<?xml version="1.0"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">

<channel>
	<title>Planet Grep</title>
	<link>http://planet.grep.be</link>
	<language>en</language>
	<description>Planet Grep - http://planet.grep.be</description>

<item>
	<title>Lionel Dricot: Simplifiez vos services pour payer moins</title>
	<guid>http://ploum.net/?p=2874</guid>
	<link>http://ploum.net/post/simplifiez-vos-services-pour-payer-moins</link>
	<description>&lt;img src=&quot;http://planet.grep.be/heads/ploum100&quot; alt=&quot;&quot; align=&quot;right&quot; style=&quot;float: right;&quot;&gt;&lt;p&gt;&lt;em&gt;Avertissement: ce billet contient des recommandations pour des services commerciaux. Ces recommandations me procurent un intérêt financier via un système de parrainage. Cet intéressement, détaillé dans le billet, affecte forcément mon objectivité. Ceci dit, n’hésitez pas à partager les autres services qui vous facilitent la vie.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;Il y a un peu moins d’un an, j’ai décidé de revoir en profondeur les services que j’utilise quotidiennement. Il existe généralement deux approches : rester chez ceux qu’on connait ou faire la chasse au moins chers grâce à de savants calculs.&lt;/p&gt;
&lt;p&gt;J’ai personnellement suivi une troisième approche : la chasse à la simplification. Plutôt que le moins cher, j’ai cherché le plus clair. Mes critères étaient les suivants :&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Interaction entièrement par Internet. Tout besoin de se rendre quelque part ou d’interagir par courrier papier est une perte de temps.&lt;/li&gt;
&lt;li&gt;Interface internet moderne et efficace. Ni flash, ni pub ni servlets abscons.&lt;/li&gt;
&lt;li&gt;Tarifs clairs. Je sais combien je vais payer sans avoir à me poser de questions ou de voir des 3,47€ qui partent tous les mois.&lt;/li&gt;
&lt;li&gt;Facturation uniquement par Internet. Un système abscons où je dois aller télécharger un PDF dans les 15 jours pour effectuer un virement n’est pas de la facturation par Internet.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Le résultat à été au dessus de mes espérances : non seulement je me suis grandement simplifié la vie mais j’ai également coupé complètement dans ces dépenses « invisibles ». La complexité est en fait un masque pour des dizaines de minuscules coûts cachés. Un 3,47€ par mois qui semble insignifiant revient tout de même à 41€ par an.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;La banque&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Premier poste qui coûte cher de manière invisible, la banque. De plus, les banques traditionnelles se font un malin plaisir à exiger que vous passiez au guichet à 2km de chez vous pour signer un papier inutile, pendant les heures d’ouvertures et avec une file de 25 minutes.&lt;/p&gt;
&lt;p&gt;Mon choix s’est porté sur &lt;a href=&quot;https://www.keytradebank.com&quot;&gt;Keytrade&lt;/a&gt; et j’en suis extrêmement satisfait.&lt;/p&gt;
&lt;p align=&quot;center&quot;&gt;&lt;img alt=&quot;&quot; src=&quot;http://ploum.net/images/logokeytrade.jpg&quot; /&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Le compte est gratuit. Aucun frais caché ou régulier.&lt;/li&gt;
&lt;li&gt;Interface web moderne, efficace. Module d’authentification simple et efficace.&lt;/li&gt;
&lt;li&gt;Pas d’impression de courrier de banque, même en PDF mais une interface d’historique du compte avec recherche.&lt;/li&gt;
&lt;li&gt;La carte de banque est gratuite en Belgique (les autres résidents UE peuvent également ouvrir un compte mais la carte est payante). Et oui, elle permet de retirer de l’argent partout.&lt;/li&gt;
&lt;li&gt;Support ultra réactif par mail, Skype ou téléphone.&lt;/li&gt;
&lt;li&gt;Interface de trading intégrée, pour ceux qui veulent découvrir la bourse (oui, j’ai essayé et c’est ce qui m’a donné l’idée d’écrire &lt;a href=&quot;http://ploum.net/post/le-probleme-avec-largent&quot; title=&quot;Le problème avec l’argent&quot;&gt;ce billet sur l’argent&lt;/a&gt;).&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Par contre, il manque une application Android de gestion de compte. Et j’espère y voir un jour la possibilité d’alimenter son compte en &lt;a href=&quot;http://ploum.net/post/bitcoin-pour-les-nuls&quot; title=&quot;Bitcoin pour les nuls&quot;&gt;bitcoins&lt;/a&gt;. La carte VISA coûte 25€ par an ce qui est un tarif normal mais, une fois encore, plus clair que 2,40€ par mois.&lt;/p&gt;
&lt;p&gt;Mon avantage : si vous mentionnez mon code parrain MM9586629499 sur &lt;a href=&quot;https://www.keytradebank.com/secure/p/openaccount/index.html&quot;&gt;le formulaire d’inscription&lt;/a&gt;, nous recevrons 30€ chacun en guise de prime de bienvenue. N’oubliez donc pas le code parrain. Et oui, vous pouvez ouvrir le compte, prendre les 30€ et fermer le compte.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;La téléphonie mobile&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Ici, je tentais de fuir les forfaits de type payer moins cher les nuits de pleine lune si vous appelez un cousin au second degré pendant un nombre de minutes impair. Je voulais un tarif simple clair. Et un site clair.&lt;/p&gt;
&lt;p&gt;Depuis que je suis passé à &lt;a href=&quot;http://mobilevikings.com/bel/fr/referral/kyUIjasodkdEAvMtxTvFomiKFZFBSUmV/&quot;&gt;Mobile Vikings&lt;/a&gt;, la question que je me pose : comment faisais-je avant ? Je paierais plus cher pour avoir un tel service.&lt;/p&gt;
&lt;p align=&quot;center&quot;&gt;&lt;img alt=&quot;&quot; src=&quot;http://ploum.net/images/logomobilevikings.jpg&quot; /&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Un système de &lt;a href=&quot;http://mobilevikings.com/bel/fr/referral/kyUIjasodkdEAvMtxTvFomiKFZFBSUmV/&quot;&gt;forfaits très clairs&lt;/a&gt; : chaque mois on paye une somme, au choix, entre 10€ et 60€. On peut changer cette somme tous les mois et le montant non utilisé peut-être reporté de mois en mois (et, autant vous dire, de mon côté je thésaurise pas mal). Je conseille le forfait à 15€ si vous utilisez pas mal de données.&lt;/li&gt;
&lt;li&gt;Des SMS gratuits et, surtout, 1h gratuite &lt;strong&gt;par jour&lt;/strong&gt; entre Vikings. En gros, si les personnes de votre entourage sont chez MV, cela ne vous coûte plus rien.&lt;/li&gt;
&lt;li&gt;Un site web ultra clair et moderne où l’on peut voir, en direct, son journal d’appels avec le coût associé.&lt;/li&gt;
&lt;li&gt;Un &lt;a href=&quot;https://twitter.com/mobilevikingsBE&quot;&gt;compte Twitter&lt;/a&gt; très actif qui informe immédiatement des problèmes sur le réseau et qui répond aux questions.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Par contre, Mobile Vikings utilise le réseau Base dont la couverture 3G n’est pas optimale. On se retrouve encore souvent en Edge.&lt;/p&gt;
&lt;p&gt;Mon avantage : si &lt;a href=&quot;http://mobilevikings.com/bel/fr/referral/kyUIjasodkdEAvMtxTvFomiKFZFBSUmV/&quot;&gt;vous vous inscrivez avec ce lien&lt;/a&gt; (ou en mentionnant mon numéro de téléphone), je reçois une recharge gratuite d’une valeur de votre première recharge. Généralement celle de 15€ (que je vous conseille).&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Mutuelle&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Ma rapide investigation des mutuelles ne m’a pas convaincu de changer. Client chez &lt;a href=&quot;https://www.partenamut.be/home&quot;&gt;Partenamut&lt;/a&gt;, j’y suis resté.&lt;/p&gt;
&lt;p align=&quot;center&quot;&gt;&lt;img alt=&quot;&quot; src=&quot;http://ploum.net/images/logopartenamut.jpg&quot; /&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Excepté l’envoi des reçus de médecin, tout peut se faire par Internet.&lt;/li&gt;
&lt;li&gt;Si le site web n’est pas la panacée, il est utilisable sans prise de tête.&lt;/li&gt;
&lt;li&gt;Support par mail et par téléphone très compétent et patient.&lt;/li&gt;
&lt;li&gt;Avantages tout à fait compétitifs avec ce que j’ai vu des autres mutuelles.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Par contre, les tarifs restent un peu obscurs.&lt;/p&gt;
&lt;p&gt;Mon avantage : aucun.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Conclusion&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Changer un de ces services prend du temps et un effort non négligeable. C’est pourquoi les services « historiques » nous noient sous la complexité. Prendre le temps de sortir et de trouver des fournisseurs simples et clairs est pourtant un investissement on ne peut plus rentable. Certainement en termes de sous mais surtout en qualité de vie. Une petite bouffé d’oxygène, un tracas en moins.&lt;/p&gt;
&lt;p&gt;Malgré tous mes efforts, je n’ai pas réussi à découvrir un fournisseur d’accès internet simple et clair. &lt;a href=&quot;http://www.edpnet.be/fr/prive&quot;&gt;Edpnet&lt;/a&gt; s’en rapproche mais leur site est un magma incompréhensible. Les offres de tous les fournisseurs sont toujours plein de chichis. Peut-être que, comme en Suède, le Parti Pirate devrait créer un FAI sans le moindre support par téléphone, avec une offre claire et précise. On peut rêver.&lt;/p&gt;
&lt;p&gt;Et vous, quels sont les services que vous conseillez pour leur simplicité et non pour leurs tarifs ?&lt;/p&gt;
 &lt;p&gt;&lt;a href=&quot;http://ploum.net/?flattrss_redirect&amp;amp;id=2874&amp;amp;md5=bdbff828b062753a19463209e8d6424b&quot; target=&quot;_blank&quot; title=&quot;Flattr&quot;&gt;&lt;img alt=&quot;flattr this!&quot; src=&quot;http://ploum.net/wp-content/plugins/flattr/img/flattr-badge-large.png&quot; /&gt;&lt;/a&gt;&lt;/p&gt;</description>
	<pubDate>Tue, 21 May 2013 10:45:37 +0000</pubDate>
</item>
<item>
	<title>Wouter Verhelst: Whee</title>
	<guid>http://grep.be/blog/en/life/tennis/cantincrode_2013</guid>
	<link>http://grep.be/blog/en/life/tennis/cantincrode_2013</link>
	<description>&lt;img src=&quot;http://planet.grep.be/heads/wouter_verhelst&quot; alt=&quot;&quot; align=&quot;right&quot; style=&quot;float: right;&quot;&gt;&lt;p&gt;Today, I played at TC Cantincrode in Mortsel, Belgium, in the first
round. This is the first year I'm playing tennis competitively, so I
was expecting to lose by a pretty wide margin. Now while I didn't win,
the margin wasn't as wide as I'd expected; 6/4 - 6/3 isn't too bad for
the non-ranked beginner that I am. For comparison: I lost my previous
match with 6/2 - 6/0, and I was not unhappy about that.&lt;/p&gt;
&lt;p&gt;Part of this was due to my opponent (by his own admission) not
playing his best; but still, I'm quite happy about my result here.&lt;/p&gt;
&lt;p&gt;My next match probably won't be &lt;em&gt;as&lt;/em&gt; good. Oh well.&lt;/p&gt;</description>
	<pubDate>Sun, 19 May 2013 19:29:00 +0000</pubDate>
</item>
<item>
	<title>Frank Goossens: Does Facebook want its chat back?</title>
	<guid>http://blog.futtta.be/?p=8839</guid>
	<link>http://feedproxy.google.com/~r/futtta/~3/76Tv-0fCF8k/</link>
	<description>&lt;p&gt;&lt;a href=&quot;http://blog.futtta.be/2013/05/19/does-facebook-want-its-chat-back/thunderbird_facebook_notauthorized/&quot; rel=&quot;attachment wp-att-8841&quot;&gt;&lt;img alt=&quot;thunderbird facebook not authorized&quot; class=&quot;alignright size-thumbnail wp-image-8841&quot; height=&quot;150&quot; src=&quot;http://blog-cdn.futtta.be/wp-content/uploads/2013/05/thunderbird_facebook_notauthorized-150x150.png&quot; width=&quot;150&quot; /&gt;&lt;/a&gt;I’m pretty pissed. A couple of months ago &lt;a href=&quot;https://www.facebook.com/sitetour/chat.php&quot; title=&quot;Facebook explains how to connect, but do they really want you to do that?&quot;&gt;I configured Thunderbird to connect to Facebook’s XMPP-powered chat&lt;/a&gt;. I did get logged out sometimes, with &lt;a href=&quot;http://blog.futtta.be/2012/11/15/now-you-can-have-my-facebook-password-as-well/&quot; title=&quot;previous post about Facebook Chat going crazy&quot;&gt;mails from Facebook saying someone tried to access my account from an unknown location&lt;/a&gt;. Given the origin IP-address mentioned (in the private 10.x.x.x-range), this looked like a Facebook-internal problem (between their XMPP &amp;amp; Authentication servers).&lt;/p&gt;&lt;p&gt;Things have however taken a turn for the worse now; I’m not only getting logged out from Facebook on my 3 devices (work Win XP PC, home Ubuntu netbook &amp;amp; Android smartphone), I’m &lt;strong&gt;now even getting locked out&lt;/strong&gt; of my account altogether, having to &lt;strong&gt;change my password&lt;/strong&gt; on my smartphone (as that one has the OTP generator in the Facebook app). This happened 4 times in the last week and it is that frustrating that &lt;strong&gt;I disabled Facebook Chat in Thunderbird&lt;/strong&gt;. And maybe that’s &lt;strong&gt;just what Facebook is aiming for&lt;/strong&gt;; encouraging users to use Facebook Chat in a Facebook-owned/ -controlled context instead of in a neutral, ad-free 3rd party application? Wankers!&lt;/p&gt;&lt;div class=&quot;yarpp-related-rss&quot;&gt;&lt;p&gt;Possibly related twitterless twaddle:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;a href=&quot;http://blog.futtta.be/2012/11/15/now-you-can-have-my-facebook-password-as-well/&quot; rel=&quot;bookmark&quot; title=&quot;Now you can have my Facebook password as well!&quot;&gt;Now you can have my Facebook password as well!&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://blog.futtta.be/2009/01/09/browserless-twaddle-facebook-plugin-for-pidgin/&quot; rel=&quot;bookmark&quot; title=&quot;Browserless twaddle; Facebook plugin for Pidgin&quot;&gt;Browserless twaddle; Facebook plugin for Pidgin&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://blog.futtta.be/2011/11/23/you-can-have-my-google-password/&quot; rel=&quot;bookmark&quot; title=&quot;You can have my Google password!&quot;&gt;You can have my Google password!&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;/div&gt; &lt;div class=&quot;feedflare&quot;&gt;
&lt;a href=&quot;http://feeds.feedburner.com/~ff/futtta?a=76Tv-0fCF8k:dh0_lyVlPW4:D7DqB2pKExk&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;http://feeds.feedburner.com/~ff/futtta?i=76Tv-0fCF8k:dh0_lyVlPW4:D7DqB2pKExk&quot; /&gt;&lt;/a&gt; &lt;a href=&quot;http://feeds.feedburner.com/~ff/futtta?a=76Tv-0fCF8k:dh0_lyVlPW4:yIl2AUoC8zA&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;http://feeds.feedburner.com/~ff/futtta?d=yIl2AUoC8zA&quot; /&gt;&lt;/a&gt; &lt;a href=&quot;http://feeds.feedburner.com/~ff/futtta?a=76Tv-0fCF8k:dh0_lyVlPW4:qj6IDK7rITs&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;http://feeds.feedburner.com/~ff/futtta?d=qj6IDK7rITs&quot; /&gt;&lt;/a&gt; &lt;a href=&quot;http://feeds.feedburner.com/~ff/futtta?a=76Tv-0fCF8k:dh0_lyVlPW4:I9og5sOYxJI&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;http://feeds.feedburner.com/~ff/futtta?d=I9og5sOYxJI&quot; /&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img height=&quot;1&quot; src=&quot;http://feeds.feedburner.com/~r/futtta/~4/76Tv-0fCF8k&quot; width=&quot;1&quot; /&gt;</description>
	<pubDate>Sun, 19 May 2013 10:58:16 +0000</pubDate>
</item>
<item>
	<title>Thomas Vander Stichele: Organizing photo libraries</title>
	<guid>http://thomas.apestaart.org/log/?p=1550</guid>
	<link>http://thomas.apestaart.org/log/?p=1550</link>
	<description>&lt;p&gt;The weather’s picking up so it’s time for spring cleaning around the house.  When I moved back to Barcelona three years ago I took with me my old analogue photos and negatives, with the idea of sorting through them at some point and getting them digitized.  And while I’m at it, maybe it’s time to pull all my various folders of photos together too and organize them.&lt;/p&gt;
&lt;p&gt;Well, I finally started.  I grouped the negatives, labeled them by year, put them in individual envelopes, and handed them off to a professional lab to scan them after doing a quick test run on one set (which turned out great, but it’s *really* annoying me that they scan to JPEG by default, charge 40% extra for TIFF, and use a non-multiple-of-8 resolution to scan at which means I can’t losslessly rotate the negatives.  Yes, I’m anal.)&lt;/p&gt;
&lt;p&gt;So now I pulled together all my various folders of photos, and before I start doing tagging and stuff like that, I want to organize them in a decent folder layout.  Googling for ideas pretty much suggests that the way to go is&lt;/p&gt;
&lt;p&gt;YYYY/MM/DD&lt;/p&gt;
&lt;p&gt;with possibly some description together with the DD&lt;/p&gt;
&lt;p&gt;I’m not really happy about that, however, because there are certain things I’d like to be able to do:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;easily see where photos come from – did I make them ? did I get them from someone ? Did I download them from Facebook ?&lt;/li&gt;
&lt;li&gt;Are these original files from a camera without editing ?&lt;/li&gt;
&lt;li&gt;Are these the original scans ? From negatives ? From actual photos ? Or are they retouched, rotated, denoised, …&lt;/li&gt;
&lt;li&gt;Are these photos SFW ? Can I point my media center slideshow to this directory and have it safely show any photos under it ? (What do you mean, you’ve never snowboarded at night in only your underwear, and mooning the photographer ?) Or maybe not even SFW, but simply watchable and reasonable quality or subject material?&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;I realize some of these issues can not be resolved simply with a directory layout.  But I’m sure some of you must have had similar issues or come up with a slightly better layout ? &lt;/p&gt;
&lt;p&gt;Point me in the right direction please.&lt;/p&gt;</description>
	<pubDate>Sat, 18 May 2013 11:51:02 +0000</pubDate>
</item>
<item>
	<title>Xavier Mertens: NoSuchCon #1 Wrap-Up</title>
	<guid>http://blog.rootshell.be/?p=21542</guid>
	<link>http://blog.rootshell.be/2013/05/17/nosuchcon-1-wrap-up/</link>
	<description>&lt;p&gt;&lt;img alt=&quot;NoSuchCon Kit&quot; border=&quot;0&quot; class=&quot;alignleft  wp-image-9380&quot; height=&quot;158&quot; src=&quot;http://blog.rootshell.be/wp-content/uploads/2013/05/IMG_3199.jpg&quot; style=&quot;border: 0px;&quot; title=&quot;IMG_3199.jpg&quot; width=&quot;210&quot; /&gt;&lt;/p&gt;
&lt;p style=&quot;text-align: justify;&quot;&gt;There are so many security conferences around the world… Some people already debated about this: Is it better to restrict the annual agenda to well-known events or let people start their own? IMHO, we need initiatives like this. It’s good to have a broad agenda with local conferences where local people can attend without spending huge amounts of money for travels and lodging (If you can go to conferences, let’s bring the conferences to you!) So, let’s welcome the newly born conference called “&lt;em&gt;NoSuchCon&lt;/em&gt;“. The &lt;a href=&quot;http://nosuchcon.org&quot;&gt;first&lt;/a&gt; edition was just organized in Paris across the last three days. Unfortunately, I was only able to attend the last day… If only I could expand my holidays like a filesystem! &lt;img alt=&quot;:-)&quot; class=&quot;wp-smiley&quot; src=&quot;http://blog.rootshell.be/wp-includes/images/smilies/icon_smile.gif&quot; /&gt;  I joined Paris early the morning to attend the first keynote. Here is a quick review of the day.&lt;/p&gt;
