<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>kill-9.it &#187; English</title>
	<atom:link href="http://www.kill-9.it/blog/index.php/category/english/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.kill-9.it/blog</link>
	<description>Coffee for the mind, pizza for the body, sushi for the soul.</description>
	<lastBuildDate>Sat, 22 May 2010 19:35:06 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Northwest Flight 253 and the &#8220;security&#8221; of it all</title>
		<link>http://www.kill-9.it/blog/index.php/2009/12/27/northwest-flight-253-and-the-security-of-it-all/</link>
		<comments>http://www.kill-9.it/blog/index.php/2009/12/27/northwest-flight-253-and-the-security-of-it-all/#comments</comments>
		<pubDate>Sat, 26 Dec 2009 23:50:17 +0000</pubDate>
		<dc:creator>zen</dc:creator>
				<category><![CDATA[English]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.kill-9.it/blog/index.php/2009/12/27/northwest-flight-253-and-the-security-of-it-all/</guid>
		<description><![CDATA[By now I think everybody has heard of the unsuccessful [terrorist?] attack to Northwestern Flight 253, where Umar Farouk Abdul Mutallab tried to mix bomb components about one hour before the plane landed. We&#8217;re so used to the restrictions applied to passengers of flights, that we almost think of them as routine, while we should [...]]]></description>
			<content:encoded><![CDATA[<p>By now I think everybody has heard of the <strong>unsuccessful</strong> [terrorist?] attack to Northwestern Flight 253, where Umar Farouk Abdul Mutallab tried to mix bomb components about one hour before the plane landed.</p>
<p>We&#8217;re so used to the restrictions applied to passengers of flights, that we almost think of them as routine, while we should always think about the effectiveness of &quot;security&quot; measures as they are applied. The most lacking resource being often common sense.</p>
<p>In this case, we can already read of the next restrictive measures, <a href="http://www.dhs.gov/ynews/releases/pr_1261853923809.shtm">on the NHS site</a>:</p>
<blockquote>
<p>The Department of Homeland Security immediately put additional screening measures into place [...]</p>
<p>Passengers flying from international locations to U.S. destinations may notice additional security measures in place. These measures are designed to be unpredictable, so passengers should not expect to see the same thing everywhere.</p>
</blockquote>
<p>So, we&#8217;ll get more restrictions, but not the same everywhere. (WTF #1)</p>
<p>Next, let&#8217;s see what the TSA has in mind for us:</p>
<blockquote>
<p>Among other things, during the final hour of flight customers must remain seated, will not be allowed to access carry-on baggage, or have personal belongings or other items on their laps[...]</p>
</blockquote>
<p>as someone else said, I&#8217;m glad that the &quot;terrorist&quot; didn&#8217;t try to blow himself up three or more hours before. Now, I will not be allowed to take a book (or put it away) during just the last hour of the flight, but this will surely scare all those terrorists that can act and think only during that last flight hour. (WTF #2)</p>
<p>I still consider myself lucky, though, <a href="http://www.startribune.com/business/11214761.html">because</a>:</p>
<blockquote>
<p>Effective today, the TSA has informed Northwest that travelers are not allowed to transport any liquids, gels, lotions or similar items in their carry-on luggage. This includes items such as beverages, hairspray, toothpaste and shampoo. These types of items can only be carried in checked luggage.</p>
</blockquote>
<p>In the end, I do not agree with those who say that as the attack was not successful, no additional security measures would be needed. I still strongly believe that in this cases <a href="http://news.yahoo.com/s/ap/us_airliner_disturbance">early intelligence</a></p>
<blockquote>
<p>Mutallab&#8217;s name had surfaced earlier on at least one U.S. intelligence database, but not to the extent that he was placed on a watch list or a no-fly list.</p>
