Showing posts with label linux. Show all posts
Showing posts with label linux. Show all posts

Monday, October 01, 2018

Laptop Disaster Recovery

Waffle Background

This is what it's like getting Windows to play "nice" with Linux some times (and vice-versa)
And I don't mean the Linux sub-systems for Windows, but actual dual-boot scenarios where the Microsoft device is sulking a little.

I've been a Surface Pro user for some years and still haven't found anything that combines the flexible form factor & performance as well. I'm a little tempted by the Surface Book range but as I'm pretty tired of the limitations of Windows I'm still a little reluctant to shell out £3k+. The SP network adaptor is very limited so if you do work on network security you'll need that USB Alfa device. 

In my cynical way of thinking I've always thought these laptops were Microsoft's way of forcing the device manufacturers to get off their lazy backsides, spurring them to try something other than the clam shell form.

It's good to see HP and Lenovo making inroads to that effect, however none of the main device manufacturers seem to have come up with anything other than copies. Even now Microsoft seem to be the only vendor still pushing for innovation.

I won't dwell too much on Apple devices - they make great devices but terrible, bland software. However it is based on a variant of OpenBSD (albeit some time distant) and the hardware is fairly good.

The SP4 seems to have maxed out the potential and over the last ten years I've changed from a staunch Windows user & dev to multiplatform. I don't really have faith in Windows for anything other than Xbox, Netflix and Visio - everything else is generally better on Linux. They're both frustrating OS's at times but for altogether different reasons.

Of course the problem is that should you, for example, go on hols to Portugal and drop your SP on the hard stone floor, the screen might shatter and crack along it's entire ... er... surface? I bought my SP3 from John Lewis through my business but later found out that they don't have an instant replacement mechanism. You'll be without the laptop for up to 8 weeks whilst they review and - in all likelihood - replace your Surface. Microsoft are careful to tell you that if you have anything on your device when you pass it to them... it's as good as gone.

The only major problem I've seen with SP - and the one that's driven the need for this blog post - is that these form factors are even more sealed than the legacy clam-shell form. You just can't open them up and replace bits without some knowledge and a lot of faith in your skills.

Instead of JLP, I'd originally got my SP4 direct from the Microsoft store, and just logged in to my MS account to select the device for a support request gets the ball rolling. This cost to me £399 inc. VAT as this device was out-of-warranty. There were problems: the self-print return envelope didn't get sent, I had to find a UPS Collection point where there are seemingly none in my local area. Not earth-shatteringly problematic.

In fact the only delivery delays were at my end - my company uses a postal service to manage inbound mail and there was a complication with the replacement devices' onward travel.
Fresh new SP4 newly unpacked on arrival
Total time including cock-ups? About 3 weeks, would have been a little over 1 with smooth sailing.

Equipment Used

So as I mentioned I'm using a Surface Pro 4, which is dual booted using Ubuntu 16 over Jake Day's superb Linux Kernel build; and Windows 10 Pro.

If you're only working with Windows I'd really recommend using the Windows backup features as they will be far easier to manage. The complexities that follow are due to the dual-boot nature of my devices.

However if you're using another encryption solution (non-MS) and need to ensure Windows doesn't try to be too clever, I'd recommend using a more assured process like the one I'm about to describe.

I was lucky though - although the screen was busted the device actually worked. Mouse & keyboard or Type cover got me around the worst. If the screen is totalled, you can try using a docking station or the mini DisplayPort out to a separate monitor - just hope that you'd already enabled USB boot otherwise you won't be able to get into the UEFI config.

Because of this I've accumulated the following useful trinkets as time has passed:
  • a 256Gb - 1Tb SDD - depending on compression and device disk size
  • a USB 3.1 external SDD case / caddy
  • a USB SD card caddy / reader + something like a 4Gb class 10 SD card; or
  • a 4 GB USB data stick
  • a USB hub
  • a type-C to type-A USB cable for the SDD caddy (likely will be different depending on which caddy you choose)
  • a large bag of patience or an appreciation of progress bars
  • a spare laptop (if you need to work whilst your primary is in repair); or
  • your desktop (if your SP4 screen is busted o
  • Surface Type keyboard (best) or USB keyboard (make sure it works with Linux and Windows OotB)
USB SD card reader, SD card, USB hub, type-C cable and Win10 Pro on USB
I of course would like to point out that all software and hardware is fully licensed and legally purchased.

Because I do a lot of things with Raspberry Pi's I tend to have a number of SD cards around and a lack of USB sticks - the SP has an SD card slot and only one USB so you tend to adjust your thinking somewhat. Replace that SD card & reader with a USB stick as suits you.

Taking The Backups

All partitions except the original Windows 10 partition are encrypted, and there's nothing on the Win partitions that provides a poacher with anything useful, so I didn't encrypt the external drive first.