&lt;p style=&quot;text-align: justify;&quot;&gt;&lt;span id=&quot;more-21542&quot;&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style=&quot;text-align: justify;&quot;&gt;Today’s keynote was presented by &lt;a href=&quot;https://twitter.com/DmitriCyber&quot;&gt;Dmitri Alperovitch&lt;/a&gt; (from Crowdstrike). His presentation had only… one slide, displayed at the end of his keynote! The first message broadcasted by Dmitri was “&lt;em&gt;We are doing wrong!&lt;/em&gt;“. Is it really a breaking news? No, major vendors, browsers, mobile phones, all of them are working to improve their security. We also have Next-Generation firewalls, powerful forensic tools and medias are talking about “&lt;em&gt;cyber-*&lt;/em&gt;” (replace the star with your favourite term) and are trying to do some awareness. So what?&lt;/p&gt;
&lt;p&gt;&lt;img alt=&quot;Dmitri Alperovitch&quot; border=&quot;0&quot; height=&quot;225&quot; src=&quot;http://blog.rootshell.be/wp-content/uploads/2013/05/IMG_3186.jpg&quot; style=&quot;display: block; margin-left: auto; margin-right: auto;&quot; title=&quot;IMG_3186.jpg&quot; width=&quot;300&quot; /&gt;&lt;/p&gt;
&lt;p style=&quot;text-align: justify;&quot;&gt;This is a paradox! Even with all those changes, we are still unable to block our adversaries. Our desire to have a “&lt;em&gt;one-size-fits-all&lt;/em&gt;” security solution is bad. We have very specific issues to address. One category of actors are hacktivists. Another one is espionage. Classic defences approach do not work with those actors. Offensive is more lucrative and cheaper. If you increase your defences, offensive guys will grow too. This is a never-ending story. A good example are DDoS. Increasing your pipe to the Internet (bandwidth) and server farms will not solve the problem. Attackers will use bigger bots! Also, how to defend against national agencies which have huge budgets? Know your enemy, this will allow you to break the asymmetry between attack &amp;amp; defense.  Find the pin-point and push on it. Attackers usually focus on a target and don’t have a look at its competitor. An idea proposed by Dmitri: can a “&lt;em&gt;bounty hunter&lt;/em&gt;” program law  help to catch attackers? Dmitri brought a big suitcase full of t-shirts and distributed them after his keynote. That’s for the show but it’s always funny to get goodies!&lt;/p&gt;
&lt;p style=&quot;text-align: justify;&quot;&gt;The first half-day was dedicated to presentations about the Windows kernel. A first one was performed by &lt;a href=&quot;https://twitter.com/lilhoser&quot;&gt;Aaron LeMasters&lt;/a&gt; about “&lt;em&gt;Crashdmp-ster diving the Windows 8 crash dump stack&lt;/em&gt;“. The Microsoft crash dump mechanism is an interesting component of the operating system. Aaron performed some researches about this feature. His project is hosted on &lt;a href=&quot;http://crashd.mp/&quot;&gt;crashd.md&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;img alt=&quot;Aaron LeMasters&quot; border=&quot;0&quot; height=&quot;300&quot; src=&quot;http://blog.rootshell.be/wp-content/uploads/2013/05/IMG_3190.jpg&quot; style=&quot;display: block; margin-left: auto; margin-right: auto;&quot; title=&quot;IMG_3190.jpg&quot; width=&quot;225&quot; /&gt;&lt;/p&gt;
&lt;p style=&quot;text-align: justify;&quot;&gt;The crash dump mechanism is a layer driver providing an I/O path to a mass storage device. It is used in two situations: when a bug check occurs (hey, it’s Windows! &lt;img alt=&quot;;-)&quot; class=&quot;wp-smiley&quot; src=&quot;http://blog.rootshell.be/wp-includes/images/smilies/icon_wink.gif&quot; /&gt; ) or to hibernate the system (&lt;a href=&quot;http://windows-dll.com/en-us/what/crashdmp-sys/&quot;&gt;crashdmp.sys&lt;/a&gt;). Aaron describe how it works. Note that the mechanism is different between Windows XP – 7 and Windows 8. With  the last version of the Microsoft OS, the crash dump subsystem can be tricked into reading and writing everywhere. That’s what Aaron explained during his talk. Based on his research, he also wrote a CTF &lt;a href=&quot;http://crashd.mp/?p=54&quot;&gt;challenge&lt;/a&gt; for SOURCE Boston and explained in details how it worked. The source code will be released soon, check out his website.&lt;/p&gt;
&lt;p style=&quot;text-align: justify;&quot;&gt;Then, a second talk immediately followed: “&lt;em&gt;Exploiting hard core pool corruption in Microsoft Windows kernel&lt;/em&gt;” by &lt;a href=&quot;https://twitter.com/NTarakanov&quot;&gt;Nikita Tarakanov&lt;/a&gt;. Today, many applications implement sandboxes (ex: browsers). To evade sandboxes, a good idea is to abuse… the low level… the kernel.&lt;/p&gt;
&lt;p&gt;&lt;img alt=&quot;Nikita Tarakanov&quot; border=&quot;0&quot; height=&quot;225&quot; src=&quot;http://blog.rootshell.be/wp-content/uploads/2013/05/IMG_3191.jpg&quot; style=&quot;display: block; margin-left: auto; margin-right: auto;&quot; title=&quot;IMG_3191.jpg&quot; width=&quot;300&quot; /&gt;&lt;/p&gt;
&lt;p style=&quot;text-align: justify;&quot;&gt;Once broken, you have access to everything. Previous vulnerabilities found in Windows kernels are memory corruption. Today, known techniques do no work anymore with Windows 8. First, Nikita reviewed how kernel pool is working and what were the “&lt;em&gt;old&lt;/em&gt;” attacks. The next part covered a new attack which works on all versions of Windows: DKOHM (“&lt;em&gt;Direct Kernel Object Header Manipulation&lt;/em&gt;“).&lt;/p&gt;
&lt;p style=&quot;text-align: justify;&quot;&gt;After a lunch break in a small Parisian restaurant, eating and talking about security, the second set of talks started again. The first one was “&lt;em&gt;XML – Out-of-band exploitation&lt;/em&gt;” by &lt;a href=&quot;https://twitter.com/a66at&quot;&gt;Yunusov Timur &lt;/a&gt;and Alexey Osipov. First part was about&lt;a href=&quot;http://www.w3resource.com/xml/parameter-entities.php&quot;&gt; parameter entities&lt;/a&gt; (“&lt;em&gt;PE&lt;/em&gt;“). Speakers reviewed then and how they work.  How work out-of-band attacks? The attacker send XML to the server which parses it and requests data from the malicious host.&lt;/p&gt;
&lt;p style=&quot;text-align: justify;&quot;&gt;&lt;img alt=&quot;Yunusov &amp;amp; Alexey&quot; border=&quot;0&quot; height=&quot;300&quot; src=&quot;http://blog.rootshell.be/wp-content/uploads/2013/05/IMG_3193.jpg&quot; style=&quot;display: block; margin-left: auto; margin-right: auto;&quot; title=&quot;IMG_3193.jpg&quot; width=&quot;225&quot; /&gt;&lt;/p&gt;
&lt;p style=&quot;text-align: justify;&quot;&gt;They also performed demos of exfiltrating data from via an XML file: &lt;span style=&quot;text-align: justify;&quot;&gt;Using DNS requests made during XML document XSLT transformation to extract information via a bunch of A queries to forged names. An other&lt;/span&gt; demo was to grab /etc/passwd from a website just be trying to validate an XML file. Sweet!&lt;/p&gt;
&lt;p style=&quot;text-align: justify;&quot;&gt;The next talk was again about kernels but this time on MacOS X! Pedro Vilaca presented “&lt;em&gt;Revisiting Mac OS X kernel root kits&lt;/em&gt;“. Rootkits are kernel extensions. Pedro reviewed interesting ideas to make them more powerful. The Mac OS landscape has less researchers and lack of public developments about rootkits. But it does not mean that more are working in the wild. Great job performed by Pedro but difficult to maintain due to the operating system being closed source.&lt;/p&gt;
&lt;p style=&quot;text-align: justify;&quot;&gt;After a coffee break, the last run of talks started. Luigi Auriemma &amp;amp; Donato Ferrante presented “&lt;em&gt;Exploiting game engines for fun &amp;amp; profit&lt;/em&gt;“.&lt;/p&gt;
&lt;p style=&quot;text-align: justify;&quot;&gt;&lt;img alt=&quot;Exploiting Game Engines&quot; border=&quot;0&quot; height=&quot;300&quot; src=&quot;http://blog.rootshell.be/wp-content/uploads/2013/05/IMG_3196.jpg&quot; style=&quot;display: block; margin-left: auto; margin-right: auto;&quot; title=&quot;IMG_3196.jpg&quot; width=&quot;225&quot; /&gt;&lt;/p&gt;
&lt;p style=&quot;text-align: justify;&quot;&gt;Why target games? Because the attack surface is huge! Did you know that some engines are sold with special licenses to military organisations? Almost all kind of people are playing once back at home. Even C-level people can be gamers during their free time. This can be a nice way of exploiting their company. The same engine can be shared across multiple games (and stuff added like Lego-blocks). The same vulnerability can be re-used! Gain of time and $$$. Game engines can be attacked on four topics:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Fragmented packets: Games are based on UDP protocol but they try to implement a TCP-over-UDP. When fragmentation occurs, the engine must rebuild the original packet. This process is performed in memory. What about trying to place the payload of a packet in another memory area?&lt;/li&gt;
&lt;li&gt;Compression: Not algorithms but index numbers.Flipping bits can be interesting&lt;/li&gt;
&lt;li&gt;Game Protocols:&lt;/li&gt;
&lt;li&gt;Customization (extensions also called “mods” and command line)&lt;/li&gt;
&lt;/ul&gt;
&lt;p style=&quot;text-align: justify;&quot;&gt;After the theori, the speakers performed some live demos. Check out &lt;a href=&quot;http://revuln.com&quot;&gt;revuln.com&lt;/a&gt; for their white paper released today!&lt;/p&gt;
&lt;p style=&quot;text-align: justify;&quot;&gt;For the next talk, the planning changed. The scheduled speaker was not able to come to France due to a visa issue. Weird! A last minute (but excellent!) speaker replaced him: &lt;a href=&quot;http://www.cs.dartmouth.edu/~sergey/&quot;&gt;Sergey Bratus&lt;/a&gt; presented “&lt;em&gt;Any input is a program&lt;/em&gt;“. I was lost, his topic was too complex! I don’t know how many people were able to fillow him in the audience.&lt;/p&gt;
&lt;p style=&quot;text-align: justify;&quot;&gt;&lt;img alt=&quot;Sergey Bratus&quot; border=&quot;0&quot; height=&quot;300&quot; src=&quot;http://blog.rootshell.be/wp-content/uploads/2013/05/IMG_3197.jpg&quot; style=&quot;display: block; margin-left: auto; margin-right: auto;&quot; title=&quot;IMG_3197.jpg&quot; width=&quot;225&quot; /&gt;&lt;/p&gt;
&lt;p style=&quot;text-align: justify;&quot;&gt;The last talk was “&lt;em&gt;Killing rats with incident response process&lt;/em&gt;” by Robinson Delaugerre and Adrien Chevalier. The result of their research is a new framework called Arsenic which will be released soon. The goal is to perform incident response in a easy way. They started the talk with some facts about incident handling and how complex it can be.&lt;/p&gt;
&lt;p style=&quot;text-align: justify;&quot;&gt;&lt;img alt=&quot;Arsenic Framework&quot; border=&quot;0&quot; height=&quot;225&quot; src=&quot;http://blog.rootshell.be/wp-content/uploads/2013/05/IMG_3198.jpg&quot; style=&quot;display: block; margin-left: auto; margin-right: auto;&quot; title=&quot;IMG_3198.jpg&quot; width=&quot;300&quot; /&gt;&lt;/p&gt;
&lt;p&gt;This process is based on three pillars:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Network analysis&lt;/li&gt;
&lt;li&gt;Host forensics&lt;/li&gt;
&lt;li&gt;Reverse engineering&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Arsenic is a their framework, written in Ruby, which brings those pillars together. They also performed live demos to detect a well-known RAT (&lt;a href=&quot;http://www.poisonivy-rat.com/&quot;&gt;Poison Ivy&lt;/a&gt;). It seems to be an interesting tool.&lt;/p&gt;
&lt;p style=&quot;text-align: justify;&quot;&gt;And that’s already done. That was a quick but interesting visit to this new event. Again, NoSuchCon, welcome in the world of security conferences! Organizers made it a success with 250 attendees (number received from a member of the organisation). I liked particularly:&lt;/p&gt;
&lt;ul&gt;
&lt;li style=&quot;text-align: justify;&quot;&gt;The idea of a “&lt;em&gt;one-cay&lt;/em&gt;” pass for people who were not able to block three consecutive days.&lt;/li&gt;
&lt;li style=&quot;text-align: justify;&quot;&gt;&lt;a href=&quot;http://www.nosuchcon.org/talks/&quot;&gt;Slides&lt;/a&gt; were available a few minutes before the talk (useful for people sitting far from the beamer)&lt;/li&gt;
&lt;li style=&quot;text-align: justify;&quot;&gt;The conference &lt;a href=&quot;http://travisgoodspeed.blogspot.be/2012/07/emulating-usb-devices-with-python.html&quot;&gt;Facedancer&lt;/a&gt; badge (made by Travis Goodspeed)&lt;/li&gt;
&lt;li style=&quot;text-align: justify;&quot;&gt;Live streaming&lt;/li&gt;
&lt;/ul&gt;
&lt;img height=&quot;1&quot; src=&quot;http://feeds.feedburner.com/~r/dev/rand/~4/huMu3V9uHRs&quot; width=&quot;1&quot; /&gt;</description>
	<pubDate>Fri, 17 May 2013 20:42:55 +0000</pubDate>
</item>
<item>
	<title>Lionel Dricot: The Fight for E-Clothing</title>
	<guid>http://ploum.net/?p=2859</guid>
	<link>http://ploum.net/post/the-fight-for-e-clothing</link>
	<description>&lt;img src=&quot;http://planet.grep.be/heads/ploum100&quot; alt=&quot;&quot; align=&quot;right&quot; style=&quot;float: right;&quot;&gt;&lt;p&gt;I meet Karl Isrich in a small restaurant. You maybe heard about the company he founded, MyVirtualTaylor, a pioneer of e-clothing. You would probably imagine Karl as one of those twenty-something golden boy. Instead, I face an average anxious guy, approximately forty years old with greyish hairs.&lt;/p&gt;
&lt;p&gt;He asked me to go to this cheap restaurant because he could not afford a more expensive dinner. Lawyers, he said. When we sat down, he gave me a business card that used to be shiny six months ago. It simply says “MyVirtualTaylor, Isrich CEO”.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Hello Karl, thanks for the meeting. MyVirtualTaylor is an e-clothing company. But what is e-clothing exactly ?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Simply put, it’s 3D printing for clothes. We have developed a clothing printer that we sell and which is the size of a washing machine. Not being bigger than a washing machine was one of our top requirements before the launch.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;The clothing printer has a tank of polymer, that you need to refill regularly, and seven dye tanks. We discovered that having seven primary colors was a good deal to reproduce most of the colors.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Through wifi, you send a .clo file to the printer then wait between ten minutes and one hour, depending on the size and the complexity of the model. Everything is automatic, you can even print a bunch of .clo in a row.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;How do you get a .clo file?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;We have an online editor on our website that allows you to design your own clothes. We have also some standard templates: shirts, ties, stuff like that.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;In fact, when we launched, we didn’t really think about that. We thought that there will be a new market for clothes creators. That’s why we wanted the .clo format to be open and documented. We sell the hardware but we didn’t want to enter the clothing market.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Can you really print anything? What are the limitations?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Currently, there are some constraints with the size. We have prototypes that can print as big as a king size bed sheet. But, of course, you can only print clothes made of polymer. No silk nor fabric.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Isn’t that a big limitation? After all, most of our clothes are made of fabric.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;It should be noted that a lot of progress have been made with polymers. We can weave the polymer in a lot of different ways in order to have the properties we want.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;But, most importantly, clothing material has always been about finding a compromise between style, comfort and durability. Durability being the critical point for quality clothes. The clothes have to go through hundred of washing cycles. Our solution was to remove durability from the equation.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Do you mean that printed clothes are not durable?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Not, they aren’t. But it is not the goal. Instead of cleaning them, you put them in the clothing printer and the polymer is cleaned, melted and ready to print new clothes.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Unfortunately, we still cannot extract the colors. The polymer is thus not perfect. We store the recycled polymer in a separate tank. When you print, you can allow the use of recycled polymer or not. It is good enough for every day but if you want a perfect white shirt for a wedding, you probably want the unused polymer.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;The part of the polymer which is worn out goes with the waste to the sewers.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;It sounds like an ecological disaster.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;That’s exactly the rumor spread by our opponents.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;But, while it is not perfect, you have to compare it with the traditional clothing industry. Clothes are usually made in huge factories in China, using harmful chemicals. Then, you have to take into account the transport, the storage, the shop. Not mentioning the gas needed to go to the shopping mall. To that, add the water and the soap used to wash the clothes. By contrast, we basically use electricity and release very little polymer. With time, we hope to be able to recycle more and more.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;&lt;/em&gt;&lt;strong&gt;&lt;em&gt;Did you talk about opponents?&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;You know, I’m an engineer. I never really cared about anything but the technological aspects. When the first clothing printers were sold, people immediately started to exchange .clo files. They took their own clothes and make .clo files to be able to reproduce them.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;One day, I received a letter from lawyers of the FCIAA, the Fashion &amp;amp; Clothing Industry Association of America. I’ve never heard of them before but, basically, they wanted me to stop my company because I was threatening their business.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;I thought it was a joke. Really. At first I was like: ”Funny. It’s like the candle industry suing Edison for inventing the lightbulb”. But it’s not funny any more.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;I can talk about this for hours. They are bad. Really bad. They are trying to destroy my life.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Can’t you let the lawyers handle that?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;For the lawsuit, of course. But there’s a lot more. I’ve been contacted by politicians. They say that I’m destroying the economy. If my product works, there will be no shops for clothes hence no jobs. They asked me: “Do you know how many Americans are working in clothing shops?”. I was accused of being anti-patriotic. From nowhere, some news laws appeared saying that clothes should have a certification in order to save children from accidental suffocation.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;From that point, it became immoral to print clothes. Last year, nobody ever thought about printing clothes and, now, it is worse than eating babies alive. There’s even webshops where you can order “Not Printed” labelled t-shirts. I’ve been attacked personally, investors have turned me back and, at the same time, I still need to pay expensive legal fees.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Isn’t that true that it’s a threat for the economy?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;It is a tool for making life easier. Any invention which free people from &lt;a href=&quot;http://ploum.net/post/backyard-digging-point&quot; title=&quot;The Backyard Digging (and filling it back afterwards) Point&quot;&gt;unnecessary labor&lt;/a&gt; seems to be a threat to the economy. But if our economy is threatened by inventions that make life better for everyone, it’s the economy we need to change, not the inventions.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What will you do next?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;I feel bitter. I’m an engineer with a new useful idea and everyone turns against me: big corporations, lawyers, politicians. Even random people in the street think that “It’s the guy destroying jobs and suffocating babies”. I’ve never signed up for that. I’ve never been into politics or anything like that. Now, I’m thinking about settling somewhere in Europe but I’m afraid that the hand of the FCIAA will follow me there. &lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Thanks Karl, I wish you the best.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Although, as a journalist, I know I should remain objective, I can’t help but feeling empathy for the guy. As I’m packing up, I notice his clothes for the first time. “So are those printed?” “Of course” “Very nice. It’s impressive.” He sighs then try to smile at me: “Thanks. If you are interested, you will find the .clo on the Pirate Bay.”. His smile feels sad, despaired. We shake hands and he slowly walk away while I stay there, helpless.&lt;/p&gt;
