<atom:link href="http://people.skolelinux.org/pere/blog/index.rss" rel="self" type="application/rss+xml" />
<item>
- <title>Time to find a new laptop, as the old one is broken after only two years</title>
- <link>http://people.skolelinux.org/pere/blog/Time_to_find_a_new_laptop__as_the_old_one_is_broken_after_only_two_years.html</link>
- <guid isPermaLink="true">http://people.skolelinux.org/pere/blog/Time_to_find_a_new_laptop__as_the_old_one_is_broken_after_only_two_years.html</guid>
- <pubDate>Fri, 3 Jul 2015 07:10:00 +0200</pubDate>
- <description><p>My primary work horse laptop is failing, and will need a
-replacement soon. The left 5 cm of the screen on my Thinkpad X230
-started flickering yesterday, and I suspect the cause is a broken
-cable, as changing the angle of the screen some times get rid of the
-flickering.</p>
+ <title>Detecting NFS hangs on Linux without hanging yourself...</title>
+ <link>http://people.skolelinux.org/pere/blog/Detecting_NFS_hangs_on_Linux_without_hanging_yourself___.html</link>
+ <guid isPermaLink="true">http://people.skolelinux.org/pere/blog/Detecting_NFS_hangs_on_Linux_without_hanging_yourself___.html</guid>
+ <pubDate>Thu, 9 Mar 2017 15:20:00 +0100</pubDate>
+ <description><p>Over the years, administrating thousand of NFS mounting linux
+computers at the time, I often needed a way to detect if the machine
+was experiencing NFS hang. If you try to use <tt>df</tt> or look at a
+file or directory affected by the hang, the process (and possibly the
+shell) will hang too. So you want to be able to detect this without
+risking the detection process getting stuck too. It has not been
+obvious how to do this. When the hang has lasted a while, it is
+possible to find messages like these in dmesg:</p>
-<p>My requirements have not really changed since I bought it, and is
-still as
-<a href="http://people.skolelinux.org/pere/blog/Thank_you_Thinkpad_X41__for_your_long_and_trustworthy_service.html">I
-described them in 2013</a>. The last time I bought a laptop, I had
-good help from
-<a href="http://www.prisjakt.no/category.php?k=353">prisjakt.no</a>
-where I could select at least a few of the requirements (mouse pin,
-wifi, weight) and go through the rest manually. Three button mouse
-and a good keyboard is not available as an option, and all the three
-laptop models proposed today (Thinkpad X240, HP EliteBook 820 G1 and
-G2) lack three mouse buttons). It is also unclear to me how good the
-keyboard on the HP EliteBooks are. I hope Lenovo have not messed up
-the keyboard, even if the quality and robustness in the X series have
-deteriorated since X41.</p>
-
-<p>I wonder how I can find a sensible laptop when none of the options
-seem sensible to me? Are there better services around to search the
-set of available laptops for features? Please send me an email if you
-have suggestions.</p>
+<p><blockquote>
+nfs: server nfsserver not responding, still trying
+<br>nfs: server nfsserver OK
+</blockquote></p>
+
+<p>It is hard to know if the hang is still going on, and it is hard to
+be sure looking in dmesg is going to work. If there are lots of other
+messages in dmesg the lines might have rotated out of site before they
+are noticed.</p>
+
+<p>While reading through the nfs client implementation in linux kernel
+code, I came across some statistics that seem to give a way to detect
+it. The om_timeouts sunrpc value in the kernel will increase every
+time the above log entry is inserted into dmesg. And after digging a
+bit further, I discovered that this value show up in
+/proc/self/mountstats on Linux.</p>
+
+<p>The mountstats content seem to be shared between files using the
+same file system context, so it is enough to check one of the
+mountstats files to get the state of the mount point for the machine.
+I assume this will not show lazy umounted NFS points, nor NFS mount
+points in a different process context (ie with a different filesystem
+view), but that does not worry me.</p>
+
+<p>The content for a NFS mount point look similar to this:</p>
+
+<p><blockquote><pre>
+[...]
+device /dev/mapper/Debian-var mounted on /var with fstype ext3
+device nfsserver:/mnt/nfsserver/home0 mounted on /mnt/nfsserver/home0 with fstype nfs statvers=1.1
+ opts: rw,vers=3,rsize=65536,wsize=65536,namlen=255,acregmin=3,acregmax=60,acdirmin=30,acdirmax=60,soft,nolock,proto=tcp,timeo=600,retrans=2,sec=sys,mountaddr=129.240.3.145,mountvers=3,mountport=4048,mountproto=udp,local_lock=all
+ age: 7863311
+ caps: caps=0x3fe7,wtmult=4096,dtsize=8192,bsize=0,namlen=255
+ sec: flavor=1,pseudoflavor=1
+ events: 61063112 732346265 1028140 35486205 16220064 8162542 761447191 71714012 37189 3891185 45561809 110486139 4850138 420353 15449177 296502 52736725 13523379 0 52182 9016896 1231 0 0 0 0 0
+ bytes: 166253035039 219519120027 0 0 40783504807 185466229638 11677877 45561809
+ RPC iostats version: 1.0 p/v: 100003/3 (nfs)
+ xprt: tcp 925 1 6810 0 0 111505412 111480497 109 2672418560317 0 248 53869103 22481820
+ per-op statistics
+ NULL: 0 0 0 0 0 0 0 0
+ GETATTR: 61063106 61063108 0 9621383060 6839064400 453650 77291321 78926132
+ SETATTR: 463469 463470 0 92005440 66739536 63787 603235 687943
+ LOOKUP: 17021657 17021657 0 3354097764 4013442928 57216 35125459 35566511
+ ACCESS: 14281703 14290009 5 2318400592 1713803640 1709282 4865144 7130140
+ READLINK: 125 125 0 20472 18620 0 1112 1118
+ READ: 4214236 4214237 0 715608524 41328653212 89884 22622768 22806693
+ WRITE: 8479010 8494376 22 187695798568 1356087148 178264904 51506907 231671771
+ CREATE: 171708 171708 0 38084748 46702272 873 1041833 1050398
+ MKDIR: 3680 3680 0 773980 993920 26 23990 24245
+ SYMLINK: 903 903 0 233428 245488 6 5865 5917
+ MKNOD: 80 80 0 20148 21760 0 299 304
+ REMOVE: 429921 429921 0 79796004 61908192 3313 2710416 2741636
+ RMDIR: 3367 3367 0 645112 484848 22 5782 6002
+ RENAME: 466201 466201 0 130026184 121212260 7075 5935207 5961288
+ LINK: 289155 289155 0 72775556 67083960 2199 2565060 2585579
+ READDIR: 2933237 2933237 0 516506204 13973833412 10385 3190199 3297917
+ READDIRPLUS: 1652839 1652839 0 298640972 6895997744 84735 14307895 14448937
+ FSSTAT: 6144 6144 0 1010516 1032192 51 9654 10022
+ FSINFO: 2 2 0 232 328 0 1 1
+ PATHCONF: 1 1 0 116 140 0 0 0
+ COMMIT: 0 0 0 0 0 0 0 0
+
+device binfmt_misc mounted on /proc/sys/fs/binfmt_misc with fstype binfmt_misc
+[...]
+</pre></blockquote></p>
+
+<p>The key number to look at is the third number in the per-op list.
+It is the number of NFS timeouts experiences per file system
+operation. Here 22 write timeouts and 5 access timeouts. If these
+numbers are increasing, I believe the machine is experiencing NFS
+hang. Unfortunately the timeout value do not start to increase right
+away. The NFS operations need to time out first, and this can take a
+while. The exact timeout value depend on the setup. For example the
+defaults for TCP and UDP mount points are quite different, and the
+timeout value is affected by the soft, hard, timeo and retrans NFS
+mount options.</p>
+
+<p>The only way I have been able to get working on Debian and RedHat
+Enterprise Linux for getting the timeout count is to peek in /proc/.
+But according to
+<ahref="http://docs.oracle.com/cd/E19253-01/816-4555/netmonitor-12/index.html">Solaris
+10 System Administration Guide: Network Services</a>, the 'nfsstat -c'
+command can be used to get these timeout values. But this do not work
+on Linux, as far as I can tell. I
+<ahref="http://bugs.debian.org/857043">asked Debian about this</a>,
+but have not seen any replies yet.</p>
+
+<p>Is there a better way to figure out if a Linux NFS client is
+experiencing NFS hangs? Is there a way to detect which processes are
+affected? Is there a way to get the NFS mount going quickly once the
+network problem causing the NFS hang has been cleared? I would very
+much welcome some clues, as we regularly run into NFS hangs.</p>
</description>
</item>
<item>
- <title>MakerCon Nordic videos now available on Frikanalen</title>
- <link>http://people.skolelinux.org/pere/blog/MakerCon_Nordic_videos_now_available_on_Frikanalen.html</link>
- <guid isPermaLink="true">http://people.skolelinux.org/pere/blog/MakerCon_Nordic_videos_now_available_on_Frikanalen.html</guid>
- <pubDate>Thu, 2 Jul 2015 14:10:00 +0200</pubDate>
- <description><p>Last oktober I was involved on behalf of
-<a href="http://www.nuug.no/">NUUG</a> with recording the talks at
-<a href="http://www.makercon.no/">MakerCon Nordic</a>, a conference for
-the Maker movement. Since then it has been the plan to publish the
-recordings on <a href="http://www.frikanalen.no/">Frikanalen</a>, which
-finally happened the last few days. A few talks are missing because
-the speakers asked the organizers to not publish them, but most of the
-talks are available. The talks are being broadcasted on RiksTV
-channel 50 and using multicast on Uninett, as well as being available
-from the Frikanalen web site. The unedited recordings are
-<a href="https://www.youtube.com/user/MakerConNordic/">available on
-Youtube too</a>.</p>
-
-<p>This is the list of talks available at the moment. Visit the
-<a href="http://beta.frikanalen.no/video/?q=makercon">Frikanalen video
-pages</a> to view them.</p>
-
-<ul>
-
- <li>Evolutionary algorithms as a design tool - from art
- to robotics (Kyrre Glette)</li>
-
- <li>Make and break (Hans Gerhard Meier)</li>
-
- <li>Making a one year school course for young makers
- (Olav Helland)</li>
-
- <li>Innovation Inspiration - IPR Databases as a Source of
- Inspiration (Hege Langlo)</li>
-
- <li>Making a toy for makers (Erik Torstensson)</li>
-
- <li>How to make 3D printer electronics (Elias Bakken)</li>
-
- <li>Hovering Clouds: Looking at online tool offerings for Product
- Design and 3D Printing (William Kempton)</li>
-
- <li>Travelling maker stories (Øyvind Nydal Dahl)</li>
-
- <li>Making the first Maker Faire in Sweden (Nils Olander)</li>
-
- <li>Breaking the mold: Printing 1000’s of parts (Espen Sivertsen)</li>
-
- <li>Ultimaker — and open source 3D printing (Erik de Bruijn)</li>
-
- <li>Autodesk’s 3D Printing Platform: Sparking innovation (Hilde
- Sevens)</li>
-
- <li>How Making is Changing the World – and How You Can Too!
- (Jennifer Turliuk)</li>
-
- <li>Open-Source Adventuring: OpenROV, OpenExplorer and the Future of
- Connected Exploration (David Lang)</li>
-
- <li>Making in Norway (Haakon Karlsen Jr., Graham Hayward and Jens
- Dyvik)</li>
-
- <li>The Impact of the Maker Movement (Mike Senese)</li>
-
-</ul>
-
-<p>Part of the reason this took so long was that the scripts NUUG had
-to prepare a recording for publication were five years old and no
-longer worked with the current video processing tools (command line
-argument changes). In addition, we needed better audio normalization,
-which sent me on a detour to
-<a href="http://people.skolelinux.org/pere/blog/Measuring_and_adjusting_the_loudness_of_a_TV_channel_using_bs1770gain.html">package
-bs1770gain for Debian</a>. Now this is in place and it became a lot
-easier to publish NUUG videos on Frikanalen.</p>
+ <title>How does it feel to be wiretapped, when you should be doing the wiretapping...</title>
+ <link>http://people.skolelinux.org/pere/blog/How_does_it_feel_to_be_wiretapped__when_you_should_be_doing_the_wiretapping___.html</link>
+ <guid isPermaLink="true">http://people.skolelinux.org/pere/blog/How_does_it_feel_to_be_wiretapped__when_you_should_be_doing_the_wiretapping___.html</guid>
+ <pubDate>Wed, 8 Mar 2017 11:50:00 +0100</pubDate>
+ <description><p>So the new president in the United States of America claim to be
+surprised to discover that he was wiretapped during the election
+before he was elected president. He even claim this must be illegal.