</blockquote>
<p>is much more useful than a guy asking me to leave my water bottle at the security check.</p>
<p>In the meanwhile, it leaves me surprised that the bomber left from an airport that the <a href="http://www.african-aviation.com/index.php?option=com_content&#038;view=article&#038;catid=16:africa&#038;id=178:the-transportation-security-administrationconfirms-lagos-airport-security-compliance">TSA confirmed compliant</a> just a month ago. Again: either the airport security failed, or the security procedures and requirements are just wrong.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.kill-9.it/blog/index.php/2009/12/27/northwest-flight-253-and-the-security-of-it-all/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Intel&#8217;s Activex</title>
		<link>http://www.kill-9.it/blog/index.php/2009/12/03/intels-activex/</link>
		<comments>http://www.kill-9.it/blog/index.php/2009/12/03/intels-activex/#comments</comments>
		<pubDate>Thu, 03 Dec 2009 19:38:34 +0000</pubDate>
		<dc:creator>zen</dc:creator>
				<category><![CDATA[English]]></category>
		<category><![CDATA[Geek]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.kill-9.it/blog/?p=495</guid>
		<description><![CDATA[So, who am I supposed to trust? (it turns out that Husdawg LLC is a perfectly &#8220;legal&#8221; ActiveX provider, but Intel does not mention them anywhere &#8212; just hoping people will click through?)]]></description>
			<content:encoded><![CDATA[<p>So, who am I supposed to trust?</p>
<p><a href="http://farm3.static.flickr.com/2562/4137384969_41c4ef5333_o.png"><img src="http://farm3.static.flickr.com/2562/4137384969_41c4ef5333_o.png"/></a></p>
<p>(it turns out that <a href="http://www.husdawg.com/">Husdawg LLC</a> is a perfectly &#8220;legal&#8221; ActiveX provider, but Intel does not mention them anywhere &#8212; just hoping people will click through?)</p>
]]></content:encoded>
			<wfw:commentRss>http://www.kill-9.it/blog/index.php/2009/12/03/intels-activex/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Snow Leopard Trash, again</title>
		<link>http://www.kill-9.it/blog/index.php/2009/11/12/snow-leopard-trash-again/</link>
		<comments>http://www.kill-9.it/blog/index.php/2009/11/12/snow-leopard-trash-again/#comments</comments>
		<pubDate>Thu, 12 Nov 2009 22:58:11 +0000</pubDate>
		<dc:creator>zen</dc:creator>
				<category><![CDATA[English]]></category>
		<category><![CDATA[Geek]]></category>
		<category><![CDATA[apple]]></category>

		<guid isPermaLink="false">http://www.kill-9.it/blog/?p=480</guid>
		<description><![CDATA[At first I did not notice, but emptying the trash took ages, even &#8220;not securely&#8221;. Well, being the geek I am I did a quick dtruss on the Locum process, which spit out a huge list of write_nocancel syscalls. So, it seems it was actually writing stuff over the files I asked him to delete, [...]]]></description>
			<content:encoded><![CDATA[<p>At first I did not notice, but emptying the trash took ages, even &#8220;not securely&#8221;.<br />
Well, being the geek I am I did a quick dtruss on the Locum process, which spit out a huge list of write_nocancel syscalls. So, it seems it was actually writing stuff over the files I asked him to delete, even if I never asked him to (I just did a right click on the Trash icon, and selected &#8220;Empty Trash&#8221;). WTF?</p>
<p>Well, I learned (thanks Google) that Snow Leopard does a secure erase of the trash by default. Annoying.<br />
And that I did not realize that until now. Embarassing.</p>
<p>So, this can be solved at least in two ways:</p>
<p><strong>The GUI one</strong><br />
Go into Finder preferences, Advanced, and uncheck &#8220;Empty Trash securely&#8221;</p>
<p align=center><img src="http://www.kill-9.it/images/finderpref.png" alt="Finder Preferences Window" /></p>
<p>or</p>
<p><strong>the CLI one</strong><br />
Go into ~/Library/Preferences, convert the Finder preferences to xml (it&#8217;s binary by default)<br />