&lt;p&gt; &lt;/p&gt;
&lt;p&gt;&lt;em&gt;This post is part of the &lt;a href=&quot;https://plus.google.com/b/105291290729539808122/105291290729539808122/posts&quot;&gt;Letters from the Future&lt;/a&gt; collection and is dedicated to &lt;a href=&quot;http://blog.brokep.com/&quot;&gt;Brokep&lt;/a&gt; for announcing his political involvement during the writing of this text. Picture by &lt;a href=&quot;http://www.flickr.com/photos/35034348013@N01/285908461&quot;&gt;Anna Banana&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;
 &lt;p&gt;&lt;a href=&quot;http://ploum.net/?flattrss_redirect&amp;amp;id=2859&amp;amp;md5=10250f59ffd5613b89c5d1719671142f&quot; target=&quot;_blank&quot; title=&quot;Flattr&quot;&gt;&lt;img alt=&quot;flattr this!&quot; src=&quot;http://ploum.net/wp-content/plugins/flattr/img/flattr-badge-large.png&quot; /&gt;&lt;/a&gt;&lt;/p&gt;</description>
	<pubDate>Fri, 17 May 2013 16:23:35 +0000</pubDate>
</item>
<item>
	<title>Frank Goossens: Music from Our Tube: Modeselektor Essential Mix</title>
	<guid>http://blog.futtta.be/?p=8834</guid>
	<link>http://feedproxy.google.com/~r/futtta/~3/czYlwuoMjrI/</link>
	<description>&lt;p&gt;BBC Radio 1 has a great series called the “&lt;a href=&quot;http://www.bbc.co.uk/programmes/b006wkfp&quot; title=&quot;Essential Mix website&quot;&gt;Essential Mix&lt;/a&gt;“. There’s &lt;a href=&quot;https://www.youtube.com/results?search_query=essential+mix+bbc&quot; title=&quot;essential mix on youtube&quot;&gt;a lot of those on YouTube&lt;/a&gt; and &lt;a href=&quot;http://www.modeselektor.com/&quot; title=&quot;Modeselektor (Made in Germany)&quot;&gt;Modeselektor&lt;/a&gt;‘s is one of the truely great ones amongst those. Enjoy!&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;http://blog.futtta.be/2013/05/17/music-from-our-tube-modeselektor-essential-mix/&quot;&gt;&lt;img alt=&quot;YouTube Video&quot; src=&quot;http://i.ytimg.com/vi/ZxCs8h3moho/0.jpg&quot; /&gt;&lt;/a&gt;&lt;br /&gt;Watch this video &lt;a href=&quot;http://youtu.be/ZxCs8h3moho&quot;&gt;on YouTube&lt;/a&gt; or on &lt;a href=&quot;http://icant.co.uk/easy-youtube/?http://www.youtube.com/watch?v=ZxCs8h3moho&quot;&gt;Easy Youtube&lt;/a&gt;.&lt;/p&gt;&lt;div class=&quot;yarpp-related-rss&quot;&gt;&lt;p&gt;Possibly related twitterless twaddle:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;a href=&quot;http://blog.futtta.be/2013/05/03/music-from-our-tube-seelenluft/&quot; rel=&quot;bookmark&quot; title=&quot;Music from Our Tube; Seelenluft&quot;&gt;Music from Our Tube; Seelenluft&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://blog.futtta.be/2013/04/22/music-from-our-tube-laura-mvula/&quot; rel=&quot;bookmark&quot; title=&quot;Music from Our Tube; Laura Mvula&quot;&gt;Music from Our Tube; Laura Mvula&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://blog.futtta.be/2010/05/18/lite-youtube-embeds-in-wordpress/&quot; rel=&quot;bookmark&quot; title=&quot;Lite YouTube Embeds in WordPress&quot;&gt;Lite YouTube Embeds in WordPress&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;/div&gt; &lt;div class=&quot;feedflare&quot;&gt;
&lt;a href=&quot;http://feeds.feedburner.com/~ff/futtta?a=czYlwuoMjrI:Cce1hCb7l-Y:D7DqB2pKExk&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;http://feeds.feedburner.com/~ff/futtta?i=czYlwuoMjrI:Cce1hCb7l-Y:D7DqB2pKExk&quot; /&gt;&lt;/a&gt; &lt;a href=&quot;http://feeds.feedburner.com/~ff/futtta?a=czYlwuoMjrI:Cce1hCb7l-Y:yIl2AUoC8zA&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;http://feeds.feedburner.com/~ff/futtta?d=yIl2AUoC8zA&quot; /&gt;&lt;/a&gt; &lt;a href=&quot;http://feeds.feedburner.com/~ff/futtta?a=czYlwuoMjrI:Cce1hCb7l-Y:qj6IDK7rITs&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;http://feeds.feedburner.com/~ff/futtta?d=qj6IDK7rITs&quot; /&gt;&lt;/a&gt; &lt;a href=&quot;http://feeds.feedburner.com/~ff/futtta?a=czYlwuoMjrI:Cce1hCb7l-Y:I9og5sOYxJI&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;http://feeds.feedburner.com/~ff/futtta?d=I9og5sOYxJI&quot; /&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img height=&quot;1&quot; src=&quot;http://feeds.feedburner.com/~r/futtta/~4/czYlwuoMjrI&quot; width=&quot;1&quot; /&gt;</description>
	<pubDate>Fri, 17 May 2013 14:02:13 +0000</pubDate>
</item>
<item>
	<title>Frederic Hornain: [Automation] Cloudforms – May/June 2013 – Belgium</title>
	<guid>http://fhornain.wordpress.com/?p=1651</guid>
	<link>http://fhornain.wordpress.com/2013/05/17/automation-cloudforms-mayjune-2013-belgium/</link>
	<description>&lt;p&gt;&lt;img alt=&quot;CloudForms&quot; class=&quot;alignleft size-full wp-image-1652&quot; height=&quot;340&quot; src=&quot;http://fhornain.files.wordpress.com/2013/05/mycloudforms.png?w=460&amp;amp;h=340&quot; width=&quot;460&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Dear *,&lt;/p&gt;
&lt;p&gt;Next week, I will do a presentation about Cloudforms (Hybrid cloud management solution) [1][2].&lt;br /&gt;
If your company or you are based in BeNeLux and are interested by this presentation, just let me know and I will try to arrange a meeting for you.&lt;/p&gt;
&lt;p&gt;[1]&lt;a href=&quot;https://www.redhat.com/solutions/&quot; target=&quot;_blank&quot; title=&quot;Redhat Solutions&quot;&gt; https://www.redhat.com/solutions/&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;[2]&lt;a href=&quot;http://www.redhat.com/products/cloud-computing/cloudforms/&quot; target=&quot;_blank&quot; title=&quot;Cloudforms&quot;&gt; http://www.redhat.com/products/cloud-computing/cloudforms/&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;BR&lt;br /&gt;
Frederic&lt;/p&gt;
&lt;br /&gt;  &lt;a href=&quot;http://feeds.wordpress.com/1.0/gocomments/fhornain.wordpress.com/1651/&quot; rel=&quot;nofollow&quot;&gt;&lt;img alt=&quot;&quot; border=&quot;0&quot; src=&quot;http://feeds.wordpress.com/1.0/comments/fhornain.wordpress.com/1651/&quot; /&gt;&lt;/a&gt; &lt;img alt=&quot;&quot; border=&quot;0&quot; height=&quot;1&quot; src=&quot;http://stats.wordpress.com/b.gif?host=fhornain.wordpress.com&amp;amp;blog=6345193&amp;amp;post=1651&amp;amp;subd=fhornain&amp;amp;ref=&amp;amp;feed=1&quot; width=&quot;1&quot; /&gt;</description>
	<pubDate>Fri, 17 May 2013 11:50:02 +0000</pubDate>
</item>
<item>
	<title>Wim Coekaerts: ksplice and how it really helps with 0day stuff</title>
	<guid>https://blogs.oracle.com/wim/entry/ksplice_and_how_it_really</guid>
	<link>https://blogs.oracle.com/wim/entry/ksplice_and_how_it_really</link>
	<description>So a nasty bug report came out the other day on linux, a serious exploit. Everyone scrambled to get a kernel built and (tested) and released and then there's of course the effort of bringing down applications, multi-tiered environments being way more complex in terms of orchestration of bringing down multiple systems, installing the updated kernel and rebooting and bringing everything back up in an orderly fashion.
&lt;p&gt;
Of course for all our customers that use ksplice and enjoy the cool zero downtime patching, theyt might not even have noticed if they ran *as many do* ksplice in automated mode or others just had to issue one single very simple command and they were done. No applications to bring down, no systems to reboot... and still safe, secure, patched, current.
&lt;/p&gt;&lt;p&gt;
some more specifics on the ksplice blog &lt;a href=&quot;https://blogs.oracle.com/ksplice/entry/ksplice_update_for_cve_2013&quot;&gt;here&lt;/a&gt;.
&lt;/p&gt;&lt;p&gt;
There's also Time to release. The ksplice patch was available on Tuesday (5/14) while the RPM for the kernel was released on Thursday (5/16) by us and the other similar distributions.  No hassle...&lt;/p&gt;</description>
	<pubDate>Thu, 16 May 2013 20:00:12 +0000</pubDate>
</item>
<item>
	<title>Dries Buytaert: Want more features in Drupal 8? Help fix bugs!</title>
	<guid>http://buytaert.net/2956 at http://buytaert.net</guid>
	<link>http://buytaert.net/want-more-features-in-drupal-8-help-fix-bugs</link>
	<description>&lt;div class=&quot;field field-name-taxonomy-vocabulary-1 field-type-taxonomy-term-reference field-label-above&quot;&gt;&lt;div class=&quot;field-label&quot;&gt;Topic: &lt;/div&gt;&lt;div class=&quot;field-items&quot;&gt;&lt;div class=&quot;field-item even&quot;&gt;&lt;a href=&quot;http://buytaert.net/tag/drupal&quot;&gt;Drupal&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;field field-name-body field-type-text-with-summary field-label-hidden&quot;&gt;&lt;div class=&quot;field-items&quot;&gt;&lt;div class=&quot;field-item even&quot;&gt;&lt;p&gt;In Drupal core, we use &lt;a href=&quot;http://drupal.org/core/thresholds&quot;&gt;issue thresholds&lt;/a&gt; to manage technical debt. Both critical (release-blocking) and major (non-release-blocking, high-impact issues) are considered. When we have more open issues than our thresholds, we do not commit new features.&lt;/p&gt;
&lt;p&gt;Currently, we have &lt;a href=&quot;http://drupal.org/project/issues/search/drupal?version[0]=8.x&amp;amp;version[1]=7.x&amp;amp;status[0]=1&amp;amp;status[1]=8&amp;amp;status[2]=13&amp;amp;status[3]=14&amp;amp;status[4]=15&amp;amp;priorities[0]=1&amp;amp;categories[0]=bug&quot;&gt;27 critical bugs&lt;/a&gt;, &lt;a href=&quot;http://drupal.org/project/issues/search/drupal?version[0]=8.x&amp;amp;version[1]=7.x&amp;amp;status[0]=1&amp;amp;status[1]=8&amp;amp;status[2]=13&amp;amp;status[3]=14&amp;amp;status[4]=15&amp;amp;priorities[0]=1&amp;amp;categories[0]=task&quot;&gt;41 critical tasks&lt;/a&gt;, &lt;a href=&quot;http://drupal.org/project/issues/search/drupal?version[0]=8.x&amp;amp;version[1]=7.x&amp;amp;status[0]=1&amp;amp;status[1]=8&amp;amp;status[2]=13&amp;amp;status[3]=14&amp;amp;status[4]=15&amp;amp;priorities[0]=4&amp;amp;categories[0]=bug&quot;&gt;155 major bugs&lt;/a&gt;, and &lt;a href=&quot;http://drupal.org/project/issues/search/drupal?version[0]=8.x&amp;amp;version[1]=7.x&amp;amp;status[0]=1&amp;amp;status[1]=8&amp;amp;status[2]=13&amp;amp;status[3]=14&amp;amp;status[4]=15&amp;amp;priorities[0]=4&amp;amp;categories[0]=task&quot;&gt;149 major tasks&lt;/a&gt;. This is more than twice our current thresholds for critical issues, and about 50% more than our thresholds for major issues. We need your help to resolve these issues so that we can resume adding new features to Drupal 8.  That would be a very exciting place to get to!&lt;/p&gt;
&lt;p&gt;There are many ways to help, including not only programming but also updating these issues' summaries, testing the patches, and making sure the patches still apply. I encourage everyone to collaborate on major and critcal issues, and to consider making them a focus at the &lt;a href=&quot;http://portland2013.drupal.org/program/sprints&quot;&gt;DrupalCon Portland sprints&lt;/a&gt;.&lt;/p&gt;
&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
	<pubDate>Thu, 16 May 2013 16:30:33 +0000</pubDate>
</item>
<item>
	<title>Jochen Maes: Tribute To Mady</title>
	<guid>tag:https://blog.sejo-it.be,2013-05-16:tribute_to_mady.html</guid>
	<link>https://blog.sejo-it.be/tribute_to_mady.html</link>
	<description>&lt;p&gt;\\//,&lt;/p&gt;
&lt;p&gt;A month ago I posted a small text for Mady. Mady was a friend that carried a huge burden.&lt;/p&gt;
&lt;p&gt;She had &lt;a class=&quot;reference external&quot; href=&quot;https://en.wikipedia.org/wiki/Huntington's_disease&quot;&gt;Huntigton's disease&lt;/a&gt; , an illness that takes away pretty much everything you have control of, you can read about the specifics of the disease on the page I linked to.
I've been thinking a lot about what I can do to get more attention towards the disease. I can only do my small part and hope that others will too.&lt;/p&gt;
&lt;p&gt;As of now I will work 1 day per year for the &lt;a class=&quot;reference external&quot; href=&quot;http://www.huntingtonliga.be/&quot;&gt;Huntington Liga&lt;/a&gt; and hopefully more people will do this.
That day will be 10 June. Every year as of now. Why June 10th? Because it's her birthday.&lt;/p&gt;
&lt;p&gt;Whatever money I earn that day will go to the &lt;a class=&quot;reference external&quot; href=&quot;http://www.huntingtonliga.be/&quot;&gt;Huntington Liga&lt;/a&gt;, whether I work 10, 12 or 5 hours.&lt;/p&gt;
&lt;p&gt;I hope that will turn out to be Belgium's national Huntington's day, Mady would love that.&lt;/p&gt;
&lt;p&gt;Finally, the 5 companies/individuals that donate the most to the Liga will get me one full day to work for them for free, just mail me the payment proof!&lt;/p&gt;
&lt;p&gt;I hope I have to work at least 5 days for free this year.&lt;/p&gt;
&lt;p&gt;LLAP!&lt;/p&gt;</description>
	<pubDate>Thu, 16 May 2013 14:05:00 +0000</pubDate>
</item>
<item>
	<title>Wouter Verhelst: Single-stepping init systems</title>
	<guid>http://grep.be/blog/en/computer/debian/single_step_init</guid>
	<link>http://grep.be/blog/en/computer/debian/single_step_init</link>
	<description>&lt;img src=&quot;http://planet.grep.be/heads/wouter_verhelst&quot; alt=&quot;&quot; align=&quot;right&quot; style=&quot;float: right;&quot;&gt;&lt;p&gt;The Linux init systems are a bit in flux at the moment. That is,
they're in flux &lt;em&gt;in Debian&lt;/em&gt;; outside Debian, most other
distributions have stepped away from sysvinit and towards something else
(systemd, openrc, or upstart). I've not been a proponent of any switch,
though I understand the reasoning, and it probably makes sense for us to
switch at &lt;em&gt;some&lt;/em&gt; point. But yesterday, the fact that this
customer's system was running sysvinit and not systemd or upstart saved
me quite a bit.&lt;/p&gt;
&lt;p&gt;There's a server. It has one quadcore processor. For reasons that I
won't go into here, the customer wants an extra quadcore processor to be
added to the system.&lt;/p&gt;
&lt;p&gt;After having done so, I power on the system... only to see it power
itself off at some point during boot. I did notice &lt;em&gt;some&lt;/em&gt; kernel
messages fly by just moments before the system would power itself off,
but it was impossible for me to read them. So what did I do?&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;Boot the system with &lt;tt&gt;init=/bin/bash&lt;/tt&gt;,&lt;/li&gt;
&lt;li&gt;After having booted the system, go to &lt;tt&gt;/etc/rcS.d&lt;/tt&gt; and
manually run each and every one of the scripts there in turn. When the
system powers off, I know what the problem is.&lt;/li&gt;
&lt;li&gt;Disable the init script that causes the problem, and boot the system
normally.&lt;/li&gt;&lt;/ul&gt;
&lt;p&gt;That last bit is, obviously, a bit of an ugly workaround; the better
way to fix this issue would have been to debug what the &lt;em&gt;actual&lt;/em&gt;
issue was, and implement a proper fix. However, I didn't have time for
that (the fact that there was need for a second quadcore chip explains
how much this system is in use), and the workaround was acceptable for
the customer. It is not the first time that this ability to single-step
the init system has saved me. The fact that sysvinit is so simplistic is
what makes this possible, and I consider that one of its most important
features.&lt;/p&gt;
&lt;p&gt;Recently, I came into contact with a distribution that uses systemd
as its init system (in casu, Arch Linux). I had made a mistake in
configuration; I had installed and enabled a graphical login system, but
had no xterm or similar available, and had done something else wrong
through which I couldn't get a regular shell on the console anymore,
either. To fix this, I tried doing something like the above (running
with init=/bin/bash and single-stepping the init system), but found that
doing so with systemd is nigh impossible. In the end, I knew what
exactly the problem was and could disable automatically starting the
login manager through removing a symlink, but it brought home the issue
that debugging a similar issue when running systemd rather than sysvinit
might be a lot harder to do.&lt;/p&gt;
&lt;p&gt;We'll see what the future brings.&lt;/p&gt;</description>
	<pubDate>Thu, 16 May 2013 11:42:00 +0000</pubDate>
</item>
<item>
	<title>Mattias Geniar: Setting custom puppet facts from within your Vagrantfile</title>
	<guid>http://mattiasgeniar.be/?p=3994</guid>
	<link>http://feedproxy.google.com/~r/mattiasgeniar/~3/YVb4CS7AcHE/</link>
	<description>&lt;p&gt;You may want to set custom puppet facts in your development environment by specifying them in your Vagrantfile, so you can have a unique fact per developer or identify your own environment. Here's a quick way to do that.&lt;br /&gt;
&lt;span id=&quot;more-3994&quot;&gt;&lt;/span&gt;&lt;br /&gt;
First: make sure you are running the latest version of facter (yum update facter), it should be at least version 1.7 as it supports custom facts easily (check with 'facter --version').&lt;/p&gt;
&lt;pre&gt;$ facter --version
1.7.1&lt;/pre&gt;
&lt;p&gt;Now, before the Vagrantfile changes, your facter facts will look like this. The solution is within the :shell provider, in the first few lines of the Vagrantfile.&lt;/p&gt;
&lt;pre&gt;$ facter | grep 'custom'
[empty]&lt;/pre&gt;
&lt;p&gt;Your Vagrantfile can now be modified to look like this, to set up custom facts.&lt;/p&gt;
&lt;pre&gt;Vagrant::Config.run do |config|&lt;strong&gt;
  # First: run a shell provisioner to set up the custom facts
  config.vm.provision :shell do |shell|
    shell_cmd = &quot;&quot;

