Search This Blog

Monday, April 20, 2020

Infosec security considerations for the Norwegian smittestopp covid19 tracking application

Norway has employed contact tracing as one of the measures in the fight against the Covid19 pandemic with its "Smittestopp" application. That application was hailed as safe to use and was even recommended by the Norwegian prime minister who prompted the public to download and use the app (link in Norwegian). While urgent situations require urgent measures and I personally consider the app a step in the right direction, there are serious technical/information security objections about the way Norway has implemented it. Some of them concern the structure of tracing applications in general, whereas others are specific to how the Simula Lab and FHI have chosen to roll it out.  I offer these opinions as an active infosec researcher and IT practitioner. I am employed by the University of Oslo and I consult for a private cybersecurity firm, but I declare openly that I have no conflict of interest with the authors that made the "Smittestopp" app, neither I express in this article the views of the University of Oslo nor Steelcyber Scientific. Opinions are my own. 

It is my assertion that people should think twice before downloading and using the "Smittestopp" application in its current form/implementation. This is especially true for people that use older Android (versions 8 and 9) mobile devices, as well as older versions of iPhones AND perform important (business critical) functions with them: e-banking, logging in  to sensitive systems, etc. 
 
Before I list the technical objections in support of my assertion, it's useful for the reader to read excellent general references on how contact tracing works in principle. The Norwegian implementation follows the same principle, yet with distinct choices that really degrade the quality of the solution. 

My first objection has to do with the accuracy of Bluetooth to estimate the proximity of other devices. This is not only a problem in the Norwegian implementation but a global issue. In particular, the Bluetooth protocol uses the Received Signal Strength Indicator (RSSI) to measure distance between devices. The principle is that the stronger the signal, the closer the devices are to each other. However, different bluetooth chipset implementations measure RSSI in slightly different ways. In addition, a particular variant of Bluetooth called 'Bluetooth Low Energy' or 'Bluetooth LE' that seems to be available in most mobile phones and is used for proximity sensing is very noisy. It's transmission frequency often interferes with other devices in the 2.4 GHz range, such as older WiFi routers, unshielded USB cables, microwave ovens. The device would do its best to extend the 'beacons' (pulses that use to advertise the presence and availability) by keeping constant time and regulating the transmission power to overcome other sources of interference. In such a frequency congested environment, a real distance of 1.5 meters could really be estimated as 2.5 meters (false negative), or a real distance of 2.5 meters could be  estimated to over 1.5 meters (false positive). The reliability of the collected data will certainly have to be software corrected by unproven heuristics. Bluetooth 5.1 will improve the data reliability, however, as it came out in the second half of 2019, we will not see it being adopted by mobile phone vendors until sometime in 2020/21. Most devices operate with the noisy and inaccurate Bluetooth LE, as I write this. 

My second objection is with the cyber security aspects of having your Bluetooth LE advertising all the time in the open important device credentials, exchanging data and all this in an extended transmission range. Amongst the various things advertised in the open by a Covid19 tracking app (the Norwegian "Smittestopp" is no exception) is a unique device identifier (or UUID). The idea here is to be able to identify you with the rest of the devices that are in proximity and have your phone say "Hi, I am here! Are you there?", without revealing your real world identity (name, phone number) to the rest of the mobile phone users. This is an essential aspect of user privacy because the theory says that an adversary can use unique identifiers of your phones (MAC address, IMEI) to get back to you. Your mobile phone provider for example, logs the IMEI address and relates IMEI addresses and phone numbers. The thing here is that even if the Simula/FHI app authors take all the precautions in the world to make a good, anonymous UUID to broadcast your presence, they cannot control other vulnerabilities that exist in the implementation protocol. These vulnerabilities exist for a wide range of mobile phone bluetooth chipsets and mobile operating systems. Various Android Bluetooth and Apple Bluetooth implementations have been found vulnerable and historically, the abuse of the Bluetooth protocol in what we call as bluejacking/bluesnarfing attacks has caused problems. Remember, Bluetooth LE can transmit sometimes up to 100 meters, check the specs of the protocol, it can certainly do that to try and overcome noisy environments by regulating transmission power. That's music to the ears of an adversary who can exploit these weaknesses to execute arbitrary code in your vulnerable mobile phone. This can seriously jeopardize anonymity and mobile device integrity.

So far, I hope I have established a good basis that justifies why bluetooth can provide unreliable data and open the door to attacks, let alone the things it will do to the battery of a mobile phone. This is not specific to the Norwegian implementation of the app. The following paragraphs will elaborate on the objections I have on the peculiar aspects of the Norwegian implementation.

First of all, I have to pick on the fact that Simula/FHI have claimed the shortness of time for not releasing open source code for the purposes of transparency and critical system review. I regret saying that this is shockingly contrary to every good research practice. When a public institution/research entity that is funded in general by taxpayer's money (even if not for the purposes of the "smittestop" project) should never go down that way. You are asking people to trust you with their personal data. We (experts and practitioners) have no way to see critical issues such as how you generate the UUID and what exactly are you doing to handle the Bluetooth inaccuracies. I will also need to criticize their statements that Open Source does not contribute to privacy. The issue here is not to contest whether closed source or open source is more suitable to safeguard privacy.  We can easily refute their arguments by stating that the Linux kernel whose source code and is open at large is used by mission/life critical systems successfully. The issue is how one can enable a process for a suitable number of experts to comment on and improve. I have no doubt that Simula and FHI have capable people. I doubt that they and the (IMHO) intransparently appointed panel of external experts have enough experties to secure systems whose scope and scale are similar to the needs of the task in such a short time. Have these people approved the app as safe and reliable and if yes, how did they miss issues pointed out here as well as many other ones?

Finally, the transparency and expert review measures do not concern only the source code but the entire infrastructure including central storage/processing activities. We are assured that all relevant measures have been taken to safeguard the data, yet no standards that these procedures/infrastructure adhere to are mentioned. I wonder why.

Thursday, March 19, 2020

Steps to increase your online/Internet usage efficiency during the coronavirus outbreak

The world is in the process of adapting to remote work/home office solutions. This is something that is going to last throughout the coronavirus outbreak and is a practice/paradigm that is going to remain long after the world tackles the covid19 pandemic. The world wide telecommunications infrastructure is as critical as the health system facilities and the transportation/supply chain. We need to keep the world going and if we are not coordinated and able to communicate/exchange information, this is not going to be good for us. 

As the world is correctly trying to flaten the curve of the covid19 cases to ease the burden on national/regional health systems, it also needs to flaten the load on the telecommunications infrastructure for the same reasons. Regional, national and international data networks are already facing traffic capacity problems. This is because a large number of the wired and wireless services (Mobile telephony, home broadband services) operate on a contention ratio principle. In simple terms, if we have for example 10000 users in an infrastructure, the data networks are designed to serve only 1000 of them simultaneously. The 1001st simultaneous user would either experience drop of service or degraded service quality (slow not well functioning connections). While the contention ratio principle is not directly applicable to more modern networks (say Fiber to Home/Premises), it applies to a large part of the world, where copper/telephone wire is still the medium of offering broadband services (ADSL/ADSL+). Consequently, even if you are in a country where it has very good capacity on broadband networks and telephony (South Korea,Japan, Scandinavian countries), your online actions still impact the infrastructure on countries that are less well equipped in their infrastructure (sadly most other countries, including Europe, the US, Africa, India, China).   

If these problems increase and outpace the efforts of Internet Service and Telecommunication providers to gradually increase (where possible) the capacity, ISPs will start rationing/prioritize the traffic and this will impact everyone in a negative. As a network and devops engineer, I already see this problem and I would like to suggest simple steps that will make a big impact on traffic numbers and will help everyone.

1. Avoid sending/forwarding those long 'funny' viral videos on social media/WhatsApp/Viber chat: If you are at home on an ADSL connection which is asymmetric, or on a mobile data plan in a densely populated area, you are using scarce valuable capacity (and possibly money, eating up your account credit). Is it really important that you send the video? Can you just send a text describing the situation or even a voice call, when you check on your folks/friends instead and talk about it? That might be preferable.

2. Use video calls only when absolutely necessary: That might sound harsh, right now that most of us are closed at home and we need human contact. If for example, you are a psychologist and you need visual on your patient, do use it by all means. However, if you want to call someone for a practical issue (shopping, arrange something) do you really have to video call? If something is short, practical and can be done by voice, please think before pressing the Video call button. Choose the voice only option instead. This is especially true for work online meetings with a large number of participants. If you only need to listen and watch a screencast from the presenter in an online meeting, why do you really need your camera on?

3. Please throttle down your torrent/P2P traffic: If you share large files via torrent from home/work connections, consider throttling down (limiting) the traffic both in terms of speed and number of torrent connections. Most P2P torrent applications allow you to do that. I know it is tempting to use the capacity of a good fiber connection with your hard earned money. However, be considerate to others and use the capacity you have in a responsible manner. 