However if you're working on a mobile device without disk encryption - especially for work or where there's anything sensitive on it - you should really protect yourself. If your SP is shafted now though and you need to take a backup before sending it back to the shop, just encrypt the removable SDD.

You will need to ensure that the appropriate boot options are set in your UEFI config. I also disable secure boot as there's a number of security packages that don't work with it on Linux, and it doesn't provide a huge amount more than a deterrent on a Microsoft-made device.
Enable USB, disable PX network & IPv6, finally relock the configuration and ensure a UEFI config password is set 
Please note that all the commands from here on in are based on bash (Linux).
One SDD - I'm going to re-use this in my desktop at some point so went upmarket

I use the Inateck SDD cases - they work well, are robust and nicely designed

If you need to encrypt your external device due to the reasons I've mentioned above, and example would be:
sudo cryptsetup luksFormat --cipher serpent-xts-plain64 --hash whirlpool --key-size 256 --use-random /dev/sdd2

Where:

  • use cryptsetup benchmark to list all the ciphers and hashes your machine supports
  • I've selected serpent-xts as I don't entirely believe AES is best placed under guidance of NIST
  • I've selected whirlpool as a hash algorithm simply to demonstrate you have the option
  • /dev/sdd2 just happened to be the device name I was using 

You can add a key file if you like, but just remember you'll have to make that file available on the SD card on the live installer we'll be creating. It may not provide the security on the key file itself that we should employ - a decent horse battery staple will do. Grown-up explanation with big words here if you want it.

This is just one route as LUKS is common to a number of distros. Veracrypt and others are also excellent as well as x-platform. You'll just need to ensure the packages or executables are available in your live installation distro-of-choice.

You'll need another OS to boot into from a USB (or SD if you can make that work) device: I opted for Tails as Ubuntu 16 didn't live boot very well. Rather than tread old ground you can read up on that here.

USB hub holding the USB SD card reader with Tails on it; and the other cable goes to the portable SDD
Actually in that photo is a Surface Bluetooth Keyboard: great keyboard action and layout but needs a re-sync / pair when booting between OS's, and won't pair during boot for things like FDE password entry. Such a shame that it's basically only usable once you've booted into your OS. Avoid. The MS Sculpt Keyboard is USB-dongle and great to use. They've been practising making keyboards for thirty years so no matter what you think of their software they still make arguably the best finger peripherals.

Assuming you've now got Tails on a USB-able device and have prepped a partition on your USB SDD, plug it all in and boot into the Tails loader, making sure you've enabled root.
You can run the live installer with an encrypted file store, but you still need to change the defaults every boot
Once in, open up a root terminal and figure out what name Tails has given to your USB SDD. Among many ways of doing this you can try lsblk. In my case there was only the SP NVME device and the external SDD, so were both obviously distinct.

lsblk example output
You'll need to mount the SDD to allow you to to use dd to capture backups. Create a new folder with a mkdir /media/backup, mount your SDD with something like mount /dev/<name> /media/backup then CD into this folder.

You can run the following command for each partition you have, or just the whole device. I took backups of individual partitions "just in case" too.

WARNING: the dd command is sometimes referred to as the "disk destroyer". It doesn't validate much before executing your request so make absolutely sure you have the right sources and targets!

dd if=/dev/nvme0n1 bs=1024 conv=sync,noerror | gzip nvme0n1.gzip

You can use pipe view in there like this too:

dd if=/dev/nvme0n1 bs=1024 conv=sync,noerror | pv | gzip nvme0n1.gzip

That'll give you an indication of progress if you're so inclined. Once that's complete I'd recommend you wipe the disk with zeros and then randoms. There's documentation on the ArchLinux wiki so I won't duplicate here.

You'll need to do some maths to work out the block size of your actual disk and you don't need to do this if you were using FDE on all your partitions on this disk. I did it anyway as I was sending the device back to vendor and wanted to leave no trace of the types of opsec I employ.

You just don't know who's handling the device once it's returned to vendor.

Restoration

Again, ensure you enable root in the Tails boot config and apply whatever locals you need.

Because we're using a live installer to manage the disk restore, as we did in the backup, we can't guarantee that the device name will be the same. Use lsblk again and take a note of the correct device (use size or number of partitions if you're not sure).

open root terminal and script it like so:

# make a folder to neatly mount the external drive to
mkdir /media/restore
# mount the device again
mount /dev/<device> /media/restore
# change the working directory to reduce typing in the next command
cd /media/restore

I've already got my entire disk image gzipped, so I'm going to decompress that image and write it straight to the disk. I just don't care what the default SP4 install state is and I have a Win10 Pro USB key plus device license if anything goes wrong.

So I used:
gzip -dc nvme0n1.gzip | pv | dd of=/dev/nvme0n1 bs=4096 conv=sync,noerror

The first time I rebooted I nearly panicked... I got nasty error messages and returned to the UEFI config. Removing the boot order lock setting and allowing the device to get used to itself again sorted that out.
So happy to see the GRUB screen after restore. Now for all the updates since the backup was taken...