    # Make sure the facts directory exists
    shell_cmd &amp;lt;&amp;lt; &quot;mkdir -p /etc/facter/facts.d/; &quot;

    # Add as much of these lins for any custom fact you want
    shell_cmd &amp;lt;&amp;lt; &quot;echo 'custom_fact1=the value of the fact' &amp;gt; /etc/facter/facts.d/custom_fact1.txt; &quot;

    # Run the inline shell to create those facts
    shell.inline = &quot;#{shell_cmd}&quot;
  end
&lt;/strong&gt;
  # Then: run puppet like you normally would
  config.vm.provision :puppet do |puppet|
    puppet.manifests_path = &quot;manifests&quot;
    puppet.manifest_file = &quot;my_manifest.pp&quot;
  end
end&lt;/pre&gt;
&lt;p&gt;After a 'vagrant provision', your facts will be updated.&lt;/p&gt;
&lt;pre&gt;$ facter | grep custom
custom_fact1=the value of the fact&lt;/pre&gt;
&lt;p&gt;And you can now use the $::custom_fact1 variable within your manifests/modules.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Update 16/5&lt;/strong&gt;: as &lt;a href=&quot;https://github.com/dieterdemeyer&quot;&gt;Dieter De Meyer&lt;/a&gt; &lt;a href=&quot;https://gist.github.com/dieterdemeyer/5591083&quot;&gt;pointed out&lt;/a&gt;, there's a more elegant solution using the puppet provider itself. The downside is the facts are only available if you use 'vagrant provision' to start a Puppet run, if you use Puppet from within the virtual machine, these facts won't be present (see the &lt;a href=&quot;https://github.com/mattiasgeniar/puppet-vagrant_helper_scripts&quot;&gt;Vagrant Helper Scripts for Puppet&lt;/a&gt; to speed up your Puppet deployments).&lt;/p&gt;
&lt;pre&gt;Vagrant::Config.run do |config|
  config.vm.define :test do |vmconfig|
    vmconfig.vm.provision :puppet do |puppet|
      puppet.manifests_path = &quot;manifests&quot;
      puppet.manifest_file = &quot;test.pp&quot;
      puppet.module_path = [ &quot;../&quot;, &quot;./modules&quot; ]
      puppet.facter = {
        &quot;custom_fact1&quot; =&amp;gt; &quot;value1&quot;,
        &quot;custom_fact2&quot; =&amp;gt; &quot;value2&quot;
      }
      puppet.options = &quot;--verbose&quot;
    end
  end
end&lt;/pre&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;img height=&quot;1&quot; src=&quot;http://feeds.feedburner.com/~r/mattiasgeniar/~4/YVb4CS7AcHE&quot; width=&quot;1&quot; /&gt;</description>
	<pubDate>Wed, 15 May 2013 22:17:38 +0000</pubDate>
</item>
<item>
	<title>Lionel Dricot: Les faiseurs de pluie et de beau temps</title>
	<guid>http://ploum.net/?p=2850</guid>
	<link>http://ploum.net/post/faiseurs-de-pluie-et-de-beau-temps</link>
	<description>&lt;img src=&quot;http://planet.grep.be/heads/ploum100&quot; alt=&quot;&quot; align=&quot;right&quot; style=&quot;float: right;&quot;&gt;&lt;p&gt;Comme chaque année, &lt;a href=&quot;http://www.nestup.be/&quot;&gt;Nest’up&lt;/a&gt; tient ses promesses. Et la fournée 2015 ne semble pas faillir à la tradition. Parmi les heureux nominés, nous avons rencontré Géraldine et Fabien, initiateurs du projet MeteoroLogic.&lt;/p&gt;
&lt;p&gt;« C’est un module entièrement autonome que chacun peut imprimer chez lui moyennant l’achat de deux trois composants. Il est également possible de nous le commander déjà monté pour une somme modique. L’apport d’énergie est fait grâce à des capteurs ventouses éoliens et des petits panneaux solaires. » fait Fabien en nous présentant un parallélépipède cylindrique fraîchement sorti de son imprimante 3D.&lt;/p&gt;
&lt;p&gt;Géographe et météorologue de formation, le jeune homme avoue avoir toujours eu un faible pour l’électronique. « Je me construisais des stations météo de plus en plus sophistiquées. Mais j’avais du mal à me procurer certaines pièces. L’impression 3D a été une illumination et j’ai décidé de créer ma propre station. J’ai lancé un projet Kickstarter afin de pouvoir y consacrer mon été plutôt que de travailler dans un fast-food. En échange, j’ai élevé les plans de mon travail dans le domaine public. »&lt;/p&gt;
&lt;p&gt;C’est d’ailleurs suite à un article dans le journal de l’université intitulé « Les projets de nos étudiants » que Géraldine rencontrera Fabien. À cette époque, la future ingénieur en informatique se cherche un sujet de thèse de master en intelligence artificielle.&lt;/p&gt;
&lt;p&gt;« L’idée m’est venue un jour où j’ai vu mon flux Twitter se remplir de lamentations sur la pluie alors qu’à la fenêtre de mon kot, le soleil brillait. Quatre minutes plus tard, la drache s’abattait. Twitter avait été plus rapide que les nuages. Je me suis dit qu’on devrait pouvoir bâtir un modèle prédictif qui se base sur la position des tweets météo. Mais quand j’ai vu le projet de Fabien, j’ai tout de suite imaginé le potentiel de connecter ces stations en réseau, par internet. »&lt;/p&gt;
&lt;p&gt;Si le potentiel semble en effet intéressant, le modèle économique l’est moins : les plans sont disponibles gratuitement, le logiciel est open source et MeteoroLogic vend les stations météo au prix coûtant. D’ailleurs, les particuliers souhaitant avoir une station météo dans leur jardin ne sont probablement pas légion. Fabien nous détrompe.&lt;/p&gt;
&lt;p&gt;« Avec l’essor de la domotique, il devient très utile d’avoir une station météo ultra-personnalisée connectée à votre wifi qui vous donne la température exacte, le vent, l’humidité et peut prédire une averse à trois minutes près. Il est possible d’optimiser les périodes d’aération en hiver pour minimiser la perte de chaleur et, en été, au contraire de diminuer le besoin d’air conditionné. Tout est automatique et vous pouvez être averti sur votre smartphone dès qu’une pluie s’annonce afin de rentrer le linge qui sèche. Nous allons établir des partenariats avec les sociétés domotiques, ce qui devrait nous assurer un revenu. »&lt;/p&gt;
&lt;p&gt;Mais comment une simple station pourrait-elle faire des prévisions aussi précises ? C’est ici qu’intervient la thèse de Géraldine.&lt;/p&gt;
&lt;p&gt;« Imaginez des milliers de stations météo un peu partout dans le pays, connectées à Internet avec un GPS pour connaitre leur localisation précise. Chaque station va utiliser les informations issues des autres stations pour bâtir un modèle personnalisé du temps local. Techniquement, j’ai utilisé un réseau de neurones pour construire un modèle adaptatif. Chaque station météo découvre ses voisins et obtient leurs données à travers un protocole décentralisé inspiré par BitTorrent. Au départ, toutes les informations se valent, la station météo en Chine n’a a priori pas plus de valeur que celle du voisin. Mais, au fur et à mesure, les prédictions vont s’affiner tout en tenant compte des spécificités locales. La station va apprendre que si il pleut soudainement chez le voisin, la pluie locale ne tarde jamais alors que la météo en Chine ne semble pas avoir d’influence. Ce qui est génial, c’est que nous n’utilisons pas les modèles météorologiques traditionnels. »&lt;/p&gt;
&lt;p&gt;Chaque station utilise donc les autres pour affiner ses prédictions. Et plus il y aura de stations, au plus les prédictions seront précises. Mais les prédictions restent ultra locales.&lt;/p&gt;
&lt;p&gt;« Je travaille également à un modèle pour récupérer toutes ces informations et prédire le temps à un endroit arbitraire pourvu qu’il ne soit pas trop éloigné d’au moins une station. Cet algorithme ne sera pas open source car le but est de vendre cette carte météo globale à des acteurs comme les journaux, les aéroports, les entreprises. Mais toutes les données sont publiques, MeteoroLogic n’est pas dans une situation privilégiée : nous nous contentons de nous connecter à ce réseau de stations comme n’importe qui. C’est ce qui fait la beauté du projet : une fois que les plans et le code source de la station météo sont publiques, plus rien ne peut arrêter l’explosion de ce météo-web. »&lt;/p&gt;
&lt;p&gt;Le résultat sera-t-il à la hauteur des prédictions professionnelles ? Quelques stations d’un coût d’une petite centaine d’euros parviendront-elles à égaler les satellites lancés à grand frais en orbite géostationnaire ? Fabien et Géraldine l’espèrent. D’ailleurs, l’ESA, l’Agence Spatiale Européenne, a déjà annoncé suivre de très près les résultats des deux jeunes entrepreneurs.&lt;/p&gt;
&lt;p&gt; &lt;/p&gt;
&lt;p&gt;&lt;em&gt;Photo par &lt;a href=&quot;http://www.flickr.com/photos/11342119@N04/2747967301&quot;&gt;Retromoderns&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
 &lt;p&gt;&lt;a href=&quot;http://ploum.net/?flattrss_redirect&amp;amp;id=2850&amp;amp;md5=b9b6b0de90472a9dd45c36ee44741eb1&quot; target=&quot;_blank&quot; title=&quot;Flattr&quot;&gt;&lt;img alt=&quot;flattr this!&quot; src=&quot;http://ploum.net/wp-content/plugins/flattr/img/flattr-badge-large.png&quot; /&gt;&lt;/a&gt;&lt;/p&gt;</description>
	<pubDate>Tue, 14 May 2013 19:55:47 +0000</pubDate>
</item>
<item>
	<title>Tom Baeyens: The Case For Cases</title>
	<guid>tag:blogger.com,1999:blog-4309414151374220630.post-7444618973516309132</guid>
	<link>http://processdevelopments.blogspot.com/2013/05/the-case-for-cases.html</link>
	<description>Last year, the data produced in the world would fill DVD stack reaching from the Earth to moon and back. And it's growing exponentially. What does that mean for the enterprise?  Piles of data do not always result in more information.  On the contrary.&lt;br /&gt;&lt;br /&gt;Especially for people performing knowledge work, it means it becomes harder to sift through vast amounts of information sources and share the right information with the appropriate people.  It's not only time consuming, it's also risky.  Tweets, Google+, Facebook, Blogs and Press articles are abundant and have typically a low signal-to-noise ratio.  On top of that employees have to keep track of what's happening in their CRM, document management and many other enterprise systems.  This means a greater exposure to loads of data that becomes on average less relevant. Procrastination never had an easier job looking for susceptible victims.  &lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://icons.iconarchive.com/icons/aha-soft/business/256/Brief-case-icon.png&quot; style=&quot;clear: right; float: right; margin-bottom: 1em; margin-left: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;200&quot; src=&quot;http://icons.iconarchive.com/icons/aha-soft/business/256/Brief-case-icon.png&quot; width=&quot;200&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;a href=&quot;http://en.wikipedia.org/wiki/Advanced_case_management&quot; target=&quot;_blank&quot;&gt;A case management solution&lt;/a&gt; is a fancy word for a system to share and discuss important topics in an business environment.  It's function is to bring people together on topics like eg introducing a new sales strategy or an important customer that may cancel a big order.  A case is the most efficient instrument to share related documents, links and tasks for topics like that.  In other words, a case is a social collaboration space for a specific topic.&lt;br /&gt;&lt;br /&gt;To some extend, the scope of a case could be compared with an email discussion thread.  Before you bring it on, let me explain why that is a &lt;a href=&quot;https://www.google.com/search?q=the+problem+with+email&quot; target=&quot;_blank&quot;&gt;problem&lt;/a&gt;.  Email is ubiquitous and serves its purpose as the least common denominator for communication.  But using email has major drawbacks when used as the tool of collaboration.  First, you have to assume that people always hit Reply-All.  Reading a conversation where some people answer inline, some answer on top and some at the bottom is a challenge to say the least.  Searching the latest version of an attachment in a conversation is hard and error prone.  Involving someone later in an email discussion is hopeless as not everyone includes the whole discussion thread. &lt;br /&gt;&lt;br /&gt;Don't get me wrong, I'm not saying cases should replace email threads.  People will continue to leverage email as a unified inbox for the foreseeable future.  But cases provide a much better structure for information that is currently buried in the emails themselves.  I think we will see a shift towards email being the unified notification inbox and the content will be stored in dedicated systems like case management systems.&lt;br /&gt;&lt;br /&gt;For organizations larger then 10 people, it's a matter of professionalism to equip employees with a case management system.  It's the way to share relevant information in chaotic world with loads of noise and only a bit of signal.  People will be better informed and collaborating becomes simpler.  These improvements in the internal organization already justify adopting a case management system.  The bonus comes from collaborations with external business partners like prospects, clients and suppliers.  The advantages are just the same in this situation, and on top you show a professional approach to doing business.&lt;br /&gt;Regrettably, not all solutions use the term case for this concept.  Some solutions call it a task and others invent a new name.  But it should be clear that every organization deserves a solution for social collaboration and case management is a crucial aspect of that.</description>
	<pubDate>Tue, 14 May 2013 09:59:51 +0000</pubDate>
</item>
<item>
	<title>Jan Vansteenkiste: Working with git submodules: tips ‘n tricks</title>
	<guid>http://vstone.eu/?p=1346</guid>
	<link>http://vstone.eu/working-with-git-submodules-tips-n-tricks/</link>
	<description>&lt;p&gt;Some people hate it, nobody loves it, but it’s a good way to split codebase in different components/repositories.&lt;/p&gt;
&lt;p&gt;I have been using submodules a LOT for puppet development (all those puppet modules…). Some people might propose alternatives (puppet-tree, librarian), but I rather stick with what I already know.&lt;/p&gt;
&lt;p&gt;Dealing with submodules in git is mainly painful because the parent repository doesn’t really know/care what is inside the submodule. He only keeps track of the hash that links the commit. Another downside is that your submodules mostly always end up in a detached state and after checking out a branch, you kinda forget on what commit the parent repository has.&lt;/p&gt;
&lt;p&gt;You can put them in your ~/.gitconfig file in the alias section:&lt;/p&gt;
&lt;h2&gt;git tags&lt;/h2&gt;
&lt;p&gt;Little different from the default git tag: Uses sort to do natural sort with version numbers. Note, your sort version must be new enough.&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;tags = !sh -c 'git tag | sort -V'&lt;/code&gt;&lt;/pre&gt;
&lt;h2&gt;git update&lt;/h2&gt;
&lt;p&gt;Run in the root of the ‘parent’ repository&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;update = !sh -c 'git pull &amp;amp;&amp;amp; git fetch --tags &amp;amp;&amp;amp; git submodule update --recursive &amp;amp;&amp;amp; git submodule foreach git tag -f parent-$(git describe --contains --all HEAD)'&lt;/code&gt;&lt;/pre&gt;
&lt;ol&gt;
&lt;li&gt;Pull from the remote&lt;/li&gt;
&lt;li&gt;Fetch remote tags&lt;/li&gt;
&lt;li&gt;Update submodules (recursive)&lt;/li&gt;
&lt;li&gt;Create a tag on each submodule called parent-BRANCH with BRANCH being the branch the current parent repository is on&lt;/li&gt;
&lt;/ol&gt;
&lt;h2&gt;git noparent&lt;/h2&gt;
&lt;p&gt;Removes the parent-* tags from all repositories (recursive).&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;noparent = !sh -c 'git tag -d $(git tag | grep ^parent ) &amp;amp;&amp;amp;  git submodule foreach git noparent'&lt;/code&gt;&lt;/pre&gt;
&lt;ol&gt;
&lt;li&gt;Remove all tags matching ^parent&lt;/li&gt;
&lt;li&gt;Do the same for each submodule (recursive)&lt;/li&gt;
&lt;/ol&gt;
&lt;h2&gt;git safepush&lt;/h2&gt;
&lt;p&gt;Remove parent tags, make sure we don’t create a merge commit and push.&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;safepush = !sh -c 'git noparent &amp;amp;&amp;amp; git pull --rebase &amp;amp;&amp;amp; git push &amp;amp;&amp;amp; git push --tags'&lt;/code&gt;&lt;/pre&gt;
&lt;ol&gt;
&lt;li&gt;Remove parent tags, we don’t want to push them by accident&lt;/li&gt;
&lt;li&gt;Fetch remote changes and rebase&lt;/li&gt;
&lt;li&gt;Push push push!&lt;/li&gt;
&lt;/ol&gt;
&lt;h2&gt;git pushtags&lt;/h2&gt;
&lt;p&gt;Remove parent tags and push all the tags.&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;pushtags = !sh -c 'git noparent &amp;amp;&amp;amp; git push --tags'&lt;/code&gt;&lt;/pre&gt;
&lt;ol&gt;
&lt;li&gt;Remove the parent tags we have set&lt;/li&gt;
&lt;li&gt;Push tags&lt;/li&gt;
&lt;/ol&gt;</description>
	<pubDate>Tue, 14 May 2013 05:35:51 +0000</pubDate>
</item>
<item>
	<title>Patrick Debois: Compiling a nodejs projects as a single binary</title>
	<guid>http://www.jedi.be/blog/2013/05/14/Compiling - packaging a nodejs project as a single binary/</guid>
	<link>http://feedproxy.google.com/~r/jedi/IZwx/~3/qRTb1uLPo4A/</link>
	<description>&lt;p&gt;Let's face it, if you write software it's often hard to distribute it: you have the runtime , the modules you depend on and your software itself. Sure you can package that all but packages ofter require you to have root-privileges to install.&lt;/p&gt;