4. Use Netflix/YouTube and other content streaming providers responsibly: Watching a movie/listening to music is an important entertainment human need. However, considering doing it in the following manner:
  • Try not to segregate your movie choices (your partner watches one, your kids another and you on your own, just because you have your own device). It's good for the parents from time to time to watch kids movies. Try to find content that you can watch altogether from one device. Streaming services account for a very large amount of the world-wide Internet traffic. Reducing that in a responsible manner will increase network capacity and server energy bills (yes, believe it or not, the energy consumption is a fact, backend servers do consume a lot of electricity).
  • If you find that you keep watching the same videos (music, other) from YouTube again and again, do consider using tools to download them and keep playing them from your local hard drive whenever you want offline. There might be of course legal issues with doing this. However, as long as you do not use your local playing for profit (unlikely that you are going to have a gig in your home for money), you should be OK. Doing that in times like this means you are a responsible person and not someone that violates copyright or tries to rob YouTube of advertisement revenue. This is my own opinion of course.  
  • Please do not stream movies while you are not watching them. 

5. Please avoid queuing on call center telephone lines when possible: How many times have you been annoyed listening to that 'elevator' music while waiting to get in touch with the service desk and you have listened to the 'Your call is important for us, all of our reps are busy, please wait while we try to help you' kind of message? Well, many call centers do offer the option of calling you back at the earliest opportunity. If they do, please exercise that option, rather than keeping the phone connection playing this for an hour. You are doing yourself and the phone infrastructure a favor. 

6. Use data compression to keep the size of your files down before sending/downloading them, improve network response times and (please) do not attach them to emails
  • Compression is not applicable for photos/images and videos and music files as these might already be compressed or may not be compressible. However, if you have plenty of large text documents (Word, Power Point, Spreadsheets, PDF documents, programming language source code) that you need to send/download from work, consider using compressions tools like these to reduce their size before a transfer. This will reduce both the burden in communication networks as well as the transfer time. 
  • For the most advanced users, compression is a technology that is used to improve interactive response on latency sensitive traffic. A great example of this is the SSH compression option. When this is used in conjunction with X forwarding to gain access to remote desktop environments, it improves both bandwidth consumption as well as the response time of remote desktop environments. 
  • Finally, compressed or uncompressed files, even if it is within the few megabytes size limit that mail servers accept, please avoid attaching large files on emails. This overloads mail servers and as email is critical for many business functions, I recommend using specific file sharing services instead of email attachments. Examples of services that offer file sharing functionality are given here.  
Stay safe and use the Internet efficiently and in a responsible manner!

Sunday, December 2, 2018

First sysadmin/devops impression on RHEL 8 (article 1 -- initial impressions and installation overview )

If you are a Linux techie and fan of the RedHat ecosystem, you might have received word that the beta version of RHEL 8 is out. Years ago, I did a popular cover story for RHEL 7. It seems natural that I should continue the tradition and do the same with RHEL 8, even as it is still being polished. Chances are that by the time the final GA/production release is out, certain performance and versioning bits might be slightly different, so you are warned that this blog post will change, to reflect the expected changes.

Let's start with a visual which is really the first thing you are going to see if you start the graphical target, which RedHat now calls the 'Workstation' environment group (more on that later, when I describe the installation bits). I bet it will look familiar to you (excluding the wallpaper) especially if you are a Fedora 28/29 user.



Yes, it is GNOME 3.28, in particular version 3.28.2, the same as Fedora 28. No surprises there as the Fedora project is used as the testbed for things that will eventually end up in the RHEL release. Wayland is at play by default here, although breath easily, as you can keep X.Org with your binary NVIDIA drivers and your multi-GPU setup (that will not work with Wayland, this is not a RHEL 8 thing).

Other important component versions that mark the RHEL 8 beta release are:
  • the Linux 4.18 kernel, 4.18.0-32.el8 in particular. This is a big and welcome step considering that RHEL 7 is based around the 3.10 kernel, which is really outdated in many respects (the latest at the time of writing was3.10.0-957.1.3.el7). As I write this, both active Fedora versions (28 and 29) have moved to the 4.19 kernel, but it seems that RHEL 8 has touch base with the 4.18 version and is likely to remain with that kernel. System stability and a more conservative environment when it comes to the backporting features and fixes (such as the Spectre and Meltdown patches that have substantial negative performance impact on the 4.20 kernel).
  • The default gcc version is now 8.2.1 20180905, in line with the active Fedora distros. Compare that to RHEL 7's 4.8.5 20150623 also showing its date. Just so that I am not misunderstood, if you run RHEL 7, you could install more modern compilers by using the Redhat's software collection repos (rhel-server-rhscl-7-rpms, the devtoolset-6* and devtoolset-7* yum packages). I emphasize the word *default* here, which means what comes with the basic installation and the simplest of entitlements. 4.8.5 is really out of date, it would make sense if Redhat makes an effort to set the default one to 4.9.4 for RHEL 7.
  • Pythonistas should feel right at home, but they should note that only Python3 is installed by default, version 3.6.6 in particular. Python developers need to explicitly install the available python2 packages. Python 2.7.15-15 is there, but with limited support. Again, that's not Redhat's decision as Python 2 is reaching EOL by the end of 2019. The sooner you migrate your apps to Python3 the better, with or without RHEL 8.

  • Perl fans should find a system wide version of 5.26.2 on RHEL 8. In comparison, RHEL 7 has Perl version 5.16.3. IMHO, if you run something production grade with Perl, you should at least be on 5.24.x these days to get the best performance and functionality. 
  • What you used to do with yum can now be done with dnf. That should not be news to you, especially if you have been following the Fedora releases. The introduction of the dnf tool has to do with important changes in the way software packages are tagged, installed and used (keep reading).

A few words about installing RHEL 8 now, as there are some notable changes there. RHEL 8 seems to organize software content by means of using two software repositories:
  • The BaseOS repo: This includes RPM based packages for the core functionality of the operating system that can be searched, installed/deployed with dnf in pretty much the same way one used to do it with yum in RHEL 7. 
  • The Appstream repo: This includes utilities to run real world workloads (for example databases, web servers, runtime environments) that can be organized either as RPM packages (like in the BaseOS repo) OR as multi-versioned collections (called streams) organized in modules. Modules are RPM extensions and their streams should allow you to choose among different versions of the package.
The concept of Application Streaming should give you the ability to have a module (say X) that offers you the Y and Z versions (streams) of a webserver. If Y is the production and Z the development version of that webserver, the Appstream repo should give you the ability to install X:Y on production systems and X:Z on your development cluster, all from one repo with a single command. You cannot install both versions in parallel on a system (unless you run your webservers in containers), but you should be able to install and run a specific version at a time.

If you are thinking that someone is trying to re-invent the wheel, you are probably right. You could previously achieve the same functionality on RHEL 7 and other platforms with the Software Collections and you could also deploy things like Environment Modules to achieve the same result, albeit at a slightly higher complexity. The idea is to perform everything here from specific repos and via your package manager. Software collections require more repos and they modify your Shell environment in ways that can create complex issues. Well, I am not trying to convince you to use one or the other here. You will be the judge of what works best for you.

There will be an additional article exploring the issue of Application Streaming. For now, this article will conclude with an overview of the RHEL 8 installation. I am going to outline the steps of installing a Virtual Machine hosted guest instance. My host operating system is Fedora 28 with its stock KVM/QEMU components. I dedicated 4 vCPUs, 4 Gigs of RAM, a functioning NAT enabled virtual NIC (to ensure that I can reach Redhat's subscription management infrastructure) and about 20 Gigs of a VirtIO disk for my qcow2 image.

There are many ways to install a RHEL 8 instance and should start with Redhat's Customer portal. The one I describe here is the Anaconda graphical installer from the Binart DVD images. You will need an account and an active subscription (that you can obtain by request if you have a portal account). This will enable you to download the beta test distro in a number of ways, as shown below.



I chose to download the 8.0 Beta Binary DVD, although the KVM Guest Image would have worked equally well (I wanted a complete set on a DVD image).

After verifying the SHA-256 checksum, I immediately proceeded to install my guest image and was greeted by the first installation screen, choosing the installation language.


The main 'installation summary' screen feels very familiar to those of you that have recently installed a Fedora distro, although a couple options ('SECURITY POLICY' and 'System Purpose') seem new.


The next step was to chose and test my keyboard layouts. I chose a Nordic (Norwegian), English and Greek keyboards and they seem to work OK.


I *would* suggest that you choose to set your 'Time & Date' settings next, but this is not a good idea. This is additional feedback I would like to pass on the Redhat team. You see, if you go to the 'Time & Date' settings, you choose your time zone and attempt to turn on the Network Time Protocol (NTP) by clicking on the ON/OFF 'Network Time' button, the button will refuse to stay on the 'ON' state.


The seasoned sysadmin/developer might figure out that this is due to the fact that the NTP server was not reachable: Although I had a perfectly ready virtual NIC standing by, this was not enabled by default. The correct order is thus to jump first to the 'Network & Host Name' settings, enable the NIC and ensure you are online.


I can now navigate back to the 'Time & Date' settings and verify that NTP is on ('Network Time' button is set to 'ON'). Timing is important. I feel that turning the configured NIC on by default OR alternatively displaying some kind of error message (like 'Cannot turn Network Time on because your NIC is inactive')when the NIC is turned off would result in a smoother user experience for an Enterprise Operating System.