War Report

So for a device that cost roughly £2k and was out of warranty, and assuming I'd bought all those parts especially for the job; the total damage would have been around £700. As it was, I had all the parts already from various projects over the years.

If you have these devices in a corporate network I'd recommend taking a base image and ensuring your directory services force a network sync for all your user files. Anything else is the responsibility of the users and providing them a device with FDE enabled mitigates most other things. There's tools out there that do this across multiple OS's.

Costs to my company: £399 for the Microsoft part, around £250 for the SDD, and about £50 for the cables, cases and SD card. That's an expensive repair in comparison to some case opening and SDD swapping with a desktop or Dell laptop. It also cost me about an hour to sort out Tails, encrypt my drive and do the backup and about 30 mins restore.

If I'd had the base image and a replacement device that would figure to about 45 mins (including updates and file syncs post system restore), which isn't too bad along with a reduction in hardware & therefore cost.

Glad I'm operational again but this is the Achilles heel of the SP - and devices like it - cost of ownership is very high, as is maintenance and repair.

Friday, April 06, 2018

Took Some Finding

I've had some of my servers report that something has been running updates off-schedule, and it's taken me a good while to figure it out.

Some flavours of Debian - including Raspbian - have no unattended-upgrades service but do apply a cron job which triggers silent package updates.

I run all updates on a specific schedule so I can easily tell the difference in logs & reporting between a breach and an actual update so this isn't appropriate for our use at work. So the first advice I'd supply before using the configuration below is that ensure you have a valid and automated update mechanism to ensure your servers are kept up-to-date.

For example, I often use a custom script which not only does the update but then sends an encrypted message containing information about the update (or other types of jobs).

So with that in mind - and rather than altering package deployed cron scripts - I'd suggest changing (or creating) the /etc/apt/apt.conf.d/10periodic config to add or modify the Periodic apt setting to "disabled like this:

 APT::Periodic::Enable "0";

I suppose I could have put this on Stack Overflow but it's not really a question.

Tuesday, October 18, 2016

Running VMWare Player on an Ubuntu 16 SP4


I had some minor headaches trying to get a decent hypervisor working on Linux desktop, and figured out a more manageable approach whilst retaining secure boot & UEFI.

One of the initial challenges is actually getting to the download for the VMW Player - rather than the full (paid for) Workstation etc. but can be found here at the time of writing. VMWare seem to have made it far simpler to access than when I first dug it out. NB this is only for non-commercial use, otherwise you'll need the paid-for Pro version.

Had to use Chromium as FF didn't want to play with vmware.com
Of concern for me was the lack of checksum or PGP verification for the download, something VMWare need to work on. The other major annoyance is that every time the kernel is updated this process needs to be repeated.

High-Level Views

The reason you may need to do this is that you've tried to use VMWare Player / Worktation but the networking does not work. After digging into your logs you'll see that the drivers couldn't be loaded at boot time.

Unlike VirtualBox et al VMWare seems a lot more stable on my SP4 i7 16GB, and can run multiple VMs without the need to have their UI windows open. It also seems to handle host-guest device management (e.g. USB) far better.

Personally, I was tired of VB being flakey and am used to VMware and Hyper-V.

Step-by-Step

  1. Download the VMWare bundle from the link listed above
  2. Apply executable permissions via sudo chmod ug+x <vmw.bundle> 
  3. Run the .bundle (it's just a shell script) via sudo ./<vmw.bundle
  4. Once the installer has completed you may need a reboot - if you do you'll see systemd errors relating to failed service starts for the vmware.service due to the unsigned network drivers vmmon / vmnet 
  5. You'll need to run the kernel module updater - either via GUI or via sudo vmware-modconfig --console --install-all - this ensures that the modules VMWare needs to operate it's core networking capability are available
GUI version of the installer is invoked if you try and run the player at this point
This step should produce a script output ending something like this:
Starting VMware services:
   Virtual machine monitor                                            failed
   Virtual machine communication interface                             done
   VM communication interface socket family                            done
   Blocking file system                                                done
   Virtual ethernet                                                   failed
   VMware Authentication Daemon                                        done
Unable to start services
 


Checking the status of system services should show vmware loaded but unable to run.
This indicates that everything is ready for signing now the modules are ready. After step #5 download or clone a copy of this signer script and follow the instructions. You will be asked to create a password during generation, which is then requested during MOK install after you reboot.

Expanding on That

The last item on that list is a bit abrupt but there's a couple of things you must do. Firstly you need to adapt the certificate definition to your own needs.

Change the subject of each of the certificates from "/C=CountyCode/ST=OfficeState/L=OfficeCity/O=Dept/CN=local.yourdomain.ext" on line 9 as appropriate to your specific needs. Ensure that these details are not accessible by anyone other than yourself.