&lt;p&gt;Therefore at times it's convenient to have a single file/binary distribution. Download the executable and run it.
For ruby project you can convert things into a single jar using Jruby. A good example is the &lt;a href=&quot;http://logstash.net&quot;&gt;logstash&lt;/a&gt; project: download 1 file , run it and you're in business.
But you'd still require the java runtime to be installed. (thanks Apple, NOT).&lt;/p&gt;

&lt;p&gt;This is a extra of the GO language but I was looking for a similar thing for &lt;strong&gt;nodejs&lt;/strong&gt;.
And the following documentation is the closest I could it get: (it works!)&lt;/p&gt;

&lt;h2&gt;Compiling plain javascript (no external modules)&lt;/h2&gt;

&lt;p&gt;Enter &lt;a href=&quot;https://github.com/crcn/nexe&quot;&gt;nexe&lt;/a&gt; a tool to compile nodejs projects to an executable binary.&lt;/p&gt;

&lt;p&gt;The way it works is:
- it downloads the &lt;a href=&quot;http://nodejs.org/download/&quot;&gt;nodejs source&lt;/a&gt; of your choice
- it creates a single file nodejs source (using &lt;a href=&quot;https://github.com/crcn/sardines&quot;&gt;sardines&lt;/a&gt; )
- it monkey patches the nodejs code to include this single file in the binary (adding it to the lib/nexe.js directory)&lt;/p&gt;

&lt;p&gt;Creating a binary is as simple as:&lt;/p&gt;

&lt;pre&gt;$ nexe -i myproject.js -o myproject.bin -r 0.10.3&lt;/pre&gt;


&lt;p&gt;Caveats:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;I had an issue with unicode chars that got converted: it uses uglify.js and this needs to be configured to leave them alone
&lt;a href=&quot;https://github.com/crcn/sardines/pull/13&quot;&gt;Sardines Patch Unichode&lt;/a&gt; . This was necessary to get &lt;a href=&quot;https://github.com/c3ks/terminal.js&quot;&gt;terminal.js&lt;/a&gt; to compile&lt;/li&gt;
&lt;li&gt;Next issue was to get &lt;a href=&quot;https://github.com/LearnBoost/socket.io-client&quot;&gt;socket.io-client&lt;/a&gt; to compile: the swfobject has document and navigator objects, so this had to be fixed as well - &lt;a href=&quot;https://github.com/crcn/sardines/pull/14&quot;&gt;Sardines Patch Document &amp;amp; Navigator&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;


&lt;p&gt;Alternatives:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/rogerwang/node-webkit/wiki/How-to-package-and-distribute-your-apps&quot;&gt;Node-webkit&lt;/a&gt; to package nodejs apps that require UI interaction&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;http://tidesdk.multipart.net/docs/user-dev/generated/&quot;&gt;http://tidesdk.multipart.net/docs/user-dev/generated/&lt;/a&gt; - seems similar but could not really grasp it&lt;/li&gt;
&lt;li&gt;AppJS - &lt;a href=&quot;http://appjs.org/#why&quot;&gt;http://appjs.org/#why&lt;/a&gt; - aims to create HTML5/Javascript native apps&lt;/li&gt;
&lt;li&gt;NPKG - &lt;a href=&quot;https://github.com/wearefractal/npkg&quot;&gt;https://github.com/wearefractal/npkg&lt;/a&gt; - old but interesting code&lt;/li&gt;
&lt;/ul&gt;


&lt;h2&gt;Embedding a native module (in the nodejs binary)&lt;/h2&gt;

&lt;p&gt;Many of these single packaging tools, suffer from the problem of handline native modules.&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;https://github.com/crcn/nexe&quot;&gt;nexe&lt;/a&gt; doesn't handle native modules (yet).&lt;/p&gt;

&lt;p&gt;But with a little persistance and creativity, this is what I did to add the &lt;a href=&quot;https://github.com/chjj/pty.js/&quot;&gt;pty.js&lt;/a&gt; native module directly to the nodejs binary&lt;/p&gt;

&lt;pre&gt;$ tar -xzvf node-v0.8.21.tar.gz
$ cd node-v0.8.21

# Copy the native code in the src directory
# If there is a header file copy/adapt it too
$ cp ~/dev/terminal.js/node_modules/pty.js/src/unix/pty.cc src/node_pty.cc

# Correct the export name of the module
# Add the node_ prefix to the node_module name
# Last line should read - NODE_MODULE(node_pty, init)

# add node_pty to src/node_extensions.h (f.e. right after node_zlib)
# NODE_EXT_LIST_ITEM(node_pty)

# Copy the pty.js file
$ cp ~/dev/pty.js/lib/pty.js lib/pty.js

# Add the pty.js to the node.gyp
# Somewhere in the library list add pty.js
# Somewhere in the source list add node_pty.cc

# Adapt the namings/bindings in lib/pty.js
# 1) replace: var pty = require('../build/Release/pty.node');
#    with: var binding = process.binding('pty');
# 2) replace all references to pty. to binding.

$ make clean
$ ./configure
$ make

&lt;/pre&gt;


&lt;p&gt;Now you have a custom build &lt;strong&gt;node&lt;/strong&gt; in &lt;strong&gt;out/Release/node&lt;/strong&gt;
The filesize was about 10034856 , you can further strip it and 6971192 (6.6M)&lt;/p&gt;

&lt;p&gt;Now you need to remove the native dependency from your package.json before you nexe build it&lt;/p&gt;

&lt;h2&gt;Packaging the file&lt;/h2&gt;

&lt;p&gt;A single binary now makes it easy to to make a curl installer from it as it only requires you to download file. &lt;a href=&quot;http://spin.atomicobject.com/2011/11/23/considered-harmful/&quot;&gt;Remember the caveat of this.&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;And you can still package it up:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;create a rpm, deb, etc.. package from it using &lt;a href=&quot;https://github.com/jordansissel/fpm&quot;&gt;fpm&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;or create a native MacOSX .app file from it as &lt;a href=&quot;https://twitter.com/mathias&quot;&gt;Matthias Bynens&lt;/a&gt; suggest in &lt;a href=&quot;http://mathiasbynens.be/notes/shell-script-mac-apps&quot;&gt;http://mathiasbynens.be/notes/shell-script-mac-apps&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/subtleGradient/Appify-UI&quot;&gt;https://github.com/subtleGradient/Appify-UI&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;http://blog.coolaj86.com/articles/how-to-create-an-osx-pkg-installer.html&quot;&gt;http://blog.coolaj86.com/articles/how-to-create-an-osx-pkg-installer.html&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;build a DMG - &lt;a href=&quot;http://www.recital.com/index.php?option=com_content&amp;amp;view=article&amp;amp;id=108%3Ahowto-build-a-dmg-file-from-the-command-line-on-mac-os-x&amp;amp;Itemid=59&quot;&gt;http://www.recital.com/index.php?option=com_content&amp;amp;view=article&amp;amp;id=108%3Ahowto-build-a-dmg-file-from-the-command-line-on-mac-os-x&amp;amp;Itemid=59&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;


&lt;h2&gt;Extras&lt;/h2&gt;

&lt;p&gt;&lt;a href=&quot;https://groups.google.com/forum/#!topic/nodejs/mPIcq5mHihM&quot;&gt;Rant about why it's a good or bad Idea - Secure Nodejs distribution&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;More info on the process.binding:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;http://blog.carbonfive.com/2011/03/14/node-js-part-ii-spelunking-in-the-code/&quot;&gt;http://blog.carbonfive.com/2011/03/14/node-js-part-ii-spelunking-in-the-code/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://groups.google.com/forum/?fromgroups#!topic/nodejs/R5fDzBr0eEk&quot;&gt;https://groups.google.com/forum/?fromgroups#!topic/nodejs/R5fDzBr0eEk&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;


&lt;p&gt;Convert nodejs projects to single file/beautifier:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Npk - &lt;a href=&quot;https://github.com/cfsghost/npk&quot;&gt;https://github.com/cfsghost/npk&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;UglifyJS - &lt;a href=&quot;https://github.com/mishoo/UglifyJS/&quot;&gt;https://github.com/mishoo/UglifyJS/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;RequireJS - &lt;a href=&quot;http://requirejs.org/&quot;&gt;http://requirejs.org/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Browserify - &lt;a href=&quot;http://browserify.org/&quot;&gt;http://browserify.org/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;OneJS - &lt;a href=&quot;https://github.com/azer/onejs&quot;&gt;https://github.com/azer/onejs&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;


