Archive for Computing

The World Today

The world today is in an interesting state, I’m not sure if i’m looking forward to what might be on it’s way, but at the same time I believe that human beings in themselves are a catalyst for the planet. Speeding up processes (often of damage) that would take otherwise countless years.

The World Today

I’ve decided to start posting again on the azio.org blog. Last year a business was stolen from me, and I  also lost the love of my life which was a very painful process.

I’ve decided though, back to modern sociopolitical issues , Linux based Open Source works, and lots of projects based on the unusual and interesting.

Real geek stuff basically. I’d just like to thank all the people who enjoy reading azio.org and all the tidbits of info on here.

Comments (12)

Facebook Fraud on the Rise!

In recent months, the economic downturn has been something nearby everyones ear, be it radio, TV, word of mouth, or otherwise. It seems though that the scams will continue and for quite some time during the credit crunch.

Helping criminal fraudsters since the economic downturn

We ask ourselves in wonder, and quickly state “Facebook? Fraud? No, no, no. They have safeguards and vetting for such ads”. You’d be correct, but for some reason Facebook are quite happy letting countless hundreds of fraudsters access 15.4 million people per ad.  This is clearly unnacceptable and presents yet again another dangerous trend in irresponsible business practices online.

Now, as we know the CMA (Computer Misuse Act) is a internationally widely misunderstood and misinterpreted legislation, and often revised to meet a changing need of regulations to prevent both criminal and civil crimes being committed with the use of computer and internet technology. There has always been a grey area in which fraudsters are able to hide and operate almost entirely with impunity.  Frankly though, we feel a public outcry is the only response deserved for Facebook profiteering from fraudsters. A symbiosis of association is quite illegal, with or without knowledge (criminal). I believe a strong case can and will be put forward by myself or some other party to ensure that such phenomena cannot repeat itself.

Facebook clearly state they have a filtering/vetting system. Perhaps they could state why they are allowing organised crime to be advertised on their site to their users? See how much facebook cares about their users? Only as much as the monetization, it seems, it’s not cheap to run facebook. Infact when talking about facebook user ROI they will refer to it in pence.. however the real cost to us from fraudsters can reach the hundreds of thousands. Obviously customer value and monetization are clearly mutually exclusive goals. Something of which either requires massive addressing via the CMA, or other currently existing legislations to remove organised crime by association.

A dangerous criminal-commercial symbiosis has formed where commercial entities are prepared to turn a blind eye to clearly illegal pyramid or matrix schemes. Often refered to as scams!

Often in such schemes the scammer will have a website that noticeably has no Google Index, Alexa Rank, backlinks, yahoo rank, msn rank. Infact I and others could go as far to blame the user for being soppy and not checking such blisteringly obvious things. Question though, how mainstream is facebook? How many people on facebook are technicians? It’s a good question, and quickly explains the Beeb’s recent interest in the story about rising frauds related crime since the economic downturn. Also, often the scammer will insist he had recently no options left, no job or promise of success and that *his* scheme, for instance “Gmoney” or “google money” works and generates thousands of $. Also a “free” pack will be offered, always requiring the user to give their creditcard details or a monetary payment of somekind for the “postage”. Often the user may be charged more than the postage list price quoted by said scammer. More often than not that money is lost due to the embarassment of being had, or rather simply because they were desperate and spent their last crumbs on something silly, and have better things to do than trying to get a few dollar, or a few hundred dollars back.

First of all it should be clear that people who use terms like “google will make you money” is pretty disassociative, they are clearly stepping back and saying - “hey google will make you rich” but giving you a clear impression it’s their work, and their “book/starter kit” will tell you everything you need to know to make money on google. Well here’s the wakeup call. Google will tell you everything you need how to make money on google, because they did it first! It’s everywhere: strategies, tutorials, guides, SEO, this stuff already exists, it’s free! And not everyone makes money on it AT ALL. Success ISN’T assured! Losing ones money usually is, especially in matrix schemes. Moreso in Pyramid schemes, and an outright guarantee from someone claiming you can make a personal fortune via google with their help!! Lies, and the same old stories resurface every few years in mainstream media, for instance recently with the economic downturn.

Another great prank is pictures of fancy cars, beautiful women, their children and them, pretending to be a single father/mother. Remeber, scammers are experts in human psychology , social networking, espionate and

Promises that are too good to be true are what they say on the tin.

