]> pere.pagekite.me Git - homepage.git/blob - blog/archive/2016/11/11.rss
Generated.
[homepage.git] / blog / archive / 2016 / 11 / 11.rss
1 <?xml version="1.0" encoding="ISO-8859-1"?>
2 <rss version='2.0' xmlns:lj='http://www.livejournal.org/rss/lj/1.0/'>
3 <channel>
4 <title>Petter Reinholdtsen - Entries from November 2016</title>
5 <description>Entries from November 2016</description>
6 <link>http://people.skolelinux.org/pere/blog/</link>
7
8
9 <item>
10 <title>How to talk with your loved ones in private</title>
11 <link>http://people.skolelinux.org/pere/blog/How_to_talk_with_your_loved_ones_in_private.html</link>
12 <guid isPermaLink="true">http://people.skolelinux.org/pere/blog/How_to_talk_with_your_loved_ones_in_private.html</guid>
13 <pubDate>Mon, 7 Nov 2016 10:25:00 +0100</pubDate>
14 <description>&lt;p&gt;A few days ago I ran a very biased and informal survey to get an
15 idea about what options are being used to communicate with end to end
16 encryption with friends and family. I explicitly asked people not to
17 list options only used in a work setting. The background is the
18 uneasy feeling I get when using Signal, a feeling shared by others as
19 a blog post from Sander Venima about
20 &lt;a href=&quot;https://sandervenema.ch/2016/11/why-i-wont-recommend-signal-anymore/&quot;&gt;why
21 he do not recommend Signal anymore&lt;/a&gt; (with
22 &lt;a href=&quot;https://news.ycombinator.com/item?id=12883410&quot;&gt;feedback from
23 the Signal author available from ycombinator&lt;/a&gt;). I wanted an
24 overview of the options being used, and hope to include those options
25 in a less biased survey later on. So far I have not taken the time to
26 look into the individual proposed systems. They range from text
27 sharing web pages, via file sharing and email to instant messaging,
28 VOIP and video conferencing. For those considering which system to
29 use, it is also useful to have a look at
30 &lt;a href=&quot;https://www.eff.org/secure-messaging-scorecard&quot;&gt;the EFF Secure
31 messaging scorecard&lt;/a&gt; which is slightly out of date but still
32 provide valuable information.&lt;/p&gt;
33
34 &lt;p&gt;So, on to the list. There were some used by many, some used by a
35 few, some rarely used ones and a few mentioned but without anyone
36 claiming to use them. Notice the grouping is in realty quite random
37 given the biased self selected set of participants. First the ones
38 used by many:&lt;/p&gt;
39
40 &lt;ul&gt;
41
42 &lt;li&gt;&lt;a href=&quot;https://whispersystems.org/&quot;&gt;Signal&lt;/a&gt;&lt;/li&gt;
43 &lt;li&gt;Email w/&lt;a href=&quot;http://openpgp.org/&quot;&gt;OpenPGP&lt;/a&gt; (Enigmail, GPGSuite,etc)&lt;/li&gt;
44 &lt;li&gt;&lt;a href=&quot;https://www.whatsapp.com/&quot;&gt;Whatsapp&lt;/a&gt;&lt;/li&gt;
45 &lt;li&gt;IRC w/&lt;a href=&quot;https://otr.cypherpunks.ca/&quot;&gt;OTR&lt;/a&gt;&lt;/li&gt;
46 &lt;li&gt;XMPP w/&lt;a href=&quot;https://otr.cypherpunks.ca/&quot;&gt;OTR&lt;/a&gt;&lt;/li&gt;
47
48 &lt;/ul&gt;
49
50 &lt;p&gt;Then the ones used by a few.&lt;/p&gt;
51
52 &lt;ul&gt;
53
54 &lt;li&gt;&lt;a href=&quot;https://wiki.mumble.info/wiki/Main_Page&quot;&gt;Mumble&lt;/a&gt;&lt;/li&gt;
55 &lt;li&gt;iMessage (included in iOS from Apple)&lt;/li&gt;
56 &lt;li&gt;&lt;a href=&quot;https://telegram.org/&quot;&gt;Telegram&lt;/a&gt;&lt;/li&gt;