Moving on to the next item of interest, the 'Software Selection' settings allow you to customize what will be installed (you can always modify this post installation). The distinction between 'Server' and 'Workstation' on the Base Environment is not new. If you want something customized to combine aspects of both, your mileage may vary. I would choose either 'Server' if you do not want a graphical environment or the 'Workstation' option (this was my choice for the demo I describe here) for a GNOME graphical environment. As explained, you can always add/remove stuff after the initial installation.


The 'Installation Destination' setting offers no surprise. Here, you can choose your installation drive and possibly encrypt your partitions. Nothing new here.


What's new in RHEL 8 are the following couple of screen settings. In particular, the 'SECURITY POLICY' setting, one can choose to customize the system between two policies. These policies ensure that certain components that have to do with firewalls, audit data and other OS settings are configured in a way that adheres to strict standard rules, to maximize your security. You should always check with your resident Information Security Officer, but as a rule of thumb, if you run the system in a bank or your system is involved in processing Credit Card data, the PCI-DSS v3 Baseline policy is a good one to choose. Alternatively, you can select the OSPP protection profile for general purpose OSes.


Finally, the 'System Purpose' screen lets you categorize the Role, SLA and usage of the system. I am not clear as to how Redhat will uses these settings as part of their Support and system inventory processes, suffice to say that collecting these data can help them dedicate their resources more efficiently in a support case.


Hit the 'Begin Installation' button of the installation summary screen and while the installer is progressing, you can set the root account password and an account. Eventually, when you reboot, you should be able to see the login screen of the graphical target.

We are not done yet. The system has installed, but it has not been registered with a subscription. To do that, you will need to obtain root, ensure you have Internet access and then just type the following two commands on the shell :

subscription-manager register --username YOUR_USERNAME --password YOUR_PASSWORD

subscription-manager attach --auto

The first command will register the system to the Red Hat Subscription Management platform (you obviously need to replace YOUR_USERNAME and YOUR_PASSWORD with your own account credentials). The second command will ensure that your system will attach to the beta entitlement. When you are done, here's how it should look on the Subscription Management Portal (uuid, username and Serial Number removed):


That's it, the system is now ready for use. Stay tuned for more RHEL 8 tests and analysis!


Saturday, June 20, 2015

Ο Τσίπρας οι Μπολσεβίκοι και η Ευρωπαική Ένωση


H Γερμανία θα παίζει πάντοτε έναν καθοριστικό ρόλο στην Ευρώπη, προκαλώντας καταστροφές και μεγάλα γεγονότα. Δεν αναφέρομαι στο Β Παγκόσμιο Πόλεμο, αλλά σε τι οδήγησε σε αυτόν. Η ιστορία επαναλαμβάνεται και μερικά γεγονότα του παρελθόντος έχουν καταπληκτική ομοιότητα με σημερινές καταστάσεις.

Ένα απο αυτά τα γεγονότα, που θα έπρεπε να είναι και στο μυαλό του Έλληνα Πρωθυπουργού καθώς και των ηγετών της ΕΕ, είναι και η συνθήκη Bresk Litovsk του 1918. Δεν προσπαθώ να δώσω πολιτική ή κομματική χροιά στο θέμα, γνωρίζουν όλοι οτι ο πυρήνας του ΣΥΡΙΖΑ αποτελείται απο ακροαριστερά στοιχεία. Απλά προσπαθώ να συγκρίνω δυο γεγονότα μεγάλης σημασίας και να σκιαγραφήσω τι πρέπει να είναι στο μυαλό των ηγετών τότε και τώρα.

Η συνθήκη του Bresk-Litovsk (στα Αγγλικά) έθεσε στην ουσία την ταφόπλακα της συμμετοχής της Ρωσίας στον A' Παγκόσμιο πόλεμο. Ο Λένιν και οι Μπολσεβίκοι συνθηκολόγησαν με τις μεγάλες δυνάμεις (Γερμανία, Αυστρο-Ουγγαρία, Βουλγαρία και Τουρκία) την παράδοση της μισής Ρωσικής Αυτοκρατορικής επικράτειας στη Γερμανία. Ο Λένιν φυσικά και δεν έδωσε γη και ύδωρ χωρίς έναν καλό λόγο. Αυτή του η ενέργεια ήταν υπολογισμένη και του επέτρεψε να γατζωθεί στην εξουσία και να θεμελιώσει επαναστατικές αλλαγές. Οι Μπολσεβίκοι είχαν κερδίσει τον έλεγχο των ορυχείων και μεγάλου κλάσματος εύφορης γης της Ρωσικής επικράτειας πριν προβούν στη συνθηκολόγηση.

Οι ομοιότητες είναι πολλές με την κατάσταση στη σημερινή Ελλάδα και την ΕΕ. Ο πυρήνας του ΣΥΡΙΖΑ μιλάει για ρήξη και μη συνθηκολόγηση. Το ίδιο έλεγε και ο Λέον Τρότσκι, ο οποίος δεν ήθελε ούτε καν να ακούσει τους όρους της Γερμανίας. Στο τέλος όμως ήταν αυτός που υποχώρησε και έτσι ο Λένιν συνθηκολόγησε.

Οι Μπολσεβίκοι ήταν μια νέα δύναμη, άπειρη, όπως και ο ΣΥΡΙΖΑ. Ο Τρότσκι μετά την ουσιαστική υποχώρησή του, χρησιμοποίησε το διάλογο για τη συνθηκολόγηση σαν εφαλτήριο επαναστατικής προπαγάνδας για τους εργάτες, όπως και ο Βαρουφάκης μιλάει για ριζική αλλαγή του μοντέλου λιτότητας ώς προυπόθεση για οικονομική ανάπτυξη στην Ευρώπη (όχι μόνο στην Ελλάδα).

Υπάρχουν όμως και ουσιαστικές διαφορές ανάμεσα στο χτες και στο σήμερα. Οι διαφορές αυτές έχουν τεράστια σημασία σε μια Ευρώπη που στιγματίστηκε απο το Β' Παγκόσμιο Πόλεμο, έναν πόλεμο που άρχισε απο καθαρά οικονομικά αίτια και άφησε τα σημάδια του μέχρι και σήμερα με τις χαμηλοπληθωριστικές πολιτικές, ένα καθαρά γερμανοφοβικό προιόν.

Η Ελλάδα δεν είναι αυτοκρατορία για να δώσει γη και ύδωρ στους ισχυρούς που τη δάνεισαν. Επίσης, ο Τσίπρας δεν είναι Λένιν, όχι μόνο ιδεολογικά αλλά και στρατηγικά, απλούστατα διότι δεν έχει διαχωρήσει την εύφορη (παραγωγικοί άνθρωποι) απο την άγονη γη (άνθρωποι με ιδεολογικές εμμονές σε ξεπερασμένες πρακτικές) στην Ελλάδα. Αυτόν το διαχωρισμό δεν τον έπραξε ο Τσίπρας αλλά και οι προκάτοχοί του, για να είμαστε δίκαιοι. Δεν είναι επαναστάτης, διότι αυτό που ο πυρήνας της παράταξής του προτείνει είναι ξεπερασμένο, και ούτε καν καλώς ορισμένο. Είναι ίσως ο μόνος Έλληνας Πρωθυπουργός που είναι τραγικά μόνος, ακόμα και μέσα στην παράταξή του. Η δύναμη της εμμονής του πηγάζει όχι απο την αποφασιστικότητά του, αλλά απο την αδυναμία του να προτείνει αυτά που ο ίδιος νομίζει πως είναι η λύση, στην ίδια του την παράταξη.

Διαφορές και ευθύνες δεν υπάρχουν όμως μόνο στην Ελλάδα, αλλά και σε αυτό που αυτοί ονομάζουν ηγεσία της ΕΕ. Διότι παρόλο που η ΕΕ δε ζητά τη μισή Ελλάδα, στρουθοκαμηλίζει σε επίπεδο πολιτικής στρατηγικής, μη δεχούμενη να αποδεχθεί την αλήθεια που ακόμα και το ΔΝΤ είπε καθαρά. Το Ελληνικό χρέος όπως και η γενική εικόνα του χρέους του Ευρωπαικού Νότου ΔΕΝ αντιμετωπίζεται χωρίς μείωση χρέους (το δικαιολόγησα αυτό σε προηγούμενο άρθρο μου εδώ, στα Αγγλικά). Η λογική του να θέτεις απο τη μια μεριά ως όρο χρηματοδότησης τη συμμετοχή του ΔΝΤ και μετά να μην αποδέχεσαι αυτά που το ίδιο προτείνει είναι επιεικώς λογικά απαράδεκτη. Με η χωρίς το τραγικό λάθος των πολλαπλασιαστών που (μαζί με την αδράνεια των Ελληνικών κυβερνήσεων) επέτειναν την κρίση, τουλάχιστον το ΔΝΤ έφτασε σε ενα είδος τεχνοκρατικής ειλικρίνειας, απέναντι στο γερμανοκρατούμενο πουριτανισμό που θέλει χώρες (όχι μόνο την Ελλάδα) αδύναμες να αποπληρώσουν χρέη δυσθεώρητων μεγεθών να μένουν στο ίδιο βάσανο.