It’s easy to become involved in one of these schemes, the specific rise and targeting of facebook since the downturn can simply be labeled as a fraudsters exploitation, but how far does the exclusivity of that exploitation go? How far do the responsibilities of the content provider go as to crime? Actually, facebook could indeed be responsible for allowing criminals to use their content for ads network. Google have faced similar suits where their responsibility to patents, trademarks or misleading/fraudulent adverts as well as their users have been instilled by international courts. Facebook is still pretty fresh so it will be interesting to see how badly they are hit with the bad news they’ve been caught red handed, with their pants down, allowing criminal fraudsters to impress upon their entire userbase… if this is not a crime then it can only be pure and simple ignorance, stupidity and/or greed.

Facebook wake up! For gods sake! For your users sake!

One such Ad on facebook today:

The scammer href/link for the facebook ad:

Comments (1)

azio.org move

Hi all, friends and distant squabblers. At last azio.org has moved over to a new box in the US. wohoo! I’m really impressed with it and hope to get a lot more work done on my new business!

There are a few problems with permalinks (namely) about, projects & downloads pages. I’m not sure why, maybe something to do with mod_rewrite.

If anyone has any ideas, I’m all ears, because I’ve just finished playing and porting 3 domains, and setting up, from scratch debian etch 4.0 , tinydns, apache2, mysqld, phpmyadmin, wordpress, nameservers, configure data files. Taken me hours.

However considering that I have got tinydns down to a 3 minute job & that I setup a small consultancy business infrastructure in a night, on one machine (with no caching!) I can’t help but feel a little bit flash for it.

Anyways, wohoo, i’m off but I hope to be seeing more-of-you!

Peace,
A

Comments

Finally Some Free Time…. freedom?! naa

Finally, yay Finally, I have worked my butt off so hard at my new job in London - that I have run out of things to do, other than learning c# and .NET which feels like an ongoing process that will last forever and ever (evil laughs bellow from the background).

It finally seems like I’m getting somewhere. I must have re-learnt 5 different languages in the last 5 months, and learnt 5 new ones. Now I’ve got a pretty firm grip of xhtml + CSS, so I look forward to doing some good CSS button + layout guides, and some xhtml ones too.

Also I’ve been doing a lot of PHP/MYSQL work (yup, new dayjob keeps me super busy!) - so I should have lots and lots to talk about, instead of our usual hack, crack, thankyou - welcome back.

Comments

Efficiently using Data

This is a favourite topic of mine, in fact, most of my favourite topics involve some efficiency, efficacy or a tumbling tantrum of some kind. This post is about an important abstraction that free-thinkers, security personnel, and contractors all should be aware of.

Sometimes the information you know that isn’t relevant, identifies what is

Have you ever heard the saying of? It’s easier to write down all the people not attending than the people attending, or vice versa? It’s a logical abstraction we all live with, and use on a daily basis. Then again, it’s not really something we understand. Mainly because not many people stop for a moment to think about what really is occuring.

Again, it’s the difference between painting most of a black peice of paper white to see black text and painting a little bit of text on a sheet of paper thats white already.

There is a major factor of economy, usability, functionality & most importantly of all, it affects the difficulty of implementation. This sort of abstraction is worth using in day to day life.

It’s pretty strange really because this seems such a similar topic as my macroverse and microverse theory. It’s a pivotted, balanced, closed system. However, the “way” in which you close it is, optional. I like that in a topic.

Peace,
A

Comments

A simple c# Hello World program

Hello all, a lot of you who are new to .NET or the CSC.EXE (or mono(linux)) compiler that comes with it for windows will be wondering what the syntax and learnability of c# is like. Well I think we’ve established it’s practically javascript in an MS wrapper - it - much like javascript - has some really powerful C++ like syntax and formating to it. Below I include a quick Hello World Program I wrote by scratch. Notice the adoption of the class structure, c# is full of it - again, much like JS.
I’ve compiled this application in VS c# 2008, and it should also work fine in VS c# 2005 as well as the CSC.EXE. If you are using VS c# 2008 to write, compile and run your applications use shift+f6 (builds application) followed by a F5 (debug/run) keypress once you have typed in the code.
using System;
using System.Collections.Generic;
using System.Linq;
using System.Text;

namespace JustAQuickHelloWorldbyAzio

{
class Azio // name of class
{
public string mystring; // named string mystring of type string, publically declared (accessible outside class)
}

class Program
{
static void Main(string[] args)
{
Azio anotherazio = new Azio(); // create an object for my Azio class, lets call the object “anotherazio”
anotherazio.mystring = “Hi thar!”; // initialize the mystring data member of anotherazio object of type Azio class