Two certificates are generated - one for each driver. You can simplify to one certificate if you prefer.


Problems


  1. Errors during step 5 could mean issues with VMware version and the Linux version. I upgraded to Ubuntu 16.10 which upgraded the kernel. To solve issues in error messages with the VMW kernel module updater download the latest version of the VMware player
  2. I found that a reboot was needed between dist-upgrade of Ubuntu and VMware re-sign, otherwise something would get itself tied up in knots and have no effect on the player.

Sunday, October 16, 2016

Old News

I noticed a few news articles recently that bemused me....relating to the addition of updates to v4.8 of the Linux kernel to support touch screen on Surface Pro 3.

This is strange to me because when I dual-booted my SP3 a couple of years ago with Ubuntu 15, touch screen worked out-of-the-box. Unity and Gnome UIs don't really deal with touch-screen input very well (but Linux doesn't really have the designers that Microsoft or Apple do), but it's not too bad. The SP 3 pen right-click isn't recognised at all so you'll need a mouse anyway. I included a photo of this in operation from a much earlier blog post.

Ubuntu 15, using the SP3 pen as a mouse
 However touch-screen input doesn't work at all with the SP4 - Running Ubuntu 16.04 and Gnome - no direct touch or pen input is detected. I can't find a touch-screen device registered by the OS either so am guessing this is the lack of drivers / support from Intel for the Iris 540 and touch-screen itself.

When I get some time later this month I'll look at the Intel Linux driver programme and the latest kernel to see if there's progress.

Thursday, May 19, 2016

Surface Pro 4 vs. Linux


Surface Pro 3 seemed to be stable, relatively efficient and a good mix for a dual boot laptop. Things were pretty good all round and Windows 8.1 Enterprise worked well on the touch-screen led device - probably not a popular statement but it was designed for Surface.

My own belief is that Microsoft didn't enter the laptop market to dominate it but to force the competition to get off their lazy backsides and start thinking again. We've had a stagnated market for over a decade and it's taken the software & keyboard kids to initiate change. Apple has had to improve it's hardware to compete with both Surface Pro & Book; HP and Lenovo have had to reconsider their clamshell laptop propositions too.

Moving beyond a simple single-OS laptop replacement a growing number of penguinistas have noticed the Surface and blogged about supporting it. Personally, I'd gotten to the point with Ubuntu 15.10 on SP3 where I was pretty much using it for everything work-wise - bar Visio and Excel situations, firmware updates for the Microsoft hardware and games or modern apps such as movie streaming or Kodi.
I don't use Windows for email and have my PGP keys available only on non-Windows OS's; all my remote work is done on servers via SSH and I lock drives up with a multi-platform encryption solution. Ubuntu handled all of that and seemed to get the most support for SP3 out of all the Debian-based distros.

Ubuntu didn't really do brilliantly with touch-screen but the stylus was a pretty good mouse replacement (assuming you don't need a right click...). The SP4 stylus was a big improvement on the SP3 variant - and didn't go to sleep at random whilst you were using it.

A big plus. And not generating a BSOD when you attempt to disable power management would have been a bigger plus. Although Windows 10 - in all it's greatness - decided to fail software licensing management services without any bidding on the replacement SP3, meaning I had to deploy W8.1Ent anyway...

Then the connector between the SP3 and the type cover stopped detecting anything - I have Type Cover 3 & 4 so tried both - and with John Lewis' support policies meaning a 3 week period without a laptop whilst they repair it; I was running out of options as I need a laptop to earn money / work on client site.

Perhaps rashly, I elected to buy a Surface Pro 4, take an image of my old SP3 and deploy straight onto the SP4.

I used dd more in the last month than I have in years
Of course - that would be too easy. Microsoft have revoked support for Skylake and a significant portion of hardware drivers for the SP4 from anything but Windows 10.

Dick move Microsoft.

I wasn't prepared to disable the driver signing checks and manually install 100+ drivers. Looking forward another 12 months I would not have thanked myself for the maintenance overhead.

After a lot of research and swearing I gave up. Reset the PC.

Plan B. Good thing I took a backup of the SP4 drive before I started eh? Redeploy the boot partition, the W10 partition and the W10 recovery image (a partition at the back of the drive) and run the re-deployment.

What's this? I can put Debian straight onto the SP4? Skip a few kernel versions and maybe get that Surface Pro driver support OotB? Why mess about with downstream distros like Ubuntu? A big thumbs up to Alexander Clouter who's been persistent enough to plug away at Debian 8 on the SP4.

All went fairly well until the reboot then I discovered a problem where putting the home mount point on a LUKS provided partition seemed to keep taking out the installer. Seemed to get confused, dismount the home partition cryptsetup preventing selection for home.