Επίσης επιεικώς απαράδεκτο είναι να κλείνεις την πόρτα σε 11 εκατομμύρια ανθρώπους, με μόνο αντίδοτο τη δημοσιονομική πειθαρχία μέσω λιτότητας, μιας και συμφέρον των Ευρωπαίων φορολογούμενων είναι να πάρουν πίσω τα χρήματά τους. Οι τεχνοκράτες των δυο πλευρών διαφωνούν για το ύψος των φόρων, τα ισοδύναμα που κλείνουν τρύπες, αλλά κατα τη γνώμη μου, αφήνουν ένα σημαντικό παράγοντα εκτός των εξισώσεών τους. Τα επίσημα στοιχεία (που πολλοί αποκρύπτουν) δείχνουν οτι απο το 2009 έως σήμερα, απο την Ελλάδα έχουν φύγει περισσότερα απο 498000 άτομα παραγωγικών ηλικιών (26-48 ετών), υψηλού μορφωτικού επιπέδου, για το εξωτερικό. Παρόμοια κατάσταση αντιμετωπίζουν η Ισπανία και η Πορτογαλία, Δεν είναι λογικά άτοπο κάποιος να διαφωνεί για το ύψος φόρων και για ισοδύναμα, όταν ο φοροδοτικός ιστός μιας χώρας αποδομείται; Σημασία έχει το πόσο ή το ποιός έχει μείνει για να πληρώσει αυτούς τους φόρους; Νοιάζεται πραγματικά η Γερμανία να πάρει πίσω τα 60 δις Ευρώ που δάνεισε, όταν γνωρίζει η ίδια το οτι η πλειοψηφία των νέων ανθρώπων της Ελλάδας έχουν μετακομίσει μόνιμα στο έδαφός της;  

Η κίνηση απεμπλοκής για μένα είναι απλή και έχει δύο μέρη, τα οποία έχουν κοστολογηθεί απο εκθέσεις γνωστές και στις δύο πλευρές

-Η ΕΕ ας θέσει έγγραφα και ενυπόγραφα έναν ορίζοντα 50ετίας με σαφή αναφορά σε μέτρα ελάφρυνσης του χρέους υπο την προυπόθεση να επιτευχθεί κλιμακούμενη ανάπτυξη και με γενναιόδωρο πακέτο απασχόλησης νέων (26-40 χρονών). Αν δε δοθούν κίνητρα να επιστρέψουν και να μείνουν νέοι άνθρωποι στην Ελλάδα, οποιαδήποτε πολιτική απομείωσης/ελάφρυνσης του χρέους θα αποτύχει.

-Η Ελληνική πλευρά βλέποντας αυτόν τον όρο στο τραπέζι να αποδεχθεί πλεονάσματα του 0.75%, με ολοκλήρωση ιδιωτικοποιήσεων εντός 5ετίας, αύξηση των ορίων ηλικίας στα 68 έτη, μείωση του δημόσιου τομέα κατα 15%, αμυντικών δαπανών κατα 20%, χωρίς αύξηση φόρων και μειώσεις συντάξεων αλλά και ρήτρα παγώματος μισθών 7ετίας.

Οι συμφωνίες γίνονται με αμοιβαίες υποχωρήσεις.  Οι συνταγές υπάρχουν, η δημοσιονομική πειθαρχία δεν είναι απαραίτητα αντιπαραγωγική λιτότητα και η ανάπτυξη έρχεται μόνο όταν νέο αίμα επιστρέφει και παραμένει στην Ελλάδα.

Sunday, February 1, 2015

Why Europe will listen to Greece and the European South


 

As of the 26th of January 2015, Greece has elected a new Government,  which seems to strike a cord with the very heart of the European administration. Many were quick to point out that the new Greek Government is an anti-European one and came into power due to the fact that Greeks voted with a sentiment of anger. This may be true for a good portion of its voters, who felt betrayed by the two older traditional political parties (New Democracy and PASOK). However, there is a certain truth behind the reason Greek voters selected SYRIZA and that has nothing to do with sentiments against Europe. It has to do simply with the fact that Europe has mistreated Greece and many Greek people felt abandoned, been unable to make a living and look after their families.

As the Greek Government vows to re-negotiate the Greek debt on a European basis inside Europe, many key European politicians dismiss this need and refuse to listen to the Greek case, despite a wider European sentiment against the European policies that dictate austerity. In this article, I will prove why the reaction of the European administration is the wrong one. I shall present numbers that show why the Greek debt is not the problem of Europe. Europe faces an existential crisis and is currently unable to convince its member states about the sustainability of the collective European debt. Greece has of course been a problematic country, with systemic corruption and tax evasion. However, the worsening of the financial indicators in Greece and other problematic Eurozone members has very little to do with these factors and can be attributed more to the application of widespread austerity practices. These practices deprive the European South of vital abilities to restructure and develop their economies. This situation is not sustainable and its solution is not related on whether Greece remains or exits the Eurozone.

For the record, I claim no political affiliation or financial interest in the way I express my opinions. I would like to remain objective, and I welcome your comments.

The Greek Debt and its comparison to other Eurozone member debts

The Greek debt is best understood in comparison to other 'problematic' European countries. Throughout the article, I use the term 'problematic' to refer to Eurozone member states that have seen substantial worsening of their financial indicators. This worsening is of course due to the over application of austerity policies, which had the completely opposite effect than the intended one.  I used the Google public data platform to fetch relevant data from Eurostat and the World Bank, in order to increase the verification of these results. 

  
Graph 1: Government debt as percent of GDP - Source Eurostat

Graph 1 shows clearly that Greece has the highest Government debt as percent of GDP. However, Graph 1 also indicates two easily verifiable facts.

The first fact is that the problem is worsening not only for Greece, but for all other countries since the beginning of the Eurocrisis (starting from 2008). Despite the austerity measures suggested by the Troika 'experts',  Spain, Italy and Portugal see their GDP debt ratios increase consistently and substantially, a sign of their worsening economies. In addition, other members of the Eurozone that are not displayed in Graph 1, have also seen notable increases of the debt/GDP ratio. A few notable examples include Ireland whose ratio jumped from 44.2% in 2008 to 124.2% in 2013 and Belgium that went from 89.2% (2008) to 102.4% in 2013. All of these countries have seen austerity measures decided by the Troika or various national governments imposing a policy dictated by Brussels.

For Greece in particular, one should note two key dates. The year 2001, when Greece started using the Euro and the year 2008, when Greece started entering the spiral of the financial crisis. Systemic corruption and tax evasion in Greece were present before these dates. However, the severe worsening of the financial indicators occurred after the year 2008 and spiraled out of control after the application of the Troika policies. A classic example of the application of too much medicine on a patient that needed it, but not in that quantity.

What did the austerity measures do for the national economies of these countries?  To answer this question, we have to come to the second fact that reveals the complete picture of what happened to Greece and to some extent the rest of the problematic European economies. Graph 1 displays a clear economic deterioration, but what exactly has caused that deterioration. There are a lot of opinions about the South of Europe tied to stereotypes of lazy people, corrupt politicians. I dismiss these theories, because lazy people exist all over the world. Corruption is systemic in many South European countries. However, corruption itself is not enough to cause this type of economic deterioration. The answer lies in what happened to the GDP of these countries for the same period of time, as displayed in Graph 2 below.

  
Graph 2: GDP reduction for the lossy Eurozone economies- Source World Bank

Graph 2 shows the notable GDP reduction in various Eurozone countries. There is an important detail that is not easily shown in Graph 2. Starting in 2008, the Greek GDP went from 350 Billion Euros to 242 Billion Euros in 2013. In five years, 30% of the GDP disappeared from the pockets of the Greek citizens. We have rarely seen such a rapid GDP reduction in the global financial history, which displays clearly the weight Greek citizens had to lift on their shoulders, as a result of the austerity. In comparison, Ireland, Portugal, Spain and Italy lost approximately 8%, 10%, 10.4% and 5% of their GDP respectively, during the same period of time. 

The ostricism of the Troika and Brussels has to do with the fact that everybody is talking about Greece, like it is the largest problem of Europe. I am afraid this is a very flawed attitude. Brussels (and Germany in particular) hide their head in the sand and avoid to see the wider picture, which consists of the the actual number of Euros owed by each one of these countries. The next graph indicates the actual amount of Euros owed by each of the problem countries, because not everyone can actually appreciate the effect of the GDP debt ratio in a common currency (unless of course you are an economist).


Graph 3: General government debt in Euros - Source Eurostat

Graph 3 shows clearly that Greece is not really the factor that could derail the Eurozone train. Italy and Spain owe collectively more than 3 Trillion Euros, a staggering amount of money that cannot be absorbed by any corrective measures. These 3 Trillion Euros exclude the extra 2 Trillion Euros of France, a large part of the European economy that is also start becoming problematic.  