+Well, doh, if it is one thing the confirmations from Snowden
+documented, it is that the entire population in USA is wiretapped, one
+way or another. Of course the president candidates were wiretapped,
+alongside the senators, judges and the rest of the people in USA.</p>
+
+<p>Next, the Federal Bureau of Investigation ask the Department of
+Justice to go public rejecting the claims that Donald Trump was
+wiretapped illegally. I fail to see the relevance, given that I am
+sure the surveillance industry in USA believe they have all the legal
+backing they need to conduct mass surveillance on the entire
+world.</p>
+
+<p>There is even the director of the FBI stating that he never saw an
+order requesting wiretapping of Donald Trump. That is not very
+surprising, given how the FISA court work, with all its activity being
+secret. Perhaps he only heard about it?</p>
+
+<p>What I find most sad in this story is how Norwegian journalists
+present it. In a news reports the other day in the radio from the
+Norwegian National broadcasting Company (NRK), I heard the journalist
+claim that 'the FBI denies any wiretapping', while the reality is that
+'the FBI denies any illegal wiretapping'. There is a fundamental and
+important difference, and it make me sad that the journalists are
+unable to grasp it.</p>
+
+<p><strong>Update 2017-03-13:</strong> Look like
+<a href="https://theintercept.com/2017/03/13/rand-paul-is-right-nsa-routinely-monitors-americans-communications-without-warrants/">The
+Intercept report that US Senator Rand Paul confirm what I state above</a>.</p>
</description>
</item>
<item>
- <title>Hvem fører Medietilsynet tilsyn med?</title>
- <link>http://people.skolelinux.org/pere/blog/Hvem_f_rer_Medietilsynet_tilsyn_med_.html</link>
- <guid isPermaLink="true">http://people.skolelinux.org/pere/blog/Hvem_f_rer_Medietilsynet_tilsyn_med_.html</guid>
- <pubDate>Sun, 28 Jun 2015 23:20:00 +0200</pubDate>
- <description><p>I en global verden med eierskap på tvers, trengs det informasjon om
-hvem som har kontrollen i selskaper og bedrifter. Og for å få tilgang
-til slik informasjon for alle som ønsker å analysere eierskap, holder
-med ikke med nasjonale databaser over eierskap, det må globale
-samledatabaser med åpne data til. Heldigvis finnes det en
-internasjonal bevegelse for å gjøre selskapsinformasjon for alle land
-offentlig tilgjengelig. En slik database heter
-<a href="http://opencorporates.com">OpenCorporates</a>, der
-informasjonen er gratis tilgjengelig med en "del på samme
-vilkår"-lisens. De samler inn selskapsinformasjon, eierskap,
-konsesjonstildelinger og lignende. De manglet ganske mye for Norge,
-da bruksvilkårene til Norsk offentlig informasjon i stor grad
-blokkerer OpenCorporates fra å samle den inn.</p>
-
-<p>Men jeg er jo involvert i
-<a href="http://www.frikanalen.no/">Frikanalen</a>, som har
-TV-konsesjon, og tenkte det kunne være fint om informasjon om alle
-mediakonsesjoner var tilgjengelig i OpenCorporates, så jeg sendte
-avgårde følgende spørsmål til Medietilsynet 2015-06-22:</p>
-
-<blockquote>
-<p>Hei. Finnes det en oversikt over enhetene som Mediatilsynet fører
-tilsyn med som åpne data? Jeg lette etter den på
-&lt;URL:<a href="http://data.norge.no/">http://data.norge.no/</a>&gt; og
-&lt;URL:<a href="http://hotell.difi.no/">http://hotell.difi.no/</a>&gt; uten å
-finne noe der, og fant heller ikke noe under
-&lt;URL:<a href="http://www.medietilsynet.no/">http://www.medietilsynet.no/</a>&gt;.</p>
-
-<p>Jeg tenker på alle som har fått kringkastingskonsesjon og alle som
-er omtalt under
-&lt;URL:<a href="http://www.medietilsynet.no/mediebildet/">http://www.medietilsynet.no/mediebildet/</a>&gt;.</p>
-
-<p>Jeg skulle gjerne hatt dette maskinlesbart, og inkludert
-organisasjonsnummer og hva slags forhold mediatilsynet har til
-organisasjonene. Tanken er å importere det i
-&lt;URL:<a href="https://opencorporates.com/">https://opencorporates.com/</a>&gt; for analyse, så det bør ikke ha
-bruksbegresninger som gjør dette umulig.</p>
-</blockquote>
-
-<p>To dager senere fikk jeg svar, med de datasettene de hadde
-tilgjengelig. Svaret fra Hanne Sekkelsten hos Medietilsynet var
-informativt og imøtekommende.</p>
-
-<blockquote>
-<p>Vi viser til din e-post av 22. juni, der du ber om å få tilsendt oversikter
-over aktører Medietilsynet fører tilsyn med.</p>
-
-<p>Medietilsynet fører tilsyn med kringkastere og audiovisuelle
-bestillingstjenester som omfattes av kringkastingsloven, og med
-eierskap i aviser, fjernsyn radio og elektroniske medier etter
-medieeierskapsloven. I tillegg vil Medietilsynet etter at
-beskyttelsesloven trer i kraft fra 1. juli ha tilsyn med en rekke nye
-aktører. Nærmere informasjon om den nye loven finnes på Medietilsynets
-nettsted, her:
-<a href="http://www.medietilsynet.no/mediebransjen/bildeprogramloven/">http://www.medietilsynet.no/mediebransjen/bildeprogramloven/</a>
-. Vi har ikke utarbeidet oversikter over alle aktørene, men vi sender
-deg her de listene vi har utarbeidet, hentet fra våre databaser. Vi
-har dessverre ikke ferdige rapporter som inneholder
-organisasjonsnummer. Dersom du ønsker flere opplysninger ber vi om at
-du tar kontakt med oss slik at vi kan finne ut av hvilke opplysninger
-du trenger, og hvilke vi kan fremskaffe.</p>
-
-<p>Vedlagt følger:
-
-<ul>
-
- <li>Konsesjoner - lokalradio FM pr. 31.12.2014 [<a href="http://people.skolelinux.org/pere/blog/images/2015-06-28-medietilsynsdata/Konsesjoner_lokalradio_fm_felles_31.12.2014.pdf">PDF (original)</a>]</li>
-
- <li>Konsesjoner - lokalfjernsyn i det digitale bakkenettet for fjernsyn, pr. mars 2015 [<a href="http://people.skolelinux.org/pere/blog/images/2015-06-28-medietilsynsdata/Lokalfjernsyn_DTT_konsesjoner_mars_2015.docx">DOCX (original)</a>,
-<a href="http://people.skolelinux.org/pere/blog/images/2015-06-28-medietilsynsdata/Lokalfjernsyn_DTT_konsesjoner_mars_2015.pdf">PDF</a>]</li>
-
- <li>Konsesjoner - DAB-radio, status mars 2015 [<a href="http://people.skolelinux.org/pere/blog/images/2015-06-28-medietilsynsdata/Konsesjonaernummer_DAB.xps">XPS (original)</a>,
-<a href="http://people.skolelinux.org/pere/blog/images/2015-06-28-medietilsynsdata/Konsesjonaernummer_DAB.pdf">PDF</a>]</li>
-
- <li>Registreringspliktige kringkastere - status mars 2015: [<a href="http://people.skolelinux.org/pere/blog/images/2015-06-28-medietilsynsdata/Registreringspliktige_kringkastere_register_-_aktive.xps">XPS (original)</a>, <a href="http://people.skolelinux.org/pere/blog/images/2015-06-28-medietilsynsdata/Registreringspliktige_kringkastere_register_-_aktive.pdf">PDF</a>]
-
- <ul>
- <li>Kabelsendt fjernsyn
- <li>Satellittsendt fjernsyn
- <li>Nett-tv
- <li>Kabelsendt radio
- <li>Satellittsendt radio
- <li>Nett-radio
- </ul></li>
-</ul>
-
-<p>Vi må ta forbehold om at det kan være enkelte feil i oversiktene
-siden disse ikke er oppdaterte pr. dags dato. Vi vil foreta nye
-oppdateringer i august.</p>
-
-<p>Med hilsen</p>
-
-<p>Hanne Nistad Sekkelsten
-<br>Seniorrådgiver | Senior Legal Adviser
-<br>Medietilsynet | Norwegian Media Authority
-<br>A: Nygata 4, NO-1607 Fredrikstad
-<br>T: [telefonnummer fjernet]
-<br>E: [adresse fjernet] | W: www.medietilsynet.no
-</p>
-</blockquote>
-
-<p>Desverre er formatene for ustrukturerte til maskinell behandling og
-mangler endel informasjon, men det er gode oversikter over hvem
-Medietilsynet fører tilsyn med. Filene er på formatene PDF, XPS
-(XML-basert PDF-lignende format fra Microsoft) og DOCX, så det vil
-være en stor jobb å strukturere informasjonen på en måte som kan
-importeres i OpenCorporates. Svaret er ikke i tråd med
-<a href="http://lovdata.no/dokument/SF/forskrift/2013-04-05-959">Forskrift
-om IT-standarder i offentlig forvaltning</a> som sier epostvedlegg
-skal sendes som PDF, så jeg har gjorde PDF-utgaver av XPS og
-DOCX-utgavene tilgjengelig for å gjøre det enklere for alle å se
-innholdet.</p>
+ <title>Norwegian Bokmål translation of The Debian Administrator's Handbook complete, proofreading in progress</title>
+ <link>http://people.skolelinux.org/pere/blog/Norwegian_Bokm_l_translation_of_The_Debian_Administrator_s_Handbook_complete__proofreading_in_progress.html</link>
+ <guid isPermaLink="true">http://people.skolelinux.org/pere/blog/Norwegian_Bokm_l_translation_of_The_Debian_Administrator_s_Handbook_complete__proofreading_in_progress.html</guid>
+ <pubDate>Fri, 3 Mar 2017 14:50:00 +0100</pubDate>
+ <description><p>For almost a year now, we have been working on making a Norwegian
+Bokmål edition of <a href="https://debian-handbook.info/">The Debian
+Administrator's Handbook</a>. Now, thanks to the tireless effort of
+Ole-Erik, Ingrid and Andreas, the initial translation is complete, and
+we are working on the proof reading to ensure consistent language and
+use of correct computer science terms. The plan is to make the book
+available on paper, as well as in electronic form. For that to
+happen, the proof reading must be completed and all the figures need
+to be translated. If you want to help out, get in touch.</p>
+
+<p><a href="http://people.skolelinux.org/pere/debian-handbook/debian-handbook-nb-NO.pdf">A
+
+fresh PDF edition</a> in A4 format (the final book will have smaller
+pages) of the book created every morning is available for
+proofreading. If you find any errors, please
+<a href="https://hosted.weblate.org/projects/debian-handbook/">visit
+Weblate and correct the error</a>. The
+<a href="http://l.github.io/debian-handbook/stat/nb-NO/index.html">state
+of the translation including figures</a> is a useful source for those
+provide Norwegian bokmål screen shots and figures.</p>
</description>
</item>
<item>
- <title>Graphing the Norwegian company ownership structure</title>
- <link>http://people.skolelinux.org/pere/blog/Graphing_the_Norwegian_company_ownership_structure.html</link>
- <guid isPermaLink="true">http://people.skolelinux.org/pere/blog/Graphing_the_Norwegian_company_ownership_structure.html</guid>
- <pubDate>Mon, 15 Jun 2015 14:00:00 +0200</pubDate>
- <description><p>It is a bit work to figure out the ownership structure of companies
-in Norway. The information is publicly available, but one need to
-recursively look up ownership for all owners to figure out the complete
-ownership graph of a given set of companies. To save me the work in
-the future, I wrote a script to do this automatically, outputting the
-ownership structure using the Graphviz/dotty format. The data source
-is web scraping from <a href="http://www.proff.no/">Proff</a>, because
-I failed to find a useful source directly from the official keepers of
-the ownership data, <a href="http://www.brreg.no/">Brønnøysundsregistrene</a>.</p>
-
-<p>To get an ownership graph for a set of companies, fetch
-<a href="https://github.com/petterreinholdtsen/brreg-norway-ownership-graph">the code from git</a> and run it using the organisation number. I'm
-using the Norwegian newspaper Dagbladet as an example here, as its
-ownership structure is very simple:</p>
-
-<pre>
-% time ./bin/eierskap-dotty 958033540 > dagbladet.dot
-
-real 0m2.841s
-user 0m0.184s
-sys 0m0.036s
+ <title>Unlimited randomness with the ChaosKey?</title>
+ <link>http://people.skolelinux.org/pere/blog/Unlimited_randomness_with_the_ChaosKey_.html</link>
+ <guid isPermaLink="true">http://people.skolelinux.org/pere/blog/Unlimited_randomness_with_the_ChaosKey_.html</guid>
+ <pubDate>Wed, 1 Mar 2017 20:50:00 +0100</pubDate>
+ <description><p>A few days ago I ordered a small batch of
+<a href="http://altusmetrum.org/ChaosKey/">the ChaosKey</a>, a small
+USB dongle for generating entropy created by Bdale Garbee and Keith
+Packard. Yesterday it arrived, and I am very happy to report that it
+work great! According to its designers, to get it to work out of the
+box, you need the Linux kernel version 4.1 or later. I tested on a
+Debian Stretch machine (kernel version 4.9), and there it worked just
+fine, increasing the available entropy very quickly. I wrote a small
+test oneliner to test. It first print the current entropy level,
+drain /dev/random, and then print the entropy level for five seconds.