Console.WriteLine(”Hello World says ” + anotherazio.mystring); // Tell the c# Console (commandline) to output
// the text “Hello World says ” and the value of anotherazio.mystring which is respectfully “Hi thar!”
Console.ReadKey(); // this line instructs the program to wait for any userkey press to exit the program.
} // end of Main() function (scope)
} // end of class Program (scope)
} // end of namespace (scope)

I’ve actually just quickly reviewed the c# programming language over the last few days (& as best I can), I thought it would be nice to see a simple-esque hello world application that included classes and basic foundations of OOP, it seems to be so easy in c# in comparison to C++ but mm, then again maybe my previous experience helps :-)

Peace,

A

Comments

Howto: Securely tunnel via SSH to browse www websites over http

Hi guys, welcome to what you’ve been searching the internet frantically for. Say wa? A no-nonsense guide to anonymous, secure & encrypted port forwarding via SSH tunneling. I will tell you how in just 3 easy steps.

Step 1

Open putty, Goto the Connection-> SSH-> Tunnels and type in 7070 for source port (you can use any port but we use 7070 for this example). Do not enter a destination, but make sure `Dynamic` and `Auto` option buttons are selected like the picture below.
Securely tunnel via SSH to browse www websites

Right once you’ve done the above it should look like:
Securely tunnel via SSH to browse www websites over http
Notes: `Dynamic` option is set, after clicking add D7070 appears in `forwarded ports`. Thats perfect. Well done. Give yourself a pat on the back. Simple. Isn’t it?

Step 2

After how much of a breeze step 1 is, all that is left is you deciding which linux box you’d like to use to connect to via SSH. For my example I include a fictional machine mybox.reallyrocks.com with the default SSH port of 22. In order to feel special about yourself and save you doing this all again enter in a name to save the session. I’ve put “Spechial SSH tunnelz for webz and ting” just so it is darn clear whats going on there. Ok, see below.
Securely tunnel via SSH to browse www websites over http

What I didn’t tell you in this guide was howto click the Open button, because to setup an encrypted SSH-2 (SHA-2) connection that tunnels via a secure linux box is already so easy. I figured it’d be an insult mentioning it.

Step 3: Add your proxy settings in firefox and go crazy.

Now maybe i’ll get that job I’ve always wanted. *cough*. As if. I’m going to use firefox as an example on how to use this bloody tunnel you’ve just setup, you’re probably wondering. Not to worry, this is easier than clicking “Open”.

Script `kiddies` may say? wa wa wa whatcha type in though. Well I typed in 127.0.0.1 and the 7070 and selected the option socks v5. comon, simple things. So, Enjoy simplicity. Everybody else is so god damned cryptic about setting up tunnels and the truth of this is, anyone could do it. Yes, thats right now everything you do VIA the WWW is encrypted. The only thing that isnt is the DNS which is the thing that says where the server is. “what is google? google is 68.8.0.3 etc - thats what the DNS does”.
Securely tunnel via SSH to browse www websites in firefox

My oh My, Easy.

Peace,
A

Comments (2)

Privacy? What Privacy! The Illusion of Justification or Idealism?

Introduction

Having lived in Britain my whole life and aspired to live as a thinker, philosophiser, technician, developer, manager, project manager, liason, scientist, spiritualist, conspiracist and contrived myself towards a more `new age` look at modern sociopolitical concepts I have found myself uncovering remarkable tidbits of concept, ideas and political flim flam.

Privacy Central and the Anonymous World
For instance, under both US and EU law a common statute of privacy is established for the individual, however contrarily the modern development of computer tagging systems, highly sophisticated imaging systems, Retina scanners, genetic profiling, detailed census profiling (e.g. compulsory personal US census programme), search engines, and most importantly service based interconnectivity leave much to be admired. Being anonymous is a practical impossibility, for the average human being and the over-average cracker genius. Why we ask? Well, the way the internet works, and the way people get it, and specifically, the interdependance of intercommunications. Some may say “what say you azio?” - “what does that even mean?” - it goes, well, something like this. You get your internet through an ISP, and they most likely get their global internet coverage (known as partial or global routes in a route table for differing allocations of the internet) via someone else (or many groups or exchanges). Of course we have all seen films that make melodrama of the idea and make it look like simplicity, it really isn’t simple. We need to consider that no one business or government owns the `internet`, owns the fibre or phonelines laid in your street; but, we all have an interdependancy on those systems, and their respective dependant systems. Security and privacy wise this says “DANGER” and nothing less. This says no privacy.