Let's assume that Europe does not find an agreement with the SYRIZA government and develops the legal/procedural framework to oust Greece from the EU, in order to demonstrate what happens to the bad boys that do not keep their promises. It is true that Europe can today catch the 250 billion Euro bullet owed by Greece. However, Europe will be fooling itself. Because although it may absorb the shock waves of the comparatively small Greek debt, it will not be able to absorb the trillions of Euros owed by the rest of the stagnant national economies of the Eurozone. The reasons are simple and evident.

Graph 4: Eurozone Unemployment rate - Source Eurostat

First of all, despite a buffer of 1.1 Trillion Euros that the ECB can dedicate to kickstart the economies, Europe does not have policies, mechanisms and a clear plan to make that kind of money work, because the North and South are divided in theory, practice and culture. For more than seven years now, Eurozone officials have failed to tackle vital issues such as the unemployment issue (Graph 4), more evident in the European South. The lack of developmental capital and vision to help the  South retain young people in Greece, Spain, Italy and Portugal has led to massive migration of the productive workforce to Germany, the UK, the Scandinavia and even outside the European continent. How these countries can build a tax base to fund functioning states is a good question. As far as I know, nobody has built successful tax systems out of pensioners, students and people who have partial or no employment at all. 

As the elections in Spain are nearing and the size of the Spanish debt is much higher than the Greek one, I am sure that these data can convince even the greatest hardliners in Europe to listen to the Greek case. I am certain that the voice of reasoning in Europe will win. Greece, even battered, will eventually exist with or without the Euro (my preference is within the Euro). I am not sure that the Euro will exist without a change of policy. Greek citizens have already lost a lot (some have nothing to loose any more) and Europe should listen very carefully this time.






Tuesday, July 1, 2014

First sysadmin impressions on RHEL 7


The 10th of June 2014 was a special day for the Linux world, as Redhat released the much anticipated version 7 of its Enterprise operating system product RHEL. Code named 'Maipo' and having gone through a Beta (11/12/2013) and Release Candidate RC (23/04/2014) stage, RHEL 7 is now available (GA) and is based on Fedora 19 and the upstream kernel 3.10.

Following the blog tradition started with a 'first impression' article on RHEL 6 some years ago, I will do the same here and present a number of goodies that will keep the sysadmins/devops folks busy, in the process of deploying RHEL 7 in their production environments.

Rather than replaying in detail the excellent info of the RHEL 7 Release notes as well as the nice roadmap presentation of the 2014 RedHat Summit, I will just summarize the important changes that it brings to the daily work of sysadmin/devops teams accompanied by some hands-on videos on the concepts.

The very first thing you will notice is a 'Fedorazation' of the Graphical Installation environment. Yes, those of you that are not familiar with the new graphical Anaconda environment of the latest Fedora releases, you will discover that the old RHEL 5/6 serialized wizard menus are gone in favour of a central screen where you click to setup various aspects of the installation AND then you launch the install. You can find  a video below that demonstrates a basic RHEL 7 installation on a VM environment.


Another major change you will feel from Day 1 is the obligatory-ish interaction with systemd. Faster boot times with parallel service startup and increased manageability have their price: The days of init scripts and the 'services' command are gone-ish for RHEL. I am using the '-ish' bit because although Redhat chose to maintain the traditional concepts of runlevels for backwards compatibility (read: to prevent most non systemd friendly sysadmins to start screaming), this will certainly not be the case for the near future of RHEL 7 minor releases. Thus, now is a good time to start thinking in terms of units and targets, as opposed to init scripts and runlevels. Below you will find a video where I demonstrate the concept of interacting with systemd to start and stop services, or change the default runlevel, erhh, sorry, target of your system. Once you get used to 'systemctl', your new buddy, things will not look so bad/alien.

 

You should get used to the idea of using Linux Control Groups (cgroups). The cgroup concept is not a new one, however now is the time to get used to the new tools for administering cgroups, as the technology is one of the conceptual blocks that RHEL 7 brings in the arena of Linux Containers (see latter paragraphs). To help you, I have made a video that demonstrates how various systemd commands can be used to administer cgroups.


In the filesystem arena, you have some notable supported volume capacity expansion. In particular, XFS which is now your default filesystem (that's right, even / on an automatically partitioned install is on XFS by default) can support volumes of up to 500 Tbytes (in RHEL 6 the limit was 100 Tb). ext4 is still an option and supported in volumes no greater than 50 Tbytes (RHEL 6 had them limited to 16 Tb per volume). My advice is to really not use ext4 again on your migrated RHEL 7 systems. As I wrote four years ago in the RHEL 6 first impressions article, XFS was the way to go in terms of performance and scalability. Today, XFS is mature enough to trust for production and can be tailored to medium/large size volumes. I just do not see ext4 fitting somewhere anymore.

I have yet to produce some comparative performance figures of XFS running on the same hardware for RHEL 6 and 7. Stay tuned for this, as it takes time and effort to do some meaningful comparison.

Staying on the filesystem arena, Btrfs is offered as a tech preview on RHEL 7, but I am not happy at all with its current state (kernel  3.10.0-123.4.2.el7.x86_64 #1 SMP Thu Jun 5 21:43:43 EDT 2014). During some iozone benchmarking, btrfs broke down and that's quite disappointing. If one considers the fact that btrfs represents really the ZFS commercial Unix arena equivalent of the Linux world, even a tech preview should have been more stable. Redhat folks, I am looking forward to a more stable btrfs tech preview, please work on that task.

For those of you that are development oriented, some major version components include:

  • GNU bash, version 4.2.45(1)-release
  • gcc version 4.8.2 20140120 (Red Hat 4.8.2-16)
  • Perl  is on version 5.16.3 built for x86_64-linux-thread-multi
  • Python is on version 2.7.5

This should really update some long outdated components of RHEL 6 (especially on the gcc side of things) that were seriously hindering software development without some effort to install separate libraries, compilers, etc.

Finally, for the devops oriented folks, one of the greatest technologies that RHEL 7 is introducing is that of containers. In essence, a container is a way to package your tech apps using a lightweight environment that provides resource isolation. This cannot only seriously save some memory and CPU cycles (in comparison to hosting apps in virtualized OSes), but it can also please your developers by introducing Docker Image based containers, a technology that allows you to speed up portable application deployment. I have made a video that demonstrates the basics of using Docker (see below) and I hope this will help you orient yourselves around the technology.



Whether Docker containers will eventually replace your hypervisors is hard to say. Containers do not provide (yet) features such as redundancy and live workload migration, two business important features offered by most virtualization technologies today. Nevertheless, application serving and deployment via Docker containers is more efficient than throwing virtualized operating system images. I shall place some concrete numbers behind that claim in order to convince you to start looking at the technology.

First of all, I shall explain how I obtained those figures. I performed the tests on two identical servers ( Dell PE 1950s) with the same amount of RAM (16 Gigs), the same CPUs ( 8 cores Intel(R) Xeon(R) CPU E5345  @ 2.33GHz cores) and with identical disk drives and I/O controllers. One of these servers was running a standard KVM environment on RHEL 7. The other was running a Docker container engine on RHEL 7.

The next steps were to install:
  • An Apache server on the RHEL 7 KVM hosted VM (the served VM is on Fedora 20)
  • Docker pull and run the Fedora/Apache image from the Docker repository on the second server, to approximate the same environment as the VM on the Linux container. I also had to run the container by doing a:
     
    docker run -p 8080:80 -i -t --name=thirdcon fedora /bin/bash
         in order to give it a port on a network (testing on the local server and
         bypassing the network latency would not yield a reliable measurement)

At that point, I had two web servers running, one in a VM and one in a Docker container. I configured both Apache s to serve a simple text index.html file (no images, graphics).

I then employed the ab Apache benchmarking tool from a third independent host and for each server URL, I fired a benchmarking load with different levels of concurrency like this:

ab -c 2 -n 100000 http://serverURL/index.html
ab -c 4 -n 100000 http://serverURL/index.html
ab -c 8 -n 100000 http://serverURL/index.html

representing different numbers of concurrent requests, up to the number of cores of the VM and the container. The results are summarized in the graphs below and they are quite revealing.


The first graph shows the maximum number of concurrent requests per second achieved in each concurrency level. Docker clearly wins over KVM with just over 8000 requests per second. You should also note that the more we increase the concurrency level, the greater the difference in the result between the two technologies.

The second graph plots the time-to-completion in seconds for each benchmark. Again, Docker is faster by a margin of several seconds. That might seem small, but it really is not. A few seconds here and there, in loaded servers running larger workloads concurrently means a great deal.

This concludes the original first impression assessment of RHEL 7. I hope this contributed towards convincing you to give it a go.

That's all for now!
GM

Sunday, September 22, 2013

Επανάληψη της ιστορίας, επανάληψη των λαθών και ο Αδαμάντιος Κοραής

Κάποιοι υποστηρίζουν οτι η ιστορία επαναλαμβάνεται. Εγώ είμαι απο αυτούς που πιστεύουν οτι τα μεγάλα λάθη είναι αυτά που επαναλαμβάνονται και δημιουργούν τα ίδια μοτίβα, κάνοντας τους άλλους να νομίζουν οτι η ιστορία επαναλαμβάνεται. Αυτό είναι ίσως μια βαρυσήμαντη δήλωση και πρέπει κάπως να τεκμηριωθεί.