+Here is the situation without the ChaosKey inserted:</p>
+
+<blockquote><pre>
+% cat /proc/sys/kernel/random/entropy_avail; \
+ dd bs=1M if=/dev/random of=/dev/null count=1; \
+ for n in $(seq 1 5); do \
+ cat /proc/sys/kernel/random/entropy_avail; \
+ sleep 1; \
+ done
+300
+0+1 oppføringer inn
+0+1 oppføringer ut
+28 byte kopiert, 0,000264565 s, 106 kB/s
+4
+8
+12
+17
+21
%
-</pre>
-
-<p>The script accept several organisation numbers on the command line,
-allowing a cluster of companies to be graphed in the same image. The
-resulting dot file for the example above look like this. The edges
-are labeled with the ownership percentage, and the nodes uses the
-organisation number as their name and the name as the label:</p>
-
-<pre>
-digraph ownership {
-rankdir = LR;
-"Aller Holding A/s" -> "910119877" [label="100%"]
-"910119877" -> "998689015" [label="100%"]
-"998689015" -> "958033540" [label="99%"]
-"974530600" -> "958033540" [label="1%"]
-"958033540" [label="AS DAGBLADET"]
-"998689015" [label="Berner Media Holding AS"]
-"974530600" [label="Dagbladets Stiftelse"]
-"910119877" [label="Aller Media AS"]
-}
-</pre>
-
-<p>To view the ownership graph, run "<tt>dotty dagbladet.dot</tt>" or
-convert it to a PNG using "<tt>dot -T png dagbladet.dot >
-dagbladet.png</tt>". The result can be seen below:</p>
-
-<img src="http://people.skolelinux.org/pere/blog/images/2015-06-15-ownership-graphs-norway-dagbladet.png" width="80%">
-
-<p>Note that I suspect the "Aller Holding A/S" entry to be incorrect
-data in the official ownership register, as that name is not
-registered in the official company register for Norway. The ownership
-register is sensitive to typos and there seem to be no strict checking
-of the ownership links.</p>
+</pre></blockquote>
+
+<p>The entropy level increases by 3-4 every second. In such case any
+application requiring random bits (like a HTTPS enabled web server)
+will halt and wait for more entrpy. And here is the situation with
+the ChaosKey inserted:</p>
+
+<blockquote><pre>
+% cat /proc/sys/kernel/random/entropy_avail; \
+ dd bs=1M if=/dev/random of=/dev/null count=1; \
+ for n in $(seq 1 5); do \
+ cat /proc/sys/kernel/random/entropy_avail; \
+ sleep 1; \
+ done
+1079
+0+1 oppføringer inn
+0+1 oppføringer ut
+104 byte kopiert, 0,000487647 s, 213 kB/s
+433
+1028
+1031
+1035
+1038
+%
+</pre></blockquote>
-<p>Let me know if you improve the script or find better data sources.
-The code is licensed according to GPL 2 or newer.</p>
+<p>Quite the difference. :) I bought a few more than I need, in case
+someone want to buy one here in Norway. :)</p>
-<p>Update 2015-06-15: Since the initial post I've been told that
-"<a href="http://www.proff.dk/firma/carl-allers-etablissement-aktieselskab/københavn-v/hovedkontorer/13624518-3/">Aller
-Holding A/S</a>" is a Danish company, which explain why it did not
-have a Norwegian organisation number. I've also been told that there
-is a <a href="http://www.brreg.no/automatiske/webservices/">web
-services API available</a> from Brønnøysundsregistrene, for those
-willing to accept the terms or pay the price.</p>
+<p>Update: The dongle was presented at Debconf last year. You might
+find <a href="https://debconf16.debconf.org/talks/94/">the talk
+recording illuminating</a>. It explains exactly what the source of
+randomness is, if you are unable to spot it from the schema drawing
+available from the ChaosKey web site linked at the start of this blog
+post.</p>
</description>
</item>
<item>
- <title>Measuring and adjusting the loudness of a TV channel using bs1770gain</title>
- <link>http://people.skolelinux.org/pere/blog/Measuring_and_adjusting_the_loudness_of_a_TV_channel_using_bs1770gain.html</link>
- <guid isPermaLink="true">http://people.skolelinux.org/pere/blog/Measuring_and_adjusting_the_loudness_of_a_TV_channel_using_bs1770gain.html</guid>
- <pubDate>Thu, 11 Jun 2015 13:40:00 +0200</pubDate>
- <description><p>Television loudness is the source of frustration for viewers
-everywhere. Some channels are very load, others are less loud, and
-ads tend to shout very high to get the attention of the viewers, and
-the viewers do not like this. This fact is well known to the TV
-channels. See for example the BBC white paper
-"<a href="http://downloads.bbc.co.uk/rd/pubs/whp/whp-pdf-files/WHP202.pdf">Terminology
-for loudness and level dBTP, LU, and all that</a>" from 2011 for a
-summary of the problem domain. To better address the need for even
-loadness, the TV channels got together several years ago to agree on a
-new way to measure loudness in digital files as one step in
-standardizing loudness. From this came the ITU-R standard BS.1770,
-"<a href="http://www.itu.int/rec/R-REC-BS.1770/en">Algorithms to
-measure audio programme loudness and true-peak audio level</a>".</p>
-
-<p>The ITU-R BS.1770 specification describe an algorithm to measure
-loadness in LUFS (Loudness Units, referenced to Full Scale). But
-having a way to measure is not enough. To get the same loudness
-across TV channels, one also need to decide which value to standardize
-on. For European TV channels, this was done in the EBU Recommondaton
-R128, "<a href="https://tech.ebu.ch/docs/r/r128.pdf">Loudness
-normalisation and permitted maximum level of audio signals</a>", which
-specifies a recommended level of -23 LUFS. In Norway, I have been
-told that NRK, TV2, MTG and SBS have decided among themselves to
-follow the R128 recommondation for playout from 2016-03-01.</p>
-
-<p>There are free software available to measure and adjust the loudness
-level using the LUFS. In Debian, I am aware of a library named
-<a href="https://tracker.debian.org/pkg/libebur128">libebur128</a>
-able to measure the loudness and since yesterday morning a new binary
-named <a href="http://bs1770gain.sourceforge.net">bs1770gain</a>
-capable of both measuring and adjusting was uploaded and is waiting
-for NEW processing. I plan to maintain the latter in Debian under the
-<a href="https://qa.debian.org/developer.php?email=pkg-multimedia-maintainers%40lists.alioth.debian.org">Debian
-multimedia</a> umbrella.</p>
-
-<p>The free software based TV channel I am involved in,
-<a href="http://www.frikanalen.no/">Frikanalen</a>, plan to follow the
-R128 recommondation ourself as soon as we can adjust the software to
-do so, and the bs1770gain tool seem like a good fit for that part of
-the puzzle to measure loudness on new video uploaded to Frikanalen.
-Personally, I plan to use bs1770gain to adjust the loudness of videos
-I upload to Frikanalen on behalf of <a href="http://www.nuug.no/">the
-NUUG member organisation</a>. The program seem to be able to measure
-the LUFS value of any media file handled by ffmpeg, but I've only
-successfully adjusted the LUFS value of WAV files. I suspect it
-should be able to adjust it for all the formats handled by ffmpeg.</p>
+ <title>Detect OOXML files with undefined behaviour?</title>
+ <link>http://people.skolelinux.org/pere/blog/Detect_OOXML_files_with_undefined_behaviour_.html</link>
+ <guid isPermaLink="true">http://people.skolelinux.org/pere/blog/Detect_OOXML_files_with_undefined_behaviour_.html</guid>
+ <pubDate>Tue, 21 Feb 2017 00:20:00 +0100</pubDate>
+ <description><p>I just noticed
+<a href="http://www.arkivrad.no/aktuelt/riksarkivarens-forskrift-pa-horing">the
+new Norwegian proposal for archiving rules in the goverment</a> list
+<a href="http://www.ecma-international.org/publications/standards/Ecma-376.htm">ECMA-376</a>
+/ ISO/IEC 29500 (aka OOXML) as valid formats to put in long term
+storage. Luckily such files will only be accepted based on
+pre-approval from the National Archive. Allowing OOXML files to be
+used for long term storage might seem like a good idea as long as we
+forget that there are plenty of ways for a "valid" OOXML document to
+have content with no defined interpretation in the standard, which
+lead to a question and an idea.</p>
+
+<p>Is there any tool to detect if a OOXML document depend on such
+undefined behaviour? It would be useful for the National Archive (and
+anyone else interested in verifying that a document is well defined)
+to have such tool available when considering to approve the use of
+OOXML. I'm aware of the
+<a href="https://github.com/arlm/officeotron/">officeotron OOXML
+validator</a>, but do not know how complete it is nor if it will
+report use of undefined behaviour. Are there other similar tools
+available? Please send me an email if you know of any such tool.</p>
</description>
</item>
<item>
- <title>Hva gjør at NRK kan distribuere H.264-video uten patentavtale med MPEG LA?</title>
- <link>http://people.skolelinux.org/pere/blog/Hva_gj_r_at_NRK_kan_distribuere_H_264_video_uten_patentavtale_med_MPEG_LA_.html</link>
- <guid isPermaLink="true">http://people.skolelinux.org/pere/blog/Hva_gj_r_at_NRK_kan_distribuere_H_264_video_uten_patentavtale_med_MPEG_LA_.html</guid>
- <pubDate>Wed, 10 Jun 2015 15:20:00 +0200</pubDate>
- <description><p>Helt siden jeg i 2012 fikk beskjed fra MPEG LA om at
-<a href="http://people.skolelinux.org/pere/blog/MPEG_LA_mener_NRK_m__ha_avtale_med_dem_for___kringkaste_og_publisere_H_264_video.html">NRK
-trengte patentavtale med dem</a> hvis de distribuerte H.264-video til
-sluttbrukere, har jeg lurt på hva som gjør at NRK ikke har slik
-avtale. For noen dager siden fikk jeg endelig gjort noe med min
-undring, og sendte 2015-05-28 følgende epost til info (at) nrk.no med
-tittel "Hva gjør at NRK kan distribuere H.264-video uten patentavtale
-med MPEG LA?":</p>
-
-<p><blockquote>
-<p>Jeg lurer på en ting rundt NRKs bruk av H.264-video på sine
-websider samt distribusjon via RiksTV og kabel-TV. Har NRK vurdert om
-det er behov for en patentavtale med
-<a href="http://www.mpegla.com/">MPEG LA</a> slik det står i
-programvarelisensene til blant annet Apple Final Cut Studio, Adobe
-Premiere Pro, Avid og Apples Final Cut Pro X?</p>
-
-<p>Hvis dere har vurdert dette, hva var utfallet av en slik vurdering?</p>
-
-<p>Hvis dere ikke har vurdert dette, har NRK planer om å vurdere behovet
-for patentavtale?</p>
-
-<p>I følge en artikkel på
-<a href="https://nrkbeta.no/2012/02/01/siste-kutt-for-final-cut/">NRK
-Beta i 2012</a> har NRK brukt eller testet både Apple Final Cut
-Studio, Adobe Premiere Pro, Avid og Apples Final Cut Pro X til bruk
-for å redigere video før sending. Alle disse har bruksvilkår
-understøttet av opphavsretten som sier at de kun kan brukes til å lage
-filmer til personlig og ikke-kommersiell bruk - med mindre en har en
-lisensavtale med MPEG LA om bruk av patenter utstedt i USA for H.264.