A work that is in progress

Although my research still bears the label of an `early work` having worked with basic routing, switching, and along with other commercial ISP’s it became a quick lesson that there is, at nearly all times for a extraordinarily large amount of people - more than just the lack of privacy - but a system that independantly or collectively monitors user patterns and activity. So much so that, using a HTTP proxy is no longer safe, so much so that using even a remote dns server _SELF OWNED_ by yourself still permits a security risk. “Why?” the reader asks. I answer, because that is the nature of the internet. It is a particularly erroneous claim (and idea) that seems to have been *HIGHLY* circulated in recent and older times, the internet is anonymous. Facts say something totally different, the internet is _NOT_ anonymous, whatsoever. Infact the whole system of DNS and IP/MAC translation allows the ability for specific tracking of the majority of users. All IP (Internet-Protocol) addresses ipv4 of ipv6 are binded to unique MACID’s in hardware NIC’s (Network Interface Cards), wireless cards - even telephone systems and a multitude of other devices. A specific unique identifier for communication, of course, and uniquely the best, most expert way to track anyone, anywhere in the world. So much so that MACID’s can be traced to Credit Cards, which can be traced to people, which can be traced to their bank, their business, their family, friends and their Internet Service Provider.

Expression is pointless in an anonymous society?


Freedom
, Privacy and the Data Protection Act
The whole idea of the all seeing eye of Echelon (An unacknowledged system which makes attempts at monitoring all intercommunication systems such as satellite, radiowave, microwave, optical, bnc and hardwire communications - is not a new concept. However, the idea of the internet being wholely un-anonymous and modern systems being actively in breach of peoples basic human rights and the DPA is a new idea; an idea based solely on the assumption of misuse of data, or rather, isolation and review of sensitive and private data without due cause OR the specific ignorance of laws protecting peoples right to privacy. Those who find themselves living in the US should know privacy is not something to reject, it is a right that has been granted to their society by constitutional law, it is just and it should not be unreasonable to expect a system of technology that respects it, however - as a technician it is important to establish that the way computer systems work is on a “unique identifier” basis - otherwise the system can’t do anything. All communication systems need to know their destination, and specifically where they are coming from - so the target can reply. All communication systems route through a multitude of machines. The atypical illusion of the `common user` of P2P connections (point to point) is ridiculous, as quite clearly the data to reach that target (and indeed acknowledgement from target to the initial user source) is a neccesity for data transmission, as such, any use of technology systems - at least to an insanely high majority of people (estimated 99.99% of people) is anything but anonymous.
the way computer systems work is on a "unique identifier" basis


A little bit about the fallacical system of Privacy

Often, in law enforcement, and other security vendors - specifically airports, high security locations, music and dance venue’s, clubs, even your local stores the philosophy of “refusal to submit is admission of guilt” is considered a golden neccesity of operation. I ask “Why?”. I ask “Why?” people must be guilty to value their privacy. For instance, I would feel embarassed and personal intruded if a crowd of people watched as I showered, some wouldn’t , but some would. That is human nature, we are indeed all different. Let’s get back to the topic at hand, the fallacical idea of the system of fallacical security with an example:

Security Guard: Hello sir, I have been informed by a member of staff that you have been acting suspiciously, would you mind if I went through your back and personal items briefly.
Civilian: Yes I would mind, as that is private!
Security Guard: Sir, if you would kindly consent to me searching you for weapons, stolen items, etc then you will be able to go on your way as soon as we have established that you are innocent.
Civilian: I am innocent, however invading my privacy is not your right.
Security Guard: So you refuse to consent to being searched sir?
Civlian: Yes, Yes I do.
Security Guard:
Civilian:
Security Guard: Why disallow me to search through your posessions if you have nothing to hide?
Civilian: I have nothing to hide but my personal privacy and personal items, which I have already said.
Security Guard: Yes, but everyone else has to be searched, you are not an exception to this rule, it is for the security of you and others, and your freedom.
Civilian: My freedom is my privacy.
Security Guard: Perhaps, but refusal to consent to being searched suggests guilt, wheras compliance suggets innocence.