I tried putting all mount points into one partition and got Debian 8 loaded on it. But as soon as I got further into the configuration (around the kernel rebuild) things started going wrong. Despite long hours of research I couldn't get initramfs or hid_multitouch to deliver the right state prior to kernel build. Although I sorted out the sources I think it just needed someone with more linux experience to resolve the errors when it wandered off Alexanders plan.

More swearing. I used a couple of the old SP3 pens as darts on a dartboard and chucked some kittens in a wood chipper to make myself feel better.

At this point I had to carry the old SP3, a usb keyboard and the stylus on to client site and wasn't happy. I'd got plenty of other things to do (on top of the consultancy work during the day) and paperwork to sort out.

Right - so plan B stuffed. Plan C. This time I already had the partitions set up so just invoked the PC reset / W10 recovery process. W10 set up and updates re-installed I just grabbed the ISO for Ubuntu 16.04 Desktop and plodded through the deployment.

Same issue with the LUKS and separate home mount point - eventually gave up on the idea altogether and created a shared encrypted partition which is usable by W10 and Ubuntu, along with separate partitions for later use.

Thanks to Spideroak it was pretty easy to download and re-deploy all those custom .bashrc and .bash_alias type moments - and Evolution backups that I use to replicate my environment across machines.

Finally Operational

Windows 10 is an utter disappointment. If I'd never seen Windows 8 I would have loved it as it's a great step forward from Windows 7. It makes even more sense when you use it on a touch screen device like a Surface and with the stylus & OneNote the whole thing takes on new meanings in meetings.

However my faith in Windows 10 is gone - 8.1 was a pinnacle in user experience and there's a lot of it's logical workflows that I hope will one day be amalgamated into 10; e.g. VPN - the charms allowed me to select a configured VPN adapter whereas in the W10 right-side menu it opens the control panel VPN settings page - a wholly unnecessary screen jump for an "on/off" operation. For now though it's a step backwards.

W10 also has a recently introduced "undocumented feature" which has touch-screen and stylus stop responding seemingly at random. I'm pretty much steering clear but OneNote, Excel and Visio keep that productivity link - there's nothing that comes close on Linux unfortunately. The majority of my work is done in Linux - Architool, LibreOffice, Evolution and Office365 Enterprise (depending on the client).

Game streaming from an Xbox One though is a huge plus for W10 and the new processor & cooling fan doesn't sound like a helicopter on take-off when the slightest CPU utilisation spike hits. Did I mention that I like it that the SP4 pen doesn't fall asleep at random whilst you're using it?

Security Concerns

After all of the recent nag-malware, privacy issues and Microsoft’s collaboration with various data collection schemes I'm left only with concern that my security and data investigation work would potentially be compromised by continuing to use the ecosystem in any great way.

I've already encountered a swathe of spear phishing attempts using email addresses only available to the subjects of spam hunts or AV firms (more of that another time) and not reading my emails on Windows is good way to cut out 99% of that threat vector. The rest I can deal with via opsec & security solutions on Linux.

Hindsight is a wonderful thing and what I should have done was buy a replacement [new] SP3 i7 and just redeployed the machine image from old to new. Maybe there would have been some software licensing tied to hardware ID's - or perhaps a re-sign of secure boot certificates. But nothing as relentless as the SP4 option or as expensive. It has not proved value for money and I'll not be buying an SP5 unless it's device vendors provide drivers for the open source community.

Friday, November 20, 2015

Beneath The Surface

<abstract surface pun />
As a follow up to my last post I talked a little about how I'd become more open to options and that I'd had reservations about re-applying Windows onto my Surface Pro 3.

Obviously this isn't a default install and most of the concerns weren't because of issues with Windows - eventually I got Win 8.1 Enterprise back in there dual booting with Ubuntu. A couple of minor hitches which were resolved with a bcdedit command to force Windows to use the Grub2 loader after a file copy from the old Ubuntu boot partition to the newly-screwed Windows boot partition.

Still have to register the loaders in the secure boot registry, as is well described by David Elner (just be aware that this is an older version of Ubuntu and I could not get the kernel re-compile to work) but otherwise it's all ok.

However I thought I'd share some issues I have with SP3 and why I'm not likely to buy an SP4. For reference the PCs involved are:
  • Surface Pro 1 128Gb 4Gb i5
  • Surface Pro 3 512Gb 8Gb i7
Firstly the OS.... Windows 10 locked me out and I had no downgrade option other than a manual re-install. Something went horribly wrong after I got my replacement SP3 and for some as yet unknown reason Win10 software protection service started failing after I installed Office 2013 Pro. The knock-on effect was that I couldn't use Office, I couldn't use a lot of the feature changers (add / remove programs, anything that writes changes to registry, etc) nor would any of the safe boot options appear and I couldn't do a refresh or a factory reset either.

I didn't have any choice about Windows 10 - that was what was installed on the replacement unit.