57 &lt;li&gt;&lt;a href=&quot;https://jitsi.org/&quot;&gt;Jitsi&lt;/a&gt;&lt;/li&gt;
58 &lt;li&gt;&lt;a href=&quot;https://keybase.io/download&quot;&gt;Keybase file&lt;/a&gt;&lt;/li&gt;
59
60 &lt;/ul&gt;
61
62 &lt;p&gt;Then the ones used by even fewer people&lt;/p&gt;
63
64 &lt;ul&gt;
65
66 &lt;li&gt;&lt;a href=&quot;https://ring.cx/&quot;&gt;Ring&lt;/a&gt;&lt;/li&gt;
67 &lt;li&gt;&lt;a href=&quot;https://bitmessage.org/&quot;&gt;Bitmessage&lt;/a&gt;&lt;/li&gt;
68 &lt;li&gt;&lt;a href=&quot;https://wire.com/&quot;&gt;Wire&lt;/a&gt;&lt;/li&gt;
69 &lt;li&gt;VoIP w/&lt;a href=&quot;https://en.wikipedia.org/wiki/ZRTP&quot;&gt;ZRTP&lt;/a&gt; or controlled &lt;a href=&quot;https://en.wikipedia.org/wiki/Secure_Real-time_Transport_Protocol&quot;&gt;SRTP&lt;/a&gt; (e.g using &lt;a href=&quot;https://en.wikipedia.org/wiki/CSipSimple&quot;&gt;CSipSimple&lt;/a&gt;, &lt;a href=&quot;https://en.wikipedia.org/wiki/Linphone&quot;&gt;Linphone&lt;/a&gt;)&lt;/li&gt;
70 &lt;li&gt;&lt;a href=&quot;https://matrix.org/&quot;&gt;Matrix&lt;/a&gt;&lt;/li&gt;
71 &lt;li&gt;&lt;a href=&quot;https://kontalk.org/&quot;&gt;Kontalk&lt;/a&gt;&lt;/li&gt;
72 &lt;li&gt;&lt;a href=&quot;https://0bin.net/&quot;&gt;0bin&lt;/a&gt; (encrypted pastebin)&lt;/li&gt;
73 &lt;li&gt;&lt;a href=&quot;https://appear.in&quot;&gt;Appear.in&lt;/a&gt;&lt;/li&gt;
74 &lt;li&gt;&lt;a href=&quot;https://riot.im/&quot;&gt;riot&lt;/a&gt;&lt;/li&gt;
75 &lt;li&gt;&lt;a href=&quot;https://www.wickr.com/&quot;&gt;Wickr Me&lt;/a&gt;&lt;/li&gt;
76
77 &lt;/ul&gt;
78
79 &lt;p&gt;And finally the ones mentioned by not marked as used by
80 anyone. This might be a mistake, perhaps the person adding the entry
81 forgot to flag it as used?&lt;/p&gt;
82
83 &lt;ul&gt;
84
85 &lt;li&gt;Email w/Certificates &lt;a href=&quot;https://en.wikipedia.org/wiki/S/MIME&quot;&gt;S/MIME&lt;/a&gt;&lt;/li&gt;
86 &lt;li&gt;&lt;a href=&quot;https://www.crypho.com/&quot;&gt;Crypho&lt;/a&gt;&lt;/li&gt;
87 &lt;li&gt;&lt;a href=&quot;https://cryptpad.fr/&quot;&gt;CryptPad&lt;/a&gt;&lt;/li&gt;
88 &lt;li&gt;&lt;a href=&quot;https://github.com/ricochet-im/ricochet&quot;&gt;ricochet&lt;/a&gt;&lt;/li&gt;
89
90 &lt;/ul&gt;
91
92 &lt;p&gt;Given the network effect it seem obvious to me that we as a society
93 have been divided and conquered by those interested in keeping
94 encrypted and secure communication away from the masses. The
95 finishing remarks &lt;a href=&quot;https://vimeo.com/97505679&quot;&gt;from Aral Balkan
96 in his talk &quot;Free is a lie&quot;&lt;/a&gt; about the usability of free software
97 really come into effect when you want to communicate in private with
98 your friends and family. We can not expect them to allow the
99 usability of communication tool to block their ability to talk to
100 their loved ones.&lt;/p&gt;
101
102 &lt;p&gt;Note for example the option IRC w/OTR. Most IRC clients do not
103 have OTR support, so in most cases OTR would not be an option, even if
104 you wanted to. In my personal experience, about 1 in 20 I talk to
105 have a IRC client with OTR. For private communication to really be
106 available, most people to talk to must have the option in their
107 currently used client. I can not simply ask my family to install an
108 IRC client. I need to guide them through a technical multi-step
109 process of adding extensions to the client to get them going. This is
110 a non-starter for most.&lt;/p&gt;
