of last week, Google
cut prices for their Google Cloud Platform services. Not to be outdone, less than 24 hours later, Amazon responded by cutting prices on several Amazon Web Services offerings, including the Simple Storage Service where Tarsnap stores customer data. Now it's my turn: Effective April 1st (I nearly announced this yesterday, but decided to wait until the April Fools' jokes were out of the way) I'm cutting Tarsnap's bandwidth and monthly storage pricing from $0.30/GB to $0.25/GB.



Tarsnap now accepts Bitcoin

A year and a half ago, I
announced that Tarsnap was gaining support for credit card payments, as one of the first companies in Canada to use Stripe's newly internationalized payment processing services. This satisfied a long-standing request from Tarsnap customers — until that point, Tarsnap was only accepting payments via PayPal, a service which for a variety of reasons many people did not want to use. Today I'm happy to announce that Tarsnap is satisfying another frequent request, again with help from Stripe: Tarsnap is the first user of Stripe's support for Bitcoin payments.



How to build FreeBSD/EC2 images

I have been building
FreeBSD/EC2 images for the past three years, and based on the email I have been receiving, most people have been either using these images directly or modifying them to create images which suit their needs. However, there are some people who want to build their own images ab initio — most often, companies which have products built on "customized" versions of FreeBSD — and while I have helped a few people do this, it's better if my help is not needed. To this end, earlier today I published my code for building FreeBSD AMIs. At its core, this process has two steps: First, building a disk image; and second, turning it into an AMI.



Email delivery headaches

Email delivery used to be easy. Server A connects to Server B over SMTP, states that it has a message for Bob from Alice, then sends the message text ("We meet at midnight"). This worked fine until spam came along; to cope with a deluge of spam, an extra step was added, namely "Server B decides whether it trusts Server A to provide email from Alice for Bob". Even then, it wasn't too bad; sure, wide swaths of IPv4 address space were blacklisted, but if you had a server at a reputable ISP, you would probably not be on any of those lists. Then cloud computing happened.



Dear Google Recruiting...

We dated briefly in 2006. You flew me down to visit you in Mountain View, and I had a good time. A few weeks later you proposed to me, but I decided that you weren't really what I was looking for, and I rejected you. I know it's hard to accept, but I really think it's time you moved on.



Thoughts on the Tarsnap logo contest

Coming as I do from the worlds of academia and open source software, it was only natural that when I decided that my
online backup service needed a logo, I turned to the "crowd" with a $500 contest. While I considered using one of the many logo-design-competition sites, I decided to run the contest myself for a simple reason: Tarsnap isn't exactly like most commercial products, but it has an enthusiastic user community who understand the mindset behind it. Tarsnap is not just "online backups for the truly paranoid"; it's also very much unix software, in the sense of "do one thing well", "keep it simple (stupid)", and "tools, not policy". Running the contest myself and announcing it via the tarsnap-users mailing list might have decreased the number of graphic designers participating, but I'm sure it increased the number of people who knew something about Tarsnap. (I did, however, keep one such site in mind as a backup plan in case I didn't like any of the submitted logos.)



Introducing configinit

I have been working on bringing
FreeBSD to the Amazon EC2 platform since 2006, and for the past three years I've been blogging about my progress: First FreeBSD on t1.micro instances, then cluster compute instances, then "m1" and "m2" family large and xlarge instances, and finally in early 2012, FreeBSD could finally run on all EC2 instance types. Once I had a hacked-up version of FreeBSD which ran smoothly, I turned my attention towards polishing it: First moving my EC2 scripts into the ports tree, then using binaries from the release ISOs for the FreeBSD world, and finally in early October (with FreeBSD 10.0-ALPHA4) all the necessary bits had been merged to make it possible for me to build EC2 images completely (including the kernel) with "straight off the ISO" binaries. Next on my agenda was taking my images from "pure FreeBSD" to "FreeBSD set up to be used in the cloud", and for that I'm happy to now announce that starting from 10.0-RC1, my FreeBSD AMIs have a new feature: configinit.



Automated FreeBSD panic reporting

It is now very common for software to have built-in mechanisms for reporting crashes. Windows, OS X, Ubuntu, Android, KDE, Mozilla... there are few large codebases which don't have any such functionality. Until a few days ago, FreeBSD was an exception: The instructions on
Kernel Debugging are hidden away in the "Developer's Handbook", and for users who are not in a position to diagnose the cause of a kernel panic themselves, all that could be done is to submit a bug report via the "send-pr" utility — at which point it would join the other 500+ panic reports sitting in FreeBSD's mostly-ignored GNATS repository. A couple of weeks ago, I decided it was time to do something about this.



Don't trust me: I might be a spook

Shortly after the Snowden papers started to be published, I was invited to write an op-ed about PRISM and its implications for privacy and online security. I initially agreed, but after spending a few hours putting some thoughts together I changed my mind: I really had nothing useful to say. Yes, the NSA is spying on us, listening to our phone calls, and reading our email — but we already knew that, and a few powerpoint slides of confirmation really doesn't change anything. When the first revelations about BULLRUN — the fact that the NSA can read a lot of encrypted data on the internet — appeared, I was similarly unimpressed: If you can find a weakness in an implementation of a cryptographic system, you can often bypass the cryptography, and the US government, via defense contractors, has hundreds of open job postings for exploit writers with Top Secret clearances. If the NSA can break 2048-bit RSA, it would be a Big Deal; if they can break OpenSSL, not so much.

But the latest revelations scare me. It's one thing to find and exploit vulnerabilities in software; there's a lot of software out there which was written by developers with very little understanding of cryptography or software security, and it shows. If you care about security, we reasoned, stick to software written by people who know what they're doing — indeed, when I talk to users of Tarsnap, my online backup service, one of the most common things I hear is "you're good at security, so we know your code will keep our data safe". That reasoning is now clearly flawed: We now have evidence that the NSA is deliberately sabotaging online security — influencing (and weakening) cryptographic standards, bribing companies to insert "back doors" into their software, and even sending developers to "accidentally" insert bugs into products. It's not enough to trust that I know what I'm doing: You have to trust that I'm not secretly working for the NSA.



Historico FUG-BR Historico Lista FreeBSD, FUG-BR
[FUG-BR] FreeBSD 10 e Qmail-auditor

[FUG-BR] FreeBSD 10 e Qmail-auditor

Re: [FUG-BR] FreeBSD 10 e Qmail-auditor [Resolvido]

Re: [FUG-BR] FreeBSD 10 e Qmail-auditor [Resolvido]

[FUG-BR] Lumina - Desktop desenvolvido para PC-BSD

[FUG-BR] Lumina - Desktop desenvolvido para PC-BSD

Re: [FUG-BR] Lumina - Desktop desenvolvido para PC-BSD

Re: [FUG-BR] Lumina - Desktop desenvolvido para PC-BSD

Re: [FUG-BR] Lumina - Desktop desenvolvido para PC-BSD

Re: [FUG-BR] Lumina - Desktop desenvolvido para PC-BSD

[FUG-BR] FreeBSD 11-CURRENT

[FUG-BR] FreeBSD 11-CURRENT

Re: [FUG-BR] FreeBSD 11-CURRENT

Re: [FUG-BR] FreeBSD 11-CURRENT

Re: [FUG-BR] FreeBSD 11-CURRENT

Re: [FUG-BR] FreeBSD 11-CURRENT

Re: [FUG-BR] FreeBSD 11-CURRENT

Re: [FUG-BR] FreeBSD 11-CURRENT

Re: [FUG-BR] FreeBSD 11-CURRENT

Re: [FUG-BR] FreeBSD 11-CURRENT

Web site Grupo Brasileiro de Usuarios FreeBSD Noticias do Web site FUG-BR
FreeBSD Servindo 30% da Internet Mundial (aka FreeBSD & Netflix)

FreeBSD Servindo 30% da Internet Mundial: Não, essa notícia não é da década de 90. É de 2012. Recentemente nessa Thread (historico/html/freebsd/2012-06/threads.html#00043) da Lista da FUG-BR, comentou-se a notícia que o Netflix usa FreeBSD em sua infra-estrutura de Rede de Distribuição de Conteúdo. A informação havia sido mencionada anteriormente pelo Scott Long, desenvolvedor BSD (e FreeBSD) de longa data, que anunciou antes ter saído do Yahoo! para trabalhar no Netflix.Formalmente o uso de FreeBSD, combinado com servidores commoditie e o webserver Nginx foi informado quando o Netflix anunciou o lançamento de seu Appliace OpenConnect, que o próprio Netflix colocará nos principais Pontos de Troca de Tráfego da Internet e grandes provedores de acesso Internet sem custo para os provedores. Aqui no Brasil Netflix chega com seu Appliace OpenConnect primeiro no PTT-SP e em seguida em alguns provedores que tenho o prazer de atender como clientes da FreeBSD Brasil (http://www.freebsdbrasil.com.br).Mas o que realmente significa dizer que FreeBSD é usado no coração operacional do Netflix?Em 2011 o Netflix passou a representar 32% de todo o tráfego da Internet na América do Norte em horários de pico. E em 2012, 29% da Internet na Europa em horários de pico. Ainda em 2011 a demanda por conteúdo servido pelo Netflix/FreeBSD foi tão grande que os provedores Canadenses e Americamos começaram a reclamar da falta de capacidade e capilaridade para tanto tráfego com esse novo perfil de consumo de banda, na mesma época que Netflix ultrapassou a Apple no segmento de entrega de conteúdo multimídia sob demanda. Foi quando Netflix começou a expandir seu projeto de appliance Open Connect para colocar seu conteúdo mais perto dos provedores e clientes e onerar menos a infra-estrutura de conectividade desses ISP.No passado apenas o Yahoo! na década de 90 havia conseguido essa marca, de representar 30% de toda a Internet mundial. Hoje o Netflix representa 32% da América do Norte e 29% da Europa como mencionado em diveras fontes (procure no Google pela sua preferida), as informações mais recentes são da Arbor Networks. Não é, oficialmente toda a Internet, mas sabemos que América do Norte e Europa representa a fatia mais relevante da Internet.No passado era FreeBSD quem servia 30% de todo o tráfego da Internet, através do Yahoo!, e um pouco mais através do mp3.com, NTT Verio, America Online e outros grandes nomes do início da bolha da Internet comercial nos anos 90. Mas quem vive de passado é museu, correto? Pois bem, e hoje, em pleno 2012, décadas depois, FreeBSD novamente está servindo 1/3 da Internet mundial em horários de pico.Isso mostra que o tempo passou, mas o FreeBSD continua poderoso igual, importante igual, e ao mesmo tempo pouco conhecido e amplamente utilizado nas principais operações de missão crítica da Internet, tudo exatamente como era na época do FreeBSD 2, FreeBSD 3, só que agora no FreeBSD 9.Desde o TCP/IP, coração da Internet, lançado no 4BSD, até o DNS, e-mail, até os Root Name Servers e Refletores de Rota BGP nos pontos de troca de tráfego de Ashburn, Virginia, Los Angeles, Seattle e Milão, desde o boom do Yahoo ao boom do Netflix, o mesmo FreeBSD continua carregando a Internet nas costas... Nos anos 90, 30% da Internet era uma coisa. Em 2012, os mesmos 30% são outra coisa... são alguns Mbit/s a mais. Mostrando que a evolução do FreeBSD é constante, contínua. E você acha que Netflix é algo novo? A empresa existe de 1997, usa FreeBSD desde 1997, mas sem a mesma finalidade. Netflix era uma empresa de aluguel de DVD por correios, o serviço de entrega de conteúdo online começou a crescer em 2007 apenas, alcançando clientes mundo afora. Mas e daí? Você se pergunta... pois bem, outro software de licença BSD tem seu poder exposto pelo Netflix, o Nginx. Dê uma olhada nesse gráfico da Netcraft:http://news.netcraft.com/archives/2012/07/03/july-2012-web-server-survey.html (http://news.netcraft.com/archives/2012/07/03/july-2012-web-server-survey.html)Esse gráfico é o levantamento mais recente do uso de web servers no mundo. Vê a linha verde que começar surgir entre 2007 e 2008 e hoje é tão expressivo seu volume que começa ameaçar o IIS da Microsoft? É graças ao Netflix que o Nginx, Web Server e Inbound Proxy de licença BSD se tornou o terceiro mais utilizado da Internet.Abaixo alguns links sobre o assunto, para enquiquecer sua leitura:http://forums.freebsd.org/showthread.php?t=32558 (http://forums.freebsd.org/showthread.php?t=32558) http://lists.freebsd.org/pipermail/freebsd-stable/2012-June/068129.html (http://lists.freebsd.org/pipermail/freebsd-stable/2012-June/068129.html)http://adrianchadd.blogspot.com.br/2012/06/freebsd-netflix-cdn.html (http://adrianchadd.blogspot.com.br/2012/06/freebsd-netflix-cdn.html) http://www.h-online.com/open/news/item/Netflix-announces-Open-Connect-CDN-1612094.html (http://www.h-online.com/open/news/item/Netflix-announces-Open-Connect-CDN-1612094.html)http://www.pcmag.com/article2/0,2817,2395372,00.asp (http://www.pcmag.com/article2/0,2817,2395372,00.asp)https://signup.netflix.com/openconnect/software (https://signup.netflix.com/openconnect/software)