Στις 18 Σεπτεμβρίου του 2013, η δολοφονία του Πέτρου Φύσσα έφερε στο μυαλό τα γεγονότα του 1963. Πέρα απο τη Α. Γρηγορόπουλο (06/12/2008) και τους 4 νεκρούς της Μαρφίν το (05/05/2010), 50 χρόνια πριν, ο Γρηγόρης Λαμπράκης θα αφήσει την τελευταία του πνοή ύστερα απο δολοφονικό χτήπημα παρακρατικών οργανώσεων, οδηγώντας σε πτώση την κυβέρνηση του Κ. Καραμανλή. Δεν είναι μόνο η τραγική ομοιότητα του κινήτρου και του τρόπου με τον οποίο δολοφονήθηκαν τα δύο αυτά άτομα. Αξειοσημείωτη είναι και η ομοιότητα μεταξύ των καταστάσεων που βίωσε η Ελλάδα πέντε δεκαετίες πριν και αυτών που συμβαίνουν σήμερα. Η οικονομική αδυναμία της χώρας, η αποτυχία των παλαιών και σημερινών κυβερνήσεων να κατανείμουν ένα εισόδημα στο λαό πυροδότησε τα άκρα, με ολέθριες συνέπειες για πολλές γενιές ανθρώπων και για την ίδια την Ελλάδα. Η χούντα των συνταγματαρχών δεν είναι βέβαια απόλυτα όμοια με τον κατάπτυστο νεοναζιστικό χαρακτήρα του μορφώματος της Χρυσής Αυγής. Ούτε και με τον ακροαριστερό/αντιεξουσιαστικό χώρο που έκαψε ανθρώπους ζωντανούς (Marfin 5/5/2010) και καταστρέφει ανενόχλητος περιουσίες  Η Δημοκρατία αποκαταστάθηκε, και ο φυλακισμένος ανακριτής της υπόθεσης Λαμπράκη, Χρήστος Σατζερτάκης έγινε Πρόεδρος της το 1985. Τα βασικά και τραγικά λάθη όμως παρέμειναν και θα εξηγήσω ποια είναι αυτά τα λάθη στις επόμενες παραγράφους. Η Δικαιοσύνη καταδίκασε στελέχη της Marfin για έλλειχη κανονισμών πυρασφάλειας, δεν έκανε όμως τίποτα για αυτούς που έβαλαν τη φωτιά και σκότωσαν εργαζόμενους ανθρώπους. Ο φασισμός δεν έχει χρώμα, κόμμα, εθνικότητα. Έχει μόνο τρόπο, και είναι σαφώς ο τρόπος που κάνει το φασίστα, η βία, ο τραμπουκισμός, είτε αυτός ανήκει στον ακροδεξιό, είτε στην άλλη άκρη του φάσματος.

Ο Ουμπέρτο Έκο έγραψε το "η Μυστηριώδη Φλόγα της Βασίλισσας Λοάνα". Πέρα απο τη σαγηνευτική περιγραφή του πως λειτουργεί στην πράξη η ανθρώπινη μνήμη, περιγράφοντας την περιπέτεια ενος 60χρονου που πάσχει απο μετατραυματική αμνησία  και προσπαθεί να ξαναβρεί την ταυτότητά του, ο συγγραφέας προβάλλει μεταξύ άλλων γλαγυρότατες εικόνες της φασιστικής Ιταλίας πριν και κατά τη διάρκεια του Β Παγκοσμίου Πολέμου. Στην Ελλάδα, η Σοφία Βέμπο τραγουδούσε το κορόιδο Μουσολίνι. Απο την άλλη όμως πλευρά του νομίσματος, ο Ιωάννης Μεταξάς είπε το ιστορικό Όχι και υιοθετούσε μέρος αυτών των φασιστικών ιδεολογιών, για να επιβληθεί σε ένα περιβάλλον πολωμένο και άκρως ασταθές. Εγώ δε στέκομαι στο Χιτλερικό τύπου χαιρετισμό των μελών της ΕΟΝ. Στέκομαι σε ένα άλλο πολύ χειρότερο στοιχείο. Το διχασμό και την πόλωση, αυτό το σταθερά διαχρονικό λάθος.

Διχασμός (σχεδόν) εκατό χρόνια πριν μεταξύ φιλοβασιλικών και Βενιζελικών. Διχασμός μετά το πέρας του Β Παγκοσμίου Πολέμου μεταξύ Αριστερών και Δεξιών. Διχασμός το 1960 μεταξύ του παλατιού και της κυβέρνησης Γ. Παπανδρέου, ο οποίος μετατρέπεται σε χάος με τη χούντα (λες και η χούντα θα έρχονταν άν υπήρχε αγαστή συνεργασία μεταξύ των τότε πολιτικών, αλλά αυτά δε τα εξέταζε κανένας στο σχολείο, όταν εγώ ήμουν μαθητής. Μας έλεγαν για το Πολυτεχνείο, για την Κύπρο, για τους συνταγματάρχες και για το Γέρο της Δημοκρατίας, χωρίς όμως τα λάθη του που έδρασαν καταλυτικά στη δημιουργία του φαύλου κύκλου). Διχασμός και στη μεταπολίτευση, με τους μπλε, πράσινους, κόκκινους και τις λοιπές αποχρώσεις τους. 

Ας υποθέσουμε όμως ότι είμαι λάθος, και οτι ο διχασμός δεν είναι η αιτία επανάληψης της ιστορίας στην Ελλάδα. Απο καθαρή τύχη μετά το τραγικό συμβάν, βρέθηκα σε ένα βιβλιοπωλείο. Μπροστά στο ράφι υπήρχαν κόπιες μιας υπέροχης έκδοσης του "Επιστολές προς το Έθνος", του Αδαμάντιου Κοραή. Οι 117 σελίδες των επιστολών του πρέπει να διαβαστούν υποχρεωτικά απο κάθε σύγχρονο Έλληνα με πολιτική (όχι κομματική) συνείδηση. Είχα την ευκαιρία να το διαβάσω όλο σε μια 4ωρη πτήση. Ένιωσα μια ανατριχίλα όχι γιατί διάβαζα τα σοφά λόγια μιας απο τις μεγαλύτερες προσωπικότητες του νεοελληνικού διαφωτισμού, αλλά για το πόσο επίκαιρες είναι οι παρατηρήσεις του ακόμη και σήμερα, δείγμα της επανάληψης των τραγικών σφαλμάτων.

Γράφει λοιπόν μεταξύ άλλων ο Αδαμάντιος Κοραής αναφερόμενος "Προς τους Προεστώτας της Ελλάδος" σε μια επιστολή του με τίτλο "Ελευθέρωσις και απο τα τυραννικά πάθη", με ημερομηνία 10.1.1822:

"Οι Έλληνες έπαθαν, δια τας διχονοίας των, την δυστεχεστάτην απ' όλας τας πολιτικάς μεταβολάς, την στέρησιν της προγονικής αυτονομίας και ισονομίας, κ' εδέθηκαν εις τον ζυγόν των Ρωμαίων, όστις έμελλε να φέρη έπειτα τον βαρύτατον ζυγόν των Γραικορωμαίων αυτοκρατόρων, και τελευταίον τον οποίον σήμερον απετινάξατε ανυπόφορον ζυγόν των Τούρκων. Και της αθλίας ταύτης μεταβολής οι Κορίνθιοι μάλιστα εγεύθησαν τα πικρότερα κακά...Οι σωθέντες όμως νέοι Κορίνθιοι λησμονήσαντες, ότι δια τας διχονοίας, τας διχοστασίας και τας έριδας των γονέων των κατεστάθησαν αντ' ελευθέρων δούλοι των Ρωμαίων, τας αυτάς διχονοίας ανενέωσαν και εφύλαξαν επι τρίτην και τετάρτην γενεάν, εωσού μετά διακόσια σχεδόν έτη της πολιτικής καταστροφής των ευηγγελίσθη εις αυτούς ο απόστολος Παύλος σωτήριον άλλην θρησκευτικήν μεταβολήν, ήτις αποβάλλει πάσαν αδικίαν, και στηρίζεται, ως και πάσα νόμιμος κοσμική πολιτεία, εις την ισονομίαν...Η τόσον ολέθριος αρρώστια της διχονοίας δεν έθλιβε μόνο τους Κορινθίους, αλλ' ήτο κατά δυστυχίαν αρρωστία κοινή όλου του Ελληνικού γένους, τόσο πλέον παράδοξος, όσον οι Έλληνες εστάθησαν όλων των καλών του πολιτισμού ευρέται και πρωταίτιοι...Δια τι λοιπόν δεν ωφελήθησαν οι θαυμαστοί μας ούτοι πρόγονοι απο τα τόσα καλά, των οποίων κατεστάθησαν διδάσκαλοι εις τους άλλους;...Διότι δεν εκατάλαβαν ποτέ εις τι στέκει, και πως σώζεται η αληθινή ελευθερία. Εφλέγοντο απο τον έρωτα της ελευθερίας όλοι, αλλά πάσα μία πόλις ήθελε να δεσπόζη τας άλλας, και πας ένας πολίτης εσπούδαζε να κυριεύη τους συμπολίτας του. Η κατάρατος αυτή φιλαρχία εγέννησε την διχόνοιαν, διήγειρε τας πόλεις και τους πολίτας κατ´ αλλήλων, άναψε των εμφυλίων πολέμων την πυρκαιάν...Σπλαχνισθήτε, φίλοι αδερφοί, τους απογόνους σας, μην αφήσετ´ εις αυτούς τόσον ολέθριον κληρονομίαν αλλά παραδώσετέ των την αποκτημένη με τα αίματά σας ελευθερίαν καθαράν απο πάσα πλεονεξίαν και ανισότητα!"