&lt;p&gt;Cross compiling:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/felixge/node-cross-compiler&quot;&gt;https://github.com/felixge/node-cross-compiler&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;http://n8.io/cross-compiling-nodejs-v0.8/&quot;&gt;http://n8.io/cross-compiling-nodejs-v0.8/&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description>
	<pubDate>Tue, 14 May 2013 05:35:34 +0000</pubDate>
</item>
<item>
	<title>Xavier Mertens: Improving File Integrity Monitoring with OSSEC</title>
	<guid>http://blog.rootshell.be/?p=21440</guid>
	<link>http://blog.rootshell.be/2013/05/13/improving-file-integrity-monitoring-with-ossec/</link>
	<description>&lt;p style=&quot;text-align: justify;&quot;&gt;&lt;img alt=&quot;File Integrity Error&quot; class=&quot;alignleft size-full wp-image-21444&quot; height=&quot;126&quot; src=&quot;http://blog.rootshell.be/wp-content/uploads/2013/05/file-integrity-violated.jpg&quot; width=&quot;179&quot; /&gt;FIM or “&lt;em&gt;File Integrity Monitoring&lt;/em&gt;” can be defined as the process of validating the integrity of operating system and applications files with a verification method using a hashing algorythm like MD5 or SHA1 and then comparing the current file state with a baseline. A hash will allow the detection of files content modification but other information can be checked too: owner, permissions, modification time. Implemeting file integrity monitoring is a very good way to detect compromized servers. Not only operating system files can be monitored (/etc on UNIX, registry on Windows, share libraries, etc) but also applications (monitoring your index.php or index.html can reveal a defaced website).&lt;/p&gt;
&lt;p style=&quot;text-align: justify;&quot;&gt;During its implementation, a file integrity monitoring project may face two common issues:&lt;/p&gt;
&lt;ul&gt;
&lt;li style=&quot;text-align: justify;&quot;&gt;&lt;span style=&quot;line-height: 13px;&quot;&gt;The baseline used to be compared with the current file status must of course be trusted. To achieve this, it must be stored on a safe place where attacker cannot detect it and cannot alter it!&lt;/span&gt;&lt;/li&gt;
&lt;li style=&quot;text-align: justify;&quot;&gt;The process must be fine tuned to react only on important changes otherwise they are two risks: The real suspicious changes will be hidden in the massive flow of false-positives. People in charge of the control could miss interesting changes.&lt;/li&gt;
&lt;/ul&gt;
&lt;p style=&quot;text-align: justify;&quot;&gt;There are plenty of tools which implement FIM, commercial as well as free. My choice went to &lt;a href=&quot;http://www.ossec.net&quot; title=&quot;Link to the OSSEC website&quot;&gt;OSSEC&lt;/a&gt; for a while. My regular followers know that I already posted lot of articles about it. I also contributed to the project with a patch to add &lt;a href=&quot;http://blog.rootshell.be/2012/06/05/attackers-geolocation-in-ossec/&quot; title=&quot;Link to the blog article&quot;&gt;Geolocatization&lt;/a&gt; to alerts. This time, I wrote another patch to improve the file integraty monitoring feature of OSSEC.&lt;/p&gt;
&lt;p style=&quot;text-align: justify;&quot;&gt;&lt;span id=&quot;more-21440&quot;&gt;&lt;/span&gt;FIM has been part of the OSSEC &lt;a href=&quot;http://www.ossec.net/?page_id=165&quot; title=&quot;Link to the OSSEC features page&quot;&gt;features&lt;/a&gt; for a while and is handled by the syscheckd daemon running on all agents. How does OSSEC address the common issues reported above? To keep the baseline integrity, the databases of files (or registry for Windows agents) are stored on the manager itself. This manager is normally a well-protected server where all the OSSEC intelligence is stored. About false-positives, OSSEC implement several ways to prevent them. &lt;span style=&quot;line-height: 13px;&quot;&gt;Some files can be ignored with an &amp;lt;ignore&amp;gt; XML tag in ossec.conf:&lt;/span&gt;&lt;/p&gt;
&lt;pre&gt;&amp;lt;syscheck&amp;gt;
    &amp;lt;ignore&amp;gt;/etc/mnttab&amp;lt;/ignore&amp;gt;
&amp;lt;/syscheck&amp;gt;&lt;/pre&gt;
&lt;p style=&quot;text-align: justify;&quot;&gt;&lt;span style=&quot;line-height: 13px;&quot;&gt;This is easy to exclude files but it’s a pain to manage! Some files can be excluded using specific OSSEC rules:&lt;/span&gt;&lt;/p&gt;
&lt;pre&gt;&amp;lt;rule id=&quot;100000&quot; level=&quot;0&quot; &amp;gt;
    &amp;lt;if_group&amp;gt;syscheck&amp;lt;/if_group&amp;gt;
    &amp;lt;description&amp;gt;Ignored file changes&amp;lt;/description&amp;gt;
    &amp;lt;match&amp;gt;/etc/mnttb|/etc/hosts|/etc/resolv.conf&amp;lt;/match&amp;gt;
    &amp;lt;hostname&amp;gt;srv1&amp;lt;/hostname&amp;gt;
&amp;lt;/rule&amp;gt;&lt;/pre&gt;
&lt;p style=&quot;text-align: justify;&quot;&gt;This rule will disable notification if any change is detected on srv1 in /etc/mnttab, /etc/hosts or /etc/resolv.conf. Note that another control exists: B&lt;span style=&quot;line-height: 13px;&quot;&gt;y default when a file has changed three times, new changes will be automatically ignored. Handy but… it could be improved!&lt;/span&gt;&lt;/p&gt;
&lt;p style=&quot;text-align: justify;&quot;&gt;When I’m deploying security tools and control, my goal is to reduce the “noise” as much as possible. A side effect of file integrity monitoring is the number of false positive alerts generated when patching your systems. Keeping the latest patch level is important but hundreds of files can be replaced only by one new package! That’s why I wrote the following patch for OSSEC (more precisely for the analysisd daemon which is responsible of the decoding and alerting of events generated by agents).&lt;/p&gt;
&lt;p style=&quot;text-align: justify;&quot;&gt;I added a SQLite3 DB which contains a list of MD5 hashes to ignore when reported by agents. When a file change is reported, its &lt;strong&gt;NEW&lt;/strong&gt; MD5 hash is looked up in the DB. If found, the change is ignored. Why an external SQL database to store the hashes? To be easily populated by external tools as seen in the following schema:&lt;/p&gt;
&lt;p style=&quot;text-align: justify;&quot;&gt;&lt;img alt=&quot;OSSEC-FIM-MD5&quot; class=&quot;aligncenter size-medium wp-image-21468&quot; height=&quot;225&quot; src=&quot;http://blog.rootshell.be/wp-content/uploads/2013/05/OSSEC-FIM-MD5-300x225.png&quot; width=&quot;300&quot; /&gt;&lt;/p&gt;
&lt;p style=&quot;text-align: justify;&quot;&gt;To active this feature, apply the patch, create a SQLite3 database:&lt;/p&gt;
&lt;pre&gt;CREATE TABLE files (
    md5sum VARCHAR(32),
    file VARCHAR(256),
    time DATETIME
);
CREATE UNIQUE INDEX files_idx ON files(md5sum);&lt;/pre&gt;
&lt;p style=&quot;text-align: justify;&quot;&gt;Then, just define the MD5 database in the main ossec.conf file on your OSSEC server:&lt;/p&gt;
&lt;pre style=&quot;text-align: justify;&quot;&gt;&amp;lt;global&amp;gt;
    &amp;lt;md5db&amp;gt;/etc/md5.db&amp;lt;/md5db&amp;gt;
&amp;lt;/global&amp;gt;&lt;/pre&gt;
&lt;p style=&quot;text-align: justify;&quot;&gt;This database must contains all the MD5 hashes that you want to ignore. On Ubuntu, it’s easy to find all hashes of installed files in /var/lib/dpkg/info/*.md5sums. I wrote a simple Python script to read those files and populate the SQL database.&lt;/p&gt;
&lt;pre&gt;#!/usr/bin/python&lt;/pre&gt;
&lt;pre&gt;import fnmatch
import os
import sqlite3
import signal
import sys
def signal_handler(signal, frame):
    print &quot;Interrupted!&quot;
    if (conn):
        conn.commit()
        conn.close()
    sys.exit(0)
signal.signal(signal.SIGINT, signal_handler)
conn = sqlite3.connect('/opt/ossec/etc/md5db.db')
for file in os.listdir('/var/lib/dpkg/info'):
    if fnmatch.fnmatch(file, '*.md5sums'):
        c = conn.cursor()
        f = open('/var/lib/dpkg/info/' + file, 'r')
        l = f.readline()
        while l:
            array = l.split()
        try:
            c.execute('INSERT INTO files VALUES(&quot;' + array[0] + '&quot;,&quot;' + \
                      array[1] + '&quot;,date(&quot;now&quot;))')
        except sqlite3.Error, e:
        print &quot;%s: %s&quot; % (array[0], e.args[0])
        l = f.readline()
        conn.commit()
        f.close()
conn.close()&lt;/pre&gt;
&lt;p style=&quot;text-align: justify;&quot;&gt;After every new patch installation on my Ubuntu, the database is updated with new MD5′s. As the FIM process is executed every 6 hours (default setting) by OSSEC, you have time to update the database and reduce the false positives alerts.&lt;/p&gt;
&lt;p style=&quot;text-align: justify;&quot;&gt;The patch is available &lt;a href=&quot;http://blog.rootshell.be/wp-content/uploads/2013/05/ossec-hids-2.7.md5-patch.diff&quot; title=&quot;Link to the OSSEC patch&quot;&gt;here&lt;/a&gt;.&lt;/p&gt;
&lt;img height=&quot;1&quot; src=&quot;http://feeds.feedburner.com/~r/dev/rand/~4/7vItUl5CdJo&quot; width=&quot;1&quot; /&gt;</description>
	<pubDate>Mon, 13 May 2013 15:00:05 +0000</pubDate>
</item>
<item>
	<title>Thomas Vander Stichele: morituri and Hidden Track One Audio</title>
	<guid>http://thomas.apestaart.org/log/?p=1545</guid>
	<link>http://thomas.apestaart.org/log/?p=1545</link>
	<description>&lt;p&gt;I have tomorrow (saturday) blocked out for a whole day of &lt;a href=&quot;https://thomas.apestaart.org/morituri/trac&quot;&gt;morituri&lt;/a&gt; hacking as I will be home alone.&lt;/p&gt;
&lt;p&gt;One of the things a lot of morituri users are puzzled by is its relentless drive to extract every single sample of audio from the CD.  Currently, even if it’s a really short pre-gap, and most likely just an inaccurate master or burn, with no useful audio in it.&lt;/p&gt;
&lt;p&gt;For me, that was a design goal of morituri – I want to be able to exactly reproduce a CD as is.  That is to say, ripping a CD should extract *all* audio from the CD, and it should be possible to make a copy of that CD and then rip that copy, and end up with exactly the same result as from the original CD.  (I’m sure there’s a fancy scientific term for that that I can’t remember right now)&lt;/p&gt;
&lt;p&gt;To a lot of other people, it seems to be annoying and they don’t like having those small almost empty files lying around.&lt;/p&gt;
&lt;p&gt;So I thought I’d do something about that, and that it might be useful as well to analyze my current collection of tracks and figure out what’s in there.  Maybe I can find some hidden gems that I hadn’t noticed before?&lt;/p&gt;
&lt;p&gt;So I added a quick task to morituri that calculates the maximum sample value (I didn’t want to use my own level element in GStreamer for this as I wanted to make sure it was actual digital zero; this should be done in an element instead though, but I preferred the five minute hack for this one).&lt;/p&gt;
&lt;p&gt;And then I ran:&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;
rip debug maxsample /mnt/nas/media/audio/rip/morituri/own/album/*/00*flac
&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;Sadly, that turned up 0 as the biggest sample for all these tracks!&lt;/p&gt;
&lt;p&gt;Wait, what? I spent all that time on getting those secret tracks ripped just to get none? That’s not possible! I know some of those tracks!&lt;/p&gt;
&lt;p&gt;Maybe the algorithm is wrong.  Nope, it works fine on all the regular tracks.&lt;/p&gt;
&lt;p&gt;Oh, crap.  Maybe morituri has been ripping silence all this time because my CD drive can’t get that data off.  Yikes, that would be a bit of egg on my face.&lt;/p&gt;
&lt;p&gt;No, it works if I check that Bloc Party track I know about.&lt;/p&gt;
&lt;p&gt;Ten minutes of staring at the screen to realize that, while I was outputting names from a variable from the for loop over my arguments, the track I was actually passing to the task was always the first one.  Duh.  Problem solved.&lt;/p&gt;
&lt;p&gt;As for what I found in my collection:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;a cute radio jingle that brought back memories from a live bootleg I had made myself of Bloem.  That’s from over ten years ago, but that must have been around the time I learned about the existence of HTOA and wanted to get one in&lt;/li&gt;
&lt;li&gt;found unknown HTOA tracks on Art Brut’s Bang Bang Rock &amp;amp; Roll, Mew’s Half the world is watching me; not their best stuff&lt;/li&gt;
&lt;li&gt;soundscapey or stagesetting tracks on QOTSA’s Songs for the Deaf, Motorpsycho’s Angels and Daemons at play And Blissard; not that worth it (the Blissard track was ok, but really quiet)&lt;/li&gt;
&lt;li&gt;
Pulp hid a single piano chord in a 2 second pre-gap on This is Hardcore; very curious.  It’s not an intro to the first track, because it doesn’t fit with the sound at all.
&lt;/li&gt;
&lt;li&gt;Damien Rice hid a demo version of 9 Crimes (the first track) in the pregap; instead of piano and female vocals, he plays guitar and sings all the parts.&lt;/li&gt;
&lt;li&gt;Got reacquainted with my favourite HTOA tracks: the orchestral quasi-wordless medley on the Luke Haines/Das Capital disc; the first Bloc Party album with a beautiful instrumental (up there with the hidden track at the end of Placebo’s first album; both bands delivering an atypical but stunning moodscape; the beautiful cover of Ben Kenobi’s Theme by Arab Strap on the Cherubs EP (no idea why that landed in my album dir, that needs to be fixed); the silly Soulwax skit for their second album.
&lt;/li&gt;&lt;/ul&gt;
&lt;p&gt;Of course, Wikipedia has the &lt;a href=&quot;http://en.wikipedia.org/wiki/List_of_albums_with_tracks_hidden_in_the_pregap&quot;&gt;last word on everything&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;I note that they think Pulp recorded a cymbal, not a piano.  And now that I see the title of the QOTSA hidden track, I get the joke I think.&lt;/p&gt;
&lt;p&gt;In total, on my album collection of 1564 full CD’s, I have 171 HTOA’s ripped, 138 tracks of pure digital silence, and only about 11 are actually useful tracks.&lt;/p&gt;
&lt;p&gt;I expected to find more gems in my collection.  I’ll go through ep’s, singles and compilations next just to be sure.&lt;/p&gt;
&lt;p&gt;But with this code in hand, maybe it’s time to add something to morituri to save the silent HTOA tracks as pure .cue information.&lt;/p&gt;</description>
	<pubDate>Fri, 10 May 2013 20:38:04 +0000</pubDate>
</item>
<item>
	<title>Frank Goossens: Music from Our Tube; Harper Blynn</title>
	<guid>http://blog.futtta.be/?p=8821</guid>
	<link>http://feedproxy.google.com/~r/futtta/~3/KXW5v_ciihc/</link>
	<description>&lt;p&gt;“Knife” is great songwriting by New York’s &lt;a href=&quot;http://www.harperblynn.com/&quot; title=&quot;J. Blynn &amp;amp; Pete Harper actually&quot;&gt;Harper Blynn&lt;/a&gt;, performed live on a balcony in not-so-sunny LA for &lt;a href=&quot;http://www.balconytv.com/&quot; title=&quot;Balcony TV&quot;&gt;BalconyTV&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;http://blog.futtta.be/2013/05/10/music-from-our-tube-harper-blynn/&quot;&gt;&lt;img alt=&quot;YouTube Video&quot; src=&quot;http://i.ytimg.com/vi/aDBe0ErmpDU/0.jpg&quot; /&gt;&lt;/a&gt;&lt;br /&gt;Watch this video &lt;a href=&quot;http://youtu.be/aDBe0ErmpDU&quot;&gt;on YouTube&lt;/a&gt; or on &lt;a href=&quot;http://icant.co.uk/easy-youtube/?http://www.youtube.com/watch?v=aDBe0ErmpDU&quot;&gt;Easy Youtube&lt;/a&gt;.&lt;/p&gt;&lt;div class=&quot;yarpp-related-rss&quot;&gt;&lt;p&gt;Possibly related twitterless twaddle:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;a href=&quot;http://blog.futtta.be/2013/04/22/music-from-our-tube-laura-mvula/&quot; rel=&quot;bookmark&quot; title=&quot;Music from Our Tube; Laura Mvula&quot;&gt;Music from Our Tube; Laura Mvula&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://blog.futtta.be/2013/05/03/music-from-our-tube-seelenluft/&quot; rel=&quot;bookmark&quot; title=&quot;Music from Our Tube; Seelenluft&quot;&gt;Music from Our Tube; Seelenluft&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://blog.futtta.be/2009/08/07/voila-le-tube-dete/&quot; rel=&quot;bookmark&quot; title=&quot;Voila le tube d’été!&quot;&gt;Voila le tube d’été!&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;/div&gt; &lt;div class=&quot;feedflare&quot;&gt;
&lt;a href=&quot;http://feeds.feedburner.com/~ff/futtta?a=KXW5v_ciihc:9IILbYcZR7A:D7DqB2pKExk&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;http://feeds.feedburner.com/~ff/futtta?i=KXW5v_ciihc:9IILbYcZR7A:D7DqB2pKExk&quot; /&gt;&lt;/a&gt; &lt;a href=&quot;http://feeds.feedburner.com/~ff/futtta?a=KXW5v_ciihc:9IILbYcZR7A:yIl2AUoC8zA&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;http://feeds.feedburner.com/~ff/futtta?d=yIl2AUoC8zA&quot; /&gt;&lt;/a&gt; &lt;a href=&quot;http://feeds.feedburner.com/~ff/futtta?a=KXW5v_ciihc:9IILbYcZR7A:qj6IDK7rITs&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;http://feeds.feedburner.com/~ff/futtta?d=qj6IDK7rITs&quot; /&gt;&lt;/a&gt; &lt;a href=&quot;http://feeds.feedburner.com/~ff/futtta?a=KXW5v_ciihc:9IILbYcZR7A:I9og5sOYxJI&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;http://feeds.feedburner.com/~ff/futtta?d=I9og5sOYxJI&quot; /&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img height=&quot;1&quot; src=&quot;http://feeds.feedburner.com/~r/futtta/~4/KXW5v_ciihc&quot; width=&quot;1&quot; /&gt;</description>
	<pubDate>Fri, 10 May 2013 13:42:50 +0000</pubDate>
</item>
<item>
	<title>Frank Goossens: Dude, where’s my WordPress session?</title>
	<guid>http://blog.futtta.be/?p=8807</guid>
	<link>http://feedproxy.google.com/~r/futtta/~3/7fLOllavSSg/</link>
	<description>&lt;p&gt;WordPress is a &lt;strong&gt;favourite hackers target&lt;/strong&gt;. Some say that is because it is inherently insecure, but in reality WordPress is mainly a target because of its &lt;strong&gt;popularity&lt;/strong&gt;, because of people not keeping their &lt;strong&gt;installations up to date&lt;/strong&gt; or &lt;a href=&quot;http://engineeringevil.com/2013/04/16/massive-brute-force-attack-targets-wordpress-sites-worldwide/&quot; title=&quot;random article about the brute force &amp;quot;tsunami&amp;quot;&quot;&gt;using &lt;strong&gt;easy to guess usernames&lt;/strong&gt; and passwords&lt;/a&gt; and because of &lt;strong&gt;&lt;a href=&quot;http://www.zionsecurity.com/blog/2013/04/how-web-malware-steals-your-wordpress-and-database-passwords-using-php&quot; title=&quot;zionsecurity: timthumb exploit to harvest wp-config.php&quot;&gt;vulnerabilities&lt;/a&gt; &lt;a href=&quot;http://blog.futtta.be/2013/04/18/wp-caching-plugin-vulnerability-debrief/&quot; title=&quot;WP Caching plugin vulnerability debrief&quot;&gt;in plugins&lt;/a&gt;&lt;/strong&gt; rather then WordPress itself.&lt;/p&gt;&lt;p&gt;There is, however, &lt;strong&gt;one security-related shortcoming&lt;/strong&gt; in WordPress from a design point of view: &lt;strong&gt;sessions are not stored server-side&lt;/strong&gt;. If someone logs in, a cookie is set in the browser containing username, a session expiration timestamp and a hash. With every new request to WordPress that cookie (and specifically the hash) is checked to validate the session, but there is no check to see if there indeed was such a session.&lt;/p&gt;&lt;p&gt;This can be considered mainly a &lt;strong&gt;theoretical shortcoming&lt;/strong&gt;, not an immediately exploitable vulnerability, because;&lt;/p&gt;&lt;ol&gt;&lt;li&gt;session-cookies are set with the &lt;strong&gt;HTTPOnly-flag so XSS&lt;/strong&gt; should not be an issue&lt;/li&gt;&lt;li&gt;in an ideal world all traffic, once logged in, would be over &lt;strong&gt;HTTPS, securing against network sniffing&lt;/strong&gt;.&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;But there are other (albeit less obvious) ways to &lt;strong&gt;steal cookies or even create create new ones&lt;/strong&gt; to gain unauthorized access, as demonstrated in &lt;a href=&quot;http://blog.spiderlabs.com/2013/04/jamming-with-wordpress-sessions.html&quot; title=&quot;spiderlabs jams with wordpress sessions&quot;&gt;this very detailed blogpost&lt;/a&gt;. As explained in that article, there is no way to block “fake” session-cookies from gaining access (your &lt;a href=&quot;http://blog.futtta.be/2013/01/03/and-now-you-can-even-have-my-wordpress-password/&quot; title=&quot;And now you can even have my WordPress password!&quot;&gt;OTP plugin&lt;/a&gt; won’t protect you either) and there is no functionality to monitor and if needed delete sessions.&lt;/p&gt;&lt;p&gt;So … I wrote &lt;strong&gt;a small proof-of-concept plugin&lt;/strong&gt; that gets triggered upon login, logout and upon session verification (i.e. each request) and which &lt;strong&gt;stores sessions server-side&lt;/strong&gt;, automatically &lt;strong&gt;logging out unknown sessions&lt;/strong&gt;. With that in place, lots of other optional features could easily be added;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;display a list of all known current sessions&lt;/li&gt;&lt;li&gt;allow one or more sessions to be removed&lt;/li&gt;&lt;li&gt;compare IP address at session verification against the one at session creation and notify or logout if no match&lt;/li&gt;&lt;li&gt;compare User Agent (and optionally some HTTP accept-headers) at session verification against the one at session creation and notify or logout if no match&lt;/li&gt;&lt;li&gt;create an audit log&lt;/li&gt;&lt;li&gt;…&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;But …&lt;strong&gt; I don’t want to do this on my own&lt;/strong&gt;. &lt;a href=&quot;http://profiles.wordpress.org/futtta/&quot; title=&quot;my wordpress profile&quot;&gt;I have 3 plugins already&lt;/a&gt;, 2 of which are semi-popular and for which I try to do regular releases and provide great support (and I have a daytime-job and a wife and daughter with whom I love to spend quality time as well). Moreover I really don’t want the plugin to “just” be open source, but I want it to be &lt;strong&gt;developed in an open source, collaborative manner &lt;/strong&gt;as well.&lt;/p&gt;&lt;p&gt;So if you’re a WordPress coder, a security consultant or just an innocent passer-by and &lt;strong&gt;you are willing to code, review code, translate or document&lt;/strong&gt;, then &lt;a href=&quot;http://blog.futtta.be/contact/&quot; title=&quot;my contact form, but you can also mail me at futtta-at-gmail-dot-com&quot;&gt;do drop me a line&lt;/a&gt;. Fame (but not fortune) will be yours!&lt;/p&gt;&lt;div class=&quot;yarpp-related-rss&quot;&gt;&lt;p&gt;Possibly related twitterless twaddle:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;a href=&quot;http://blog.futtta.be/2010/05/14/web-api-security-basics/&quot; rel=&quot;bookmark&quot; title=&quot;Web API security basics&quot;&gt;Web API security basics&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://blog.futtta.be/2012/02/23/firefox-preferences-for-greater-privacy/&quot; rel=&quot;bookmark&quot; title=&quot;Firefox preferences for greater privacy&quot;&gt;Firefox preferences for greater privacy&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://blog.futtta.be/2012/08/08/wp-donottrack-user-opt-out-for-your-cookie-law-pleasure/&quot; rel=&quot;bookmark&quot; title=&quot;WP DoNotTrack: user opt-out for your Cookie Law pleasure&quot;&gt;WP DoNotTrack: user opt-out for your Cookie Law pleasure&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;/div&gt; &lt;div class=&quot;feedflare&quot;&gt;
&lt;a href=&quot;http://feeds.feedburner.com/~ff/futtta?a=7fLOllavSSg:bCGLsRsb3_E:D7DqB2pKExk&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;http://feeds.feedburner.com/~ff/futtta?i=7fLOllavSSg:bCGLsRsb3_E:D7DqB2pKExk&quot; /&gt;&lt;/a&gt; &lt;a href=&quot;http://feeds.feedburner.com/~ff/futtta?a=7fLOllavSSg:bCGLsRsb3_E:yIl2AUoC8zA&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;http://feeds.feedburner.com/~ff/futtta?d=yIl2AUoC8zA&quot; /&gt;&lt;/a&gt; &lt;a href=&quot;http://feeds.feedburner.com/~ff/futtta?a=7fLOllavSSg:bCGLsRsb3_E:qj6IDK7rITs&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;http://feeds.feedburner.com/~ff/futtta?d=qj6IDK7rITs&quot; /&gt;&lt;/a&gt; &lt;a href=&quot;http://feeds.feedburner.com/~ff/futtta?a=7fLOllavSSg:bCGLsRsb3_E:I9og5sOYxJI&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;http://feeds.feedburner.com/~ff/futtta?d=I9og5sOYxJI&quot; /&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img height=&quot;1&quot; src=&quot;http://feeds.feedburner.com/~r/futtta/~4/7fLOllavSSg&quot; width=&quot;1&quot; /&gt;</description>
	<pubDate>Thu, 09 May 2013 05:49:21 +0000</pubDate>
</item>
<item>
	<title>Dries Buytaert: Reducing risk in the Drupal 8 release schedule</title>
	<guid>http://buytaert.net/2951 at http://buytaert.net</guid>
	<link>http://buytaert.net/reducing-risk-in-the-drupal-8-release-schedule</link>
	<description>&lt;div class=&quot;field field-name-body field-type-text-with-summary field-label-hidden&quot;&gt;&lt;div class=&quot;field-items&quot;&gt;&lt;div class=&quot;field-item even&quot;&gt;&lt;p&gt;Post-Drupal 8's feature freeze, we find ourselves in a similar state as we did after Drupal 7's feature freeze:
&lt;/p&gt;&lt;ul&gt;
 &lt;li&gt;Some initiatives are mostly done, and now onto clean-ups.&lt;/li&gt;
 &lt;li&gt;Others are mostly architecturally there, but still have some pretty big gaps.&lt;/li&gt;
 &lt;li&gt;Still others are either not yet architecturally complete, have a major amount of integration/conversion work left, and/or have many outstanding critical/major bugs.&lt;/li&gt;
&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;