Support simply suggested I return it to the shop and as I'd already burned two weeks for the replacement unit after a screen failure, then another week or so (evenings only) actually re-deploying all the 'stuff' on it, I didn't think the extra effort was worth the pain. After a bit of thought I then realised now would be the perfect time to dual boot it and have a workaround for some of the issues with Windows in general. Not much to lose at that stage.

Of course now I have screen flickering issues on the unit - it seems to be some sort of physical connection issue because when I squeeze the screen in a particular place and wait an undetermined amount of time it sorts itself out. Although often I'm not sure whether the whole thing hasn't just hung and I do a hard reset. It's not a driver or software issue as only physical intervention (pressing and squeezing the unit until the screen springs back into life is not a driver fault or brightness management) and I just don't have time to send it back for another replacement; rebuild and re-deploy only to later find out the same problem might exist.

A very embarrassing problem for a touch screen device.

The pen....the pen....What a brilliant concept yet how did they screw it up so badly? It feels like a real pen, the buttons on the side are fantastic and I no longer need a mouse....just the pen and my fingers. But then all by itself it decides that it needs a rest and goes to sleep. I've tried battery replacements, holding down buttons to try and wake it up and even whacking it over a solid surface (which seems to work most often) and nothing seems to help. Of course if you try and disable power management via Windows you get a BSOD. Nice. And I'm far from alone on this one.

Windows 10 lost it's way and I struggled to get it to flow as Windows 8.1 does. 10 tries to keep the desktoptards from Windows Vista *spits* and 7 happy whilst showing promise to touch-screen owners. Sometimes I think the desktoptards were the only voices complaining about 8.1 and not enough people extolled it's virtues. So now I have 8.1 Enterprise until the end-of-life or when Windows 10 Enterprise catches up so I can access OneNote during meetings and sync my OneDrive repositories. Windows also seems to be the only way to get firmware updates for Surface so it gets a small section of the SSD to park itself. I have too many reservations about the way Microsoft is approaching some aspects of security (such as the changes to BitLocker in 8). I'm not trying to outrun any governments but if someone nicks my SP3 I want to be fairly sure they won't get my data in their lifetimes. Of course dual booting means BitLocker won't encrypt the system drive like LUKS will, so only the OS and some program files are on the open system partition, the rest is on encrypted partitions.

Ubuntu is ok too - but the touch screen integration is extremely basic and there's no handwriting tools that are anywhere good enough. The pen buttons just don't do anything at all and no matter what I try I can't get the kernel re-compile to work. With Wily Wolf the battery indicator suddenly appeared and that was a big step forward - I've also discovered that touch screen scroll & zoom does work in specific applications. At the moment I'm struggling to get routes working under OpenVPN configurations that work fine under Windows so I tend to use Windows for comms and browsing in situations where VPN is a requirement. I will fix the problem but I need to understand it first.

I've also noticed that Network Manager sometimes refuses to use the right password for WiFi networks, resolved only by a mac change and a ifdown-up on the network adapters. That seems a little shoddy to me. Evolution is a pretty good mail app and I'm not really missing Outlook that much so it's evens on that front and with LibreOffice too - there are some issues with .XLSM and the occasional corruption-and-loss of .XLSX which is beginning to get on my nerves. Ubuntu seems ok but the Pen buttons don't work and I tend to end up using a mouse - the horror! - due to that and the SP3 Pen sleepy-time issues.

In short - neither platform is doing a great job at the moment but each has its own strengths.

I'm not going for a SP4 because - as much as I've loved the Surface experience - Surface Book means I can have my cake and eat it. It's more powerful than the overpriced Macintosh (I'd only be replacing OsX with a Win & Linux dual boot anyway) and I get the clipboard & pen with OneNote and Visio that I can't be without in meetings and team updates.

Of course that is assuming they fix the current complaints and I see some indication that the pen behaviour has improved. My Surface Pro 1 is still going strong and I don't mind Windows 10 on there because I don't use it much. The rest of the family don't seem to mind it when they want to use Kodi or play some Xbox games and everyone's forgotten about the Nexus 7 completely.

Saturday, November 07, 2015

Wǒ hěn hǎo, xièxie


Some time ago I had a peek into The Other Side and didn't take it any further - but maybe that's because I didn't have a purpose or reason to take it further but I couldn't see a reason to progress, so I didn't. It just came across like a hobbyists environment with a community of snobs driving progress.

Wind the clocks forward another year or more and the landscape is vastly different. I've moved on to learning about network security, information management and have trained myself to think like a black hat (a good defensive strategy). I'm working on some exams that will give me the foundation to absorb that within my work as an architect too and because of the nature of this research I've been working on Linux.

There's some aspects of Windows (e.g. restrictions on packet injection / tampering) which the Linux community seems to lambaste Microsoft for. To me - as a noob at least - it looks like this is by design for commercial reasons. Whatever the reason it just isn't feasible to do a lot of this research on Windows.