Such situations are of course very common, and such people to challenge the system in such a way are very uncommon. Compliance is not an option in most usual circumstances. In society a “reality” of importance is established and a double standard is born people at airports may be subjected to searches in the UK, those who value their freedom (and indeed, privacy) are persecuted and accused of guilt when they excercise the same rights that security forces claim to protect.
The substitution of freedom for security to protect freedoms deserve nor attain either.
This is not an old idea, of course, but it is a new perspective of the marvels that books like 1984 by George Orwell initiated, predicted and confounded. 1984, written in 1948 and published in 1949 talk about the “BIG BROTHER IS WATCHING YOU” an idea that lives on in our hearts and minds forevermore, and will continue to do so due to the potent threat of Unique Identification systems.

The fallacical idea of injustice, or assured guilt is predefined and primal in those who value their privacy (or even those who desire privacy and agree to adhere to stringent security guidelines) - guilt is assured to all people who value freedom in this way. Refusal to consent to the removal of basic rights of privacy is considered admission of guilt and can lead to further sanctioning as much as agreeing to consent to the removal of their rights, either way freedom is lost - a soul guarantor of a system of fallacical justice.

Below is a furthering of the original idea of removal of privacy by force or otherwise. The below example is presented as an indicator to the system of justice, rather than an argument against or for removal of the nature of the justice, punishment and trialing system.

A brief hypothetical Example of Fallacical Justice:
Example 1

Judge: If you are not guilty you will submit to stringent testing, searching, etc
Civilian: No I won’t submit
Judge: then you must be guilty as if you had nothing to hide you would submit


Example 2

Judge: If you are not guilty you will submit to stringent testing, searching, etc,
Civilian: I will submit.

The Certainty of Judgement
In a modern system of commercial business tracked by software management systems and intercommunication networks there is an insideous movement towards guilt before innocence. A precident that has recently been strengthened by the concept of the “War on Terror”, and the unquenchable need to substitute freedom with security in order to protect it. As a young adult I could only compare it to the actions of a spoilt child whom when finding out he cannot keep his freedom to himself and just himself, destroys it so that others may not enjoy it.

“Let us feel no guilt from the stigma that excercising freedoms of privacy are admissions to it”

Beyond the sociopolitical ideaology, the illusion of perfect society, I find myself confounded by an illusion of the perfect system of reality management. I find myself answering the advocates of the reality system with tips and truisms from the system of idealism; idealism, I would argue is as much as an illusion as the system of reality. i.e. the system of reality uses justifications such as “you must be guilty because you refuse to be searched” - “this patient is beyond help and we cannot justify keeping him on life support”. Such bold and judgemental statements made in the interest of reality and the “life isn’t fair” philosophy are mainly ignorant of the total fallacical illusion of the concept of justification. As an advocate and admirer of the system of idealism as demonstrated in my articles, I would now be forced to argue that
the mockery and “conspiracist nonsense” spoken towards idealist concepts is a result of a society too used to inhabiting a social system based on a nonsensical & unreal system of justification; an illusion more fallacical, judgemental and unwise than the dream of idealist concepts - and most certainly, at least - as dangerous.

References:
1984 by George Orwell http://en.wikipedia.org/wiki/Nineteen_Eighty-Four

Data Protection Act UK http://www.opsi.gov.uk/acts/acts1998/ukpga_19980029_en_1

United States Consitution 3rd ammendment right to privacy:
http://en.wikipedia.org/wiki/Third_Amendment_to_the_United_States_Constitution

“Freedom is an illusion created by those with power, for those without” - M. Jacques
“Expression is meaningless in an anonymous society” - M. Jacques

Comments

Notice of Evangelical Eviction , science or religion

“Whoever undertakes to set himself up as a judge of Truth and Knowledge is shipwrecked by the laughter of the gods.” — Albert Einstein

Some quotes reach us in a great wind, others in the synchronicity of science and modern sociopolitical values, others appear to masquerade as if from nothing, ever present and ever wise.

This notice serves as a warning to anyone who thinks he knows either truth or knowledge paramount; for those who say they do wield a dangerous and harrowing force to themselves and those who would surround them.