<code>plutil -convert xml1 com.apple.finder.plist</code><br />
and change the stanza</p>
<p><code>        &lt;key&gt;EmptyTrashSecurely&lt;/key&gt;<br />
        &lt;true/&gt;</code><br />
to<code><br />
        &lt;key&gt;EmptyTrashSecurely&lt;/key&gt;<br />
        &lt;false/&gt;</code></p>
]]></content:encoded>
			<wfw:commentRss>http://www.kill-9.it/blog/index.php/2009/11/12/snow-leopard-trash-again/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Flickr.com down</title>
		<link>http://www.kill-9.it/blog/index.php/2009/10/20/flickr-com-down/</link>
		<comments>http://www.kill-9.it/blog/index.php/2009/10/20/flickr-com-down/#comments</comments>
		<pubDate>Tue, 20 Oct 2009 17:37:45 +0000</pubDate>
		<dc:creator>zen</dc:creator>
				<category><![CDATA[English]]></category>
		<category><![CDATA[Geek]]></category>

		<guid isPermaLink="false">http://www.kill-9.it/blog/?p=470</guid>
		<description><![CDATA[beepbeep:~ zen$ date Tue Oct 20 19:34:42 CEST 2009 beepbeep:~ zen$ host www.flickr.com www.flickr.com is an alias for www.flickr.vip.mud.yahoo.com. www.flickr.vip.mud.yahoo.com has address 68.142.214.24 www.flickr.vip.mud.yahoo.com mail is handled by 0 . beepbeep:~ zen$ telnet www.flickr.com 80 Trying 68.142.214.24... telnet: connect to address 68.142.214.24: Connection refused telnet: Unable to connect to remote host weird. The very same [...]]]></description>
			<content:encoded><![CDATA[<p><code><br />
beepbeep:~ zen$ date<br />
Tue Oct 20 19:34:42 CEST 2009<br />
beepbeep:~ zen$ host www.flickr.com<br />
www.flickr.com is an alias for www.flickr.vip.mud.yahoo.com.<br />
www.flickr.vip.mud.yahoo.com has address 68.142.214.24<br />
www.flickr.vip.mud.yahoo.com mail is handled by 0 .<br />
beepbeep:~ zen$ telnet www.flickr.com 80<br />
Trying 68.142.214.24...<br />
telnet: connect to address 68.142.214.24: Connection refused<br />
telnet: Unable to connect to remote host<br />
</code></p>
<p>weird.<br />
The very same www.flickr.vip.mud.yahoo.com handles api.flickr.com (which is, unsurprisingly, down).<br />
Doesn&#8217;t look smart from here.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.kill-9.it/blog/index.php/2009/10/20/flickr-com-down/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Verbosely emptying the trash</title>
		<link>http://www.kill-9.it/blog/index.php/2009/10/17/verbosely-emptying-the-trash/</link>
		<comments>http://www.kill-9.it/blog/index.php/2009/10/17/verbosely-emptying-the-trash/#comments</comments>
		<pubDate>Sat, 17 Oct 2009 12:01:48 +0000</pubDate>
		<dc:creator>zen</dc:creator>
				<category><![CDATA[English]]></category>
		<category><![CDATA[Geek]]></category>
		<category><![CDATA[apple]]></category>

		<guid isPermaLink="false">http://www.kill-9.it/blog/?p=462</guid>
		<description><![CDATA[Like it happens on Windows, when you decide to delete something OSX simply moves that file or directory to &#8220;the Trash&#8221;, which is just a hidden directory on the volume you&#8217;re deleting from. Then, you right click on the Trash icon and select &#8220;Empty trash&#8221;. This action pops up a small window like this: I [...]]]></description>
			<content:encoded><![CDATA[<p>Like it happens on Windows, when you decide to delete something OSX simply moves that file or directory to &#8220;the Trash&#8221;, which is just a hidden directory on the volume you&#8217;re deleting from. Then, you right click on the Trash icon and select &#8220;Empty trash&#8221;.<br />
This action pops up a small window like this:</p>
<p align=center>
<img src="http://www.kill-9.it/images/osxtrash.png" alt="osx trash progress window" />
</p>
<p>I grew tired of asking myself what OSX was deleting (the operation can take a while, especially when &#8212; as I often do &#8212; you&#8217;re doing a secure erase) so this ugly one-liner, run as root, will give you the file the OS is working on:</p>
<p><code><br />
ps auxw | grep -i locum | grep -v grep | awk &#039;{print $2}&#039; | xargs lsof -p | grep -i Trash | awk &#039;{print $9}&#039;<br />
</code></p>