Andrew Tanenbaum: BSD dominaria o mundo, se no fosse pelo processo da AT&T.;

O site LinuxFr.org está produzindo uma entrevista (em francês) (http://linuxfr.org/news/entretien-avec-andrew-tanenbaum-%C3%A0-propos-de-minix) com o autor, desenvolvedor e pesquisador Andrew Tanenbaum, (em inglês (http://linuxfr.org/nodes/88229/comments/1291183)). Nessa entrevista o mundialmente conhecido autor, referência bibliográfica em 8 em cada 10 trabalhos científicos de graduação e pós em nosso país, fala sobre BSD, sobre Linux, Linus Torvalds e critica a licença GPL, kernel de arquitetura monolítica, entre diversas outras opiniões que podem ser relevantes para muitos, vindas deste autor.Uma notícia curiosa é que Tanenbaum recebeu um financiamento para comercializar o MINIX 3 e em Janeiro ele começa a portar o sistema para arquitetura ARM.Mas o que salta aos olhos é sua opinião de superioridade do BSD sobre Linux e a atribuição a não dominação mundial do BSD ao processo da AT T: A razão pela qual MINIX3 não dominou o mundo é relacionada a um erro que cometi em 1992. Naquela época acreditei que o BSD é que dominaria o mundo! Já era um sistema maduro e estável. Eu não via razão alguma para querer competir com ele, então coloquei o foco acadêmico no MINIX. Quatro dos caras que desenvolviam o BSD formaram uma compania para vender o BSD comercialmente. Tinham até um número telefone bacana, 1-800-ITS-UNIX. Esse telefone os colocou (bem como a mim) pra dentro do mercado. A AT T os processou por causa desse número e o processo levou mais de 3 anos para ser resolvido. Esse era o período preciso em que Linux foi lançado e o BSD ficou estagnado devido ao processo jurídico. Quando foi resolvido Linux já tinha decolado. Meu erro foi não perceber que o processo levaria tanto tempo. Se a AT T não tivesse gerado esse processo (e comprado parte da BSDI depois), Linux nunca seria popular e o BSD dominaria o mundo! Mas Tanenbaum, hoje a tecnologia BSD está presente nos mais populares telefones celulares e tablets do mundo. A tecnologia BSD está embarcada em televisores, satélites. O TCP/IP revolucionou o mundo, a Internet em si, desde o protocolo, os refletores de rota T1 nos core-IXP americanos e europeus, os protocolos de comunicação como e-mail evoluídos do Fetchmail do Eric Allman, a resolução DNS padronizada no Berkeley Internet Name Domain system (BIND) e utilizada até hoje nos Root-NS tal qual criada por 4 alunos de Berkeley, o sistema que equipa Juniper, parte dos produtos Cisco (e portanto a infra-estrutura basica de cada rede), até o trabalho do IPv6 Samurai, Itojun, a criptografia do IPSEC, até algorítimos alternativos de enfileiramente de pacotes como HFSC, CBQ, PRIQ, WFQ que influenciam a priorização de tráfego no mundo. O sistema de controle de vôo da Boing (que cai bem menos que AirBus, a francesa reconhecidamente usa Linux), os sistemas militares baseados em XTS400, protocolos futuros como SCTP, processamento GPU, a própria Web, criada em um sistema híbrido 4.4-BSD pelo Tim Berners-Lee, o TrustedBSD finalmente implementando 30 anos de requisitos do Orange Book, o jemalloc() utilizado no Firefox, Microsoft Office e outras tecnologias, Zero Copy net, o primeiro driver open source do LTE, do 802.11s, Capsicum, os I/O Schedulers que até hoje não existiam mesmo sendo uma necessidade básica de sistemas de armazenamento, a gerência de memória, a memória virtual, o conceito de inodes e todo sistema de arquivos como conhecemos hoje, baseados em varições do UFS; o OpenSSL do https nosso de cada dia, de cada sessão de home banking, home broker e e-commerce; o OpenSSH de 9 em cada 10 sessões ssh do planeta; a alocação de páginas não constante de memória (super pages), até a pilha IP do Windows, Tanenbaum.Por tudo isso que move o mundo há décadas e por tudo que já existia e existe a frente de seu tempo (IPv6, SCTP, GPU Accel, SPages), Tanenbaum, só podemos concluir que você não errou. O BSD domina o mundo, mas em sua mais pura forma, a tecnológica. Talvez o BSD não seja o sistema mais popular do mundo (mas é o mais desejado, afinal quantos ai realmente prefere XYZ a um celular com iOS? Quem prefere um Dell com Windão a um Mac Book Pro com Mac OS X com aceleração GPU?), mas a tecnologia BSD tem sim dominado o mundo há décadas, tem tornado cada navegada nossa de cada possível, cada ligação telefônica móvel, cada e-mail viável, e se apresenta hoje anos ainda a frente, tornando disponível hoje o que provavelmente só será utilizado daqui bons anos.O processo diminuiu a taxa de ação de sistemas BSD mas ajudou a fragmentar a tecnologia BSD, e hoje ela está em lugares óbvios e outros que sequer conseguimos suspeitar. BSD não dominaria o mundo, Tanenbaum, BSD domina, você não errou o fato, errou o escopo, que é tecnológico e não operacional.Até mascote de sistemas tecnológicos é uma inovação BSD. Não haveriam penguins e peixes rechonchudos, ornitorrincos endiabrados, droidzinhos mecânicos, se não fosse pelo Beastie. Mas lógico que com o diferencial, além de mais expressivo e simpático, só nosso mascote é assinado por um gênio da animação (John Lasseter) e copyrighted por um gênio da ciência da computação (McKusick).

Infra-estrutura (FreeBSD) Unix no (Mac) OS X

No dia 01/03 o Renato (http://www.twitter.com/deadrop) me convidou pra escrever um pouco da relação Unix-BSD-OSX, pra série de artigos de segurança sendo divulgados pela IDS Tecnologia (http://www.ids.com.br/) na MacMagazine (http://www.macmagazine.com.br/). Escrevi um artigo um tanto extenso, que foi condensado propriamente ao ser publicado na MacMagazine (clique pra ver) (http://macmagazine.com.br/2012/03/01/seguranca-no-mundo-apple-infraestrutura-unix/), e partes dele serão reutilizados ao longo dos demais artigos. No entanto em particular tive pedidos pelo artigo na íntegra, então segue ele postado aqui na FUG também, espero que gostem :-) Pessoalmente gosto muito desse trecho da história dos BSD em geral e acaba ilustrando como a guerra jurídica que o CSRG/Berkeley sofreu por parte da USL/AT T quando a segunda processou Berkeley por conta dos 6 arquivos AT T restantes no BSD Unix. Lógico que pro mundo BSD foi uma passagem terrível, retardou a adoção de sistemas BSD e liberdade Open Source do código BSD. Mas teve seus lados positivos, como Torvalds e seu kernel baseado no Minix quando ele ficou inseguro ao usar o 386BSD, e nessa passagem outro ponto positivo, a criação do Mach pela universidade de Carnegie Mellon como uma alternativa ao BSD sob base BSD, posteriormente aproveitados no NeXT Step.Segue então o conteúdo, na íntegra, abaixo.

Alta Disponibilidade de Link

IntroduçãoMuitas vezes, provedores de internet ou até mesmo empresas, não têm 2 servidores para ter uma alta disponibilidade de link e servidor. E com isso, eles apenas garantem a disponibilidade de link em único servidor, isso garante que o usuário não vá ligar reclamando que não consegue navegar e bla bla bla, caso o link principal venha ficar indisponível.Para fazer isso, vou usar 2 ferramentas no FreeBSD, uma vai ser o Ifstated para fazer o monitoramento dos link e alterar a rota. E a outra vai ser o Packet Filter, o famoso PF.Caso o link venha ficar indisponível, o Ifstated vai alterar a rota para o outro link.Caso o link indisponível venha ficar disponível automaticamente, a rota vai voltar para a rota default, para o link principal.Já com o PF, vou usar para criar os NAT dos clientes em uma única linha. Ele também pode ser usado como Firewall, redundância de link (round-robin ou source-hash), redirecionamento de portas, e etc.Vamos ao trabalho. Clique abaixo para continuar lendo o artigo todo.

FreeBSD: mais rpido que Linux, at pra rodar binrios de Linux.

Phoronix confirma o que todos usuários FreeBSD que também usam Linux já sabiam, por experiência própria, as vezes com evidências, outras vezes apenas sensação tecnicamente infundada: FreeBSD consegue ser mais rápido que Linux até pra rodar binários... de Linux!Normalmente essa sensação de maior performance acontece em ambientes como banco de dados Oracle, aplicações mais simples como clientes de peer-to-peer com versão disponível apenas para Linux, e muitos outros. Acontece que mesmo a hipótese de melhor performance no FreeBSD pra rodar binários nativos Linux ser documentada até no FreeBSD Handbook, apesar dos usuários da FUG-BR de tempos em tempos enviarem alguns testemunhos com suas impressões, muitas vezes acompanhados de testes e evidências, ninguém não ligado ao desenvolvimento do FreeBSD tinha documentado testes e resultados nesse ponto.O Phoronix o fez e publicou aqui: http://www.phoronix.com/scan.php?page=article item=linux_games_bsd (http://www.phoronix.com/scan.php?page=article item=linux_games_bsd)A curiosidade é ainda mais inusitada: os testes foram feitos com jogos. Um cenário onde FreeBSD sai em completa desvantagem em modo de compatibilidade pois aceleração gráfica e outros quesitos demandam apoio do kernel em renderizações 3D, efeitos OpenGL e afins. Envolver uma camada de abstração para compatibilidade binária que dê acesso a recursos além do básico, memória, disco, CPU, e envolver aceleração gráfica 3D por si só é algo que o Projeto FreeBSD simplesmente não foca, nem testa performance.Só que o resultado ainda em cenário tão desfavorável foi em média 14% de performance a mais no FreeBSD que no Linux, pros jogos de Linux.Curiosamente foram testados PC-BSD e Ubuntu, as plataformas Linux e FreeBSD mais fáceis de usar.Outro fato importante: os testes envolveram plataformas 32 bits e 64bits, e mesmo a compat binária com Linux em 64bits que é muito nova no FreeBSD, supera Linux em 64bits.O artigo começa com uma introdução sobre o modo de compatibilidade binária do FreeBSD, tece alguns comentários e entra pra uma série de benchmarks comentados.Boa leitura.

FreeBSD 9 - Novo Instalador

Em mais uma boa contribuição em vídeo, Brivaldo apresenta o novo instalador do FreeBSD.O primeiro build de testes do FreeBSD-9.0 está disponível para download. Foram geradas imagens para as arquiteturas: amd64, i386, ia64, powerpc, powerpc64, e sparc64 que estão disponíveis nos espelhos do FreeBSD. Uma das funcionalidades mais interessantes na versão 9.0 é o novo instalador e é encorajado a todos realizar uma instalação limpa em seus sistemas de teste para verificar por problemas de instalação. Acompanhe o post original em http://blog.bibliotecaunix.org/?p=537 (http://blog.bibliotecaunix.org/?p=537)

Perdendo o medo da Instalao do FreeBSD

Nesse screencast, Brivaldo Júnior demonstra a instalação do FreeBSD de forma simples e direta. É um vídeo voltado aos novos usuários FreeBSD ou ainda não usuários, para afastar mitos e medos. Muito bom ver material para novos usuários, tão importante quanto para usuários avançados pois serve de convite para conhecer o sistema.Acesse o link original em http://blog.bibliotecaunix.org/?p=217 (http://blog.bibliotecaunix.org/?p=217)

FUG-BR disponibiliza Keyserver GnuPGP.