-Se f.eks. <a href="http://www.avid.com/static/resources/common/documents/corporate/LICENSE.pdf">bruksvilkårene for Avid</a>, <a href="http://news.cnet.com/8301-30685_3-20000101-264.html">Adobe Premiere</a> og <a href="http://images.apple.com/legal/sla/docs/finalcutstudio2.pdf">Apple Final
-Cut Studio</a> og søk etter "MPEG LA".</p>
-
-<p>Dette får meg til å lure på om det er brudd på opphavsretten å bruke
-disse verktøyene i strid med bruksvilkårene uten patentavtale med MPEG
-LA. Men NRK bruker jo tilsynelatende disse verktøyene uten patentavtale
-med MPEG LA.</p>
-
-<p>I følge forfatteren av Open Broadcast Encoder finnes det to typer
-H.264-relaterte avtaler en kan få med MPEG LA. Det er én for å lage
-programvare og utstyr som produserer H.264-video, og en annen for å
-kringkaste video som bruker H.264. Dette forteller meg at selv om
-produsentene av utstyr og programvare som NRK bruker har en slik avtale
-med MPEG LA, så trenges det en egen avtale for å kringkaste video på det
-formatet.</p>
-
-<p>I følge Ryan Rodriguez hos MPEG LA, da jeg spurte ham på epost i
-juni 2012, har NRK ikke en slik avtale med MPEG LA. Han sa videre at
-NRK trenger en slik avtale hvis NRK tilbyr H.264-kodet video til
-sluttbrukere. Jeg sjekket listen med
-<a href="http://www.mpegla.com/main/programs/AVC/Pages/Licensees.aspx">organisasjoner
-med avtale med MPEG LA</a> og NRK står fortsatt ikke der.</p>
-
-<p>Jeg lurer dermed på hva som gjør at NRK kan bruke de overnevnte
-videoredigeringsverktøyene, som tilsynelatende har krav om avtale med
-MPEG LA for å kunne brukes slik NRK bruker dem, til å lage videofiler
-for distribusjon uten å ha en avtale med MPEG LA om distribusjon av
-H.264-video? Dette er spesielt interessant å vite for oss andre som
-også vurderer å spre H.264-video etter å ha redigert dem med disse mye
-brukte videoredigeringsverktøyene.</p>
-</blockquote></p>
-
-<p>Samme dag fikk jeg automatisk svar om at min henvendelse hadde fått
-saksid 1294699. Jeg fikk deretter følgende respons fra NRK
-2015-06-09:</p>
-
-<p><blockquote>
-<p>Hei, beklager lang svartid, men det tok litt tid å finne ut hvem som kunne
-svare på dette.</p>
-
-<p>For selskaper som leverer h.264 til sluttbrukere på nett (f.eks
-NRKs nett- tv utgaver som bruker h.264) - og som leverer slike
-tjenester uten betaling fra forbrukere – er det heller ikke påkrevd
-noen patentavtale.</p>
-
-<p><a href="http://www.businesswire.com/news/home/20100825006629/en/MPEG-LA%E2%80%99s-AVC-License-Charge-Royalties-Internet#.VWb2ws_774Y">http://www.businesswire.com/news/home/20100825006629/en/MPEG-LA%E2%80%99s-AVC-License-Charge-Royalties-Internet#.VWb2ws_774Y</a></p>
-
-<p>Med vennlig hilsen
-<br>Gunn Helen Berg
-<br>Informasjonskonsulent, Publikumsservice</p>
-
-<p>NRK
-<br>Strategidivisjonen
-<Br>Sentralbord: +47 23 04 70 00
-<br>Post: NRK Publikumsservice, 8608 Mo i Rana
-<br>nrk.no / info (at) nrk.no</p>
-</blockquote></p>
-
-Da dette ikke helt var svar på det jeg lurte på, sendte jeg samme dag
-oppfølgerepost tilbake:
-
-<p><blockquote>
-<p>[Gunn Helen Berg]
-<br>> Hei, beklager lang svartid, men det tok litt tid å finne ut hvem som
-<br>> kunne svare på dette.</p>
-
-<p>Takk for svar. Men det besvarte ikke helt det jeg spurte om.</p>
-
-<p>> For selskaper som leverer h.264 til sluttbrukere på nett (f.eks NRKs
-<br>> nett- tv utgaver som bruker h.264) - og som leverer slike tjenester
-<br>> uten betaling fra forbrukere – er det heller ikke påkrevd noen
-<br>> patentavtale.
-<br>>
-<br>> http://www.businesswire.com/news/home/20100825006629/en/MPEG-LA%E2%80%99s-AVC-License-Charge-Royalties-Internet#.VWb2ws_774Y</p>
-
-<p>Spørsmålet er ikke kun om MPEG LA krever patentavtale eller ikke
-(hvilket ikke helt besvares av pressemeldingen omtalt over, gitt at
-pressemeldingen kom i 2010, to år før MPEG LA ansvarlige for
-internasjonal lisensiering egen Ryan Rodriguez fortalte meg på epost
-at NRK trenger en lisens.</p>
-
-<p>Det er uklart fra pressemeldingen hva "Internet Broadcast AVC
-Video" konkret betyr, men i følge en
-<a href="http://www.mpegla.com/main/programs/avc/Documents/avcweb.pdf">presentasjon
-fra MPEG LA med tema "AVC PAtent Portfoli License Briefing" datert
-2015-05-15</a> gjelder "Internet Broadcast AVC Video" kun kringkasting
-på Internet som ikke tilbyr valg av enkeltinnslag ("not
-title-by-title"), hvilket jo NRK gjør på sine nettsider. I tillegg
-kringkaster jo NRK H.264-video også utenom Internet (RiksTV, kabel,
-satelitt), hvilket helt klart ikke er dekket av vilkårene omtalt i
-pressemeldingen.</p>
-
-<p>Spørsmålet mitt er hvordan NRK kan bruke verktøy med bruksvilkår
-som krever avtale med MPEG LA for det NRK bruker dem til, når NRK ikke
-har avtale med MPEG LA. Hvis jeg forsto spørsmålet riktig, så mener
-NRK at dere ikke trenger avtale med MPEG LA, men uten slik avtale kan
-dere vel ikke bruke hverken Apple Final Cut Studio, Adobe Premiere
-Pro, Avid eller Apples Final Cut Pro X for å redigere video før
-sending?</p>
-
-<p>Mine konkrete spørsmål var altså:</p>
-
-<ul>
-
-<li>Hvis NRK har vurdert om det er behov for en patentavtale med MPEG LA
- slik det er krav om i programvarelisensene til blant annet Apple
- Final Cut Studio, Adobe Premiere Pro, Avid og Apples Final Cut Pro X,
- hva var utfallet av en slik vurdering? Kan jeg få kopi av vurderingen
- hvis den er gjort skriftlig?</li>
-
-<li>Hvis NRK ikke har vurdert dette, har NRK planer om å vurdere behovet
- for patentavtale?</li>
-
-<li>Hva slags saksnummer fikk min henvendelse i NRKs offentlige
- postjournal? Jeg ser at postjournalen ikke er publisert for den
- aktuelle perioden ennå, så jeg fikk ikke sjekket selv.</li>
-
-</ul>
-</blockquote></p>
-
-<p>Det hjelper å ha funnet rette vedkommende i NRK, for denne gangen
-fikk jeg svar tilbake dagen etter (2015-06-10), fra Geir Børdalen i
-NRK:</p>
-
-<p><blockquote>
-<p>Hei Petter Reinholdtsen</p>
-
-<p>Jeg har sjekket saken med distribusjonssjef for tv, Arild Hellgren
-(som var teknologidirektør da bakkenettet ble satt opp). NRK v/
-Hellgren hadde møte med MPEG LA sammen med den europeiske
-kringkastingsunionen EBU før bakkenettet for TV ble satt opp
-(igangsatt høsten 2007). I dette møtet ble det avklart at NRK/EBU ikke
-trengte noen patentavtale for h.264 i forbindelse med oppsett av
-bakkenettet eller bruk av MPEG4 h.264 som kompresjonsalgoritme fordi
-tjenesten «in full»(nor: helt) var betalt av utsendelseselskapene og
-ikke av forbrukerne.</p>
-
-<p><a href="http://www.nrk.no/oppdrag/digitalt-bakkenett-1.3214555">http://www.nrk.no/oppdrag/digitalt-bakkenett-1.3214555</a></p>
-
-<p>Det er også klart slått fast at selskaper som leverer video basert
-på MPEG4 h.264 til sluttbrukere på nett, heller ikke påkrevd noen
-patentavtale – så lenge de leverer slike tjenester uten betaling fra
-sluttbrukere.</p>
-
-<a href="http://www.businesswire.com/news/home/20100825006629/en/MPEG-LA%E2%80%99s-AVC-License-Charge-Royalties-Internet#.VWb2ws_774Y">http://www.businesswire.com/news/home/20100825006629/en/MPEG-LA%E2%80%99s-AVC-License-Charge-Royalties-Internet#.VWb2ws_774Y</a>
-
-<p>“MPEG LA announced today that its AVC Patent Portfolio License will
-continue not to charge royalties for Internet Video that is free to
-end users (known as “Internet Broadcast AVC Video”) during the entire
-life of this License. MPEG LA previously announced it would not charge
-royalties for such video through December 31, 2015 (see
-<a href="http://www.mpegla.com/Lists/MPEG%20LA%20News%20List/Attachments/226/n-10-02-02.pdf">http://www.mpegla.com/Lists/MPEG%20LA%20News%20List/Attachments/226/n-10-02-02.pdf</a>),
-and today’s announcement makes clear that royalties will continue not
-to be charged for such video beyond that time. Products and services
-other than Internet Broadcast AVC Video continue to be
-royalty-bearing.”</p>
-
-<p>Vi har derfor ikke noe behov for å vurdere noen patentavtale med
-MPEG LA.</p>
-
-<p>Understreker for øvrig at NRK ikke er låst til MPEG4 – h.264 som
-utsendelsesformat – og at vi har brukt og bruker flere andre
-alternativer i våre tjenester. Ulike «devicer» har ofte behov for
-forskjellige løsninger – og NRK har forsøkt å levere med best mulig
-kvalitet /økonomi /stabilitet avhengig av
-plattform. Produksjonsformater i NRK spenner for øvrig over en rekke
-forskjellige formater – hvor MPEG4 bare er en av disse. Når NRK kjøper
-teknisk utstyr er betaling for kodekstøtte ofte en del av
-anskaffelsesprisen for denne maskinvaren (enten dette er spesialiserte
-enkodere eller forskjellige typer produksjonsutstyr).</p>
-
-<p>Vennlig hilsen
-<br>Geir Børdalen</p>
-
-<p>________________________________________
-<br>Geir Børdalen
-<br>Investeringsansvarlig NRK / Hovedprosjektleder - Origo
-<br>Avdeling for utvikling, innovasjon, investering og eiendom
-<br>NRK medietjenester
-<br>Sentralbord: +47 23 04 70 00
-<br>Post: NRK, AUTV (RBM5), Pb. 8500 Majorstuen, 0340 Oslo
-<br>nrk.no
-</blockquote></p>
-
-<p>Et godt og grundig svar, som var informativt om hvordan NRK tenker
-rundt patentavtale med MPEG LA, men heller ikke helt besvarte det jeg
-lurte på, så jeg sendte epostoppfølging samme dag.</p>
-
-<p><blockquote>
-<p>[Geir Børdalen]
-<br>> Hei Petter Reinholdtsen</p>
-
-<p>Hei, og takk for raskt svar. Er min henvendelse journalført slik
-at den dukker opp i NRKs postjournal?</p>
-
-<p>Svaret ditt var meget nyttig, og jeg forstår ut fra det du skriver
-at avklaringen med MPEG LA rundt H.264-distribusjon via bakkenettet
-gjelder alle TV-kanaler i Norge. Hvilke saksnummer fikk dokumenter
-som ble opprettet i forbindelse med det omtalte møtet NRK v/Hellgren
-og EBU hadde med MPEG LA (dvs. referater, avtaler, etc),
-f.eks. dokumentet der formuleringen "in full" som du omtaler
-finnes?<p>
-
-<p>Men det er et par ting jeg fortsatt ikke forstår. Det ene er
-hvorfor NRKs forståelse av hva "Internet Broadcast AVC Video" dekker
-ser ut til å avvike fra det som presenteres i
-<a href="http://www.mpegla.com/main/programs/avc/Documents/avcweb.pdf">lysark
-fra MPEG LA</a> i mai, der MPEG LA på lysark med overskriften