So I created VMs through Hyper-V and researched distributions and their capbilities, settling on Debian as my initial preference. It's used as a basis for a number of other flavours including Kali, Raspbian and Ubuntu. KDE is nice and the apt system makes sense to me at this stage.

But then, of course, you start discovering limitations in the virtualised environments leading to one conclusion: You need to deploy to hardware to gain direct interaction with that hardware (and mitigate problems with networking especially). I started beefing up my knowledge of networking stacks and how to analyse network traffic, creating sandbox WiFi networks on my test router and trying to see how to break them / break into them. I found that Kali was a great place to look at this as it contained all the tools and was designed to run OotB so stuck with that on a Pi B+ for a while.

After a while I was using Archimate to design the domains of our house network and started building a HIDS and IDPS, then a DNS server, then spent a bit of cash at ModMyPi getting all the bits I needed. I set up high-grade SSH keys and improved security - I may add a VPN server in the DMZ at some point too. I've got DD-Wrt on the inner router and a custom network set-up which provides additional protection for everyone in the house.

ATX Mid-tower was replaced and needed a new use. Stick a PiRack in there and all the cables.
I suddenly realised I'd become one of the hobbyists I'd turned my nose up years ago. Now our house provides media services so the kids can fire up a film of their choice on any Surface or XBox, iPhone or Windows Phone. We have network protection running in the background emailing me when it detects or fixes a problem. The kids came up with the idea of an underwater camera so they can see the fish even when they hide (yet to be designed and built). None of this involves a Windows server.

Of course I've made significant progress in my learning and research - the next pot of which will be a short study on effective WiFi passwords vs. advice from the pub - but as a by product I've gotten far more technical than I'd expected; you end up finding things to investigate that you'd never considered before and research topics or techniques far from the original purpose.

For example, I've moved my trust away from BitLocker and am testing alternatives, using local accounts for BAU and my Microsoft accounts for connected services (such as OneDrive and XBox). It's not about tin-foil hats, the X-Files or any part of government; it's just a simple case of protecting your assets against criminals or other similar attackers.

I went with Ubuntu because it is Debian-oriented and it seems to have the most support for things that Surface Pro needs. If Debian covered a lot of it I'd have just gone straight there. I don't like the whole Amazon / internet integrations on Unity; the volume buttons don't work; the SP pen buttons don't work; sometimes the left-mouse / pen touch / finger touch just stops responding at random. There's too many suggestions out there on the forums that don't explain what each command suggested actually does (do people just copy and paste these suggestions without understanding the implications first?).

Today is the first time I've used Windows in a week - I love Windows 8.1, especially on Surface Pro. It's beautifully designed, easy to use, makes the switch between keyboard-oriented and tablet seamlessly and OneNote /OneDrive / Office is pure brilliance in design and productivity. LibreOffice and Evolution do Office well but the UX is far clunkier. There is no OneNote outside of Windows and I miss the right click pen button (I only use a mouse on Ubuntu for apps that use context menus a lot). Office365 means I get proper Powerpoint instead of the terrible LibreOffice Impress. There's no Visio equivalent though I'm learning to use Camunda Modeller and Archimate instead. I can operate on client site without Windows now though.

For me Windows 10 is a disaster as it stands. They've ruined OneDrive (where is "Available Off-line Only" for files?) although are promising to rectify the situation and I think they've been led by too many Windows XP-ers in their UI-design-by-community instead of holding their ground and pushing 8.1 on to the next level. Continuum is awesome though - the new W10/Xbox dash is great (game streaming is by far the best add-on here), W10Phone looks superb and I hope they iron out the creases on W10. None of the privacy issues bothered me because you can turn off the telemetry services and disable the data sharing but the OS itself just doesn't feel as coherent or as well thought out as 8.1 on my SP3 or Windows Phone 8.1 on my Lumia.

I'm now in a position where I've had to remove Windows 10 from my replacement Surface Pro 3 as the software licensing service locked the whole machine out (Access Denied); despite this being the default build as supplied by Microsoft. USB boot won't work even after changing the UEFI settings to enable it - I suspect something to do with the Win10 installation - but I've now copied the 8.1 Enterprise installer to a new partition on the SP3 SSD and hacked the Grub2 bootloader to give me the option to boot from it and I'm going to get Windows dual booting on it for OneNote and firmware upgrades. Encrypted SD and data partitions allow sharing between OS-es and decent OpSec can ensure Windows only knows how to access one of those for transfer.

Phew. If you'd suggested and of that to me a year ago my eyes would have glazed over and I would have probably just sent the device back to manufacturer.

But the thing is I'm still afraid to install Win8.1 in case it fudges up all the work done installing and configuring Ubuntu. I know Windows will install its own boot-loader (I've modified the same on my desktop to add back the Ubuntu option enabling dual boot again). I like Ubuntu, Raspbian and Debian - I also like the Windows ecosystem and the journey is never over but I'm reaching the point where I have enough foundation to build on for the security architecture courses. In order to design an architecture or provide solid options for businesses I still feel it's beneficial to understand the inner workings.