A FUG-BR passa a disponibilizar à comunidade seu próprio servidor de chaves PGP. O servidor encontra-se em sincronia com os principais servidores do mundo e faz troca de chaves. Portanto sua chave submetida ou atualizada no servidor PGP da FUG-BR é refletida nos principais enderecos PGP. Sei que quem usa cryptografia no dia a dia sempre tem seu servidor de chaves preferido, mas fica aqui a dica caso queira prestigiar o servidor da FUG-BR :) -- convida Edson Brandi.O servidor pode ser acessado em: http://keyserver.fug.com.br:11371/ (http://keyserver.fug.com.br:11371/)

Brincando com vnet em Jail no FreeBSD

Este tutorial é uma serie de dicas e comandos para gerenciar Jails com o novo esquema de emulação de rede que ainda esta experimental no FreeBSD. Mas já é possível usar as features que o mesmo oferece e criar um ambiente totalmente personalizado com firewall e ferramentas de diagnósticos de rede dentro de uma jail. Uma ótima definição sobre Jail esta disponível no Wikipedia no endereço: http://pt.wikipedia.org/wiki/FreeBSD_jail (http://pt.wikipedia.org/wiki/FreeBSD_jail) Para iniciar-mos o tutorial, precisamos como pre-requisito que você conheça como recompilar o kernel do FreeBSD, tarefa ao qual existem bons documentos disponíveis, a começar pelo o Handbook (http://www.freebsd.org/doc/en_US.ISO8859-1/books/handbook/). Leia mais… (http://www.luizgustavo.pro.br/blog/2010/07/29/brincando-com-vnet-em-jail-no-freebsd/#more-592)

Fundado em software BSD, nasce o DuckDuckGo (dukgo).

Nasce o Duck Duck Go (https://duckduckgo.com/) (a busca do Pato), engine de busca que ataca o mercado do Google, se anuncia como mais eficiente (https://duckduckgo.com/about.html), mais rápido e com muito mais recursos (https://duckduckgo.com/goodies.html) e mais respeito à privacidade do usuário. Para nós o relevante é constatar que além de desenvolvido sob base Open Source, fundamenta sua tecnologia essencialmente em software de Licença BSD ou derivados, como:Sistema Operacional FreeBSD (BSD) Banco de Dados PostgreSQL (BSD)NGinx Reverse Proxy (BSD)Memcached (BSD)Solr (Apache 2.0, derivada BSD)Perl (Artistic License)Acesso rápido ao site em http://dukgo.com/ (http://dukgo.com%20%20)

Web site Grupo Brasileiro de Usuarios FreeBSD Noticias do Web site FUG-BR
FreeBSD Servindo 30% da Internet Mundial (aka FreeBSD & Netflix)

FreeBSD Servindo 30% da Internet Mundial: Não, essa notícia não é da década de 90. É de 2012. Recentemente nessa Thread (historico/html/freebsd/2012-06/threads.html#00043) da Lista da FUG-BR, comentou-se a notícia que o Netflix usa FreeBSD em sua infra-estrutura de Rede de Distribuição de Conteúdo. A informação havia sido mencionada anteriormente pelo Scott Long, desenvolvedor BSD (e FreeBSD) de longa data, que anunciou antes ter saído do Yahoo! para trabalhar no Netflix.Formalmente o uso de FreeBSD, combinado com servidores commoditie e o webserver Nginx foi informado quando o Netflix anunciou o lançamento de seu Appliace OpenConnect, que o próprio Netflix colocará nos principais Pontos de Troca de Tráfego da Internet e grandes provedores de acesso Internet sem custo para os provedores. Aqui no Brasil Netflix chega com seu Appliace OpenConnect primeiro no PTT-SP e em seguida em alguns provedores que tenho o prazer de atender como clientes da FreeBSD Brasil (http://www.freebsdbrasil.com.br).Mas o que realmente significa dizer que FreeBSD é usado no coração operacional do Netflix?Em 2011 o Netflix passou a representar 32% de todo o tráfego da Internet na América do Norte em horários de pico. E em 2012, 29% da Internet na Europa em horários de pico. Ainda em 2011 a demanda por conteúdo servido pelo Netflix/FreeBSD foi tão grande que os provedores Canadenses e Americamos começaram a reclamar da falta de capacidade e capilaridade para tanto tráfego com esse novo perfil de consumo de banda, na mesma época que Netflix ultrapassou a Apple no segmento de entrega de conteúdo multimídia sob demanda. Foi quando Netflix começou a expandir seu projeto de appliance Open Connect para colocar seu conteúdo mais perto dos provedores e clientes e onerar menos a infra-estrutura de conectividade desses ISP.No passado apenas o Yahoo! na década de 90 havia conseguido essa marca, de representar 30% de toda a Internet mundial. Hoje o Netflix representa 32% da América do Norte e 29% da Europa como mencionado em diveras fontes (procure no Google pela sua preferida), as informações mais recentes são da Arbor Networks. Não é, oficialmente toda a Internet, mas sabemos que América do Norte e Europa representa a fatia mais relevante da Internet.No passado era FreeBSD quem servia 30% de todo o tráfego da Internet, através do Yahoo!, e um pouco mais através do mp3.com, NTT Verio, America Online e outros grandes nomes do início da bolha da Internet comercial nos anos 90. Mas quem vive de passado é museu, correto? Pois bem, e hoje, em pleno 2012, décadas depois, FreeBSD novamente está servindo 1/3 da Internet mundial em horários de pico.Isso mostra que o tempo passou, mas o FreeBSD continua poderoso igual, importante igual, e ao mesmo tempo pouco conhecido e amplamente utilizado nas principais operações de missão crítica da Internet, tudo exatamente como era na época do FreeBSD 2, FreeBSD 3, só que agora no FreeBSD 9.Desde o TCP/IP, coração da Internet, lançado no 4BSD, até o DNS, e-mail, até os Root Name Servers e Refletores de Rota BGP nos pontos de troca de tráfego de Ashburn, Virginia, Los Angeles, Seattle e Milão, desde o boom do Yahoo ao boom do Netflix, o mesmo FreeBSD continua carregando a Internet nas costas... Nos anos 90, 30% da Internet era uma coisa. Em 2012, os mesmos 30% são outra coisa... são alguns Mbit/s a mais. Mostrando que a evolução do FreeBSD é constante, contínua. E você acha que Netflix é algo novo? A empresa existe de 1997, usa FreeBSD desde 1997, mas sem a mesma finalidade. Netflix era uma empresa de aluguel de DVD por correios, o serviço de entrega de conteúdo online começou a crescer em 2007 apenas, alcançando clientes mundo afora. Mas e daí? Você se pergunta... pois bem, outro software de licença BSD tem seu poder exposto pelo Netflix, o Nginx. Dê uma olhada nesse gráfico da Netcraft:http://news.netcraft.com/archives/2012/07/03/july-2012-web-server-survey.html (http://news.netcraft.com/archives/2012/07/03/july-2012-web-server-survey.html)Esse gráfico é o levantamento mais recente do uso de web servers no mundo. Vê a linha verde que começar surgir entre 2007 e 2008 e hoje é tão expressivo seu volume que começa ameaçar o IIS da Microsoft? É graças ao Netflix que o Nginx, Web Server e Inbound Proxy de licença BSD se tornou o terceiro mais utilizado da Internet.Abaixo alguns links sobre o assunto, para enquiquecer sua leitura:http://forums.freebsd.org/showthread.php?t=32558 (http://forums.freebsd.org/showthread.php?t=32558) http://lists.freebsd.org/pipermail/freebsd-stable/2012-June/068129.html (http://lists.freebsd.org/pipermail/freebsd-stable/2012-June/068129.html)http://adrianchadd.blogspot.com.br/2012/06/freebsd-netflix-cdn.html (http://adrianchadd.blogspot.com.br/2012/06/freebsd-netflix-cdn.html) http://www.h-online.com/open/news/item/Netflix-announces-Open-Connect-CDN-1612094.html (http://www.h-online.com/open/news/item/Netflix-announces-Open-Connect-CDN-1612094.html)http://www.pcmag.com/article2/0,2817,2395372,00.asp (http://www.pcmag.com/article2/0,2817,2395372,00.asp)https://signup.netflix.com/openconnect/software (https://signup.netflix.com/openconnect/software)

Andrew Tanenbaum: BSD dominaria o mundo, se no fosse pelo processo da AT&T.;

O site LinuxFr.org está produzindo uma entrevista (em francês) (http://linuxfr.org/news/entretien-avec-andrew-tanenbaum-%C3%A0-propos-de-minix) com o autor, desenvolvedor e pesquisador Andrew Tanenbaum, (em inglês (http://linuxfr.org/nodes/88229/comments/1291183)). Nessa entrevista o mundialmente conhecido autor, referência bibliográfica em 8 em cada 10 trabalhos científicos de graduação e pós em nosso país, fala sobre BSD, sobre Linux, Linus Torvalds e critica a licença GPL, kernel de arquitetura monolítica, entre diversas outras opiniões que podem ser relevantes para muitos, vindas deste autor.Uma notícia curiosa é que Tanenbaum recebeu um financiamento para comercializar o MINIX 3 e em Janeiro ele começa a portar o sistema para arquitetura ARM.Mas o que salta aos olhos é sua opinião de superioridade do BSD sobre Linux e a atribuição a não dominação mundial do BSD ao processo da AT T: A razão pela qual MINIX3 não dominou o mundo é relacionada a um erro que cometi em 1992. Naquela época acreditei que o BSD é que dominaria o mundo! Já era um sistema maduro e estável. Eu não via razão alguma para querer competir com ele, então coloquei o foco acadêmico no MINIX. Quatro dos caras que desenvolviam o BSD formaram uma compania para vender o BSD comercialmente. Tinham até um número telefone bacana, 1-800-ITS-UNIX. Esse telefone os colocou (bem como a mim) pra dentro do mercado. A AT T os processou por causa desse número e o processo levou mais de 3 anos para ser resolvido. Esse era o período preciso em que Linux foi lançado e o BSD ficou estagnado devido ao processo jurídico. Quando foi resolvido Linux já tinha decolado. Meu erro foi não perceber que o processo levaria tanto tempo. Se a AT T não tivesse gerado esse processo (e comprado parte da BSDI depois), Linux nunca seria popular e o BSD dominaria o mundo! Mas Tanenbaum, hoje a tecnologia BSD está presente nos mais populares telefones celulares e tablets do mundo. A tecnologia BSD está embarcada em televisores, satélites. O TCP/IP revolucionou o mundo, a Internet em si, desde o protocolo, os refletores de rota T1 nos core-IXP americanos e europeus, os protocolos de comunicação como e-mail evoluídos do Fetchmail do Eric Allman, a resolução DNS padronizada no Berkeley Internet Name Domain system (BIND) e utilizada até hoje nos Root-NS tal qual criada por 4 alunos de Berkeley, o sistema que equipa Juniper, parte dos produtos Cisco (e portanto a infra-estrutura basica de cada rede), até o trabalho do IPv6 Samurai, Itojun, a criptografia do IPSEC, até algorítimos alternativos de enfileiramente de pacotes como HFSC, CBQ, PRIQ, WFQ que influenciam a priorização de tráfego no mundo. O sistema de controle de vôo da Boing (que cai bem menos que AirBus, a francesa reconhecidamente usa Linux), os sistemas militares baseados em XTS400, protocolos futuros como SCTP, processamento GPU, a própria Web, criada em um sistema híbrido 4.4-BSD pelo Tim Berners-Lee, o TrustedBSD finalmente implementando 30 anos de requisitos do Orange Book, o jemalloc() utilizado no Firefox, Microsoft Office e outras tecnologias, Zero Copy net, o primeiro driver open source do LTE, do 802.11s, Capsicum, os I/O Schedulers que até hoje não existiam mesmo sendo uma necessidade básica de sistemas de armazenamento, a gerência de memória, a memória virtual, o conceito de inodes e todo sistema de arquivos como conhecemos hoje, baseados em varições do UFS; o OpenSSL do https nosso de cada dia, de cada sessão de home banking, home broker e e-commerce; o OpenSSH de 9 em cada 10 sessões ssh do planeta; a alocação de páginas não constante de memória (super pages), até a pilha IP do Windows, Tanenbaum.Por tudo isso que move o mundo há décadas e por tudo que já existia e existe a frente de seu tempo (IPv6, SCTP, GPU Accel, SPages), Tanenbaum, só podemos concluir que você não errou. O BSD domina o mundo, mas em sua mais pura forma, a tecnológica. Talvez o BSD não seja o sistema mais popular do mundo (mas é o mais desejado, afinal quantos ai realmente prefere XYZ a um celular com iOS? Quem prefere um Dell com Windão a um Mac Book Pro com Mac OS X com aceleração GPU?), mas a tecnologia BSD tem sim dominado o mundo há décadas, tem tornado cada navegada nossa de cada possível, cada ligação telefônica móvel, cada e-mail viável, e se apresenta hoje anos ainda a frente, tornando disponível hoje o que provavelmente só será utilizado daqui bons anos.O processo diminuiu a taxa de ação de sistemas BSD mas ajudou a fragmentar a tecnologia BSD, e hoje ela está em lugares óbvios e outros que sequer conseguimos suspeitar. BSD não dominaria o mundo, Tanenbaum, BSD domina, você não errou o fato, errou o escopo, que é tecnológico e não operacional.Até mascote de sistemas tecnológicos é uma inovação BSD. Não haveriam penguins e peixes rechonchudos, ornitorrincos endiabrados, droidzinhos mecânicos, se não fosse pelo Beastie. Mas lógico que com o diferencial, além de mais expressivo e simpático, só nosso mascote é assinado por um gênio da animação (John Lasseter) e copyrighted por um gênio da ciência da computação (McKusick).