-"AVC/H.264 License Terms Participation Fees" og undertittel "Where
-remuneration is from other sources" skriver "Internet Broadcast AVC
-Video (not title-by-title, not subscription) – no royalty for life of
-the AVC Patent Portfolio License".</p>
-
-<p>Her leser jeg MPEG LA dithen at det kun er kringkasting uten
-abonnement via Internet som er dekket at vilkårne omtalt i
-pressemeldingen, mens jeg forstår deg dithen at NRK mener NRKs
-nettsider som også har enkeltfilmer og innslag (som jeg forstår dekket
-av formuleringen "title-by-title") dekkes av "Internet Broadcast AVC
-Video" fra MPEG LA. Hva baserer dere denne tolkningen på? Jeg har
-ikke sett noe skriftlig fra MPEG LA som støtter NRKs tolkning, og
-lurer på om dere har andre kilder enn den pressemeldingen fra 5 år
-tilbake, der NRKS forståelse av hva "Internet Broadcast AVC Video"
-dekker er beskrevet?</p>
-
-<p>Det andre er at eposten din ikke nevnte spørsmålet mitt om
-bruksvilkårene til videoredigeringsverktøyene som NRK bruker. Disse
-har som tidligere nevnt krav om at de kun skal brukes til private og
-ikke-kommersielle formål med mindre en har avtale med MPEG LA, og uten
-avtale med MPEG LA kan det jo virke som om NRK bruker verktøyene i
-strid med bruksvilkårene. Hva gjør at disse bruksvilkårene ikke
-gjelder for NRK?</p>
-</blockquote></p>
-
-<p>Noen minutter senere får jeg foreløpig siste svar i
-føljetongen:</p>
-
-<p><blockquote>
-<p>Hei igjen</p>
-
-<p>Vårt dokumentarkiv har fått en kopi (journalføringsnr kan jeg
-dessverre ikke gi deg).<p>
-
-<p>> Svaret ditt var meget nyttig, og jeg forstår ut fra det du
-<br>> skriver at avklaringen med MPEG LA rundt H.264-distribusjon via
-<br>> bakkenettet gjelder alle TV-kanaler i Norge.</p>
-
-<p>Svar: Kan ikke svare for andre enn for NRK/EBU - og for bakkenettet
-i Norge er det kun NRK som er et lisensbasert selskap. Kan ikke gi noe
-svar på saksnr på dokumenter eller ytterligere informasjon da jeg selv
-ikke var del i dette.</p>
-
-<p>> Men det er et par ting jeg fortsatt ikke forstår. ...</p>
-
-<p>Svar: Kan ikke gå ytterligere inn i dette fra min side og mitt
-fagfelt som er produksjon/publisering og systemstrukturene bak
-disse. For øvrig ligger det etter vår formening ingen begrensninger
-for NRK i mulighetene til publisering mht til kodek i
-produksjonssystemer. Som tidligere skrevet mener vi at NRK ikke
-trenger noen avtale med MPEG LA og støtter oss til det vi allerede har
-kommunisert i forrige epost.</p>
-
-<p>Mvh
-<br>Geir Børdalen</p>
-</blockquote></p>
-
-<p>Det syntes vanskelig å komme videre når NRK ikke ønsker å gå inn i
-problemstillingen rundt bruksvilkårene til videoredigeringsverktøyene
-NRK bruker, så jeg sendte takk for svarene og avsluttet utvekslingen
-så langt:</p>
-
-<p><blockquote>
-<p>Tusen takk for rask respons, og oppklarende forklaring om hvordan
-NRK tenker rundt MPEG LA.</p>
-
-<p>Jeg vil høre med NRK-arkivet for å se om de kan spore opp de
-omtalte dokumentene. Jeg setter pris på om du kan dele titler, dato
-eller annen informasjon som kan gjøre det enklere for arkivet å finne
-dem.</p>
-
-<p>Når det gjelder hvordan bruksvilkårene til
-videoredigeringsverktøyene skal tolkes, så skal jeg høre med MPEG LA
-og produsentene av verktøyene for å forsøke å få klarhet i hva de
-mener er rikgig rettstilstand.</p>
-</blockquote></p>
-
-<p>Jeg ble litt klokere, men fortsatt er det uklart for meg hva som er
-grunnlaget til NRK for å se bort fra bruksvilkår i
-videoredigeringsprogramvare som krever MPEG LA-avtale til alt annet
-enn privat og ikke-kommersiell bruk.</p>
+ <title>Ruling ignored our objections to the seizure of popcorn-time.no (#domstolkontroll)</title>
+ <link>http://people.skolelinux.org/pere/blog/Ruling_ignored_our_objections_to_the_seizure_of_popcorn_time_no___domstolkontroll_.html</link>
+ <guid isPermaLink="true">http://people.skolelinux.org/pere/blog/Ruling_ignored_our_objections_to_the_seizure_of_popcorn_time_no___domstolkontroll_.html</guid>
+ <pubDate>Mon, 13 Feb 2017 21:30:00 +0100</pubDate>
+ <description><p>A few days ago, we received the ruling from
+<a href="http://people.skolelinux.org/pere/blog/A_day_in_court_challenging_seizure_of_popcorn_time_no_for__domstolkontroll.html">my
+day in court</a>. The case in question is a challenge of the seizure
+of the DNS domain popcorn-time.no. The ruling simply did not mention
+most of our arguments, and seemed to take everything ØKOKRIM said at
+face value, ignoring our demonstration and explanations. But it is
+hard to tell for sure, as we still have not seen most of the documents
+in the case and thus were unprepared and unable to contradict several
+of the claims made in court by the opposition. We are considering an
+appeal, but it is partly a question of funding, as it is costing us
+quite a bit to pay for our lawyer. If you want to help, please
+<a href="http://www.nuug.no/dns-beslag-donasjon.shtml">donate to the
+NUUG defense fund</a>.</p>
+
+<p>The details of the case, as far as we know it, is available in
+Norwegian from
+<a href="https://www.nuug.no/news/tags/dns-domenebeslag/">the NUUG
+blog</a>. This also include
+<a href="https://www.nuug.no/news/Avslag_etter_rettslig_h_ring_om_DNS_beslaget___vurderer_veien_videre.shtml">the
+ruling itself</a>.</p>
</description>
</item>
<item>
- <title>Blir det virkelig krav om fingeravtrykk i nasjonale ID-kort?</title>
- <link>http://people.skolelinux.org/pere/blog/Blir_det_virkelig_krav_om_fingeravtrykk_i_nasjonale_ID_kort_.html</link>
- <guid isPermaLink="true">http://people.skolelinux.org/pere/blog/Blir_det_virkelig_krav_om_fingeravtrykk_i_nasjonale_ID_kort_.html</guid>
- <pubDate>Tue, 12 May 2015 11:30:00 +0200</pubDate>
- <description><p>Noen finner det vanskelig å tro at Stortinget faktisk har vedtatt å
-kreve at alle norske borgerne må avgi fingeravtrykk til politiet for å
-fungere i samfunnet. Jeg er blitt spurt hva som er grunnlaget for
-<a href="http://people.skolelinux.org/pere/blog/Norwegian_citizens_now_required_by_law_to_give_their_fingerprint_to_the_police.html">min
-påstand i forrige bloggpost</a> om at det nå blir krav om å avgi
-fingeravtrykk til politiet for å fungere som borger i Norge. De som
-spør klarer ikke lese det ut fra det som er vedtatt. Her er en liten
-oppsummering om hva jeg baserer det på. Det sies ikke direkte i
-hverken proposisjon, innstilling eller vedtak, men fremgår når en ser
-på indirekte formuleringer.</p>
-
-<p>I
-<a href="https://www.regjeringen.no/nb/dokumenter/prop.-66-l-2014-2015/id2399703/">stortingsproposisjon
-66</a>, avsnitt 6.3.5 (Avgivelse av biometriske personopplysninger)
-står det<p>
-
-<p><blockquote>
-
- <p>Departementet foreslår at både ansiktsfoto og fingeravtrykk skal
- kunne opptas og lagres som identifikasjonsdata i de nasjonale
- ID-kortene, på samme måte som i passene. Lovforslaget er derfor
- utformet i tråd med passloven § 6 annet ledd, som fastslår at det
- til bruk for senere verifisering eller kontroll av passinnehaverens
- identitet kan innhentes og lagres i passet biometrisk
- personinformasjon i form av ansiktsfoto og fingeravtrykk (to
- fingre). Dagens ordning med lagring av ansiktsfoto og fingeravtrykk
- i et kontaktløst smartkort i passet er basert på internasjonale
- standarder. Fingeravtrykkene i nasjonalt ID-kort vil bli beskyttet
- på samme måte som fingeravtrykkene i passene.</p>
-
- <p>[...]</p>
-
- <p>For norske forhold understreker departementet at innføring av
- nasjonale ID-kort sammen med innføring av nye systemer for sikrere
- utstedelse og kontroll av pass og relaterte dokumenter gir mulighet
- til å utforme ordningen slik at den best mulig møter utfordringene
- forbundet med identitetskriminalitet. Det tilsier at fingeravtrykk
- opptas og lagres i alle nasjonale ID-kort.</p>
-</blockquote></p>
-
-<p>Departementet sier altså at sin anbefaling er at fingeravtrykk skal
-opptas og lagres i alle nasjonale ID-kort. Det skrives som om det
-blir valgfritt, på samme måten som det skrives passloven, der det i
-loven sier at det kan
-«<a href="https://lovdata.no/dokument/NL/lov/1997-06-19-82#§6">innhentes
-og lagres i passet biometrisk personinformasjon i form av ansiktsfoto
-og fingeravtrykk (to fingre)</a>». Men på tross av bruken av «kan» i
-passloven er det innført krav om å avgi fingeravtrykk for å få et pass
-i Norge. Proposisjonen sier i tillegg i del 1 (Proposisjonens
-hovedinnhold) at ID-kortene skal være like pålitelig som pass og ha
-samme sikkerhetsnivå som pass. Departementet foreslår altså at
-ID-kortene skal gis etter samme regler som for pass.</p>
-
-<p>Formuleringene fra hovedinnholdet i proposisjonen er videreført i
-<a href="https://www.stortinget.no/no/Saker-og-publikasjoner/Publikasjoner/Innstillinger/Stortinget/2014-2015/inns-201415-243/?lvl=0">innstillingen
-fra stortingskomiteen</a>, der det konkret står «De foreslåtte reglene
-vil gi befolkningen tilbud om et offentlig utstedt identitetsbevis som
-vil være like pålitelig som passet, og mer praktisk å bruke som
-legitimasjon» og «Det nasjonale ID-kortet skal også holde samme
-sikkerhetsnivå som passet». Komiteen har altså ingen kommentarer
-eller innsigelser til dette forslaget, og gjorde i debatten da saken
-ble vedtatt det klart at dette var en god sak og at en enstemmig
-komité var glad for resultatet. Stortinget har dermed stilt seg helt
-og fullt bak departementets forslag.</p>
-
-<p>For meg er det åpenbart når en leser proposisjonen at «like
-pålitelig» og «samme sikkerhetsnivå» vil bli tolket av departementet
-som «med samme biometrisk informasjon som i passene», og departementet
-forklarer i tillegg i proposisjonen at de har tenkt at
-fingeravtrykkene «vil bli beskyttet på samme måte som fingeravtrykkene
-i passene». Jeg ser det dermed som åpenbart at den samme
-tvangsinnhentingen av fingeravtrykk som gjelder for pass vil bli
-viderført til de nasjonale ID-kortene.</p>
-
-<p>Det eneste som kan endre dette er massive protester fra
-befolkningen på at folk som ikke er mistenkt for noe kriminelt skal
-tvinges til å gi fingeravtrykket til politiet for å f.eks. kunne få
-bankkonto eller stemme ved valg. Det kunne få departementet til å