Ο Αδαμάντιος Κοραής συνεχίζει σε άλλες επιστολές να τονίζει οτι τα άκρα δεν είναι ποτέ λύση, ακόμα και αν στην εξουσία υπάρχουν άνθρωποι των άκρων. Μιλάει δε για μια έννοια της ελευθερίας, αυτή που στηρίζεται στη δικαιοσύνη και την ισονομία. Γράφει στην "Προς νέον πολιτικόν Ν. Πίκολον" επιστολή του, με ημερομηνία 5.6.1822 : "Την φύσιν μας, φίλε, ν´ αλλάξωμεν δεν είμεθα κύριοι. Εις την εξουσίαν μας όμως είναι, αφού γνωρίσωμεν της φύσεώς μας την εις το εν ή εις το άλλο άκρον κλίσιν, να την ανασύρωμεν προς το μέσον, όπου μόνον ευρίσκεται η αρετή...Εις όλους τούτους, Κοραή, χρεωστείς να φανείς ένας μόνο άνθρωπος, μιας μόνης ελευθερίας, της θεμελιωμένης εις την ισοτιμίαν φίλος. Με λόγον έναν, με μια μόνον φωνήν, χρεωστείς να διδάσκης και άρχοντας και αρχομένους μια μόνην διδαχήν, την εις τους αυτούς νόμους υποταγήν. Τι έχεις να φοβηθής; Τιν περί σού κρίσιν των άλλων; Αν είναι χρηστοί πολίται, δεν θέλουν αργήσειν να συμφρονήσωσι και να συμφωνήσωσι με σε. Αν είναι του γένους των Ταρτούφων, κρίνέ τους και συ, ως τους έκρινεν ο φίλος της ευνομίας Αυτοκράτωρ. ¨Όταν άλλος ψέγη σε ή μισή, έρχου επι τα ψυχάρια αυτών, δίελθε έσω και ίδε ποίοι τινες εισίν. Όψει ότι ου δει σε σπάσθαι, ίνα τούτους τι ποτέ περί σού δοκεί.¨ Οι φοβερώτεροι τούτων είναι οι σπουδαρχίδαι και σπουδοπλουτίδαι, τους οποίους συγχωρημένον είναι να φοβάσαι μη σε κακοποιήσωσι. Αλλά τον φόβον τούτον έπρεπε να συλλάβης πριν εκδυθής εις τους αγώνας. Αφού ετόλμησες να πηδήσεις εκουσίως εις της ελευθερίας την παλαίστραν, πρέπει να παλαίσεις ως λέων και όχι ως αλώπηξ, λοιπόν πολέμει ωπλισμένος όχι με το λεγόμενον πολιτικόν, αλλά με την αχώριστον της ηθικής πολιτικήν επιστήμην."
     
Η διαχρονικότητα αυτών των κειμένων αποδεικνύει λοιπόν οτι τα λάθη είναι εκείνα που επαναλαμβάνονται, γιατί όταν σε μια κοινωνία δεν υπάρχει ισονομία και διχόνοια, λογικό είναι τα άκρα να ενισχύονται. Ας δούμε λοιπόν άν ο Πρωθυπουργός θα πολεμήσει τον τραμπουκοφασισμό σαν λιοντάρι ή σαν αλεπού. Εαν δε σταθεί σαν λιοντάρι απέναντι στο μόρφωμα του φασισμού, θα είναι ο δεύτερος απόφοιτος του Άμχερστ που θα πάει στο σπίτι του. Εύχομαι τρίτος να μην υπάρξει.


Monday, August 12, 2013

The surveillance mass hysteria, the right to privacy and professionalism

I had the intention to make a commentary about the Snowden case and the mass anti-surveillance hysteria it provoked. I will defend the use of the term 'hysteria' in latter paragraphs. But then I realized that the consequences of Edward Snowden's case were far greater than I previously thought. This is not in terms of the diplomatic and geopolitical consequences of his whistle blowing acts. Government surveillance has sustained the Assange/Wikileaks blow and it will continue to do so (thankfully, because I do not agree with the acts of Snowden and Assange, but keep reading, I assure you I do not do Government propaganda here). In contrast, the thing I feared the most, was that this Snowden induced hysteria would eventually turn against hard working US businesses in the area of privacy protection. 

Unfortunately, I was proven right. A few hours prior starting the composition of these lines, I read sad news that announced the closure of Lavabit, one of the most reliable encrypted email providers. It turns out that Snowden had used Lavabit's service and this created some sort of friction, pressure and eventually service collapse of the provider. In an attempt to gauge public opinion, I opened my Twitter account. One of the comments from an individual was "I will never entrust any of my data to a US business!". Of course, surveillance is not only a US phenomenon. In Europe, Asia, Australia, the Middle East, the games of cat and mouse between those who want to safeguard their privacy and those who want to break it is on. So, it is safe to assume that a business is the worst possible place to entrust your digital assets? I am raising this question, because Lavabit is not the only company that is in this sort of business.

Now that I raised the question, I want to step back a bit. I want you to picture Edward Snowden, an IT person that ended up somehow working for the tech/contractor sector that surrounds the NSA. Did you really think that when he joined the ranks, he had no idea of what was going on in there? Do you really need a "hero" like Snowden to tell you that Governments have surveillance capability? Really?

I have started working on the Internet in 1998, and I worked on core TCP/IP protocols and Ethernet device drivers, which is what drives today most of the corporate networks. Today, I am tasked with securing some digital assets for various scientific communities, and I want to believe that I have a healthy dosage of paranoia in relation to whether my infrastructure is secure or not.

The assumption that the guy who sits on NSA/GCHQ has the will to listen to your personal communications one morning and can under all conditions is wrong and unhealthy. If you are an intelligence analyst, you are looking for needles in a haystack and you have specific problems to solve. Yes, there is data mining. Yes, there are ways to tap into your personal communications. Yes, you could be a bystander and accidentally tapped into in an attempt to locate someone, but this is less probable than you being the victim of a phishing/zero day exploit of some bandit that wants your machine for a botnet, or is after your bank account, etc.

Yes, we all have the right to privacy and trusting a communication system to deliver a message from person A to person B is important.  Read Simon Singh's  "The Code Book" and  you will see that most European Governments were operating surveillance rooms from the very early history and form of human communication. He writes about the so called "black rooms", mentioning some of the earlier examples of such a service: the Geheime Kabinetskanzlei, the secret Austrian Service, operated such a room in Vienna on the 18th century. The personnel would open certain letters of interest with care, leaving very few traces on the open envelope, they would make an exact and even translated/decoded copy of the letter, they would reseal the envelope and let the letter reach its final destination. This is one of the earliest form of industrial grade Government surveillance and a very good analogue of what is happening in our age.

Am I trying to increase your paranoia? To the contrary. Do you really think that a black room had the capacity to open/decode/translate all letters? The obvious answer is no. Cryptographers and skilled envelope openers/resealers were finite and there was a very careful targeting/sampling of senders and recipients. Is the whole process easier on the 21st Century? Well, yes and no. It is an interesting question.

The era of computers, the falling CPU/GPU/MIC hardware costs, the increased connectivity of social media and the mobile wireless technologies, the plethora of web scraping techniques and Deep Packet Inspection (DPI) software solutions have made it easier to perform surveillance on a grander scale than the era of the good old post office. However, we are far from the era of pressing a few buttons, having an email address and knowing everything about the life of every individual, as Snowden claims.

One of the greatest problems for the era of modern surveillance is "noise". In the context of surveillance data mining, "noise" is a collective term for a range of factors that prevent a mining algorithm for achieving its target (to get its info or estimate whether something is true or false: for example, whether a particular individual is related to a group of people or not. These factors include:
  • a)Fuzzy or an incredibly large amount of info to mine, well beyond the capabilities of the data mining algorithm
  • b)Inability of the mining/surveillance techniques to keep up with the amounts of information transmitted over a digital network.
  • c)Susceptibility of the mining algorithm to false negatives/positives due to design inadequacies.
With respect to factor a) above, the Internet might be a great repository of information for data mining, however it is also "polluted" with redundant, false and distributed/incomplete information. The term information overload or information pollution should not only refer to the cognitive abilities of an individual to absorb, comprehend and act on the amount of information mined from the web. It also has a negative effect on surveillance data mining algorithms.