It's good to be bilingual between Windows and Linux and none of this has been as difficult as learning Mandarin (as I originally thought it might be). It just sounded more tricky to get started than it was.

Saturday, October 18, 2014

VMWare Player Memory Issues


I had a *facepalm* moment with VMWare Player yesterday and solved it today so thought I'd share it - Either that helps someone out or makes someone laugh at my stupidity (either way it's a positive post).

I've recently been getting things deployed to my brand new Surface Pro 3 and by and large it's been painless - almost everything Windows 8'y was done instantly because of the settings sync between my Surface Pro 1 and my various desktop and R&D VMs using the same Microsoft Live ID. It's optional of course but I found that it makes a positive difference1.

The only installs I've had to do are the standard laptop / desktop installs, e.g. Visual Studio, Achimate, EA, Office, etc... And VMWare Player2.

None of these were an issue but when trying to spin up a VM I kept getting an error message telling me that there wasn't sufficient memory for the VM guest. I'd already moved VMX across from old Surface or installed new VM's from scratch so it wasn't happening all the time.

I thought that was a bit strange as my Linux guests tend to have 512Mb RAM for sandboxes and up to around 2Gb for intensive operators (such as some research tools on Kali). With 8Gb of RAM on SP3 and a few days researching memory cache in Win8.1 I was pretty confident that this wasn't the real issue.

Which of course it wasn't. Finally found this conversation chain on the VMWare forums.
Well that made a lot of sense. Should have checked UAC issues out first. I changed the application start-up options via context menu properties on %installPahth%\vmplayer.exe to run as administrator ... restart machine and - lo and behold - it seems to kick it into touch.
Hope that saves someone else the time spent on the problem :)

Sunday, July 27, 2014

MY IDE is Better Than YOUR IDE So Nurr

*sigh*
It never really changes.

Same argument - different playground.
jmonkeycoder.wordpress.com/2013/08/28/eclipse-vs-visual-studio/

Interesting article - Think there's plenty of people out there who appreciate the type of comparison.

Thought I'd pitch in as I use both Java and .NET for different clients: I often use both Eclipse and VS (although rarely at the same organisation!). Thought I'd could give a more balanced perspective. You're a Java & Eclipse person - there's nothing wrong with that; many commenters appear to be VS & .NET-ers though and I think there's more caustic discussion there.

It's great to have a side-by-side comparison but there's a lot of the functionality and features from Visual Studio in addition to your lists. There's a number of features from, say Ultimate edition that perhaps not everyone gets to play with! In particular intellitrace and the performance tools from the analysis side, and the architectural tools integration on the design side.

Don't get me wrong - VS doesn't match up to Archimate in my opinion but its tools integrate well. CodeLens is another good example but there's quite a few more.

There are a number Eclipse plugins that do some of these things but not all (which is probably why Ultimate costs > 12k GBP for a single seat license)...but then Java works a little differently, and the platforms it generally runs on are very different!

After running Eclipse on a pretty fast machine on Kali and VS on W8.1 Enterprise I don't see much difference in IDE performance for massive multi-project applications either. I have noticed performance differences in the root frameworks though.

I've always thought that developers shouldn't really have a preference between either framework but I would say there there's a clear difference in the level of productivity however that's kind of irrelevant...I would never consider using Eclipse for .NET/Mono and I haven't seen anything for Java on the Visual Studio side - lets try and forget all about J++ and J# as soon as we all can :)

For me, Java & Eclipse are extremely useful for specific scenarios and I don't think its fair to discount it as other commenters have, yet you've severely underestimated the capability of the other IDE (even for VS 2012).

Friday, May 11, 2012

Bogus Chroot

I saw the posts about the Google Chromium OS earlier this year and thought I'd take a look. An OS orientated around the old thin client principals perhaps?

From a personal interest level I thought I'd have a crack at compiling the source code myself and seeing what's involved so got the latest Ubuntu running on a VirtualBox VM and started having a play.

That was four weeks ago, and I've been distracted with tinkering on Mono and Java since. Linux has come a long way since I last used it back in around 2005 and I'm pretty rusty! Managed to follow the build instructions all the way to the point of actual build but then get a message that I have no idea about.

"Warning: Possible bogus chroot detected"

Maybe I should have just downloaded the redist and been content with that but for now, converting some of my own-time projects in .NET 4 to Java and Mono will keep me out of mischief. I quite like the Ubuntu environment: if you're a Microsoft-er with a familiarity with C# & PowerShell and have never used linux before you'll pick it up pretty quickly.

It's interesting to have a look over the technology fence and see how the Jones' have been doing lately, but I don't think I'd want to move (they're more than welcome to come over for dinner though).