-snu. Det tror jeg ikke vil skje.</p>
+ <title>A day in court challenging seizure of popcorn-time.no for #domstolkontroll</title>
+ <link>http://people.skolelinux.org/pere/blog/A_day_in_court_challenging_seizure_of_popcorn_time_no_for__domstolkontroll.html</link>
+ <guid isPermaLink="true">http://people.skolelinux.org/pere/blog/A_day_in_court_challenging_seizure_of_popcorn_time_no_for__domstolkontroll.html</guid>
+ <pubDate>Fri, 3 Feb 2017 11:10:00 +0100</pubDate>
+ <description><p align="center"><img width="70%" src="http://people.skolelinux.org/pere/blog/images/2017-02-01-popcorn-time-in-court.jpeg"></p>
+
+<p>On Wednesday, I spent the entire day in court in Follo Tingrett
+representing <a href="https://www.nuug.no/">the member association
+NUUG</a>, alongside <a href="https://www.efn.no/">the member
+association EFN</a> and <a href="http://www.imc.no">the DNS registrar
+IMC</a>, challenging the seizure of the DNS name popcorn-time.no. It
+was interesting to sit in a court of law for the first time in my
+life. Our team can be seen in the picture above: attorney Ola
+Tellesbø, EFN board member Tom Fredrik Blenning, IMC CEO Morten Emil
+Eriksen and NUUG board member Petter Reinholdtsen.</p>
+
+<p><a href="http://www.domstol.no/no/Enkelt-domstol/follo-tingrett/Nar-gar-rettssaken/Beramming/?cid=AAAA1701301512081262234UJFBVEZZZZZEJBAvtale">The
+case at hand</a> is that the Norwegian National Authority for
+Investigation and Prosecution of Economic and Environmental Crime (aka
+Økokrim) decided on their own, to seize a DNS domain early last
+year, without following
+<a href="https://www.norid.no/no/regelverk/navnepolitikk/#link12">the
+official policy of the Norwegian DNS authority</a> which require a
+court decision. The web site in question was a site covering Popcorn
+Time. And Popcorn Time is the name of a technology with both legal
+and illegal applications. Popcorn Time is a client combining
+searching a Bittorrent directory available on the Internet with
+downloading/distribute content via Bittorrent and playing the
+downloaded content on screen. It can be used illegally if it is used
+to distribute content against the will of the right holder, but it can
+also be used legally to play a lot of content, for example the
+millions of movies
+<a href="https://archive.org/details/movies">available from the
+Internet Archive</a> or the collection
+<a href="http://vodo.net/films/">available from Vodo</a>. We created
+<a href="magnet:?xt=urn:btih:86c1802af5a667ca56d3918aecb7d3c0f7173084&dn=PresentasjonFolloTingrett.mov&tr=udp%3A%2F%2Fpublic.popcorn-tracker.org%3A6969%2Fannounce">a
+video demonstrating legally use of Popcorn Time</a> and played it in
+Court. It can of course be downloaded using Bittorrent.</p>
+
+<p>I did not quite know what to expect from a day in court. The
+government held on to their version of the story and we held on to
+ours, and I hope the judge is able to make sense of it all. We will
+know in two weeks time. Unfortunately I do not have high hopes, as
+the Government have the upper hand here with more knowledge about the
+case, better training in handling criminal law and in general higher
+standing in the courts than fairly unknown DNS registrar and member
+associations. It is expensive to be right also in Norway. So far the
+case have cost more than NOK 70 000,-. To help fund the case, NUUG
+and EFN have asked for donations, and managed to collect around NOK 25
+000,- so far. Given the presentation from the Government, I expect
+the government to appeal if the case go our way. And if the case do
+not go our way, I hope we have enough funding to appeal.</p>
+
+<p>From the other side came two people from Økokrim. On the benches,
+appearing to be part of the group from the government were two people
+from the Simonsen Vogt Wiik lawyer office, and three others I am not
+quite sure who was. Økokrim had proposed to present two witnesses
+from The Motion Picture Association, but this was rejected because
+they did not speak Norwegian and it was a bit late to bring in a
+translator, but perhaps the two from MPA were present anyway. All
+seven appeared to know each other. Good to see the case is take
+seriously.</p>
+
+<p>If you, like me, believe the courts should be involved before a DNS
+domain is hijacked by the government, or you believe the Popcorn Time
+technology have a lot of useful and legal applications, I suggest you
+too <a href="http://www.nuug.no/dns-beslag-donasjon.shtml">donate to
+the NUUG defense fund</a>. Both Bitcoin and bank transfer are
+available. If NUUG get more than we need for the legal action (very
+unlikely), the rest will be spend promoting free software, open
+standards and unix-like operating systems in Norway, so no matter what
+happens the money will be put to good use.</p>
+
+<p>If you want to lean more about the case, I recommend you check out
+<a href="https://www.nuug.no/news/tags/dns-domenebeslag/">the blog
+posts from NUUG covering the case</a>. They cover the legal arguments
+on both sides.</p>
</description>
</item>
<item>
- <title>Norwegian citizens now required by law to give their fingerprint to the police</title>
- <link>http://people.skolelinux.org/pere/blog/Norwegian_citizens_now_required_by_law_to_give_their_fingerprint_to_the_police.html</link>
- <guid isPermaLink="true">http://people.skolelinux.org/pere/blog/Norwegian_citizens_now_required_by_law_to_give_their_fingerprint_to_the_police.html</guid>
- <pubDate>Sun, 10 May 2015 16:00:00 +0200</pubDate>
- <description><p>5 days ago, the Norwegian Parliament decided, unanimously, that all
-citizens of Norway, no matter if they are suspected of something
-criminal or not, are
-<a href="https://www.holderdeord.no/votes/1430838871e">required to
-give fingerprints to the police</a> (vote details from Holder de
-ord). The law make it sound like it will be optional, but in a few
-years there will be no option any more. The ID will be required to
-vote, to get a bank account, a bank card, to change address on the
-post office, to receive an electronic ID or to get a drivers license
-and many other tasks required to function in Norway. The banks plan
-to stop providing their own ID on the bank cards when this new
-national ID is introduced, and the national road authorities plan to
-change the drivers license to no longer be usable as identity cards.
-In effect, to function as a citizen in Norway a national ID card will
-be required, and to get it one need to provide the fingerprints to
-the police.</p>
-
-<p>In addition to handing the fingerprint to the police (which
-promised to not make a copy of the fingerprint image at that point in
-time, but say nothing about doing it later), a picture of the
-fingerprint will be stored on the RFID chip, along with a picture of
-the face and other information about the person. Some of the
-information will be encrypted, but the encryption will be the same
-system as currently used in the passports. The codes to decrypt will
-be available to a lot of government offices and their suppliers around
-the globe, but for those that do not know anyone in those circles it
-is good to know that
-<a href="http://www.theguardian.com/technology/2006/nov/17/news.homeaffairs">the
-encryption is already broken</a>. And they
-<a href="http://www.networkworld.com/article/2215057/wireless/bad-guys-could-read-rfid-passports-at-217-feet--maybe-a-lot-more.html">can
-be read from 70 meters away</a>. This can be mitigated a bit by
-keeping it in a Faraday cage (metal box or metal wire container), but
-one will be required to take it out of there often enough to expose
-ones private and personal information to a lot of people that have no
-business getting access to that information.</p>
-
-<p>The new Norwegian national IDs are a vehicle for identity theft,
-and I feel sorry for us all having politicians accepting such invasion
-of privacy without any objections. So are the Norwegian passports,
-but it has been possible to function in Norway without those so far.
-That option is going away with the passing of the new law. In this, I
-envy the Germans, because for them it is optional how much biometric
-information is stored in their national ID.</p>
-
-<p>And if forced collection of fingerprints was not bad enough, the
-information collected in the national ID card register can be handed
-over to foreign intelligence services and police authorities, "when
-extradition is not considered disproportionate".</p>
-
-<p>Update 2015-05-12: For those unable to believe that the Parliament
-really could make such decision, I wrote
-<a href="http://people.skolelinux.org/pere/blog/Blir_det_virkelig_krav_om_fingeravtrykk_i_nasjonale_ID_kort_.html">a
-summary of the sources I have</a> for concluding the way I do
-(Norwegian Only, as the sources are all in Norwegian).</p>
+ <title>Nasjonalbiblioteket avslutter sin ulovlige bruk av Google Skjemaer</title>
+ <link>http://people.skolelinux.org/pere/blog/Nasjonalbiblioteket_avslutter_sin_ulovlige_bruk_av_Google_Skjemaer.html</link>
+ <guid isPermaLink="true">http://people.skolelinux.org/pere/blog/Nasjonalbiblioteket_avslutter_sin_ulovlige_bruk_av_Google_Skjemaer.html</guid>
+ <pubDate>Thu, 12 Jan 2017 09:40:00 +0100</pubDate>
+ <description><p>I dag fikk jeg en skikkelig gladmelding. Bakgrunnen er at før jul
+arrangerte Nasjonalbiblioteket
+<a href="http://www.nb.no/Bibliotekutvikling/Kunnskapsorganisering/Nasjonalt-verksregister/Seminar-om-verksregister">et
+seminar om sitt knakende gode tiltak «verksregister»</a>. Eneste
+måten å melde seg på dette seminaret var å sende personopplysninger
+til Google via Google Skjemaer. Dette syntes jeg var tvilsom praksis,
+da det bør være mulig å delta på seminarer arrangert av det offentlige
+uten å måtte dele sine interesser, posisjon og andre
+personopplysninger med Google. Jeg ba derfor om innsyn via
+<a href="https://www.mimesbronn.no/">Mimes brønn</a> i
+<a href="https://www.mimesbronn.no/request/personopplysninger_til_google_sk">avtaler
+og vurderinger Nasjonalbiblioteket hadde rundt dette</a>.