111
112 &lt;p&gt;I would like to be able to do video phone calls, audio phone calls,
113 exchange instant messages and share files with my loved ones, without
114 being forced to share with people I do not know. I do not want to
115 share the content of the conversations, and I do not want to share who
116 I communicate with or the fact that I communicate with someone.
117 Without all these factors in place, my private life is being more or
118 less invaded.&lt;/p&gt;
119 </description>
120 </item>
121
122 <item>
123 <title>My own self balancing Lego Segway</title>
124 <link>http://people.skolelinux.org/pere/blog/My_own_self_balancing_Lego_Segway.html</link>
125 <guid isPermaLink="true">http://people.skolelinux.org/pere/blog/My_own_self_balancing_Lego_Segway.html</guid>
126 <pubDate>Fri, 4 Nov 2016 10:15:00 +0100</pubDate>
127 <description>&lt;p&gt;A while back I received a Gyro sensor for the NXT
128 &lt;a href=&quot;mindstorms.lego.com&quot;&gt;Mindstorms&lt;/a&gt; controller as a birthday
129 present. It had been on my wishlist for a while, because I wanted to
130 build a Segway like balancing lego robot. I had already built
131 &lt;a href=&quot;http://www.nxtprograms.com/NXT2/segway/&quot;&gt;a simple balancing
132 robot&lt;/a&gt; with the kids, using the light/color sensor included in the
133 NXT kit as the balance sensor, but it was not working very well. It
134 could balance for a while, but was very sensitive to the light
135 condition in the room and the reflective properties of the surface and
136 would fall over after a short while. I wanted something more robust,
137 and had
138 &lt;a href=&quot;https://www.hitechnic.com/cgi-bin/commerce.cgi?preadd=action&amp;key=NGY1044&quot;&gt;the
139 gyro sensor from HiTechnic&lt;/a&gt; I believed would solve it on my
140 wishlist for some years before it suddenly showed up as a gift from my
141 loved ones. :)&lt;/p&gt;
142
143 &lt;p&gt;Unfortunately I have not had time to sit down and play with it
144 since then. But that changed some days ago, when I was searching for
145 lego segway information and came across a recipe from HiTechnic for
146 building
147 &lt;a href=&quot;http://www.hitechnic.com/blog/gyro-sensor/htway/&quot;&gt;the
148 HTWay&lt;/a&gt;, a segway like balancing robot. Build instructions and
149 &lt;a href=&quot;https://www.hitechnic.com/upload/786-HTWayC.nxc&quot;&gt;source
150 code&lt;/a&gt; was included, so it was just a question of putting it all
151 together. And thanks to the great work of many Debian developers, the
152 compiler needed to build the source for the NXT is already included in
153 Debian, so I was read to go in less than an hour. The resulting robot
154 do not look very impressive in its simplicity:&lt;/p&gt;
155
156 &lt;p align=&quot;center&quot;&gt;&lt;img width=&quot;70%&quot; src=&quot;http://people.skolelinux.org/pere/blog/images/2016-11-04-lego-htway-robot.jpeg&quot;&gt;&lt;/p&gt;
157
158 &lt;p&gt;Because I lack the infrared sensor used to control the robot in the
159 design from HiTechnic, I had to comment out the last task
160 (taskControl). I simply placed /* and */ around it get the program
161 working without that sensor present. Now it balances just fine until
162 the battery status run low:&lt;/p&gt;
163
164 &lt;p align=&quot;center&quot;&gt;&lt;video width=&quot;70%&quot; controls=&quot;true&quot;&gt;
165 &lt;source src=&quot;http://people.skolelinux.org/pere/blog/images/2016-11-04-lego-htway-balancing.ogv&quot; type=&quot;video/ogg&quot;&gt;
166 &lt;/video&gt;&lt;/p&gt;
167
168 &lt;p&gt;Now we would like to teach it how to follow a line and take remote
169 control instructions using the included Bluetooth receiver in the NXT.&lt;/p&gt;
170
171 &lt;p&gt;If you, like me, love LEGO and want to make sure we find the tools
172 they need to work with LEGO in Debian and all our derivative
173 distributions like Ubuntu, check out
174 &lt;a href=&quot;http://wiki.debian.org/LegoDesigners&quot;&gt;the LEGO designers
175 project page&lt;/a&gt; and join the Debian LEGO team. Personally I own a
176 RCX and NXT controller (no EV3), and would like to make sure the