&lt;p&gt;From here on out, we need to be more strategic about what patches we do and do not allow into Drupal core directly, and this means we have to make some tough decisions. Every patch we commit needs to not move Drupal 8 further from a &quot;shippable state&quot;.&lt;/p&gt;

&lt;p&gt;There are essentially two categories of initiatives (both official and unofficial) that are incomplete:
&lt;/p&gt;&lt;ol&gt;
&lt;li&gt;Code already in HEAD, that we do not plan on reverting, and completion of which is critical to releasing Drupal 8. Examples are &lt;a href=&quot;http://drupal.org/node/1775842&quot;&gt;CMI&lt;/a&gt;, &lt;a href=&quot;http://drupal.org/node/1818580&quot;&gt;Entity NG&lt;/a&gt;, &lt;a href=&quot;http://drupal.org/node/1971384&quot;&gt;Router&lt;/a&gt; conversions. Incremental patches committed to these issues help move Drupal towards release.&lt;/li&gt;
&lt;li&gt;Code &lt;em&gt;not&lt;/em&gt; currently in HEAD, or libraries that are sitting around effectively unused by the rest of Drupal. Examples are &lt;a href=&quot;http://drupal.org/node/1757550&quot;&gt;Twig&lt;/a&gt;, &lt;a href=&quot;http://drupal.org/node/1921610&quot;&gt;CSS re-organization&lt;/a&gt;, and &lt;a href=&quot;http://drupal.org/node/1812720&quot;&gt;parts of SCOTCH&lt;/a&gt;. Incremental patches committed to these issues move Drupal towards &quot;uncharted territory&quot;, and could put the release of Drupal 8 at risk.&lt;/li&gt;
&lt;/ol&gt;&lt;p&gt;&lt;/p&gt;

&lt;p&gt;Therefore, the core committers plan to employ the following strategy when deciding what we do/don't commit to Drupal 8 going forward:&lt;/p&gt;

&lt;div class=&quot;figure&quot;&gt;
&lt;img alt=&quot;Commit decision flowchart&quot; src=&quot;http://buytaert.net/sites/buytaert.net/files/images/drupal/commit-decision-flowchart.jpg&quot; style=&quot;border: 1px solid #ccc; padding: 4px;&quot; /&gt;

&lt;/div&gt;

&lt;p&gt;First, a patch will be evaluated to see if it belongs to a larger &quot;meta&quot; issue. For the vast majority of issues in the Drupal 8 queue, the answer will be no. For example, routine bug fixes and self-contained DX (Developer Experience) improvements can simply be committed once they're ready.&lt;/p&gt;

&lt;p&gt;If an issue &lt;em&gt;is&lt;/em&gt; part of a larger meta issue, the question will be whether that meta issue is &lt;em&gt;critical&lt;/em&gt; to shipping Drupal 8. If so, the &quot;does this move us towards release?&quot; question is satisfied, and these patches will be committed as they're ready. An example of this is individual CMI conversions; we cannot ship Drupal 8 without all parts of it being deployable through the configuration management system. Similarly, we cannot ship with two methods of declaring routes.&lt;/p&gt;

&lt;p&gt;If the meta issue is &lt;em&gt;not&lt;/em&gt; deemed critical for release, but we can still ship Drupal 8 with part of it done, then we will also commit patches as they're ready. Views conversions are a good example of this. While it would be nice to ship Drupal 8 with all administrative pages converted to Views, we can still ship Drupal 8 with some converted and others not.&lt;/p&gt;

&lt;p&gt;If the patch is part of a larger, non-critical meta issue, but getting part of it done is worse than getting none of it done (an incomplete state will hold up release of Drupal 8), then we're in a &quot;danger zone&quot; and need to look at possible options:
&lt;/p&gt;&lt;ol&gt;
 &lt;li&gt;First, we should see if the patch can be re-worked, or parts of it split off, into self-contained issues. Then those issues' patches can just be committed via the normal process.&lt;/li&gt;
 &lt;li&gt;If there is no other option than completing the entire meta issue, then core maintainers will work with each individual team to determine a &quot;cut-off date&quot; for their work (which allows sufficient time prior to July 1 for integration), as well as the safest way for their work to continue without holding up the release. Possible strategies could include:
  &lt;ul&gt;
   &lt;li&gt;a larger patch containing the meta issue in its entirety, with no follow-ups, where it is still feasible to use a patch-based workflow (e.g. CSS re-organization).&lt;/li&gt;
   &lt;li&gt;a branch off the Drupal core repository that is merged in when deemed acceptable in the case of larger conversion efforts (e.g. Twig)&lt;/li&gt;
   &lt;li&gt;a sandbox project where larger refactoring is still necessary (e.g. SCOTCH).&lt;/li&gt;
  &lt;/ul&gt;
If the work is ready &lt;em&gt;in its entirety&lt;/em&gt; (i.e. working upgrade path, passing all core gates) by the cut-off date, it will be eligible for Drupal 8. However, if not ready in time, it will have to be postponed to Drupal 9. While this is definitely painful for teams that have worked so hard but yet still miss the deadline, it is preferable to delaying the Drupal 8 release indefinitely.&lt;/li&gt;
&lt;/ol&gt;

&lt;h3&gt;Summary&lt;/h3&gt;