Infra-estrutura (FreeBSD) Unix no (Mac) OS X

No dia 01/03 o Renato (http://www.twitter.com/deadrop) me convidou pra escrever um pouco da relação Unix-BSD-OSX, pra série de artigos de segurança sendo divulgados pela IDS Tecnologia (http://www.ids.com.br/) na MacMagazine (http://www.macmagazine.com.br/). Escrevi um artigo um tanto extenso, que foi condensado propriamente ao ser publicado na MacMagazine (clique pra ver) (http://macmagazine.com.br/2012/03/01/seguranca-no-mundo-apple-infraestrutura-unix/), e partes dele serão reutilizados ao longo dos demais artigos. No entanto em particular tive pedidos pelo artigo na íntegra, então segue ele postado aqui na FUG também, espero que gostem :-) Pessoalmente gosto muito desse trecho da história dos BSD em geral e acaba ilustrando como a guerra jurídica que o CSRG/Berkeley sofreu por parte da USL/AT T quando a segunda processou Berkeley por conta dos 6 arquivos AT T restantes no BSD Unix. Lógico que pro mundo BSD foi uma passagem terrível, retardou a adoção de sistemas BSD e liberdade Open Source do código BSD. Mas teve seus lados positivos, como Torvalds e seu kernel baseado no Minix quando ele ficou inseguro ao usar o 386BSD, e nessa passagem outro ponto positivo, a criação do Mach pela universidade de Carnegie Mellon como uma alternativa ao BSD sob base BSD, posteriormente aproveitados no NeXT Step.Segue então o conteúdo, na íntegra, abaixo.

Alta Disponibilidade de Link

IntroduçãoMuitas vezes, provedores de internet ou até mesmo empresas, não têm 2 servidores para ter uma alta disponibilidade de link e servidor. E com isso, eles apenas garantem a disponibilidade de link em único servidor, isso garante que o usuário não vá ligar reclamando que não consegue navegar e bla bla bla, caso o link principal venha ficar indisponível.Para fazer isso, vou usar 2 ferramentas no FreeBSD, uma vai ser o Ifstated para fazer o monitoramento dos link e alterar a rota. E a outra vai ser o Packet Filter, o famoso PF.Caso o link venha ficar indisponível, o Ifstated vai alterar a rota para o outro link.Caso o link indisponível venha ficar disponível automaticamente, a rota vai voltar para a rota default, para o link principal.Já com o PF, vou usar para criar os NAT dos clientes em uma única linha. Ele também pode ser usado como Firewall, redundância de link (round-robin ou source-hash), redirecionamento de portas, e etc.Vamos ao trabalho. Clique abaixo para continuar lendo o artigo todo.

FreeBSD: mais rpido que Linux, at pra rodar binrios de Linux.

Phoronix confirma o que todos usuários FreeBSD que também usam Linux já sabiam, por experiência própria, as vezes com evidências, outras vezes apenas sensação tecnicamente infundada: FreeBSD consegue ser mais rápido que Linux até pra rodar binários... de Linux!Normalmente essa sensação de maior performance acontece em ambientes como banco de dados Oracle, aplicações mais simples como clientes de peer-to-peer com versão disponível apenas para Linux, e muitos outros. Acontece que mesmo a hipótese de melhor performance no FreeBSD pra rodar binários nativos Linux ser documentada até no FreeBSD Handbook, apesar dos usuários da FUG-BR de tempos em tempos enviarem alguns testemunhos com suas impressões, muitas vezes acompanhados de testes e evidências, ninguém não ligado ao desenvolvimento do FreeBSD tinha documentado testes e resultados nesse ponto.O Phoronix o fez e publicou aqui: http://www.phoronix.com/scan.php?page=article item=linux_games_bsd (http://www.phoronix.com/scan.php?page=article item=linux_games_bsd)A curiosidade é ainda mais inusitada: os testes foram feitos com jogos. Um cenário onde FreeBSD sai em completa desvantagem em modo de compatibilidade pois aceleração gráfica e outros quesitos demandam apoio do kernel em renderizações 3D, efeitos OpenGL e afins. Envolver uma camada de abstração para compatibilidade binária que dê acesso a recursos além do básico, memória, disco, CPU, e envolver aceleração gráfica 3D por si só é algo que o Projeto FreeBSD simplesmente não foca, nem testa performance.Só que o resultado ainda em cenário tão desfavorável foi em média 14% de performance a mais no FreeBSD que no Linux, pros jogos de Linux.Curiosamente foram testados PC-BSD e Ubuntu, as plataformas Linux e FreeBSD mais fáceis de usar.Outro fato importante: os testes envolveram plataformas 32 bits e 64bits, e mesmo a compat binária com Linux em 64bits que é muito nova no FreeBSD, supera Linux em 64bits.O artigo começa com uma introdução sobre o modo de compatibilidade binária do FreeBSD, tece alguns comentários e entra pra uma série de benchmarks comentados.Boa leitura.

FreeBSD 9 - Novo Instalador

Em mais uma boa contribuição em vídeo, Brivaldo apresenta o novo instalador do FreeBSD.O primeiro build de testes do FreeBSD-9.0 está disponível para download. Foram geradas imagens para as arquiteturas: amd64, i386, ia64, powerpc, powerpc64, e sparc64 que estão disponíveis nos espelhos do FreeBSD. Uma das funcionalidades mais interessantes na versão 9.0 é o novo instalador e é encorajado a todos realizar uma instalação limpa em seus sistemas de teste para verificar por problemas de instalação. Acompanhe o post original em http://blog.bibliotecaunix.org/?p=537 (http://blog.bibliotecaunix.org/?p=537)

Perdendo o medo da Instalao do FreeBSD

Nesse screencast, Brivaldo Júnior demonstra a instalação do FreeBSD de forma simples e direta. É um vídeo voltado aos novos usuários FreeBSD ou ainda não usuários, para afastar mitos e medos. Muito bom ver material para novos usuários, tão importante quanto para usuários avançados pois serve de convite para conhecer o sistema.Acesse o link original em http://blog.bibliotecaunix.org/?p=217 (http://blog.bibliotecaunix.org/?p=217)

FUG-BR disponibiliza Keyserver GnuPGP.

A FUG-BR passa a disponibilizar à comunidade seu próprio servidor de chaves PGP. O servidor encontra-se em sincronia com os principais servidores do mundo e faz troca de chaves. Portanto sua chave submetida ou atualizada no servidor PGP da FUG-BR é refletida nos principais enderecos PGP. Sei que quem usa cryptografia no dia a dia sempre tem seu servidor de chaves preferido, mas fica aqui a dica caso queira prestigiar o servidor da FUG-BR :) -- convida Edson Brandi.O servidor pode ser acessado em: http://keyserver.fug.com.br:11371/ (http://keyserver.fug.com.br:11371/)

Brincando com vnet em Jail no FreeBSD

Este tutorial é uma serie de dicas e comandos para gerenciar Jails com o novo esquema de emulação de rede que ainda esta experimental no FreeBSD. Mas já é possível usar as features que o mesmo oferece e criar um ambiente totalmente personalizado com firewall e ferramentas de diagnósticos de rede dentro de uma jail. Uma ótima definição sobre Jail esta disponível no Wikipedia no endereço: http://pt.wikipedia.org/wiki/FreeBSD_jail (http://pt.wikipedia.org/wiki/FreeBSD_jail) Para iniciar-mos o tutorial, precisamos como pre-requisito que você conheça como recompilar o kernel do FreeBSD, tarefa ao qual existem bons documentos disponíveis, a começar pelo o Handbook (http://www.freebsd.org/doc/en_US.ISO8859-1/books/handbook/). Leia mais… (http://www.luizgustavo.pro.br/blog/2010/07/29/brincando-com-vnet-em-jail-no-freebsd/#more-592)

Fundado em software BSD, nasce o DuckDuckGo (dukgo).

Nasce o Duck Duck Go (https://duckduckgo.com/) (a busca do Pato), engine de busca que ataca o mercado do Google, se anuncia como mais eficiente (https://duckduckgo.com/about.html), mais rápido e com muito mais recursos (https://duckduckgo.com/goodies.html) e mais respeito à privacidade do usuário. Para nós o relevante é constatar que além de desenvolvido sob base Open Source, fundamenta sua tecnologia essencialmente em software de Licença BSD ou derivados, como:Sistema Operacional FreeBSD (BSD) Banco de Dados PostgreSQL (BSD)NGinx Reverse Proxy (BSD)Memcached (BSD)Solr (Apache 2.0, derivada BSD)Perl (Artistic License)Acesso rápido ao site em http://dukgo.com/ (http://dukgo.com%20%20)

Web site Grupo Brasileiro de Usuarios FreeBSD Noticias do Web site FUG-BR
FreeBSD Servindo 30% da Internet Mundial (aka FreeBSD & Netflix)

FreeBSD Servindo 30% da Internet Mundial: Não, essa notícia não é da década de 90. É de 2012. Recentemente nessa Thread (historico/html/freebsd/2012-06/threads.html#00043) da Lista da FUG-BR, comentou-se a notícia que o Netflix usa FreeBSD em sua infra-estrutura de Rede de Distribuição de Conteúdo. A informação havia sido mencionada anteriormente pelo Scott Long, desenvolvedor BSD (e FreeBSD) de longa data, que anunciou antes ter saído do Yahoo! para trabalhar no Netflix.Formalmente o uso de FreeBSD, combinado com servidores commoditie e o webserver Nginx foi informado quando o Netflix anunciou o lançamento de seu Appliace OpenConnect, que o próprio Netflix colocará nos principais Pontos de Troca de Tráfego da Internet e grandes provedores de acesso Internet sem custo para os provedores. Aqui no Brasil Netflix chega com seu Appliace OpenConnect primeiro no PTT-SP e em seguida em alguns provedores que tenho o prazer de atender como clientes da FreeBSD Brasil (http://www.freebsdbrasil.com.br).Mas o que realmente significa dizer que FreeBSD é usado no coração operacional do Netflix?Em 2011 o Netflix passou a representar 32% de todo o tráfego da Internet na América do Norte em horários de pico. E em 2012, 29% da Internet na Europa em horários de pico. Ainda em 2011 a demanda por conteúdo servido pelo Netflix/FreeBSD foi tão grande que os provedores Canadenses e Americamos começaram a reclamar da falta de capacidade e capilaridade para tanto tráfego com esse novo perfil de consumo de banda, na mesma época que Netflix ultrapassou a Apple no segmento de entrega de conteúdo multimídia sob demanda. Foi quando Netflix começou a expandir seu projeto de appliance Open Connect para colocar seu conteúdo mais perto dos provedores e clientes e onerar menos a infra-estrutura de conectividade desses ISP.No passado apenas o Yahoo! na década de 90 havia conseguido essa marca, de representar 30% de toda a Internet mundial. Hoje o Netflix representa 32% da América do Norte e 29% da Europa como mencionado em diveras fontes (procure no Google pela sua preferida), as informações mais recentes são da Arbor Networks. Não é, oficialmente toda a Internet, mas sabemos que América do Norte e Europa representa a fatia mais relevante da Internet.No passado era FreeBSD quem servia 30% de todo o tráfego da Internet, através do Yahoo!, e um pouco mais através do mp3.com, NTT Verio, America Online e outros grandes nomes do início da bolha da Internet comercial nos anos 90. Mas quem vive de passado é museu, correto? Pois bem, e hoje, em pleno 2012, décadas depois, FreeBSD novamente está servindo 1/3 da Internet mundial em horários de pico.Isso mostra que o tempo passou, mas o FreeBSD continua poderoso igual, importante igual, e ao mesmo tempo pouco conhecido e amplamente utilizado nas principais operações de missão crítica da Internet, tudo exatamente como era na época do FreeBSD 2, FreeBSD 3, só que agora no FreeBSD 9.Desde o TCP/IP, coração da Internet, lançado no 4BSD, até o DNS, e-mail, até os Root Name Servers e Refletores de Rota BGP nos pontos de troca de tráfego de Ashburn, Virginia, Los Angeles, Seattle e Milão, desde o boom do Yahoo ao boom do Netflix, o mesmo FreeBSD continua carregando a Internet nas costas... Nos anos 90, 30% da Internet era uma coisa. Em 2012, os mesmos 30% são outra coisa... são alguns Mbit/s a mais. Mostrando que a evolução do FreeBSD é constante, contínua. E você acha que Netflix é algo novo? A empresa existe de 1997, usa FreeBSD desde 1997, mas sem a mesma finalidade. Netflix era uma empresa de aluguel de DVD por correios, o serviço de entrega de conteúdo online começou a crescer em 2007 apenas, alcançando clientes mundo afora. Mas e daí? Você se pergunta... pois bem, outro software de licença BSD tem seu poder exposto pelo Netflix, o Nginx. Dê uma olhada nesse gráfico da Netcraft:http://news.netcraft.com/archives/2012/07/03/july-2012-web-server-survey.html (http://news.netcraft.com/archives/2012/07/03/july-2012-web-server-survey.html)Esse gráfico é o levantamento mais recente do uso de web servers no mundo. Vê a linha verde que começar surgir entre 2007 e 2008 e hoje é tão expressivo seu volume que começa ameaçar o IIS da Microsoft? É graças ao Netflix que o Nginx, Web Server e Inbound Proxy de licença BSD se tornou o terceiro mais utilizado da Internet.Abaixo alguns links sobre o assunto, para enquiquecer sua leitura:http://forums.freebsd.org/showthread.php?t=32558 (http://forums.freebsd.org/showthread.php?t=32558) http://lists.freebsd.org/pipermail/freebsd-stable/2012-June/068129.html (http://lists.freebsd.org/pipermail/freebsd-stable/2012-June/068129.html)http://adrianchadd.blogspot.com.br/2012/06/freebsd-netflix-cdn.html (http://adrianchadd.blogspot.com.br/2012/06/freebsd-netflix-cdn.html) http://www.h-online.com/open/news/item/Netflix-announces-Open-Connect-CDN-1612094.html (http://www.h-online.com/open/news/item/Netflix-announces-Open-Connect-CDN-1612094.html)http://www.pcmag.com/article2/0,2817,2395372,00.asp (http://www.pcmag.com/article2/0,2817,2395372,00.asp)https://signup.netflix.com/openconnect/software (https://signup.netflix.com/openconnect/software)