+Personopplysningsloven legger klare rammer for hva som må være på
+plass før en kan be tredjeparter, spesielt i utlandet, behandle
+personopplysninger på sine vegne, så det burde eksistere grundig
+dokumentasjon før noe slikt kan bli lovlig. To jurister hos
+Nasjonalbiblioteket mente først dette var helt i orden, og at Googles
+standardavtale kunne brukes som databehandlingsavtale. Det syntes jeg
+var merkelig, men har ikke hatt kapasitet til å følge opp saken før
+for to dager siden.</p>
+
+<p>Gladnyheten i dag, som kom etter at jeg tipset Nasjonalbiblioteket
+om at Datatilsynet underkjente Googles standardavtaler som
+databehandleravtaler i 2011, er at Nasjonalbiblioteket har bestemt seg
+for å avslutte bruken av Googles Skjemaer/Apps og gå i dialog med DIFI
+for å finne bedre måter å håndtere påmeldinger i tråd med
+personopplysningsloven. Det er fantastisk å se at av og til hjelper
+det å spørre hva i alle dager det offentlige holder på med.</p>
</description>
</item>
<item>
- <title>What would it cost to store all phone calls in Norway?</title>
- <link>http://people.skolelinux.org/pere/blog/What_would_it_cost_to_store_all_phone_calls_in_Norway_.html</link>
- <guid isPermaLink="true">http://people.skolelinux.org/pere/blog/What_would_it_cost_to_store_all_phone_calls_in_Norway_.html</guid>
- <pubDate>Fri, 1 May 2015 19:30:00 +0200</pubDate>
- <description><p>Many years ago, a friend of mine calculated how much it would cost
-to store the sound of all phone calls in Norway, and came up with the
-cost of around 20 million NOK (2.4 mill EUR) for all the calls in a
-year. I got curious and wondered what the same calculation would look
-like today. To do so one need an idea of how much data storage is
-needed for each minute of sound, how many minutes all the calls in
-Norway sums up to, and the cost of data storage.</p>
+ <title>Bryter NAV sin egen personvernerklæring?</title>
+ <link>http://people.skolelinux.org/pere/blog/Bryter_NAV_sin_egen_personvernerkl_ring_.html</link>
+ <guid isPermaLink="true">http://people.skolelinux.org/pere/blog/Bryter_NAV_sin_egen_personvernerkl_ring_.html</guid>
+ <pubDate>Wed, 11 Jan 2017 06:50:00 +0100</pubDate>
+ <description><p>Jeg leste med interesse en nyhetssak hos
+<a href="http://www.digi.no/artikler/nav-avslorer-trygdemisbruk-ved-a-spore-ip-adresser/367394">digi.no</a>
+og
+<a href="https://www.nrk.no/buskerud/trygdesvindlere-avslores-av-utenlandske-ip-adresser-1.13313461">NRK</a>
+om at det ikke bare er meg, men at også NAV bedriver geolokalisering
+av IP-adresser, og at det gjøres analyse av IP-adressene til de som
+sendes inn meldekort for å se om meldekortet sendes inn fra
+utenlandske IP-adresser. Politiadvokat i Drammen, Hans Lyder Haare,
+er sitert i NRK på at «De to er jo blant annet avslørt av
+IP-adresser. At man ser at meldekortet kommer fra utlandet.»</p>
+
+<p>Jeg synes det er fint at det blir bedre kjent at IP-adresser
+knyttes til enkeltpersoner og at innsamlet informasjon brukes til å
+stedsbestemme personer også av aktører her i Norge. Jeg ser det som
+nok et argument for å bruke
+<a href="https://www.torproject.org/">Tor</a> så mye som mulig for å
+gjøre gjøre IP-lokalisering vanskeligere, slik at en kan beskytte sin
+privatsfære og unngå å dele sin fysiske plassering med
+uvedkommede.</p>
+
+<P>Men det er en ting som bekymrer meg rundt denne nyheten. Jeg ble
+tipset (takk #nuug) om
+<a href="https://www.nav.no/no/NAV+og+samfunn/Kontakt+NAV/Teknisk+brukerstotte/Snarveier/personvernerkl%C3%A6ring-for-arbeids-og-velferdsetaten">NAVs
+personvernerklæring</a>, som under punktet «Personvern og statistikk»
+lyder:</p>
-<p>The 2005 numbers are from
-<a href="http://www.digi.no/analyser/2005/10/04/vi-prater-stadig-mindre-i-roret">digi.no</a>,
-the 2012 numbers are from
-<a href="http://www.nkom.no/aktuelt/nyheter/fortsatt-vekst-i-det-norske-ekommarkedet">a
-NKOM report</a>, and I got the 2013 numbers after asking NKOM via
-email. I was told the numbers for 2014 will be presented May 20th,
-and decided not to wait for those, as I doubt they will be very
-different from the numbers from 2013.</p>
+<p><blockquote>
-<p>The amount of data storage per minute sound depend on the wanted
-quality, and for phone calls it is generally believed that 8 Kbit/s is
-enough. See for example a
-<a href="http://www.cisco.com/c/en/us/support/docs/voice/voice-quality/7934-bwidth-consume.html#topic1">summary
-on voice quality from Cisco</a> for some alternatives. 8 Kbit/s is 60
-Kbytes/min, and this can be multiplied with the number of call minutes
-to get the storage requirements.</p>
+<p>«Når du besøker nav.no, etterlater du deg elektroniske spor. Sporene
+dannes fordi din nettleser automatisk sender en rekke opplysninger til
+NAVs tjener (server-maskin) hver gang du ber om å få vist en side. Det
+er eksempelvis opplysninger om hvilken nettleser og -versjon du
+bruker, og din internettadresse (ip-adresse). For hver side som vises,
+lagres følgende opplysninger:</p>
-<p>Storage prices varies a lot, depending on speed, backup strategies,
-availability requirements etc. But a simple way to calculate can be
-to use the price of a TiB-disk (around 1000 NOK / 120 EUR) and double
-it to take space, power and redundancy into account. It could be much
-higher with high speed and good redundancy requirements.</p>
+<ul>
+<li>hvilken side du ser på</li>
+<li>dato og tid</li>
+<li>hvilken nettleser du bruker</li>
+<li>din ip-adresse</li>
+</ul>
-<p>But back to the question, What would it cost to store all phone
-calls in Norway? Not much. Here is a small table showing the
-estimated cost, which is within the budget constraint of most medium
-and large organisations:</p>
+<p>Ingen av opplysningene vil bli brukt til å identifisere
+enkeltpersoner. NAV bruker disse opplysningene til å generere en
+samlet statistikk som blant annet viser hvilke sider som er mest
+populære. Statistikken er et redskap til å forbedre våre
+tjenester.»</p>
-<table border="1">
-<tr><th>Year</th><th>Call minutes</th><th>Size</th><th>Price in NOK / EUR</th></tr>
-<tr><td>2005</td><td align="right">24 000 000 000</td><td align="right">1.3 PiB</td><td align="right">3 mill / 358 000</td></tr>
-<tr><td>2012</td><td align="right">18 000 000 000</td><td align="right">1.0 PiB</td><td align="right">2.2 mill / 262 000</td></tr>
-<tr><td>2013</td><td align="right">17 000 000 000</td><td align="right">950 TiB</td><td align="right">2.1 mill / 250 000</td></tr>
-</table>
+</blockquote></p>
-<p>This is the cost of buying the storage. Maintenance need to be
-taken into account too, but calculating that is left as an exercise
-for the reader. But it is obvious to me from those numbers that
-recording the sound of all phone calls in Norway is not going to be
-stopped because it is too expensive. I wonder if someone already is
-collecting the data?</p>
+<p>Jeg klarer ikke helt å se hvordan analyse av de besøkendes
+IP-adresser for å se hvem som sender inn meldekort via web fra en
+IP-adresse i utlandet kan gjøres uten å komme i strid med påstanden om
+at «ingen av opplysningene vil bli brukt til å identifisere
+enkeltpersoner». Det virker dermed for meg som at NAV bryter sine
+egen personvernerklæring, hvilket
+<a href="http://people.skolelinux.org/pere/blog/Er_lover_brutt_n_r_personvernpolicy_ikke_stemmer_med_praksis_.html">Datatilsynet
+fortalte meg i starten av desember antagelig er brudd på
+personopplysningsloven</a>.
+
+<p>I tillegg er personvernerklæringen ganske misvisende i og med at
+NAVs nettsider ikke bare forsyner NAV med personopplysninger, men i
+tillegg ber brukernes nettleser kontakte fem andre nettjenere
+(script.hotjar.com, static.hotjar.com, vars.hotjar.com,
+www.google-analytics.com og www.googletagmanager.com), slik at
+personopplysninger blir gjort tilgjengelig for selskapene Hotjar og
+Google , og alle som kan lytte på trafikken på veien (som FRA, GCHQ og
+NSA). Jeg klarer heller ikke se hvordan slikt spredning av
+personopplysninger kan være i tråd med kravene i
+personopplysningloven, eller i tråd med NAVs personvernerklæring.</p>
+
+<p>Kanskje NAV bør ta en nøye titt på sin personvernerklæring? Eller
+kanskje Datatilsynet bør gjøre det?</p>
</description>
</item>
<item>
- <title>First Jessie based Debian Edu beta release</title>
- <link>http://people.skolelinux.org/pere/blog/First_Jessie_based_Debian_Edu_beta_release.html</link>
- <guid isPermaLink="true">http://people.skolelinux.org/pere/blog/First_Jessie_based_Debian_Edu_beta_release.html</guid>
- <pubDate>Sun, 26 Apr 2015 14:10:00 +0200</pubDate>
- <description><p>I am happy to report that the Debian Edu team sent out
-<a href="https://lists.debian.org/debian-edu-announce/2015/04/msg00000.html">this
-announcement today</a>:</p>
-
-<pre>
-the Debian Edu / Skolelinux project is pleased to announce the first
-*beta* release of Debian Edu "Jessie" 8.0+edu0~b1, which for the first
-time is composed entirely of packages from the current Debian stable
-release, Debian 8 "Jessie".
-
-(As most reading this will know, Debian "Jessie" hasn't actually been
-released by now. The release is still in progress but should finish
-later today ;)
-
-We expect to make a final release of Debian Edu "Jessie" in the coming
-weeks, timed with the first point release of Debian Jessie. Upgrades
-from this beta release of Debian Edu Jessie to the final release will
-be possible and encouraged!
-
-Please report feedback to debian-edu@lists.debian.org and/or submit
-bugs: http://wiki.debian.org/DebianEdu/HowTo/ReportBugs
-
-Debian Edu - sometimes also known as "Skolelinux" - is a complete
-operating system for schools, universities and other
-organisations. Through its pre- prepared installation profiles
-administrators can install servers, workstations and laptops which
-will work in harmony on the school network. With Debian Edu, the
-teachers themselves or their technical support staff can roll out a
-complete multi-user, multi-machine study environment within hours or
-days.
-
-Debian Edu is already in use at several hundred schools all over the
-world, particularly in Germany, Spain and Norway. Installations come
-with hundreds of applications pre-installed, plus the whole Debian
-archive of thousands of compatible packages within easy reach.
-
-For those who want to give Debian Edu Jessie a try, download and
-installation instructions are available, including detailed
-instructions in the manual explaining the first steps, such as setting
-up a network or adding users. Please note that the password for the
-user your prompted for during installation must have a length of at
-least 5 characters!
-
-== Where to download ==
-
-A multi-architecture CD / usbstick image (649 MiB) for network booting
-can be downloaded at the following locations:
-
- http://ftp.skolelinux.org/skolelinux-cd/debian-edu-8.0+edu0~b1-CD.iso
- rsync -avzP ftp.skolelinux.org::skolelinux-cd/debian-edu-8.0+edu0~b1-CD.iso .
-
-The SHA1SUM of this image is: 54a524d16246cddd8d2cfd6ea52f2dd78c47ee0a
-
-Alternatively an extended DVD / usbstick image (4.9 GiB) is also
-available, with more software included (saving additional download
-time):
-
- http://ftp.skolelinux.org/skolelinux-cd/debian-edu-8.0+edu0~b1-USB.iso
- rsync -avzP ftp.skolelinux.org::skolelinux-cd/debian-edu-8.0+edu0~b1-USB.iso
-
-The SHA1SUM of this image is: fb1f1504a490c077a48653898f9d6a461cb3c636
-
-Sources are available from the Debian archive, see
-http://ftp.debian.org/debian-cd/8.0.0/source/ for some download
-options.
-
-== Debian Edu Jessie manual in seven languages ==
-
-Please see https://wiki.debian.org/DebianEdu/Documentation/Jessie/ for
-the English version of the Debian Edu jessie manual.
-
-This manual has been fully translated to German, French, Italian,
-Danish, Dutch and Norwegian Bokmål. A partly translated version exists
-for Spanish. See http://maintainer.skolelinux.org/debian-edu-doc/ for
-online version of the translated manual.
-
-More information about Debian 8 "Jessie" itself is provided in the
-release notes and the installation manual:
-- http://www.debian.org/releases/jessie/releasenotes
-- http://www.debian.org/releases/jessie/installmanual
-
-
-== Errata / known problems ==
-
- It takes up to 15 minutes for a changed hostname to be updated via
- DHCP (#780461).
-
- The hostname script fails to update LTSP server hostname (#783087).
-
-Workaround: run update-hostname-from-ip on the client to update the
-hostname immediately.
-
-Check https://wiki.debian.org/DebianEdu/Status/Jessie for a possibly
-more current and complete list.
-
-== Some more details about Debian Edu 8.0+edu0~b1 Codename Jessie released 2015-04-25 ==
-
-=== Software updates ===
-
-Everything which is new in Debian 8 Jessie, e.g.:
-
- * Linux kernel 3.16.7-ctk9; for the i386 architecture, support for
- i486 processors has been dropped; oldest supported ones: i586 (like
- Intel Pentium and AMD K5).
-
- * Desktop environments KDE Plasma Workspaces 4.11.13, GNOME 3.14,
- Xfce 4.12, LXDE 0.5.6
- * new optional desktop environment: MATE 1.8
- * KDE Plasma Workspaces is installed by default; to choose one of
- the others see the manual.