This can apply to many works and ideas. Thankyou Einstein, for a more restful day than usual!!

Comments

McAfee admits to direct copyright infringement and breaking GPL license openly - shock.

this story surprised me personally, and it will just go, and continue to, show that people really are mindless to the fact that the M$ slaves have more money, more resources and generally, could get away with murder - at least - if it was in a contract :D Original Article Source: Inquirer - check it out it’s a good read.

McAfee throws some FUD at the GPL

Comment Hits its own investors’ confidence

SATURDAY the sky was a sullen violet overcast at dawn, spitting volleys of rain onto the patio roof. Intermittant wind gusts ruffled the laurel hedge out back and swayed the limbs of the big fir tree in the neighbor’s back yard. A few of the cats ventured out but soon retreated back indoors to get out of the cold winter storm that had swept up the Pacific coast from San Francisco overnight.

In the chill morning dark, quiet except for the sounds of wind and rain outside, it seemed only fitting to happen upon the news of yet more FUD manure thrown at open source software by a vassal of the Volish empire, against its own interests.

* * *

In its annual report, Windows security software vendor McAfee told its investors that open source software licence terms it vaguely characterised as ” ambiguous” might “result in unanticipated obligations regarding our products.”

“To the extent that we use ‘open source’ software, we face risks,” McAfee stated.

McAfee explained: “Use of GPL software could subject certain portions of our proprietary software to the GPL requirements, which may have adverse effects on our sales of the products incorporating any such software.”

That statement says several things. First, it reveals that McAfee does use at least some open source software derived code in its products. Second, it betrays that McAfee has misappropriated that open source software and thus is committing copyright infringement, because it doesn’t distribute that open source software derivative source code. Third, by calling its products that include open source software code “proprietary”, McAfee shows that it really doesn’t want to shoulder its GPL licence obligations, but instead wants to both have its cake and eat it too.

The company might have more honestly admitted that, to the extent it might have been abusing open source software by ignoring its licence requirements, it might have to distribute its modified open source software source code to its customers, or at least make it easily available to any customers who might want to obtain it.

That is all that the GPL requires. It explicitly permits that products that use GPL licenced software may be sold, subject only to the requirement that the source code to components that are GPL licenced must be distributed or made available.

Merely including both proprietary and open source software in the same package or on the same distribution media doesn’t transfer GPL requirements from open source components to proprietary components. McAfee ought to consult with the Free Software Foundation if its management and attorneys are not well versed in the accepted methods for keeping proprietary and open source software separate while still allowing them to work together. The FSF will be glad to help them out.

Even if it were to publish all of the source code for, let’s say, its antivirus product, McAfee would certainly be able to keep its virus signatures database proprietary and confidential. That’s data not code, so it couldn’t be subject to GPL disclosure. McAfee’s antivirus product’s marketability wouldn’t be diminished in the least and end-users would still need update subscriptions even if they had the software free.

After all, the long term end-user value of any antivirus product is in the ongoing malware detection and research performed by the vendor, not in the executable module scanning and signature database matching software machinery by itself.

Of course, McAfee might simply be mortified at the thought of having competent customer programmers viewing its software source code. That might be poorly designed and structured, embarrassingly kludgey, or riddled with clumsy coding, and so on. It might even have glaring design loopholes that could be exploited by malware authors if they became widely known. Then again, one doesn’t really need source code to find design flaws, given some sophisticated debugging tools.

Perhaps McAfee believes in “security by obscurity” and that’s the reason it doesn’t want to reveal its modified open source code. But it, and all of the other Windows security software vendors, should know better. After all, that’s been Microsoft’s approach within Windows itself, and it’s been proven to be totally ineffective. The Windows security software vendors only have demand for their products because the Vole’s whole “security by obscurity” approach has failed and continues to fail.

Besides, properly designed security software can’t be defeated simply by knowing exactly how it works. Well designed security routines have checks that malware code can neither satisfy nor avoid, authorisation tests it can’t pass, and function, memory and file protections it can’t evade to reach sensitive resources, and so on. There’s exemplary open source software that is quite highly secure despite being entirely open for anyone to read. OpenBSD is only one example of several.

However, even if one or more of these is the case, that doesn’t excuse continuing GPL violations. The only possible GPL violation cures are to either distribute the derivative open source code or recode the functions in a clean room environment. That, or completely redesign and rewrite the application… entirely from scratch.