Andrew Tanenbaum: BSD dominaria o mundo, se no fosse pelo processo da AT&T.;

O site LinuxFr.org está produzindo uma entrevista (em francês) (http://linuxfr.org/news/entretien-avec-andrew-tanenbaum-%C3%A0-propos-de-minix) com o autor, desenvolvedor e pesquisador Andrew Tanenbaum, (em inglês (http://linuxfr.org/nodes/88229/comments/1291183)). Nessa entrevista o mundialmente conhecido autor, referência bibliográfica em 8 em cada 10 trabalhos científicos de graduação e pós em nosso país, fala sobre BSD, sobre Linux, Linus Torvalds e critica a licença GPL, kernel de arquitetura monolítica, entre diversas outras opiniões que podem ser relevantes para muitos, vindas deste autor.Uma notícia curiosa é que Tanenbaum recebeu um financiamento para comercializar o MINIX 3 e em Janeiro ele começa a portar o sistema para arquitetura ARM.Mas o que salta aos olhos é sua opinião de superioridade do BSD sobre Linux e a atribuição a não dominação mundial do BSD ao processo da AT T: A razão pela qual MINIX3 não dominou o mundo é relacionada a um erro que cometi em 1992. Naquela época acreditei que o BSD é que dominaria o mundo! Já era um sistema maduro e estável. Eu não via razão alguma para querer competir com ele, então coloquei o foco acadêmico no MINIX. Quatro dos caras que desenvolviam o BSD formaram uma compania para vender o BSD comercialmente. Tinham até um número telefone bacana, 1-800-ITS-UNIX. Esse telefone os colocou (bem como a mim) pra dentro do mercado. A AT T os processou por causa desse número e o processo levou mais de 3 anos para ser resolvido. Esse era o período preciso em que Linux foi lançado e o BSD ficou estagnado devido ao processo jurídico. Quando foi resolvido Linux já tinha decolado. Meu erro foi não perceber que o processo levaria tanto tempo. Se a AT T não tivesse gerado esse processo (e comprado parte da BSDI depois), Linux nunca seria popular e o BSD dominaria o mundo! Mas Tanenbaum, hoje a tecnologia BSD está presente nos mais populares telefones celulares e tablets do mundo. A tecnologia BSD está embarcada em televisores, satélites. O TCP/IP revolucionou o mundo, a Internet em si, desde o protocolo, os refletores de rota T1 nos core-IXP americanos e europeus, os protocolos de comunicação como e-mail evoluídos do Fetchmail do Eric Allman, a resolução DNS padronizada no Berkeley Internet Name Domain system (BIND) e utilizada até hoje nos Root-NS tal qual criada por 4 alunos de Berkeley, o sistema que equipa Juniper, parte dos produtos Cisco (e portanto a infra-estrutura basica de cada rede), até o trabalho do IPv6 Samurai, Itojun, a criptografia do IPSEC, até algorítimos alternativos de enfileiramente de pacotes como HFSC, CBQ, PRIQ, WFQ que influenciam a priorização de tráfego no mundo. O sistema de controle de vôo da Boing (que cai bem menos que AirBus, a francesa reconhecidamente usa Linux), os sistemas militares baseados em XTS400, protocolos futuros como SCTP, processamento GPU, a própria Web, criada em um sistema híbrido 4.4-BSD pelo Tim Berners-Lee, o TrustedBSD finalmente implementando 30 anos de requisitos do Orange Book, o jemalloc() utilizado no Firefox, Microsoft Office e outras tecnologias, Zero Copy net, o primeiro driver open source do LTE, do 802.11s, Capsicum, os I/O Schedulers que até hoje não existiam mesmo sendo uma necessidade básica de sistemas de armazenamento, a gerência de memória, a memória virtual, o conceito de inodes e todo sistema de arquivos como conhecemos hoje, baseados em varições do UFS; o OpenSSL do https nosso de cada dia, de cada sessão de home banking, home broker e e-commerce; o OpenSSH de 9 em cada 10 sessões ssh do planeta; a alocação de páginas não constante de memória (super pages), até a pilha IP do Windows, Tanenbaum.Por tudo isso que move o mundo há décadas e por tudo que já existia e existe a frente de seu tempo (IPv6, SCTP, GPU Accel, SPages), Tanenbaum, só podemos concluir que você não errou. O BSD domina o mundo, mas em sua mais pura forma, a tecnológica. Talvez o BSD não seja o sistema mais popular do mundo (mas é o mais desejado, afinal quantos ai realmente prefere XYZ a um celular com iOS? Quem prefere um Dell com Windão a um Mac Book Pro com Mac OS X com aceleração GPU?), mas a tecnologia BSD tem sim dominado o mundo há décadas, tem tornado cada navegada nossa de cada possível, cada ligação telefônica móvel, cada e-mail viável, e se apresenta hoje anos ainda a frente, tornando disponível hoje o que provavelmente só será utilizado daqui bons anos.O processo diminuiu a taxa de ação de sistemas BSD mas ajudou a fragmentar a tecnologia BSD, e hoje ela está em lugares óbvios e outros que sequer conseguimos suspeitar. BSD não dominaria o mundo, Tanenbaum, BSD domina, você não errou o fato, errou o escopo, que é tecnológico e não operacional.Até mascote de sistemas tecnológicos é uma inovação BSD. Não haveriam penguins e peixes rechonchudos, ornitorrincos endiabrados, droidzinhos mecânicos, se não fosse pelo Beastie. Mas lógico que com o diferencial, além de mais expressivo e simpático, só nosso mascote é assinado por um gênio da animação (John Lasseter) e copyrighted por um gênio da ciência da computação (McKusick).

Infra-estrutura (FreeBSD) Unix no (Mac) OS X

No dia 01/03 o Renato (http://www.twitter.com/deadrop) me convidou pra escrever um pouco da relação Unix-BSD-OSX, pra série de artigos de segurança sendo divulgados pela IDS Tecnologia (http://www.ids.com.br/) na MacMagazine (http://www.macmagazine.com.br/). Escrevi um artigo um tanto extenso, que foi condensado propriamente ao ser publicado na MacMagazine (clique pra ver) (http://macmagazine.com.br/2012/03/01/seguranca-no-mundo-apple-infraestrutura-unix/), e partes dele serão reutilizados ao longo dos demais artigos. No entanto em particular tive pedidos pelo artigo na íntegra, então segue ele postado aqui na FUG também, espero que gostem :-) Pessoalmente gosto muito desse trecho da história dos BSD em geral e acaba ilustrando como a guerra jurídica que o CSRG/Berkeley sofreu por parte da USL/AT T quando a segunda processou Berkeley por conta dos 6 arquivos AT T restantes no BSD Unix. Lógico que pro mundo BSD foi uma passagem terrível, retardou a adoção de sistemas BSD e liberdade Open Source do código BSD. Mas teve seus lados positivos, como Torvalds e seu kernel baseado no Minix quando ele ficou inseguro ao usar o 386BSD, e nessa passagem outro ponto positivo, a criação do Mach pela universidade de Carnegie Mellon como uma alternativa ao BSD sob base BSD, posteriormente aproveitados no NeXT Step.Segue então o conteúdo, na íntegra, abaixo.

Alta Disponibilidade de Link

IntroduçãoMuitas vezes, provedores de internet ou até mesmo empresas, não têm 2 servidores para ter uma alta disponibilidade de link e servidor. E com isso, eles apenas garantem a disponibilidade de link em único servidor, isso garante que o usuário não vá ligar reclamando que não consegue navegar e bla bla bla, caso o link principal venha ficar indisponível.Para fazer isso, vou usar 2 ferramentas no FreeBSD, uma vai ser o Ifstated para fazer o monitoramento dos link e alterar a rota. E a outra vai ser o Packet Filter, o famoso PF.Caso o link venha ficar indisponível, o Ifstated vai alterar a rota para o outro link.Caso o link indisponível venha ficar disponível automaticamente, a rota vai voltar para a rota default, para o link principal.Já com o PF, vou usar para criar os NAT dos clientes em uma única linha. Ele também pode ser usado como Firewall, redundância de link (round-robin ou source-hash), redirecionamento de portas, e etc.Vamos ao trabalho. Clique abaixo para continuar lendo o artigo todo.

FreeBSD: mais rpido que Linux, at pra rodar binrios de Linux.

Phoronix confirma o que todos usuários FreeBSD que também usam Linux já sabiam, por experiência própria, as vezes com evidências, outras vezes apenas sensação tecnicamente infundada: FreeBSD consegue ser mais rápido que Linux até pra rodar binários... de Linux!Normalmente essa sensação de maior performance acontece em ambientes como banco de dados Oracle, aplicações mais simples como clientes de peer-to-peer com versão disponível apenas para Linux, e muitos outros. Acontece que mesmo a hipótese de melhor performance no FreeBSD pra rodar binários nativos Linux ser documentada até no FreeBSD Handbook, apesar dos usuários da FUG-BR de tempos em tempos enviarem alguns testemunhos com suas impressões, muitas vezes acompanhados de testes e evidências, ninguém não ligado ao desenvolvimento do FreeBSD tinha documentado testes e resultados nesse ponto.O Phoronix o fez e publicou aqui: http://www.phoronix.com/scan.php?page=article item=linux_games_bsd (http://www.phoronix.com/scan.php?page=article item=linux_games_bsd)A curiosidade é ainda mais inusitada: os testes foram feitos com jogos. Um cenário onde FreeBSD sai em completa desvantagem em modo de compatibilidade pois aceleração gráfica e outros quesitos demandam apoio do kernel em renderizações 3D, efeitos OpenGL e afins. Envolver uma camada de abstração para compatibilidade binária que dê acesso a recursos além do básico, memória, disco, CPU, e envolver aceleração gráfica 3D por si só é algo que o Projeto FreeBSD simplesmente não foca, nem testa performance.Só que o resultado ainda em cenário tão desfavorável foi em média 14% de performance a mais no FreeBSD que no Linux, pros jogos de Linux.Curiosamente foram testados PC-BSD e Ubuntu, as plataformas Linux e FreeBSD mais fáceis de usar.Outro fato importante: os testes envolveram plataformas 32 bits e 64bits, e mesmo a compat binária com Linux em 64bits que é muito nova no FreeBSD, supera Linux em 64bits.O artigo começa com uma introdução sobre o modo de compatibilidade binária do FreeBSD, tece alguns comentários e entra pra uma série de benchmarks comentados.Boa leitura.

