Wednesday, August 17, 2011

Printing and scanning with HP Deskjet 3050 on Fedora 15

I've been running Fedora 15 from a Live USB drive, primarily to test Gnome 3, but I've also been wondering how easy it would be to do all the things I need to do on my computer on Fedora 15.
Today I tried to use my printer to print and scan. It's an HP deskjet j610 wireless printer/scanner which I'd previously configured in Debian and now connects to my router. In Debian Squeeze I'd had to manually install the latest version of the HP printer software hplip, because new versions of the software come out regularly to support new printer and Squeeze came with a version in the repositories that was too old to recognise my printer. Fedora 15 has just been released, so I hoped it would come with HP software up-to-date enough to work with my printer.
I managed to print fairly easily. I went to Applications>Other>Printing and my printer was listed as a Network printer. Adding the printer prompted for the download of an HP driver, and after tinstalling the driver, I was able to print a test page.
Scanning was more of a problem. Simple Scan was installed but couldn't see my scanner. I reckoned I would need hplip again, so I installed that [from the Fedora repository, not from HP]. I found I also needed hplip-gui. However, the hplip GUI disn't automatically discover my printer, and I had to add the printer's IP address (look in the router's DHCP Client List or print the report in the wireless section of the printer menu) using Manual Discovery.


After the manual discovery, hplip recognised my printer and I could do a scan in Simple Scan. However, I also found the HP Deskjet 3050 was listed twice in Printers now, so installing and setting hplip might be the best way to set up the printer- hplip can also check ink levels which is useful.

[I did this from a Live USB- in an actual install, I had to enter username root and the root password  to add the printer.]

Tuesday, August 16, 2011

Microsoft's bad reputation(s)

A new report claims that Internet Explorer 9 is far better at blocking socially-engineered malware than other browsers. (This is malware which tricks the user into installing it rather than look for security weakness in software to install automatically.) IE9 is claimed to have a 96% protection rate, and its closest rival only a 13% protection rate.

Normally I'm quite sceptical of reports like this because they often turn out to have been sponsored by the firm that did so well, and that the test proves to have been biased in some way to favour the sponsor's product.
In this case, this doesn't seem to be true. The test is not Microsoft funded and the testing organisation seems to have gathered its own test samples. (However, Trend Micro has contested the findings.)
Microsoft has achieved this success using something it calls SmartScreen URL Reputation and Application Reputation. In other words, they are trying to blacklist every malicious URL that comes into existence, and whitelist every good download that exists on the web. Their users will be warned if a web site is malicious or if a download is known to be good.
How does Microsoft identify malicious URLs? windowsteamblog.com explains:
SmartScreen's reputation systems begin with telemetry feeds: reports from end users, data from third parties, traffic from URLs showing up in e-mail, logs from our services, etc. Some of these feeds contain billions of URLs per day. Other feeds contain URLs that a third party has certified to be known phishing sites, and still others contain little more than the fact that an URL has appeared in spam e-mail messages.
(End users? Does that mean that Microsoft checks every URL Internet Explorer users visit? Well, as Microsoft call it a cloud-based URL-reputation service, I would imagine yes. Cloud based would imply that URLs are sent to the mother ship to be categorised good or bad, or investigated if unknown.)

These feeds are checked largely by an artificial intelligence, but in some cases by human analysts.
we take every URL in every feed and use machine learning to predict the probability that the URL is abusive. At a high level, this involves examining each URL for suspicious substrings (for example, the word "pharmacy" in the URL), looking up the history of the URL–its associated domain, IPs, DNS servers, routers, subnets, ASNs–and combining these into tens of thousands of potentially predictive features for the URL. We then apply models based in machine learning, which pore over these features and separate the abusive URLs from the honest ones. Most of the time, we are confident enough in the findings of our machine learning engine that we can flag a URL as abusive based on this recommendation alone. Sometimes a URL is suspicious but we're not certain; we send many of these suspicious URLs to our analysts for final classification.
Microsoft seems to be being quite aggressive in extending this list of suspected malicious URLs:
With the right evidence, SmartScreen's reputation system will flag whole domains as abusive.

URLs and domains are concepts that let humans refer to computers. But every computer that's directly on the Internet also has a numeric code, called its IP address, that lets other computers refer to it. For example, 109.22.33.142 might be the IP address of the computer that's running the web server that's hosting the canada-pharmacy.us domain. SmartScreen's reputation system tracks these as well and will mark specific web server IP addresses as abusive. SmartScreen will also generalize to other computers "in the neighborhood" of known bad ones. For example, IP addresses are often allocated in blocks, and it's likely that the person who owns 109.22.33.142 also owns 109.22.33.143 and .144 and .145. We use knowledge about the way infrastructure blocks are allocated–into subnets, ASN (Autonomous System Number) blocks, the way message routing works, and more–to figure out what other computers the abusers own, and prevent those abusers from attacking Microsoft customers.

DNS servers are another key to SmartScreen's reputation system. DNS servers translate the URLs that you type into your browser into the IP addresses used by computers. SmartScreen assigns a lower reputation score to DNS servers that seem to know just a little bit too much about abusive domain names.
The aim is to increase the "costs that abusers incur as we dig deeper into their infrastructure".

Source: windowsteamblog.com.