<p>It will output something like this:<br />
<code>/Volumes/FAT80GB/.Trashes/502/xcode3210a432.dmg</code></p>
<p>You can wrap that command inside the usual while/sleep loop if you want something that keeps you updated on what is going on &#8212; or make it an alias for your favourite shell.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.kill-9.it/blog/index.php/2009/10/17/verbosely-emptying-the-trash/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Snow Leopard, ssh-agent and an everlasting memory</title>
		<link>http://www.kill-9.it/blog/index.php/2009/10/06/snow-leopard-ssh-agent-and-an-everlasting-memory/</link>
		<comments>http://www.kill-9.it/blog/index.php/2009/10/06/snow-leopard-ssh-agent-and-an-everlasting-memory/#comments</comments>
		<pubDate>Tue, 06 Oct 2009 19:31:11 +0000</pubDate>
		<dc:creator>zen</dc:creator>
				<category><![CDATA[English]]></category>
		<category><![CDATA[Geek]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[apple]]></category>

		<guid isPermaLink="false">http://www.kill-9.it/blog/?p=423</guid>
		<description><![CDATA[If you recently switched from an older (pre 10.6) version of OS X to the latest baby, and have the old habit of using ssh to connect around, you may have noticed a singular behaviour: while the older versions always asked you for a passphrase (you have a passphrase set on your private key, right?) [...]]]></description>
			<content:encoded><![CDATA[<p>If you recently switched from an older (pre 10.6) version of OS X to the latest baby, and have the old habit of using ssh to connect around, you may have noticed a singular behaviour: while the older versions always asked you for a passphrase (<em>you <strong>have</strong> a passphrase set on your private key, right?</em>) the new OS 10.6.x does it <strong>just the first time</strong> you use it.</p>
<p>Now, no doubt it is handy and user-friendly and automagical and&#8230; but I feel it disturbing: if by chance I hand over the laptop to somebody for a quick glance at a web page, for example, she can use it to connect anywhere without my consent &#8212; ok, I&#8217;m oversimplifying, but you get the idea.</p>
<p>The mistery lies into our old friend ssh-agent: it is spawn using<br />
<code>/System/Library/LaunchAgents/org.openbsd.ssh-agent.plist</code><br />
<em>[on a single line for yout copying pleasure]</em> as a configuration file and it will cache your passphrase the first time you use ssh.<br />
Up to here it&#8217;s fine.</p>
<p>What is troublesome to me is that the default cache time is unlimited (see the man page, this is the default behaviour when it is launched without specifying a &#8220;-t&#8221; option) therefore it will never forget the passphrase until I logout &#8212; being the only user of my laptop, this does not happen often.</p>
<p>Enter the joy of xml configuration files: edit the <code>org.openbsd.ssh-agent.plist</code>, and add the option to your liking, that is change this<br />
<code><br />
&lt;array&gt;<br />
&lt;string&gt;/usr/bin/ssh-agent&lt;/string&gt;<br />
&lt;string&gt;-l&lt;/string&gt;<br />
&lt;/array&gt;<br />
</code><br />
to something like this<br />
<code><br />
&lt;array&gt;<br />
&lt;string&gt;/usr/bin/ssh-agent&lt;/string&gt;<br />
&lt;string&gt;-l&lt;/string&gt;<br />
&lt;string&gt;-t&lt;/string&gt;<br />
&lt;string&gt;120&lt;/string&gt;<br />
&lt;/array&gt;<br />
</code><br />
if a couple of minutes of &#8220;grace period&#8221; suit your usage.<br />
Then, just kill the process &#8212; it will spawn again the next time you use ssh.</p>
<p>[By the way:<br />
Dear Internet, posting code like the XML up here sucks big time.<br />
It took me more time to format the two snippets to render correctly then writing the whole post.<br />
What do you use to ease this pain?<br />
thank you.]</p>
]]></content:encoded>
			<wfw:commentRss>http://www.kill-9.it/blog/index.php/2009/10/06/snow-leopard-ssh-agent-and-an-everlasting-memory/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>At a new $HOME</title>