FreeBSD 9 - Novo Instalador

Em mais uma boa contribuição em vídeo, Brivaldo apresenta o novo instalador do FreeBSD.O primeiro build de testes do FreeBSD-9.0 está disponível para download. Foram geradas imagens para as arquiteturas: amd64, i386, ia64, powerpc, powerpc64, e sparc64 que estão disponíveis nos espelhos do FreeBSD. Uma das funcionalidades mais interessantes na versão 9.0 é o novo instalador e é encorajado a todos realizar uma instalação limpa em seus sistemas de teste para verificar por problemas de instalação. Acompanhe o post original em http://blog.bibliotecaunix.org/?p=537 (http://blog.bibliotecaunix.org/?p=537)

Perdendo o medo da Instalao do FreeBSD

Nesse screencast, Brivaldo Júnior demonstra a instalação do FreeBSD de forma simples e direta. É um vídeo voltado aos novos usuários FreeBSD ou ainda não usuários, para afastar mitos e medos. Muito bom ver material para novos usuários, tão importante quanto para usuários avançados pois serve de convite para conhecer o sistema.Acesse o link original em http://blog.bibliotecaunix.org/?p=217 (http://blog.bibliotecaunix.org/?p=217)

FUG-BR disponibiliza Keyserver GnuPGP.

A FUG-BR passa a disponibilizar à comunidade seu próprio servidor de chaves PGP. O servidor encontra-se em sincronia com os principais servidores do mundo e faz troca de chaves. Portanto sua chave submetida ou atualizada no servidor PGP da FUG-BR é refletida nos principais enderecos PGP. Sei que quem usa cryptografia no dia a dia sempre tem seu servidor de chaves preferido, mas fica aqui a dica caso queira prestigiar o servidor da FUG-BR :) -- convida Edson Brandi.O servidor pode ser acessado em: http://keyserver.fug.com.br:11371/ (http://keyserver.fug.com.br:11371/)

Brincando com vnet em Jail no FreeBSD

Este tutorial é uma serie de dicas e comandos para gerenciar Jails com o novo esquema de emulação de rede que ainda esta experimental no FreeBSD. Mas já é possível usar as features que o mesmo oferece e criar um ambiente totalmente personalizado com firewall e ferramentas de diagnósticos de rede dentro de uma jail. Uma ótima definição sobre Jail esta disponível no Wikipedia no endereço: http://pt.wikipedia.org/wiki/FreeBSD_jail (http://pt.wikipedia.org/wiki/FreeBSD_jail) Para iniciar-mos o tutorial, precisamos como pre-requisito que você conheça como recompilar o kernel do FreeBSD, tarefa ao qual existem bons documentos disponíveis, a começar pelo o Handbook (http://www.freebsd.org/doc/en_US.ISO8859-1/books/handbook/). Leia mais… (http://www.luizgustavo.pro.br/blog/2010/07/29/brincando-com-vnet-em-jail-no-freebsd/#more-592)

Fundado em software BSD, nasce o DuckDuckGo (dukgo).

Nasce o Duck Duck Go (https://duckduckgo.com/) (a busca do Pato), engine de busca que ataca o mercado do Google, se anuncia como mais eficiente (https://duckduckgo.com/about.html), mais rápido e com muito mais recursos (https://duckduckgo.com/goodies.html) e mais respeito à privacidade do usuário. Para nós o relevante é constatar que além de desenvolvido sob base Open Source, fundamenta sua tecnologia essencialmente em software de Licença BSD ou derivados, como:Sistema Operacional FreeBSD (BSD) Banco de Dados PostgreSQL (BSD)NGinx Reverse Proxy (BSD)Memcached (BSD)Solr (Apache 2.0, derivada BSD)Perl (Artistic License)Acesso rápido ao site em http://dukgo.com/ (http://dukgo.com%20%20)

FreeBSD VuXML Documenting security issues in FreeBSD and the FreeBSD Ports Collection
django -- multiple vulnerabilities



OpenSSL -- Remote Data Injection / DoS



bugzilla -- Cross-Site Request Forgery



bugzilla -- Social Engineering



FreeBSD Security Advisories Security advisories published from the FreeBSD Project
FreeBSD-SA-14:06.openssl



FreeBSD-SA-14:05.nfsserver



FreeBSD-SA-14:04.bind



FreeBSD-SA-14:03.openssl



FreeBSD-SA-14:02.ntpd



FreeBSD-SA-14:01.bsnmpd



FreeBSD-SA-13:14.openssh



FreeBSD-SA-13:13.nullfs



FreeBSD-SA-13:12.ifioctl



FreeBSD-SA-13:11.sendfile



FreshPorts news The place for ports
devel/git - 1.9.2

Update to 1.9.2. Now back to grabbing distfiles from kernel.org mirrors as google code is no longer updated. Fix an issue with packlist when using PERL. [1] PR: [1]: ports/188677 Submitted by: Bartek Rutkowski Horia Racoviceanu (private mail)

net/py-netifaces - 0.8_1

- Update to 0.8 PR: ports/187419 Submitted by: swills (myself) Approved by: maintainer timeout (count@211.ru, >6 weeks)

devel/otrs - 3.3.5_1

- Update the port to 3.3.6 - Move to www category: OTRS is actually web based ticket system and it has nothing with development. PR: ports/188847 Submitted by: "Mikhail T." (maintainer) Security: CVE-2014-2554

www/otrs - 3.3.6

- Update the port to 3.3.6 - Move to www category: OTRS is actually web based ticket system and it has nothing with development. PR: ports/188847 Submitted by: "Mikhail T." (maintainer) Security: CVE-2014-2554

net/wireshark - 1.10.7

Update to 1.10.7 and convert to new LIB_DEPENDS.

security/beecrypt - 4.2.1_1

When -march=FOO happens to be among CFLAGS, unexpected things could occur (for example, -march=core2 used to break build). Not a FreeBSD problem even -- Linux crowd was bitten by this too (and misdiagnosed it). Our package-building does not include the flag, which is why we haven't seen this before. Attempt to help configure better detect the architecture and CPU-capabilities -- and use assembler-implementations of various routines, where possible. ("make check" is almost 30% faster now) Ensure, SSE2-specific code builds properly with clang as well as gcc. Ensure, the author's "make check" runs as regression-test. Add another patch found on SourceForge. (Attempt to) unbreak on PowerPC -- untested. Bump PORTREVISION. Take maintainership for the time being, to deal with any fallout.

dns/dnsmasq - 2.70,1

Upgrade to new upstream version 2.70. Upstream changelog: Fix crash, introduced in 2.69, on TCP request when dnsmasq compiled with DNSSEC support, but running without DNSSEC enabled. Thanks to Manish Sing for spotting that one. Fix regression which broke ipset functionality. Thanks to Wang Jian for the bug report. Submitted by: Herbert J. Skuhra

graphics/linux-adobesvg - 3.01.x88

Add staging support

graphics/linplasma - 1.0_1

- Add staging support - Convert to new LIB_DEPENDS format, options framework

graphics/liblug - 1.0.6_5

- Add staging support - Convert to new LIB_DEPENDS format

graphics/libaux - 1.0_6

- Add staging support - Fix letter capitalization in COMMENT - Switch to PLIST_FILES

textproc/spellutils - 0.7_3

Since I'm there, change my e-mail.

textproc/spellutils - 0.7_3

- Stagify; - Define the license; - Pet portlint. Todo: check if the mastersite is definitely down or not.

graphics/lcms-python - 1.19

- Add staging support - Convert to new LIB_DEPENDS format - Remove non-standard info from pkg-descr

Título Descrição
RNP participa do NETmundial, Encontro Multissetorial Global sobre o Futuro da Governana da Internet

A RNP participou, nos dias 23 e 24 de abril, do NETmundial 2014

RNP seleciona quatro projetos da comunidade cientfica para o WRNP

Colaborao e pluralidade sero ainda mais latentes na 15 edio do Workshop da RNP (WRNP), que acontecer nos dias 5 e 6/5, em Florianpolis, Santa Catarina. A primeira sesso do evento ser composta por quatro projetos selecionados na chamada de apresentaes comunidade cientifica. Dentre as inmeras propostas recebidas, de trabalhos apoiados ou no pela RNP, a organizao selecionou os seguintes projetos para compor o tempo disponvel na programao: Plataformas Abertas para Infraestruturas Definidas por Software7: Projeto, Implementao e Experimentos Equipe: Magnos Martinello, Universidade Federal do Esprito Santo (UFES); Rodolfo Villaa, UFES; Alextian Liberato, Instituto Federal de Educao, Cincia e Tecnologia do Esprito Santo, IFES; Eros Spalla, IFEs; Diego Rossi Mafioletti, UFES; e Renato Cabelino Ribeiro, UFES. Resource Management in IaaS Cloud Platforms made Flexible through Programmability Equipe: Juliano Wickboldt, Universidade Federal do Rio Grande do Sul (UFRGS); e Lisandro Zambenedetti Granville, UFRGS. GT-ATER (Acelerao do Transporte de Dados com o Emprego de Redes de Circuitos Dinmicos) Equipe: Kleber Cardoso, Universidade Federal de Gois (UFG); e San Correa, UFG. Anlise de Incidentes de Segurana com o Mapa Auto Organizvel de Kohonen Equipe: Bruno, Universidade Estadual de Londrina (UEL); e Rodrigo Miani, Universidade Federal de Uberlndia (UFU). Conhea a programao completa do 15 WRNP no site do evento.

Evento marca o incio do servio experimental CNC

Depois de passar pelas primeiras fases do programa de grupos de trabalho, entre 2010 e 2012, o Grupo de Trabalho Computao em Nuvem para Cincia (GT-CNC) chegou fase experimental, ltima etapa do ciclo de pesquisa e desenvolvimento da RNP. O CNC visa oferecer uma infraestrutura para armazenamento de dados, de forma segura e eficiente para pesquisadores, professores e alunos. O workshop de abertura do servio experimental foi realizado no dia 24/3, no hotel Golden Tulip, no Rio de Janeiro. O evento reuniu representantes da equipe que desenvolveu o projeto, da Universidade Federal do Par (UFPA) e Universidade Federal do Rio Grande do Norte (UFRN), as instituies selecionadas pela RNP para atuarem como usurios experimentais nesta fase do projeto, alm da prpria RNP e representantes dos PoPs SC e PA. Dentre os usurios experimentais esto, por exemplo, o Instituto Federal de Mato Grosso do Sul (IFMS) e a Universidade Federal da Bahia (UFBA).

RNP fecha nova parceria com a Capes (MEC) para utilizao do servio eduroam

A Rede Nacional de Ensino e Pesquisa (RNP) acaba de fechar um novo programa de aes com a Coordenao de Aperfeioamento de Pessoal de Nvel Superior (Capes), fundao do Ministrio da Educao (MEC) responsvel pela expanso e consolidao da ps-graduao stricto sensu no pas. Em prol do avano das polticas pblicas para a educao no Brasil, a partir de agora, a Capes poder usufruir do eduroam (education roaming), servio de acesso internet sem fio, desenvolvido para a comunidade internacional de ensino e pesquisa, gerido e operado no Brasil pela RNP. Com isso, a Capes passa a ser a primeira autarquia federal vinculada ao MEC e o segundo ponto na cidade de Braslia (Distrito Federal)

Rute inaugura outro ncleo em Fortaleza e alcana os 92 ncleos em operao no Brasil

No dia 26/3, foi inaugurado mais um ncleo da Rede Universitria de Telemedicina (Rute), projeto coordenado pela Rede Nacional de Ensino e Pesquisa (RNP) e integrado ao programa Telessade Brasil Redes. O beneficiado foi o Hospital de Messejana (HMS), em Fortaleza, no Cear. A cerimnia de inaugurao contou com a presena do diretor-geral do Hospital de Messejana, Ernani Ximenes, e do coordenador nacional da Rute, Luiz Ary Messina, que participou por videoconferncia, da Universidade Federal do Esprito Santo (UFES). Com a inaugurao, a Rute passa a ter 92 ncleos inaugurados e em plena operao, localizados em hospitais universitrios e de ensino, em todos os estados do Brasil. Em 2006, quando foi implantada, a Rute abrangia apenas 19 instituies pelo pas. A iniciativa, que integra e conecta hospitais pblicos universitrios e de ensino, dava seus primeiros passos, com a criao de ncleos de telemedicina e telessade, em prol do desenvolvimento da educao e da pesquisa em sade no pas. Hoje, est presente em mais de 150 hospitais universitrios e de ensino e, at o final de 2014, sero implantados outros 17 ncleos, alcanando o total de 108 ncleos de telemedicina em funcionamento. Lanada pelo Ministrio de Cincia, Tecnologia e Inovao (MCTI), com apoio da Financiadora de Estudos e Projetos (Finep) e coordenao da RNP, a iniciativa j considerada uma das maiores do mundo e, em 2012, recebeu a qualificao de melhor prtica em telemedicina na Amrica Latina e Caribe, pelo Banco Interamericano de Desenvolvimento (BID), Organizao Pan-Americana da Sade (OPAS) e Comisso Econmica para Amrica Latina e Caribe (CEPAL). Em 2013, a Rute tambm se destacou no cenrio internacional por uma ao indita no Brasil: a primeira transmisso de quatro cirurgias em 4K (resoluo quatro vezes superior full HD), em tempo real e de forma simultnea, diretamente do Brasil para os Estados Unidos, a partir de quatro ncleos, nos hospitais universitrios de Porto Alegre (HCPA/UFRGS), do Esprito Santo (HUCAM/UFES) e do Rio Grande do Norte (HUOL/UFRN), e na Faculdade de Odontologia da Universidade de So Paulo (USP). Estudantes, pesquisadores e profissionais de sade no s assistiram s cirurgias detalhadamente, uma vez que o corao passou a ter o tamanho de um ser humano na tela, como discutiram com os especialistas em tempo real. Para 2014, j esto sendo planejadas duas novas transmisses de cirurgias em eventos de larga escala.