177 Debian tools needed to program the systems I own work as they
178 should.&lt;/p&gt;
179 </description>
180 </item>
181
182 <item>
183 <title>Aktivitetsbånd som beskytter privatsfæren</title>
184 <link>http://people.skolelinux.org/pere/blog/Aktivitetsb_nd_som_beskytter_privatsf_ren.html</link>
185 <guid isPermaLink="true">http://people.skolelinux.org/pere/blog/Aktivitetsb_nd_som_beskytter_privatsf_ren.html</guid>
186 <pubDate>Thu, 3 Nov 2016 09:55:00 +0100</pubDate>
187 <description>&lt;p&gt;Jeg ble så imponert over
188 &lt;a href=&quot;https://www.nrk.no/norge/forbrukerradet-mener-aktivitetsarmband-strider-mot-norsk-lov-1.13209079&quot;&gt;dagens
189 gladnyhet på NRK&lt;/a&gt;, om at Forbrukerrådet klager inn vilkårene for
190 bruk av aktivitetsbånd fra Fitbit, Garmin, Jawbone og Mio til
191 Datatilsynet og forbrukerombudet, at jeg sendte følgende brev til
192 forbrukerrådet for å uttrykke min støtte:
193
194 &lt;blockquote&gt;
195
196 &lt;p&gt;Jeg ble veldig glad over å lese at Forbrukerrådet
197 &lt;a href=&quot;http://www.forbrukerradet.no/siste-nytt/klager-inn-aktivitetsarmband-for-brudd-pa-norsk-lov/&quot;&gt;klager
198 inn flere aktivitetsbånd til Datatilsynet for dårlige vilkår&lt;/a&gt;. Jeg
199 har ønsket meg et aktivitetsbånd som kan måle puls, bevegelse og
200 gjerne også andre helserelaterte indikatorer en stund nå. De eneste
201 jeg har funnet i salg gjør, som dere også har oppdaget, graverende
202 inngrep i privatsfæren og sender informasjonen ut av huset til folk og
203 organisasjoner jeg ikke ønsker å dele aktivitets- og helseinformasjon
204 med. Jeg ønsker et alternativ som &lt;em&gt;ikke&lt;/em&gt; sender informasjon til
205 skyen, men derimot bruker
206 &lt;a href=&quot;http://people.skolelinux.org/pere/blog/Fri_og__pen_standard__slik_Digistan_ser_det.html&quot;&gt;en
207 fritt og åpent standardisert&lt;/a&gt; protokoll (eller i det minste en
208 dokumentert protokoll uten patent- og opphavsrettslige
209 bruksbegrensinger) til å kommunisere med datautstyr jeg kontrollerer.
210 Er jo ikke interessert i å betale noen for å tilrøve seg
211 personopplysninger fra meg. Desverre har jeg ikke funnet noe
212 alternativ så langt.&lt;/p&gt;
213
214 &lt;p&gt;Det holder ikke å endre på bruksvilkårene for enhetene, slik
215 Datatilsynet ofte legger opp til i sin behandling, når de gjør slik
216 f.eks. Fitbit (den jeg har sett mest på). Fitbit krypterer
217 informasjonen på enheten og sender den kryptert til leverandøren. Det
218 gjør det i praksis umulig både å sjekke hva slags informasjon som
219 sendes over, og umulig å ta imot informasjonen selv i stedet for
220 Fitbit. Uansett hva slags historie som forteller i bruksvilkårene er
221 en jo både prisgitt leverandørens godvilje og at de ikke tvinges av
222 sitt lands myndigheter til å lyve til sine kunder om hvorvidt
223 personopplysninger spres ut over det bruksvilkårene sier. Det er
224 veldokumentert hvordan f.eks. USA tvinger selskaper vha. såkalte
225 National security letters til å utlevere personopplysninger samtidig
226 som de ikke får lov til å fortelle dette til kundene sine.&lt;/p&gt;
227
228 &lt;p&gt;Stå på, jeg er veldig glade for at dere har sett på saken. Vet
229 dere om aktivitetsbånd i salg i dag som ikke tvinger en til å utlevere
230 aktivitets- og helseopplysninger med leverandøren?&lt;/p&gt;
231
232 &lt;/blockquote&gt;
233
234 &lt;p&gt;Jeg håper en konkurrent som respekterer kundenes privatliv klarer å
235 nå opp i markedet, slik at det finnes et reelt alternativ for oss som
236 har full tillit til at skyleverandører vil prioritere egen inntjening
237 og myndighetspålegg langt foran kundenes rett til privatliv. Jeg har
238 ingen tiltro til at Datatilsynet vil kreve noe mer enn at vilkårene
239 endres slik at de forklarer eksplisitt i hvor stor grad bruk av
240 produktene utraderer privatsfæren til kundene. Det vil nok gjøre de
241 innklagede armbåndene «lovlige», men fortsatt tvinge kundene til å
242 dele sine personopplysninger med leverandøren.&lt;/p&gt;
243 </description>
244 </item>
245
246 </channel>
247 </rss>