- * the browsers Iceweasel 31 ESR and Chromium 41
- * LibreOffice 4.3.3
- * GOsa 2.7.4
- * LTSP 5.5.4
- * CUPS print system 1.7.5
- * new boot framework: systemd
- * Educational toolbox GCompris 14.12
- * Music creator Rosegarden 14.02
- * Image editor Gimp 2.8.14
- * Virtual stargazer Stellarium 0.13.1
- * golearn 0.9
- * tuxpaint 0.9.22
- * New version of debian-installer from Debian Jessie.
- * Debian Jessie includes about 43000 packages available for installation.
- * More information about Debian 8 Jessie is provided in its release
- notes and the installation manual, see the link above.
-
-=== Installation changes ===
-
- Installations done via PXE now also install firmware automatically
- for the hardware present.
-
-=== Fixed bugs ===
-
-A number of bugs have been fixed in this release; the most noticeable
-from a user perspective:
-
- * Inserting incorrect DNS information in Gosa will no longer break
- DNS completely, but instead stop DNS updates until the incorrect
- information is corrected (710362)
-
- * shutdown-at-night now shuts the system down if gdm3 is used (775608).
-
-=== Sugar desktop removed ===
-
-As the Sugar desktop was removed from Debian Jessie, it is also not
-available in Debian Edu jessie.
-
-
-== About Debian Edu / Skolelinux ==
-
-Debian Edu, also known as Skolelinux, is a Linux distribution based on
-Debian providing an out-of-the box environment of a completely
-configured school network. Directly after installation a school server
-running all services needed for a school network is set up just
-waiting for users and machines being added via GOsa², a comfortable
-Web-UI. A netbooting environment is prepared using PXE, so after
-initial installation of the main server from CD or USB stick all other
-machines can be installed via the network. The provided school server
-provides LDAP database and Kerberos authentication service,
-centralized home directories, DHCP server, web proxy and many other
-services. The desktop contains more than 60 educational software
-packages and more are available from the Debian archive, and schools
-can choose between KDE, GNOME, LXDE, Xfce and MATE desktop
-environment.
-
-== About Debian ==
-
-The Debian Project was founded in 1993 by Ian Murdock to be a truly
-free community project. Since then the project has grown to be one of
-the largest and most influential open source projects. Thousands of
-volunteers from all over the world work together to create and
-maintain Debian software. Available in 70 languages, and supporting a
-huge range of computer types, Debian calls itself the universal
-operating system.
-
-== Thanks ==
-
-Thanks to everyone making Debian and Debian Edu / Skolelinux happen!
-You rock.
-</pre>
+ <title>Where did that package go? &mdash; geolocated IP traceroute</title>
+ <link>http://people.skolelinux.org/pere/blog/Where_did_that_package_go___mdash__geolocated_IP_traceroute.html</link>
+ <guid isPermaLink="true">http://people.skolelinux.org/pere/blog/Where_did_that_package_go___mdash__geolocated_IP_traceroute.html</guid>
+ <pubDate>Mon, 9 Jan 2017 12:20:00 +0100</pubDate>
+ <description><p>Did you ever wonder where the web trafic really flow to reach the
+web servers, and who own the network equipment it is flowing through?
+It is possible to get a glimpse of this from using traceroute, but it
+is hard to find all the details. Many years ago, I wrote a system to
+map the Norwegian Internet (trying to figure out if our plans for a
+network game service would get low enough latency, and who we needed
+to talk to about setting up game servers close to the users. Back
+then I used traceroute output from many locations (I asked my friends
+to run a script and send me their traceroute output) to create the
+graph and the map. The output from traceroute typically look like
+this:
+
+<p><pre>
+traceroute to www.stortinget.no (85.88.67.10), 30 hops max, 60 byte packets
+ 1 uio-gw10.uio.no (129.240.202.1) 0.447 ms 0.486 ms 0.621 ms
+ 2 uio-gw8.uio.no (129.240.24.229) 0.467 ms 0.578 ms 0.675 ms
+ 3 oslo-gw1.uninett.no (128.39.65.17) 0.385 ms 0.373 ms 0.358 ms
+ 4 te3-1-2.br1.fn3.as2116.net (193.156.90.3) 1.174 ms 1.172 ms 1.153 ms
+ 5 he16-1-1.cr1.san110.as2116.net (195.0.244.234) 2.627 ms he16-1-1.cr2.oslosda310.as2116.net (195.0.244.48) 3.172 ms he16-1-1.cr1.san110.as2116.net (195.0.244.234) 2.857 ms
+ 6 ae1.ar8.oslosda310.as2116.net (195.0.242.39) 0.662 ms 0.637 ms ae0.ar8.oslosda310.as2116.net (195.0.242.23) 0.622 ms
+ 7 89.191.10.146 (89.191.10.146) 0.931 ms 0.917 ms 0.955 ms
+ 8 * * *
+ 9 * * *
+[...]
+</pre></p>
+
+<p>This show the DNS names and IP addresses of (at least some of the)
+network equipment involved in getting the data traffic from me to the
+www.stortinget.no server, and how long it took in milliseconds for a
+package to reach the equipment and return to me. Three packages are
+sent, and some times the packages do not follow the same path. This
+is shown for hop 5, where three different IP addresses replied to the
+traceroute request.</p>
+
+<p>There are many ways to measure trace routes. Other good traceroute
+implementations I use are traceroute (using ICMP packages) mtr (can do
+both ICMP, UDP and TCP) and scapy (python library with ICMP, UDP, TCP
+traceroute and a lot of other capabilities). All of them are easily
+available in <a href="https://www.debian.org/">Debian</a>.</p>
+
+<p>This time around, I wanted to know the geographic location of
+different route points, to visualize how visiting a web page spread
+information about the visit to a lot of servers around the globe. The
+background is that a web site today often will ask the browser to get
+from many servers the parts (for example HTML, JSON, fonts,
+JavaScript, CSS, video) required to display the content. This will
+leak information about the visit to those controlling these servers
+and anyone able to peek at the data traffic passing by (like your ISP,
+the ISPs backbone provider, FRA, GCHQ, NSA and others).</p>
+
+<p>Lets pick an example, the Norwegian parliament web site
+www.stortinget.no. It is read daily by all members of parliament and
+their staff, as well as political journalists, activits and many other
+citizens of Norway. A visit to the www.stortinget.no web site will
+ask your browser to contact 8 other servers: ajax.googleapis.com,
+insights.hotjar.com, script.hotjar.com, static.hotjar.com,
+stats.g.doubleclick.net, www.google-analytics.com,
+www.googletagmanager.com and www.netigate.se. I extracted this by
+asking <a href="http://phantomjs.org/">PhantomJS</a> to visit the
+Stortinget web page and tell me all the URLs PhantomJS downloaded to
+render the page (in HAR format using
+<a href="https://github.com/ariya/phantomjs/blob/master/examples/netsniff.js">their
+netsniff example</a>. I am very grateful to Gorm for showing me how
+to do this). My goal is to visualize network traces to all IP
+addresses behind these DNS names, do show where visitors personal
+information is spread when visiting the page.</p>
+
+<p align="center"><a href="www.stortinget.no-geoip.kml"><img
+src="http://people.skolelinux.org/pere/blog/images/2017-01-09-www.stortinget.no-geoip-small.png" alt="map of combined traces for URLs used by www.stortinget.no using GeoIP"/></a></p>
+
+<p>When I had a look around for options, I could not find any good
+free software tools to do this, and decided I needed my own traceroute
+wrapper outputting KML based on locations looked up using GeoIP. KML
+is easy to work with and easy to generate, and understood by several
+of the GIS tools I have available. I got good help from by NUUG
+colleague Anders Einar with this, and the result can be seen in
+<a href="https://github.com/petterreinholdtsen/kmltraceroute">my
+kmltraceroute git repository</a>. Unfortunately, the quality of the
+free GeoIP databases I could find (and the for-pay databases my
+friends had access to) is not up to the task. The IP addresses of
+central Internet infrastructure would typically be placed near the
+controlling companies main office, and not where the router is really
+located, as you can see from <a href="www.stortinget.no-geoip.kml">the
+KML file I created</a> using the GeoLite City dataset from MaxMind.
+
+<p align="center"><a href="http://people.skolelinux.org/pere/blog/images/2017-01-09-www.stortinget.no-scapy.svg"><img
+src="http://people.skolelinux.org/pere/blog/images/2017-01-09-www.stortinget.no-scapy-small.png" alt="scapy traceroute graph for URLs used by www.stortinget.no"/></a></p>
+
+<p>I also had a look at the visual traceroute graph created by
+<a href="http://www.secdev.org/projects/scapy/">the scrapy project</a>,
+showing IP network ownership (aka AS owner) for the IP address in
+question.
+<a href="http://people.skolelinux.org/pere/blog/images/2017-01-09-www.stortinget.no-scapy.svg">The
+graph display a lot of useful information about the traceroute in SVG
+format</a>, and give a good indication on who control the network
+equipment involved, but it do not include geolocation. This graph
+make it possible to see the information is made available at least for
+UNINETT, Catchcom, Stortinget, Nordunet, Google, Amazon, Telia, Level
+3 Communications and NetDNA.</p>
+
+<p align="center"><a href="https://geotraceroute.com/index.php?node=4&host=www.stortinget.no"><img
+src="http://people.skolelinux.org/pere/blog/images/2017-01-09-www.stortinget.no-geotraceroute-small.png" alt="example geotraceroute view for www.stortinget.no"/></a></p>
+
+<p>In the process, I came across the
+<a href="https://geotraceroute.com/">web service GeoTraceroute</a> by
+Salim Gasmi. Its methology of combining guesses based on DNS names,
+various location databases and finally use latecy times to rule out
+candidate locations seemed to do a very good job of guessing correct
+geolocation. But it could only do one trace at the time, did not have
+a sensor in Norway and did not make the geolocations easily available
+for postprocessing. So I contacted the developer and asked if he
+would be willing to share the code (he refused until he had time to
+clean it up), but he was interested in providing the geolocations in a
+machine readable format, and willing to set up a sensor in Norway. So
+since yesterday, it is possible to run traces from Norway in this
+service thanks to a sensor node set up by
+<a href="https://www.nuug.no/">the NUUG assosiation</a>, and get the
+trace in KML format for further processing.</p>
+
+<p align="center"><a href="http://people.skolelinux.org/pere/blog/images/2017-01-09-www.stortinget.no-geotraceroute-kml-join.kml"><img
+src="http://people.skolelinux.org/pere/blog/images/2017-01-09-www.stortinget.no-geotraceroute-kml-join.png" alt="map of combined traces for URLs used by www.stortinget.no using geotraceroute"/></a></p>
+
+<p>Here we can see a lot of trafic passes Sweden on its way to
+Denmark, Germany, Holland and Ireland. Plenty of places where the
+Snowden confirmations verified the traffic is read by various actors
+without your best interest as their top priority.</p>
+
+<p>Combining KML files is trivial using a text editor, so I could loop
+over all the hosts behind the urls imported by www.stortinget.no and
+ask for the KML file from GeoTraceroute, and create a combined KML
+file with all the traces (unfortunately only one of the IP addresses
+behind the DNS name is traced this time. To get them all, one would
+have to request traces using IP number instead of DNS names from
+GeoTraceroute). That might be the next step in this project.</p>
+
+<p>Armed with these tools, I find it a lot easier to figure out where
+the IP traffic moves and who control the boxes involved in moving it.
+And every time the link crosses for example the Swedish border, we can
+be sure Swedish Signal Intelligence (FRA) is listening, as GCHQ do in
+Britain and NSA in USA and cables around the globe. (Hm, what should
+we tell them? :) Keep that in mind if you ever send anything
+unencrypted over the Internet.</p>
+
+<p>PS: KML files are drawn using
+<a href="http://ivanrublev.me/kml/">the KML viewer from Ivan
+Rublev<a/>, as it was less cluttered than the local Linux application
+Marble. There are heaps of other options too.</p>
+
+<p>As usual, if you use Bitcoin and want to show your support of my
+activities, please send Bitcoin donations to my address
+<b><a href="bitcoin:15oWEoG9dUPovwmUL9KWAnYRtNJEkP1u1b&label=PetterReinholdtsenBlog">15oWEoG9dUPovwmUL9KWAnYRtNJEkP1u1b</a></b>.</p>
</description>
</item>