Workshops apresenta GTs 2013-2014

No dia 12/3, a Rede Nacional de Ensino e Pesquisa (RNP) promoveu o Workshop de Grupos de Trabalho 2013-2014. Na reunio, realizada no Rio de Janeiro e transmitida por videoconferncia para as outras unidades da RNP e PoPs, os coordenadores dos oitos projetos integrantes do programa de GTs e dois coordenadores de servios experimentais (resultantes de GTs) apresentaram os objetivos e os desafios de seus trabalhos.

Presidncia promove consulta pblica sobre o futuro da internet no mundo

Secretaria-Geral da Presidncia da Repblica A Secretaria-Geral da Presidncia da Repblica (SG-PR), por meio do portal participa.br, realiza consulta pblica at o dia 17/4, sobre direitos e princpios fundamentais para garantir o futuro democrtico e orientar a governana mundial da internet. Os autores das 15 propostas mais votadas podero participar diretamente do NET Mundial - maior evento de governana da internet, em So Paulo, dias 23 e 24/4 - e discutir suas ideias com especialistas internacionais. O encontro organizado pela SG em parceria com o Comit Gestor da Internet no Brasil (CGI.br), a prefeitura de So Paulo e a /1Net (plataforma abrangente e aberta para discutir assuntos de governana da rede). Para participar da consulta pblica basta acessar participa.br/netmundial e opinar sobre as trs perguntas que esto em discusso:

Por meio do Disseminao Ginga, TV Unesp cria aplicativo de interatividade em seu jornal

Desde o dia 17/03, o jornal Unesp Notcias da TV Unesp, de Bauru, So Paulo, tem apresentado uma inovao pouco explorada no jornalismo televisivo brasileiro. Trata-se do aplicativo de interatividade via controle remoto, exibido no telejornal, que permite o acesso a contedo complementar s principais reportagens mostradas, alm do perfil do entrevistado do dia e informaes de servio como telefones e sites relacionados, entre outras funes. O aplicativo interativo foi desenvolvido por meio do projeto de apoio

RNP assina trs acordos de Cooperao Tcnica do projeto da rede GigaCandanga

Na ltima tera, dia 18/3, em evento realizado na Universidade de Braslia (UnB), foram assinados trs Acordos de Cooperao Tcnica (ACT) do projeto de interiorizao da rede metropolitana de Braslia, GigaCandanga, que tem como objetivo interligar dez campi da universidade, 14 unidades do Instituto Federal de Braslia (IFB) e trs unidades da Empresa Brasileira de Pesquisa Agropecuria (Embrapa). Durante a cerimnia, estiveram presentes representantes do Ministrio do Planejamento, Oramento e Gesto (MPOG), da Secretaria do Planejamento do Governo do Distrito Federal, o reitor da UnB, Ivan Camargo, o diretor-geral da RNP, Nelson Simes, o diretor-adjunto de Gesto de Servios da RNP, Antnio Carlos Nunes, o gerente de projetos da RNP, Celso Barbosa, e o diretor de infraestrutura da Companhia Energtica de Braslia (CEB), Caubi Santana. A interiorizao da rede GigaCandanga faz parte do programa Veredas Novas, uma iniciativa conjunta dos ministrios da Cincia, Tecnologia e Inovao (MCTI), da Educao (MEC) e das Comunicaes (MC), em parceria com a Associao Nacional dos Dirigentes das Instituies Federais de Educao Superior (ANDIFES) e com o Conselho Nacional das Instituies da Rede Federal de Educao Profissional, Cientfica e Tecnolgica (CONIF), que visa conectar, em alta velocidade, todos os campi no interior de universidades e institutos tecnolgicos RNP.

RNP d sequncia capacitao do projeto Cidades Digitais, em Curitiba

Teve incio hoje, dia 17/03, a aula inaugural dos cursos de capacitao do projeto Cidades Digitais, em Curitiba (PR). Os cursos - com durao de oito dias - sero ministrados pela Escola Superior de Redes que, em parceria com o Departamento de Informtica da Universidade Federal do Paran, montou um centro de treinamento, com capacidade para 19 participantes. Os cursos fazem parte do programa Formao em Governana de TI e est dividido em trs mdulos: Fundamentos da Governana de TI, Gerenciamento de Servios de TI e Gerenciamento de Projetos de TI. O objetivo das capacitaes desenvolver as competncias, a sustentao e a implantao das redes nos municpios, incluindo os nveis estratgico, ttico, operacional redes e operacional sistemas. A ESR a responsvel pela capacitao de 1200 funcionrios das 80 prefeituras contempladas na primeira fase do projeto.

Alertas do CAIS
CAIS-Alerta: Resumo dos Boletins de Segurana Microsoft - Dezembro/2012

Microsoft Security Bulletin Summary for December 2012

CAIS-Alerta: Resumo dos Boletins de Segurana Microsoft - Novembro/2012

Microsoft Security Bulletin Summary for November 2012

CAIS-Alerta: Resumo dos Boletins de Segurana Microsoft - Outubro/2012

Microsoft Security Bulletin Summary for October 2012

CAIS-Resumo - Maio a Agosto de 2012

Alertas, vulnerabilidades e incidentes de segurana

CAIS-Alerta: Resumo dos Boletins de Segurana Microsoft - Setembro/2012

Microsoft Security Bulletin Summary for September 2012

CAIS-Alerta: Resumo dos Boletins de Segurana Microsoft - Agosto/2012

Microsoft Security Bulletin Summary for August 2012

CAIS-Alerta: Resumo dos Boletins de Segurana Microsoft - Julho/2012

Microsoft Security Bulletin Summary for July 2012

CAIS-Alerta: Resumo dos Boletins de Segurana Microsoft - Junho/2012

Microsoft Security Bulletin Summary for June 2012

CAIS-Resumo - Janeiro a Abril de 2012

Alertas, vulnerabilidades e incidentes de segurana

CAIS-Alerta: Resumo dos Boletins de Segurana Microsoft - Maio/2012

Microsoft Security Bulletin Summary for May 2012

CAIS-Alerta: Resumo dos Boletins de Segurana Microsoft - Abril/2012

Microsoft Security Bulletin Summary for April 2012

CAIS-Alerta: Resumo dos Boletins de Segurana Microsoft - Maro/2012

Microsoft Security Bulletin Summary for March 2012

Fim do Horrio de Vero 2011/2012

Alerta do CAIS 20120224

CAIS-Alerta: Resumo dos Boletins de Segurana Microsoft - Fevereiro/2012

Microsoft Security Bulletin Summary for February 2012

CAIS Resumo - Setembro a Dezembro

Alertas, vulnerabilidades e incidentes de segurana

CAIS-Alerta: Resumo dos Boletins de Segurana Microsoft - Janeiro/2012

Microsoft Security Bulletin Summary for December 2012

CAIS-Alerta: Resumo dos Boletins de Segurana Microsoft - Dezembro/2011

Microsoft Security Bulletin Summary for December 2011

CAIS-Alerta: Resumo dos Boletins de Segurana Microsoft - Novembro/2011

Microsoft Security Bulletin Summary for November 2011

CAIS-Alerta: Vulnerabilidade no JBoss

Alerta do CAIS 20111107

CAIS-Alerta: Resumo dos Boletins de Segurana Microsoft - Outubro/2011

Microsoft Security Bulletin Summary for October 2011

BR-Linux.org Desde 1996 levando o Linux a sério
Linux Foundation organiza, e Google, Facebook, Microsoft e outras doam milhes de dlares ao cdigo aberto aps crise do Heartbleed

Via tecnologia.terra.com.

Governo no vai insistir em data center no pas

Via g1.globo.com: A Presidente da Repblica disse nesta quinta-feira (24) que o governo no vai insistir na obrigatoriedade de os provedores de internet instalarem os data centers no Brasil.

Mandriva Conectiva contrata analista de pr-venda (SP)

Enviado por Mandriva Conectiva :

Vaga Rails RJ

Enviado por Alexandre Costa (alexandrecosta

Como Instalar o Minecraft no Ubuntu 14.04 usando o Minecraft Installer

Enviado por Edivaldo Brito (edivaldobezerra

Como instalar o conversor de mdia Format Junkie no Ubuntu 14.04

Enviado por Edivaldo Brito (edivaldobezerra

TDC 2014 Florianpolis: apoio de gigantes da tecnologia e mais de 1600 inscritos

Enviado por TDC:

Palestra RJ: Blender 3D - Explorando novos recursos

Enviado por Eliane Domingos de Sousa (ciclodepalestras

FLISOL 2014 em Novo Hamburgo-RS

Enviado por Daniel Bauermann (dbauermann

Empresa portuguesa responsvel por projeto de tecnologia eletrnica impressa atinge objetivo no kickstarter em 72 horas

Enviado por Joo Fernando Costa Jnior (joaofernando

FreeBSD Project News News from the FreeBSD Project
New committer: Kurt Jaeger (ports)



January-March, 2014 Status Report



New committer: Johannes Jost Meixner (ports)



FreeBSD Project to participate in Google Summer of Code 2014



FreeBSDJournal First Edition Available



October-December, 2013 Status Report



New committer: Rodrigo Osorio (ports)



New committer: Tycho Nightingale (src)



New committer: Michael Gmelin (ports)



FreeBSD 10.0-RELEASE Available



OpenBSD Journal The OpenBSD Community.
m2k14: Stuart Henderson on Triage

Stuart Henderson (sthen@) was the first developer to submit a report from the recent m2k14 hackathon:

I set off for Marrakech planning to look at updating DB in ports and taking care of changes needed in ports for a UVM diff for mpi@, but ended up getting swept away by the wave of destruction in ports from removal of the dangerous RAND_egd API in libssl, removal of Heimdal Kerberos from the base OS and (to a lesser extent) the final removal of altq, so frequent port builds and mopping up were the order of the day, and other projects were put on the back-burner.

Read more...

KerberosV removed from -current

This gem of a commit message from reyk@ waves a not-so-fond farewell to Kerberos V:

The complexity and quality of kerberosV and the fact that almost
nobody is using it doesn't justify to have it in base - disable and
remove it.  If the 2 two people who use it still want it, they can
make a port or recompile OpenBSD on their own.

There is a quote in theo.c from August 2010: "basically, dung beetles
fucking.  that's what kerberosV + openssl is like".

Discussed with many.  Tests by henning@ reyk@ and others.
ok deraadt@ henning@

Another story of unmaintained and possibly unused code that ends up in the attic. Any Kerberos users out there who want it back will need to step forward and contribute one way or the other. Some code is obviously worth cleaning up, other code is destined for retirement, it seems.

It's Official: The OpenSSL Overhaul Is A Fork: Welcome LibreSSL in OpenBSD 5.6

Yes, it's official. The recent work in
cleaning up OpenSSL is now officially a fork, with its own website and donation link.

The project's name going forward is LibreSSL, and according to the (so far spartan) website, the first release will be included in OpenBSD 5.6, which is expected to be released November 1st, 2014.