Lots of information means an ever increasing rate of information transfer (b). Modern data networking speeds increase all the time, especially large data backbones where we have speeds of even 100 Gigabits/sec at the time of writing. If one combines this fact with the use of encryption, as Bruce Schneier points out in this paper/article, it becomes evident that DPI techniques are falling behind. You will be surprised how difficult it is to silently decrypt traffic of an SSH tunnel with moderately adequate encryption. You can setup something like this between two cloud hosts, even amongst different cloud providers and protect your voice, ephemeral chat communication and everything else that is important to you.  No man in the middle will have an easy way into what your network packets really contain. This techniques have actually been employed successfully by knowledgeable individuals to bypass Government censorship and surveillance firewalls. Egypt, Iran and China are some notable examples.

For factor c), I am sure you must have had an example of false negative or positive in your anti-virus software. If not, you are an extremely lucky person. Are you a sysadmin of an IDS/IPS/firewall system? You should also be very lucky if you never dealt with a signature/rule that let bad traffic in or kept good/legitimate traffic out. It works the same way with surveillance mining algorithms. They are not perfect and they suffer from the same problems: wrong things are flagged up as dangerous and many dangerous things are not flagged at all. Associate Professor Gehan Gunasekara suggested that the public should try and test this susceptibility of the surveillance mining algorithms by polluting their Bayasian analysis modules and cause them to flood them with false negatives. I do not suggest that you do that, but I mention this as a sign of proof that the susceptibility is there and with or without disobedience, the problems exists.

Hopefully, you are convinced now that the claim of the "hero" Snowden is not exactly accurate and that if you take reasonable precautions and trust high stakes information to professionals, you can have a company protecting your digital assets. Not everything is point and click for a Government surveillance analyst and unless you do something really sinister, you can go and do your daily business without feeling threatened or be hysterical.

I would like to close with a statement which is even more serious than the previous ones. The closure of Lavabit is wrong. Innovative businesses that protect the privacy of individuals that have a non threatening interest to protect their private/business information is a core value of the information society. The US administration needs to understand that if they kill the trust of the public to privacy protecting businesses, they are going to strike a big blow at the heart of their digital economy. Whatever the issue was with Lavabit, it can be solved by

i)strengthening the admission requirements to such services and
ii)dealing more effectively within their own infrastructures with the problem of rogue insiders. Technologies to aid that process do exist!

After all, a stark contrast between Ladar Lavison and Edward Snowden is that the first complied with the law and offered a service to the people. Edward Snowden also offered a service to the people, but that is not his whistle blowing act. That was his personal choice. That's exactly why the first one is a professional and the second is a rogue insider. That is also why I would entrust my email data to Lavabit.

Saturday, June 15, 2013

Τι θα έλεγε (είπε) ο Μάνος Χατζιδάκις για το κλείσιμο της ΕΡΤ



Σήμερα συμπληρώνονται 19 χρόνια απο το θάνατο του Μάνου Χατζιδάκι και το Τρίτο Πρόγραμμα δεν υπάρχει. Για να πούμε και "του στραβού το δίκιο" (συγγνώμη για την καυστικότητά μου, ξέρετε ποιον εννοώ, αλλά το εννοώ μεταφορικά), τα κόκκαλα του Μάνου θα έτριζαν με αυτά που έβλεπε να γίνονται μέσα στην ΕΡΤ. 

Ο ίδιος άλλωστε τα είχε πει δέκα χρόνια πριν το θάνατό του, το 1984. Τις απόψεις αυτές τις είχα συνοψίσει εδώ σε ένα άρθρο μου για την 36η επέτειο της αποκατάστασης της Δημοκρατίας. Ανατρέψτε σε αυτές και θα δείτε έναν Μάνο απογοητευμένο, αλλά διορατικό, κυνικό αλλά ρεαλιστή.

Μέσα στην αναμπουμπούλα, τη συγκίνηση και αυθόρμητη συμπαράσταση του κόσμου στην ΕΡΤ για το αντιδημοκρατικό κλείσιμό της (σε καμια πολιτισμένη χώρα δεν υπήρξε ποτέ απόφαση να κλείσει η δημόσια ραδιοτηλεόραση σε λιγότερο απο 24 ώρες, χωρίς καν να συζητηθεί το θέμα απο τους πολιτικούς της δημόσια) πρέπει κάποιος να αντιπαραθέσει το γεγονός ότι η ΕΡΤ δεν λειτουργούσε όπως έπρεπε. Μπορεί να μην ήταν ελλειματική, αλλά ο διορισμός δικών μας παιδιών, η υπερκοστολόγιση παραγωγών σε βάρος του Έλληνα φορολογούμενου, ο άκρατος κομματικός συνδικαλισμός (ειδικά στο Δημοσιογραφικό τομέα) ήταν γεγονός και εξίσου αντιδημοκρατικός με το κλείσιμό της.

Τα κόκκαλα του Μάνου όμως θα έτριζαν και με τον άκρατο φασισμό, με τον τρόπο που επέλεξε ο Πρωθυπουργός Αντώνης Σαμαράς να κλείσει/αναδιοργανώσει/επανιδρύσει (πείτε το όπως θέλετε) την ΕΡΤ. Η αποστολή ΜΑΤ σε πομπούς για να κλείσουν το σήμα, ο προπυλακισμός πολιτών και δημοσιογράφων για να βγούν απο τα κτίρια και τις εγκαταστάσεις της ΕΡΤ, η μη ύπαρξη διαβούλευσης επι του θέματος στη Βουλή των Ελλήνων είναι μια λογική τριάδα επιχειρημάτων που δικαιολογεί το χαρακτηρισμό  "άκρατος φασισμός". Έστω και εαν αυτός ο φασισμός αυτή τη στιγμή δεν αντιπαραβάλλεται με τον επίσης άκρατο, αντιπαραγωγικό και αντιδημοκρατικό τρόπο λειτουργίας των κομματικών συνδικάτων της ΕΡΤ.

Υπάρχει όμως και κάτι άλλο κατά του Πρωθυπουργού, το οποίο δημιουργεί λύπη και είναι περίτρανη απόδειξη της αποτυχίας του να ελέγξει μια κατάσταση όπως η ΕΡΤ, διότι υπάρχουν πολλές ΕΡΤ στο δημόσιο τομέα στην Ελλάδα. Είναι το πρόσωπο του ολοκληρωτισμού, της κοινωνικής στάμπας, της λογικής του ότι μαζί με τα ξερά πρέπει να καίγονται και τα χλωρά. Όλοι στην ΕΡΤ είναι χαραμοφάηδες; Δεν επέδειξε η ΕΡΤ, έστω και με τον καρπό κλάσματος των εργαζομένων της έναν πολιτισμό, ένα αρχείο παρακαταθήκη για τη χώρα; Εγώ, μέχρι σήμερα, ΔΕΝ έχω ακούσει καλύτερο ραδιόφωνο απο το Τρίτο. 


Η αποφυγή ενος τέτοιου ολοκληρωτισμού είναι μέρος της καρδιάς ενός Δημοκρατικού πολιτεύματος. Είναι αυτή που επιβραβεύει τους ευσυνείδητους επαγγελματίες και χαντακώνει τους ασυνείδητους πραγματικούς χαραμοφάηδες που δεν έχουν θέση σε ένα δημόσιο αξίωμα. Απόδειξη για τους πρώτους αποτελούν αυτά που είδαμε και βλέπουμε, όσο η ΕΡΤ είναι κλειστή. Με τους μουσικούς των συνόλων να παίζουν κλαίγοντας, τους μηχανικούς και τεχνικούς της ΕΡΤ που πασχίζουν να συνεχίσουν με τα 1000 Ευρώ το μήνα και το οικογενειακά βάρη απο πίσω τους, το έργο της ΕΡΤ.

 Για να επαναλάβω δυο λόγια απο το Μάνο κλείνοντας
- Για τη δημόσια διοίκηση είπε "Είναι χρόνια η αρρώστια μας και θα υπάρξει για χρόνια. Δεν ξέρω τι είναι εκείνο που θα τα αλλάξει τα πράγματα και θα τα προχωρήσει."
-Για τη Ελλάδα είπε "Η Ευρωπαική ενότητα τι νομίζετε οτι είναι; Θα γίνουμε μια επαρχία στην οποία θα μας διοικεί η Ευρώπη. Και θα χουμε μια ψευδαίσθηση οτι συνδιοικούμεθα στην Ευρώπη. Λοιπόν αυτή δεν είναι μια σκλαβία;"..."Υπάρχει καμιά εγγύηση σωστής ανάπτυξης στον τόπο αυτό; Ποτέ!...Περι τουρκοκρατίας λοιπόν, ασφαλώς θα είναι μια μορφή της Ευρωπαικής μας θητείας, που βέβαια δε θα μπορέσουμε ποτέ να απαλλαγούμε ούτε να ελευθερωθούμε, διότι θα είναι επιλογή μας, διότι επι τουρκοκρατίας έγινε υποταγή μας. Αυτή είναι η διαφορά!"

Πόσο δίκιο είχε αυτός ο άνθρωπος 29 χρόνια πριν τη σημερινή μέρα! Τελεία και παύλα.