If McAfee didn’t like the GPL or want to abide by its licence terms, it should have written its own blasted software rather than stealing code from the open source community in violation of the GPL and the US Copyright Act. It’s far too late now.

There’s nothing at all “ambiguous” about the terms of the GPL, either. Contrary to McAfee’s snide, scurrilous suggestion, the GPL is a simple, straightforward software licence with no confusing or onerous terms. Compared to the McAfee EULA — or especially a Microsoft EULA — the GPL is a veritable model of simple software licence clarity.

McAfee also feigned to be “troubled” that the terms of the GPL have never been tested in court, supposedly. Well, that’s simply false. The GPL has been upheld in a German court of law, under the Berne Convention that conformed international copyright protection, to which the US is a signatory since 1988, and which is now under the auspices of the UN World Intellectual Property Organisation (WIPO).

The only reason that the GPL has never been “tested” in a US court of law is that every potential defendant in a copyright infringement lawsuit based upon the GPL has chosen to settle out of court rather than risk losing in court.

The US Copyright Act provides for statutory damages of up to $180,000 for each and every instance of willful copyright infringement.

Before it further disparages the GPL, McAfee should contemplate paying multiple authors of open source software licenced under the GPL $180,000 for each copy of its unlicenced and therefore copyright infringing products it ever shipped. One suspects that not even Microsoft has that much money, and certainly not McAfee.

Also, how can McAfee pretend that the redistribution obligations relating to open source software that are so clearly stated in the GPL were “unanticipated” by it?

That claim is tantamount to the admission that McAfee had previously assumed that it could get away with violating the GPL with impunity. Either that, or it’s an admission by McAfee’s executive management of their utterly gross incompetence at directing and managing a legally responsible software development enterprise.

These few statements in its annual report, taken at face value, can’t be viewed as encouraging for investor confidence in McAfee’s executive management team or future business prospects. Indeed, should McAfee’s stock decline in market value, it’s not unimaginable that these statements could come to be cited as evidence of mismanagement in stockholder lawsuits. Under Sarbanes-Oxley, executives might even be held personally liable for causing the corporation to incur legal liabilities. Having disclosed bad management after the fact might not get them off the hook.

On the other hand, open source software developers whose source code McAfee might have misappropriated aren’t likely to sue the company for damages. That’s not the point of the GPL, which merely requires that those developers who modify and redistribute open source software also return those derivative works into the open source software development community. GPL compliance is the objective, not monetary gain, and fortunately for all, compliance is almost always possible.

But McAfee probably knows all of this. So what was the point of the FUD attack?

One can only speculate, but it’s obvious that all of the Windows security software vendors like McAfee are totally dependent upon Microsoft’s dominant Windows OS marketshare for their very existence. Apple Mac and Linux systems aren’t nearly as vulnerable to malware as Windows, which by its very design practically invites infestations of all sorts, the whole menagerie — viruses, adware, spyware, trojans, worms and bots. Without the Vole’s Windows monopoly to provide their customer base, parasitic Windows security vendors like McAfee could not stay in business long. There’s a powerful motive for McAfee to denigrate open source.

Linux users don’t buy antivirus software because Linux isn’t anywhere nearly as insecure as Windows, by orders of magnitude. It just isn’t needed to run Linux.

Perhaps McAfee is afraid that Linux desktop penetration is heading up, which it is, and wants to do whatever it can to slow its takeup, especially in corporations.

That does seem possible, even plausible, but if that’s the case, McAfee is failing to appreciate the direction from which the worst threat to its future viability is most likely to come. Growing uptake of desktop Linux won’t kill off McAfee’s business.

Long before Linux makes big inroads on the desktop, Microsoft will have escaped from federal antitrust oversight. Then the Vole will bundle security functions into Windows and staff its own malware research lab, putting McAfee out of business.

Or perhaps McAfee will offer software that does something actually productive, instead of living as a mere parasite of the Vole, a remora on the Windows shark.

* * *

It’s later Saturday morning and the wind’s died down. The cats are sauntering out again to patrol the soggy grounds under a bright grey, featureless overcast sky. µ

Original Article Source: http://www.theinquirer.net/gb/inquirer/news/2008/01/05/mcafee-throws-fud-gpl

Comments (3)

« Previous entries