But is Microsoft being too aggressive in blocking URLs, and downloads, because the Application Reputation system is also URL based?
The Sophos nakedsecurity blog contends that there is a 30-75% chance that Application Reputation warnings will be a false positive.
There's certainly evidence that Microsoft is sometimes getting it wrong:
Ever since the release of Internet Explorer 9, we (and other smaller sites) have been plagued by visitors who, when they attempt to download our stationery files, see a strong warning in Internet Explorer 9 about downloading and installing our files. This is worrisome. Even visitors who have been downloading our stationery for over a decade are writing and expressing their concern about the safety of our files.

We’ve changed nothing as far as the way our files are created. The problem lies with Microsoft and Internet Explorer 9′s obviously misnamed, SmartScreen filter.
And concern that Microsoft's aggressive attitude to abusers is damaging legitimate users:
When users who know us and have trusted us for years write us expressing their concern, what do you think users who have just discovered our site are going to do? You’re right: They’re going to leave and never come back. There is nothing we can do about it – Microsoft doesn’t care about the damage this kind of thing causes to small, niche sites like ours. They’re concerned about Microsoft and protecting what’s left of its reputation.
thundercloud.net

The Sophos nakedsecurity blog identifies the problem:
Users think, "If this were truly dangerous, it would have simply been blocked, right?" Microsoft's statistics show that in a real world attack 99% of users did delete the file, but this warning message is still a new phenomenon. It will be interesting to see how many click through over the long run.

Even worse, if up to 75% of the time you get the warning you are downloading a legitimate file, will you continue to pay attention to the warning when it really matters?
The statistics show that at the moment the warnings are causing Internet Explore 9 users to delete legitimate downloads. Internet Explorer 9 users need to be aware of this issue.

Microsoft may be saving you from yourself (to save its reputation?), but handing out some undeserved bad reputations. Don't assume that a SmartScreen download warning mean a file is malware, but don't become complacent and assume a warning is a false-positive too. Get the balance right.

Monday, August 15, 2011

Fedora 15 Live USB

I've been trying Fedora 15 (and Gnome 3) from a Live USB. I've had a Live CD since the beta but my CD is failing and read errors mean programs fail to launch even if the OS does load. I'd tried a USB installation a year or so ago when I was distro hopping, but without luck. This time the USB boot worked, with only a minor hitch.
I downloaded the Live image from Fedora,and copied it to my USB drive using these instructions. I then bumped up the USB drive in my BIOS boot options and let the computer reboot... to see this message:
isolinux.bin missing or corrupt
I'd made a small error in the device name of the USB. After copying the Live image correctly, I could boot into Fedora.
The USB boot is stable and fast, and fun to play with.
I'm tempted to install it and get used to it, but this is my "production environment" as computers you occasionally do some work on from time to time are described nowadays, and I don't want to be scrabbling to install a printer or scanner or get email working on a new system.
I haven't used Gnome 3 long enough to say anything other than I'm enjoying it so far, except, why did Fedora make the Gnome icon set the default? The Gnome icon set is dull. The icons look like they were created around the same time as Windows 95.




Saturday, August 13, 2011

Fedora 15 has Gnome 3

DesktopLinux.com has the story (although they're too dumb to realise they've posted a screenshot of Fedora 13 running Gnome 2. Epic fail, I believe the appropriate colloquial comment on the interwebs).
DesktopLinux.com also reports that Linus Torvalds doesn't like Gnome 3.
I've tried Gnome 3 on the Fedora live CD, and I would love to install Fedora and try it for longer, maybe as a dual boot with Debian Squeeze, but my CD drive is failing and keeps crashing while running live CD's or install disks.
I had to make do with this in-depth trial report from Adam Craig (actually of the Fedora 15 beta). It pretty much sums up my impressions of Gnome 3, and my feeling that people should try out Gnome 3 for a couple of weeks before condemning it. Something that's been round for a long time and we're all used to is not always the best way of doing things. After all, Gnome 2 is basically a Windows 95 paradigm.




Flash player 11 beta

Flash player 11 beta is available from Adobe. As I mentioned in a previous post, if you already have the Flash player installed on Linux, it's just a case of dropping the new file into the right directory.
The big news seems to be 64 bit support (which I don't need) but there are other new features.
I wonder if the new version will work with my web cam?

Tuesday, August 2, 2011

Ripping to be legal in UK

Millions of people regularly convert movies on DVDs and music on CDs into a format that they can move around more easily, although most do not realise that it technically illegal.

"The review pointed out that if you have a situation where 90% of your population is doing something, then it's not really a very good law," said Simon Levine, head of the intellectual property and technology group at DLA Piper.

BBC News Technology.

Saturday, July 30, 2011

Intelligence quotient and browser usage

OR: Correlation is not proof of causation.

New online study says Internet Explorer users are dumb, smarter users use Firefox, even smarter users use Chrome, but the smartest users use Opera.


Internet Explorer users confirm they are dumb by threatening a dumb lawsuit.

I think the Internet Explorer 6 result may have something to do with my previous post. Does the daily tedium of office life for civil service and other corporate users of IE6 decrease IQ with time?

(Story first seen on the Debian Forum.)

Update: The BBC has the story.
The findings have been treated with scepticism by Professor David Spiegelhalter of Cambridge University's Statistical Laboratory: "They've got IE6 users with an IQ of around eighty. That's borderline deficient, marginally able to cope with the adult world.
Just for fun, I tried searching Google for an image of an Internet Explorer user to see if it matched the description.

LOL.

Image: shoutEx.

Update 2: The story seems to have been a hoax, according to the BBC.