		<link>http://www.kill-9.it/blog/index.php/2009/09/27/at-a-new-home/</link>
		<comments>http://www.kill-9.it/blog/index.php/2009/09/27/at-a-new-home/#comments</comments>
		<pubDate>Sun, 27 Sep 2009 16:30:08 +0000</pubDate>
		<dc:creator>zen</dc:creator>
				<category><![CDATA[English]]></category>
		<category><![CDATA[Events]]></category>

		<guid isPermaLink="false">http://www.kill-9.it/blog/?p=417</guid>
		<description><![CDATA[Finally everything (hopefully) has been moved &#8212; if you read this post, the DNS you use has been updated to the new IP. Sorry it has taken a while, this type of configuration is fairly new to me and a little bit more complex than the previous one &#8212; including the upgrade of all the [...]]]></description>
			<content:encoded><![CDATA[<p>Finally everything (hopefully) has been moved &#8212; if you read this post, the DNS you use has been updated to the new IP.</p>
<p>Sorry it has taken a while, this type of configuration is fairly new to me and a little bit more complex than the previous one &#8212; including the upgrade of all the software I was using, and an operating system swap.<br />
I hope this setup will be stable for a while: it carries some of the advantages you will always hope you&#8217;ll not be using but that will be extremely useful those few times (remote reboots anyone?).</p>
<p>Last but not least, I&#8217;d like to thank both the people who have been hosting my old machine (you know who you are) and those hosting the &#8220;new&#8221; one.</p>
<p>All these people have always been extremely kind and helpful even when they had no other particular reason than friendship.<br />
I have a long list of beers that I owe them and I&#8217;m determined to pay down my debt :)</p>
]]></content:encoded>
			<wfw:commentRss>http://www.kill-9.it/blog/index.php/2009/09/27/at-a-new-home/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>National Internet filtering/censorship in Australia</title>
		<link>http://www.kill-9.it/blog/index.php/2009/04/27/national-internet-filteringcensorship-in-australia/</link>
		<comments>http://www.kill-9.it/blog/index.php/2009/04/27/national-internet-filteringcensorship-in-australia/#comments</comments>
		<pubDate>Mon, 27 Apr 2009 08:51:17 +0000</pubDate>
		<dc:creator>zen</dc:creator>
				<category><![CDATA[English]]></category>
		<category><![CDATA[links]]></category>

		<guid isPermaLink="false">http://www.kill-9.it/blog/?p=354</guid>
		<description><![CDATA[Watch and share the video above of three of the worlds leading IT security experts talking about MANDATORY national internet filtering/censorship in Australia. This is the first test run of nationwide mandatory censorship in a western democracy. It cannot be allowed to succeed or to infect other countries. There is a war being waged once [...]]]></description>
			<content:encoded><![CDATA[<p>Watch and share the <strong>video </strong>above of three of the worlds <strong>leading IT security experts </strong>talking about <strong>MANDATORY </strong>national internet filtering/censorship in <strong>Australia</strong>. This is the first test run of nationwide mandatory censorship in a western democracy. It <strong>cannot </strong>be allowed to succeed or to infect other countries. There is a <strong>war </strong>being waged once more against the open nature and collaborative power of the internet. The internet is a giant <strong>mirror </strong>held up to humankind. We should fix the <strong>root causes </strong>of our issues, rather than sweep the bits under the carpet and <strong>cripple </strong>the medium.</p>
<p>Interviewees:</p>
<ol>
<li>Dan Kaminsky, Director</li>
<li>Pete Lindstrom, Director</li>
<li>Marcus Ranum, Chief Security Officer</li>
</ol>
<p><strong><a href="http://www.nodecity.com/empower">http://www.nodecity.com/empower</a></strong></p>
]]></content:encoded>
			<wfw:commentRss>http://www.kill-9.it/blog/index.php/2009/04/27/national-internet-filteringcensorship-in-australia/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