Read more...

Faster and more capable whatis(1)/apropos(1)

Not one to get lost in the OpenSSL/m2k14 shuffle, Ingo Schwarze (schwarze@) has, after much work and improvement, updated the man page search functionality:

Date: Fri, 18 Apr 2014 04:00:48 -0600 (MDT)
From: Ingo Schwarze 
To: source-changes@cvs.openbsd.org
Subject: CVS: cvs.openbsd.org: src

CVSROOT:        /cvs
Module name:    src
Changes by:     schwarze@cvs.openbsd.org        2014/04/18 04:00:48

Modified files:
        etc            : weekly
        libexec        : Makefile
        usr.bin        : Makefile
        usr.bin/mandoc : Makefile
        usr.sbin/pkg_add/OpenBSD: Add.pm Delete.pm Paths.pm PkgCreate.pm
        share/man      : Makefile
        share/man/man8 : daily.8

Log message:
Switch to the new makewhatis(8)/apropos(1)/whatis(1) combo.
"commit the switch now" espie@  "go for it" deraadt@

See the apropos(1) manual for a description of what's new.
On machines where you want the full functionality,
run "sudo makewhatis" and put "MAKEWHATISARGS=' '" into weekly.local(8).
Otherwise, when upgrading via source, run "sudo makewhatis -Q".
Read more...

freebsd - Google Notícias Google Notícias
FreeBSD quarterly status report - OS News


FreeBSD quarterly status report
OS News
The first quarter of 2014 was, again, a hectic and productive time for FreeBSD. The Ports team released their landmark first quarterly stable branch. FreeBSD continues to grow on the ARM architecture, now running on an ARM-based ChromeBook. SMP is ...



FreeBSD mit verbesserter ARM-Untersttzung - Pro-Linux


FreeBSD mit verbesserter ARM-Untersttzung
Pro-Linux
FreeBSD 10 konnte im Januar freigegeben werden. Die neue Version luft auf dem Raspberry Pi und ist nur ein Beispiel fr den generellen Fortschritt der ARM-Untersttzung bei FreeBSD. Die Fortschritte von FreeBSD auf ARM zeigen sich auch in der ...



iXsystems Partners with FreeBSD News to Expand FreeBSD Events ... - Virtual-Strategy Magazine (press release)


iXsystems Partners with FreeBSD News to Expand FreeBSD Events ...
Virtual-Strategy Magazine (press release)
iXsystems has been the all-around FreeBSD company since its inception. From sponsoring PC-BSD to adopting the FreeNAS Project and turning it into a robust enterprise-class storage solution, iXsystems has always looked out for ways to help FreeBSD and ...

e mais »


FreeBSD 10, Converting from RELEASE to STABLE - LXer (press release)


FreeBSD 10, Converting from RELEASE to STABLE
LXer (press release)
Because of a [bug in mpd][1] which is fixed in 10-STABLE I wanted to move one of my FreeBSD machines from 10.0-RELEASE to 10.0-STABLE. The process to do so is fairly simple. Basically, you check out the new source code, build the world, build the ...



Vigil@nce - FreeBSD : dni de service via NFS Server - Global Security Mag


Vigil@nce - FreeBSD : dni de service via NFS Server
Global Security Mag
Le produit FreeBSD dispose d'un service NFS. Lorsqu'un client NFS authentifi renomme un rpertoire, la fonction nfsrvd_rename() utilise un verrou. Cependant, ce verrou est pris dans le sens inverse. Si deux oprations de renommage s'effectuent en ...

e mais »


bsd - Google Notícias Google Notícias
PC-BSD is developing its own desktop environment - OS News


PC-BSD is developing its own desktop environment
OS News
The PC-BSD project is developing its own desktop environment from scratch! The ultimate plan is for Lumina to become a full-featured, open-source desktop environment that may ultimately replace KDE as its default desktop environment. A Phoronix reader ...



BSD Buys 26% Stake in Plaza Indonesia - Jakarta Globe


BSD Buys 26% Stake in Plaza Indonesia
Jakarta Globe
BSD bought an additional 922.7 million shares, or 25.99 percent of the company, for Rp 2 trillion ($177 million) from Paraga Artamida, another property subsidiary of Sinarmas Land, the company said in a brief prospectus published in Investor Daily on ...



Beaverton school notes: BSD budget cuts some technology ... - The Oregonian


Beaverton school notes: BSD budget cuts some technology ...
The Oregonian
Montclair Elementary technology assistant Joann Vazquez talks about students at the small school learning computer code and how to build an working Lego robot. The school district budget increases the time for physical education and music but it gets ...



BSD Medical Ships BSD-2000/3D/MR Image Guided Hyperthermia ... - Wall Street Journal


BSD Medical Ships BSD-2000/3D/MR Image Guided Hyperthermia ...
Wall Street Journal
BSD Medical Corporation (NASDAQ:BSDM) (Company or BSD) (www.BSDMedical.com), a leading provider of medical systems that utilize heat therapy to treat cancer, announced today that the Company has shipped a BSD-2000/3D/MR Image Guided ...

e mais »


BSD board OKs new budget, plans early May vote - Bennington Banner


BSD board OKs new budget, plans early May vote
Bennington Banner
The $37,000 that BSD voted to cut from includes $20,214 in savings from renegotiating the SVSU's contract with the school bus company, $1,034 in savings on dental insurance for employees, a $1,250 decrease in budgeted allowances for postage, a $3,000 ...



Beaverton school notes: BSD budget adds teachers and music in ... - The Oregonian


Beaverton school notes: BSD budget adds teachers and music in ...
The Oregonian
Beaverton parent and music supporter Doug Garnet thanked the Beaverton School District for taking the first steps to returning music to the schools. The district is adding music teachers and doubling instruction time in 2014-15. (Wendy Owen/Beaverton ...

e mais »


Lumina: Neuer Qt-Desktop fr PC-BSD - Golem.de


Lumina: Neuer Qt-Desktop fr PC-BSD
Golem.de
Anzeige. Das auf FreeBSD aufbauende System PC-BSD legt Wert darauf, Nutzern eine grafische Oberflche sowie eine leichte Installation zu bieten und setzt bisher standardmig auf KDE-Software. Der Entwickler Ken Moore hat nun mit Lumina eine neu ...



PING: Red Hat, PC-BSD, Audacious, AMD Catalyst, Viber


PING: Red Hat, PC-BSD, Audacious, AMD Catalyst, Viber

BSD's marketing sales in Q1 down by 30% - Jakarta Post


BSD's marketing sales in Q1 down by 30%
Jakarta Post
PT Bumi Serpong Damai (BSD), one of the country's largest property developers, booked Rp 1.76 trillion (US$154 million) in marketing sales in the first quarter of this year, down by more than 30 percent compared to the same period in 2013. According to ...



BSD Medical Corporation (BSDM) Receives Approval to Transfer ... - MarketWatch


BSD Medical Corporation (BSDM) Receives Approval to Transfer ...
MarketWatch
SALT LAKE CITY, Apr 23, 2014 (BUSINESS WIRE) -- BSD Medical Corporation (NASDAQ:BSDM) (Company or BSD) ( www.BSDMedical.com ), a leading provider of medical systems that utilize heat therapy to treat cancer, today announced that the Company ...

e mais »


freebsd - Google News Google News
FreeBSD 10, Converting from RELEASE to STABLE - LXer (press release)


FreeBSD 10, Converting from RELEASE to STABLE
LXer (press release)
Because of a [bug in mpd][1] which is fixed in 10-STABLE I wanted to move one of my FreeBSD machines from 10.0-RELEASE to 10.0-STABLE. The process to do so is fairly simple. Basically, you check out the new source code, build the world, build the ...



FreeBSD quarterly status report - OS News


FreeBSD quarterly status report
OS News
The first quarter of 2014 was, again, a hectic and productive time for FreeBSD. The Ports team released their landmark first quarterly stable branch. FreeBSD continues to grow on the ARM architecture, now running on an ARM-based ChromeBook. SMP is ...



iXsystems Partners with FreeBSD News to Expand FreeBSD Events and ... - MyHostNews.com (press release)


iXsystems Partners with FreeBSD News to Expand FreeBSD Events and ...
MyHostNews.com (press release)
iXsystems has been the all-around FreeBSD company since its inception. From sponsoring PC-BSD to adopting the FreeNAS Project and turning it into a robust enterprise-class storage solution, iXsystems has always looked out for ways to help FreeBSD and ...



bsd - Google News Google News
PC-BSD is developing its own desktop environment - OS News


PC-BSD is developing its own desktop environment
OS News
The PC-BSD project is developing its own desktop environment from scratch! The ultimate plan is for Lumina to become a full-featured, open-source desktop environment that may ultimately replace KDE as its default desktop environment. A Phoronix reader ...



BSD Medical Corporation (BSDM) Receives Approval to Transfer Listing to ... - Business Wire (press release)


BSD Medical Corporation (BSDM) Receives Approval to Transfer Listing to ...
Business Wire (press release)
SALT LAKE CITY--(BUSINESS WIRE)--BSD Medical Corporation (NASDAQ:BSDM) (Company or BSD) (www.BSDMedical.com), a leading provider of medical systems that utilize heat therapy to treat cancer, today announced that the Company received ...

and more »


Beaverton school notes: BSD budget adds teachers and music in 2014-15; top ... - The Oregonian


Beaverton school notes: BSD budget adds teachers and music in 2014-15; top ...
The Oregonian
Beaverton parent and music supporter Doug Garnet thanked the Beaverton School District for taking the first steps to returning music to the schools. The district is adding music teachers and doubling instruction time in 2014-15. (Wendy Owen/Beaverton ...

and more »


BSD Buys 26% Stake in Plaza Indonesia - Jakarta Globe


BSD Buys 26% Stake in Plaza Indonesia
Jakarta Globe
Bumi Serpong Damai, a property unit of Sinar Mas Land, has bought an additional stake in Plaza Indonesia Realty, making it the majority shareholder in the company, which operates the Plaza Indonesia shopping mall. BSD bought an additional 922.7 million ...



BSD Medical Ships BSD-2000/3D/MR Image Guided Hyperthermia System for ... - MarketWatch


BSD Medical Ships BSD-2000/3D/MR Image Guided Hyperthermia System for ...
MarketWatch
SALT LAKE CITY, Apr 22, 2014 (BUSINESS WIRE) -- BSD Medical Corporation (NASDAQ:BSDM) (Company or BSD) ( www.BSDMedical.com ), a leading provider of medical systems that utilize heat therapy to treat cancer, announced today that the Company ...

and more »


Beaverton school notes: BSD budget cuts some technology assistants, ISB ... - The Oregonian


Beaverton school notes: BSD budget cuts some technology assistants, ISB ...
The Oregonian
Montclair Elementary technology assistant Joann Vazquez talks about students at the small school learning computer code and how to build an working Lego robot. The school district budget increases the time for physical education and music but it gets in ...



BSD board OKs new budget, plans early May vote - Bennington Banner


BSD board OKs new budget, plans early May vote
Bennington Banner
The $37,000 that BSD voted to cut from includes $20,214 in savings from renegotiating the SVSU's contract with the school bus company, $1,034 in savings on dental insurance for employees, a $1,250 decrease in budgeted allowances for postage, a $3,000 ...



Issue not resolved with India due to subservient policy: Left parties - Financial Express Bangladesh


Issue not resolved with India due to subservient policy: Left parties
Financial Express Bangladesh
Earlier on Thursday afternoon, CPB-BSD Left Alliance launched their 3-day road-march towards Teesta Barrage demanding equitable share of waters of 54 common rivers, including the Teesta, flowing into Bangladesh from India. The road-march started ...

and more »


Manzurul blasts govt for 'subservience' to India - Bangladesh News 24 hours


Manzurul blasts govt for 'subservience' to India
Bangladesh News 24 hours
The CPB and Bangladesher Samajtantrik Dal (BSD) are jointly agitating to press for an equal share of Teesta river waters, still a sticky issue between India and Bangladesh. The CPB and BSD activists and supporters embarked on a three-day march on ...

and more »


'Rivers to remain just a memory' - Financial Express Bangladesh


'Rivers to remain just a memory'
Financial Express Bangladesh
Leaders of the alliance of Communist Party of Bangladesh (CPB) and Bangladesher Samajtantrik Dal (BSD), who are taking part in the three-day 'Teesta March', have observed that rivers would remain just a memory to the future generation if justified shares ...

and more »


Online:
Ns temos 16 visitantes online


Devil Store - Sua loja BSD
FreeBSD Brasil LTDA

FUG-BR: Desde 1999, espalhando BSD pelo Brasil.