The bottom line is that every patch we commit to Drupal 8 from now on has to help us get to a &lt;strong&gt;shippable state&lt;/strong&gt;: it has to work, be performant (or be a &lt;em&gt;required&lt;/em&gt; stepping stone towards more performant code), be well-documented and well-tested, and provide the right developer experience (DX). Getting Drupal 8 ready for release will take a big effort, and the core contributors could use all the help they can get. Now is the time to &lt;a href=&quot;http://drupal.org/community-initiatives/drupal-core&quot;&gt;jump in and help&lt;/a&gt;.&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
	<pubDate>Thu, 09 May 2013 01:22:40 +0000</pubDate>
</item>
<item>
	<title>Xavier Mertens: The Race For Resources</title>
	<guid>http://blog.rootshell.be/?p=21410</guid>
	<link>http://blog.rootshell.be/2013/05/08/the-race-for-resources/</link>
	<description>&lt;p style=&quot;text-align: justify;&quot;&gt;&lt;img alt=&quot;Storage&quot; class=&quot;alignleft  wp-image-21411&quot; height=&quot;180&quot; src=&quot;http://blog.rootshell.be/wp-content/uploads/2013/05/storage.jpg&quot; width=&quot;180&quot; /&gt;Today, disk space is not an issue for most of us. I remember when my father came back at home with my first hard drive (80MB!) for my Amiga in the Nineties. My reaction was “&lt;em&gt;Wow, we will never fill it!&lt;/em&gt;“. Today, if I make a sum of all my storage at home, I’m above 10TB! And I’m sure that I will have to add more capacity in the coming months. No, this blog post is not related to “&lt;em&gt;big data&lt;/em&gt;” but more a reflection about how developers write applications today. Again, when I was learning programming languages, professors always remembered to the students to keep our eyes on our resources: memory, CPU cycles, I/O and storage. One of the golden rule was: “&lt;em&gt;If you allocated memory, don’t forget to free it! malloc() means free()&lt;/em&gt;“. Yeah, at this time, there was no &lt;a href=&quot;http://en.wikipedia.org/wiki/Garbage_collection_(computer_science)&quot; title=&quot;Link to Wikipedia&quot;&gt;garbage collector&lt;/a&gt;. I’m a little bit nostalgic tonight! &lt;img alt=&quot;;-)&quot; class=&quot;wp-smiley&quot; src=&quot;http://blog.rootshell.be/wp-includes/images/smilies/icon_wink.gif&quot; /&gt; . Today, computer resources are not a problem anymore. Their prices continue to decrease and the reflex of most developers is just to add resources (“&lt;em&gt;Your application is slow? Add 2 cores and 2 gig of memory&lt;/em&gt;“).&lt;/p&gt;
&lt;p style=&quot;text-align: justify;&quot;&gt;I’ll show you a good example of the explosion of resource requirements. Today I was performing some cleanup on my corporate laptop. Being a consultant, it runs plenty of tools such as management consoles provided by $VENDORS. Working for multiple customers running different versions of this product (a well-known firewall brand), I’ve different versions of the tools installed. Of course, I need to keep multiple versions because you need to use the right one to access the firewall running the corresponding version. Just have a look at this screenshot:&lt;/p&gt;
&lt;div class=&quot;wp-caption aligncenter&quot; id=&quot;attachment_21414&quot; style=&quot;width: 310px;&quot;&gt;&lt;a href=&quot;http://blog.rootshell.be/wp-content/uploads/2013/05/checkpoint-software-size.png&quot;&gt;&lt;img alt=&quot;Console Tools Size&quot; class=&quot;size-medium wp-image-21414&quot; height=&quot;217&quot; src=&quot;http://blog.rootshell.be/wp-content/uploads/2013/05/checkpoint-software-size-300x217.png&quot; width=&quot;300&quot; /&gt;&lt;/a&gt;&lt;p class=&quot;wp-caption-text&quot;&gt;(Click to enlarge)&lt;/p&gt;&lt;/div&gt;
&lt;p&gt;I wonder what will ask the next version of the console as disk storage…&lt;/p&gt;
&lt;img height=&quot;1&quot; src=&quot;http://feeds.feedburner.com/~r/dev/rand/~4/nLKtzTJNKrU&quot; width=&quot;1&quot; /&gt;</description>
	<pubDate>Wed, 08 May 2013 21:35:11 +0000</pubDate>
</item>
<item>
	<title>Stephane Delcroix: It's all about monkeys</title>
	<guid>tag:blogger.com,1999:blog-1907372157232963850.post-7193370015501394403</guid>
	<link>http://blog.reblochon.org/2013/05/its-all-about-monkeys.html</link>
	<description>&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://4.bp.blogspot.com/-0-SMJ211mjE/UYoD_gyas_I/AAAAAAAADpY/pSXjts4UgwI/s1600/IMG_9583.jpg&quot; style=&quot;clear: right; float: right; margin-bottom: 1em; margin-left: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;240&quot; src=&quot;http://4.bp.blogspot.com/-0-SMJ211mjE/UYoD_gyas_I/AAAAAAAADpY/pSXjts4UgwI/s320/IMG_9583.jpg&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/div&gt;Yesterday evening, May 7, two belgian user groups,  &lt;a href=&quot;http://madn.be/&quot;&gt;MADN&lt;/a&gt; and &lt;a href=&quot;http://www.dotnethub.be/&quot;&gt;DotNetHub&lt;/a&gt; invited me to give a 2 hour introduction session on creating multi-platforms mobile applications in c# with Xamarin 2.0.&lt;br /&gt;&lt;br /&gt;Microsoft Belgium was hosting the session, and the room was packed !&lt;br /&gt;&lt;br /&gt;I really enjoyed that evening, and just wanted to thank you all: attendees for their presence and interactions, MADN and DNH for the invite and the bottle of wine, Microsoft Belgium for the place, food and drinks, and Xamarin for the give away licences, monkeys and t-shirts.&lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://files.reblochon.org/2013-05-07%20Creating%20xplat%20app%20with%20Xamarin2.0.pdf&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;480&quot; src=&quot;http://1.bp.blogspot.com/-WoYejrOlcdk/UYoKu8VHROI/AAAAAAAADpw/O-sM2av9Joo/s640/2013-05-08_1019.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;</description>
	<pubDate>Wed, 08 May 2013 13:00:03 +0000</pubDate>
</item>
<item>
	<title>Lionel Dricot: The Cost of Being Convinced</title>
	<guid>http://ploum.net/?p=2842</guid>
	<link>http://ploum.net/post/the-cost-of-being-convinced</link>
	<description>&lt;img src=&quot;http://planet.grep.be/heads/ploum100&quot; alt=&quot;&quot; align=&quot;right&quot; style=&quot;float: right;&quot;&gt;&lt;p&gt;When debating, we usually consider that opinions are merely resulting of being exposed to logical arguments. And understanding them. If arguments are logical and understood, people will change their mind.&lt;/p&gt;
&lt;p&gt;Anybody having been connected long enough on the internet knows that it never happens. Everybody stays on his own position. But why?&lt;/p&gt;
&lt;p&gt;The reason is simple: changing opinion has a cost. A cost that we usually ignore. A good exercice is to try to evaluate this cost before any debate. For yourself and for the counterpart.&lt;/p&gt;
&lt;p&gt;Let’s take a music fan that was convinced that piracy hurts artists. Convincing him that it’s not the case and that &lt;a href=&quot;http://ploum.net/post/open-letter-pirated-artists&quot; title=&quot;An Open Letter To Pirated Artists&quot;&gt;piracy is not immoral&lt;/a&gt; means to him that, firstly, he was dumb enough to be brainwashed by major companies and that, secondly, the money spent on CD is a complete waste.&lt;/p&gt;
&lt;p&gt;Each time you will tell him “Piracy is not hurting artists and not immoral”, he will ear “You are stupid and you wasted money for years”.&lt;/p&gt;
&lt;p&gt;This is quite a high cost but not impossible to overcome. It means that arguments should not only convince him, but also overcome that cost.&lt;/p&gt;
&lt;p&gt;Worst: intuitively, we take the symmetry of costs for granted.&lt;/p&gt;
&lt;p&gt;Let’s take the good old god debate.&lt;/p&gt;
&lt;p&gt;For the atheist, the cost of being convinced is usually admitting being wrong. This is a non-negligible cost but sometimes possible. Most non-hardcore atheists are thus quite ready to be convinced. They enter any religious debate expecting the same mindset from the opponents.&lt;/p&gt;
&lt;p&gt;But the opposite is not true. For a religious person, believing in god is&lt;br /&gt;
often a very important part of her life. In most case, this is something inherited from her parents. Some life choices have been made because of her belief. The person is often engaged in activities and societies related to her belief. It could be as far as being the core foundation of her social circles.&lt;/p&gt;
&lt;p&gt;When you say “God doesn’t exist”, the religious will hear “You are stupid, your parents were liars, you wrecked your life and you have no reason to see your friends anymore”.&lt;/p&gt;
&lt;p&gt;It looks like a joke, right? It isn’t. But, subconsciously, it is exactly what people feel and understand. No wonder that religious debates are so emotional.&lt;/p&gt;
&lt;p&gt;Why do you think that some religious communities are fighting any individual atheist? Why do you think that any religion always try to get money or personal involvement from you? Because they want to increase the cost of not believing in them. Scammers understand that very well: they will ask you more and more money to increase the cost of you realizing it’s a scam.&lt;br /&gt;
Before any argument, any debate, ask everyone to answer sincerely to the question “what will happen if I’m convinced? What will I do? What will change in my life?”.&lt;/p&gt;
&lt;p&gt;More often than not, changing opinion is simply not an option. Which settle any debate before the start.&lt;/p&gt;
&lt;p&gt;And you? Which of your opinions are too costly to be changed? And what can you do to improve the situation?&lt;/p&gt;
&lt;p&gt; &lt;/p&gt;
&lt;p&gt;&lt;em&gt;Picture by &lt;a href=&quot;http://www.flickr.com/photos/33227787@N05/8334993349&quot;&gt;r.nial.bradshaw&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
 &lt;p&gt;&lt;a href=&quot;http://ploum.net/?flattrss_redirect&amp;amp;id=2842&amp;amp;md5=1a479d0b36aeded6638e31301c4c9eb0&quot; target=&quot;_blank&quot; title=&quot;Flattr&quot;&gt;&lt;img alt=&quot;flattr this!&quot; src=&quot;http://ploum.net/wp-content/plugins/flattr/img/flattr-badge-large.png&quot; /&gt;&lt;/a&gt;&lt;/p&gt;</description>
	<pubDate>Wed, 08 May 2013 09:39:29 +0000</pubDate>
</item>
<item>
	<title>Ruben Vermeersch: It’s all about being productive</title>
	<guid>http://savanne.be/?p=791</guid>
	<link>http://savanne.be/791-its-all-about-being-productive/</link>
	<description>&lt;p class=&quot;lead&quot;&gt;Stuff like this makes me sad:&lt;/p&gt;&lt;blockquote class=&quot;twitter-tweet&quot; width=&quot;550&quot;&gt;&lt;p&gt;apparently rethinkdb’s official js client is coffeescript hahahah &lt;a href=&quot;https://twitter.com/search/%23fail&quot;&gt;#fail&lt;/a&gt;&lt;/p&gt;&lt;p&gt;— TJ Holowaychuk (@tjholowaychuk) &lt;a href=&quot;https://twitter.com/tjholowaychuk/status/331886624612941824&quot;&gt;May 7, 2013&lt;/a&gt;&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;Also, the github issue where TJ requests that everything gets rewritten in plain JavaScript: &lt;a href=&quot;https://github.com/rethinkdb/rethinkdb/issues/766&quot;&gt;https://github.com/rethinkdb/rethinkdb/issues/766&lt;/a&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;strong&gt;We’ve been here before&lt;/strong&gt;&lt;br /&gt; Language discussions aren’t new (nor is &lt;a href=&quot;http://en.wikipedia.org/wiki/Editor_war&quot;&gt;vim vs. emacs&lt;/a&gt;). In the &lt;a href=&quot;http://www.gnome.org/&quot;&gt;GNOME&lt;/a&gt; community we’ve seen a ton of them. Just recently there was a huge one at the DX Hackfest.&lt;/p&gt;&lt;p&gt;GNOME/Mono developers have certainly received their dose of crap thrown at them. But so have GNOME developers that preferred Vala, Python, JavaScript, or even just GObject/C. Whatever you seem to be using, it’s never the right thing for someone.&lt;/p&gt;&lt;p&gt;Have all these years of shedding words over it solved anything? Frankly: no. We are still seeing a large combination of languages being used and all of those projects have good reasons to do so.&lt;/p&gt;&lt;p&gt;I get TJ’s point though: by using &lt;a href=&quot;http://coffeescript.org/&quot;&gt;CoffeeScript&lt;/a&gt;, the &lt;a href=&quot;http://www.rethinkdb.com/&quot;&gt;rethinkdb&lt;/a&gt; people are making it harder for the wider JS community to contribute to their project. But…&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;strong&gt;It really doesn’t matter&lt;/strong&gt;&lt;br /&gt; Most open-source projects (or modules) don’t have a ton of contributors. It’s usually a modest team of core maintainers/developers that do the bulk of the work. And that’s fine: the success of a project should not be measured by the number of contributors, but by the quality of the software it produces.&lt;/p&gt;&lt;p&gt;This smallish team of core developers will have their own good reasons for picking up a certain language. They’ll use the language that they feel most productive with for the task at hand. And that’s a good thing, they are mostly the people that move the project forward.&lt;/p&gt;&lt;p&gt;The biggest barrier to contributing on a project is not the language, there are &lt;a href=&quot;https://www.kernel.org/&quot;&gt;plenty&lt;/a&gt; of &lt;a href=&quot;http://wordpress.org/&quot;&gt;projects&lt;/a&gt; &lt;a href=&quot;http://www.kde.org/&quot;&gt;written&lt;/a&gt; in unproductive languages that get a ton of contributions. Any good programmer can pick up a new language up quickly (and TJ is more than just a good programmer, he’s a fantastic one, much respect). The bigger hurdle is the specific domain knowledge involved.&lt;/p&gt;&lt;p&gt;Let’s all agree to disagree and have some respect for each other’s opinions, they are all valid anyway.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;small&gt;PS: I’ll be heavily moderating comments that try to turn this into a flame-war. I’m writing this to find some more respect and understanding.&lt;/small&gt;&lt;/p&gt;</description>
	<pubDate>Wed, 08 May 2013 06:58:24 +0000</pubDate>
</item>
<item>
	<title>Thomas Vander Stichele: Votes for talks at open source conferences</title>
	<guid>http://thomas.apestaart.org/log/?p=1537</guid>
	<link>http://thomas.apestaart.org/log/?p=1537</link>
	<description>&lt;p&gt;I’ve never been a fan of voting for talks, because it tends to be poorly implemented under the guise of democracy.  Of course it’s easy for me to talk, I’ve never organized anything at that scale.&lt;/p&gt;
&lt;p&gt;I’ll give two examples on why I feel this way, one of which triggering today’s blog post.&lt;/p&gt;
&lt;p&gt;First off, my colleague Marek submitted a talk to Djangocon.  The talk was about how to use &lt;a href=&quot;https://github.com/f3at/feat&quot;&gt;feat&lt;/a&gt; (a toolkit we wrote for livetranscoding) to serve Django pages, but in such a way that they can use Deferreds to remove the concurrency bottleneck of “1 request at a time” per process running Django.&lt;/p&gt;
&lt;p&gt;Personally, to me, this is one of the most irritating design choices of Django – from the ground up it was built synchronously (which could have been fine in most places).  But the fact that, when you get a request, you have to always synchronously respond to it (and block every other request for that process in the meantime) is a design choice that could have easily been avoided.&lt;/p&gt;
&lt;p&gt;In our particular use case, it was really painful.  If our website has to do an API request to some other service we don’t control that can easily take 30 seconds, our process throughput suddenly becomes 2 pages per minute.  All the while, the server is sitting there waiting.&lt;/p&gt;
&lt;p&gt;Yes, you can throw RAM at the problem and start 30 times more processes; or thread out API requests; or farm it out to Celery, and do some back-and-forthing to see when the call’s done.  Or do any other number of workarounds for a fundamental design choice.&lt;/p&gt;
&lt;p&gt;Since we like Twisted, we preferred to throw Twisted at the problem, and ended up with something that worked.&lt;/p&gt;
&lt;p&gt;Anyway, that’s a lot of setup to explain what the talk was about.  Marek submitted the talk to DjangoCon, and honestly I didn’t expect it to get much traction because, when you’re inside Django, you think like Django, and you don’t really realize that this is a real problem.  Most people who do realize it switch away to something else.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;But to my surprise, Marek’s talk was the most-voted talk!&lt;/strong&gt; I wish I could link to the results, but of course that vote site is no longer online.&lt;/p&gt;
&lt;p&gt;I guess I expected that would mean he’d be presenting at DjangoCon this year.  So I asked him today when his talk was, and he said “Oh that’s right.  I did not get accepted.”&lt;/p&gt;
&lt;p&gt;Well, that was a surprise.  Of course, the organising committee reserves the right to decide on their own – maybe they just didn’t like the talk.  But if you ask your potential visitors to vote, you’d expect the most-voted talk to make it on the schedule no ?&lt;/p&gt;
&lt;p&gt;The feedback Marek got from them was surprising too, though.  Their first response was that this talk was too similar to another talk, titled “How to combine JavaScript &amp;amp; Django in a smart way”.  Now, I’m not a JavaScript expert, but from the title alone I can already tell that it’s very unlikely that these two talks have many similarities beyond the word ‘Django’.&lt;/p&gt;
&lt;p&gt;After refuting that point, their second reason was that they wanted more experienced speakers (but they didn’t ask Marek for his experience), and their third reason was that the talk was in previous editions of DjangoCon US/EU (it’s unclear whether they meant his talk or the JavaScript one, but Marek’s definitely wasn’t, and we couldn’t find any mention of the other talk in previous conferences.  I’m also not sure why that even matters one way or the other. This email thread was in Polish, so I have to rely on Marek’s interpretation of it)&lt;/p&gt;
&lt;p&gt;Personally, my reaction would have been to complain to the organizers or Django maintainers.  Marek’s flegmatic attitude was much better though – after such an exchange, he simply doesn’t want to have anything to do with the conference.&lt;/p&gt;
&lt;p&gt;He’s probably right – &lt;strong&gt;it’s hard to argue with someone who doesn’t want to invite you and is lying about the reasons.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;The second example is &lt;a href=&quot;http://bcndevcon.org/&quot;&gt;BCNDevCon&lt;/a&gt;, a great conference here in Barcelona, organized by a guy who used to work for Flumotion who I have enormous respect for.  I’ve never seen anyone create such a big conference over so little time.&lt;/p&gt;
&lt;p&gt;He believes strongly in the democratic aspect, and as far as I can tell constructs the schedule solely based on the votes.&lt;/p&gt;
&lt;p&gt;Sadly I didn’t go to the last one, and the reason is simply because I felt that the talks that made it were too obviously corporate.  A lot of talks were about Microsoft products, and you could tell that they won votes because people’s coworkers voted on talks.  I’m not saying that’s necessarily wrong – given that he worked at our company and has friends here, I’m sure people working here presenting at his conference have also done vote tending.  It’s natural to do so.  But there should be a way to balance that out.&lt;/p&gt;
&lt;p&gt;I think the idea of voting is good, but implementation matters too.  Ideally, you would only want people that actually are going to show up to vote.  I have no idea how you can ensure that, though.  Do you ask people to pre-pay ? Do you ask them to commit to pay if at least 50% of their votes make it in the final schedule, kickstarter-style ?&lt;/p&gt;
&lt;p&gt;These two examples are on opposite extremes of voting.  One conference simply disregards completely what people vote on.  If I had voted or bought a ticket, I would feel lied to.  Why waste the time of so many people? The other conference puts so much stock in the vote, that I feel the final result was strongly affected.  I seriously doubt all those Windows 8 voters actually showed up.&lt;/p&gt;
&lt;p&gt;Does anyone have good experiences with conference voting that did work? Feel free to share!&lt;/p&gt;</description>
	<pubDate>Tue, 07 May 2013 17:08:31 +0000</pubDate>
</item>
<item>
	<title>Xavier Mertens: Mine is Bigger Than Yours!</title>
	<guid>http://blog.rootshell.be/?p=21370</guid>
	<link>http://blog.rootshell.be/2013/05/06/mine-is-bigger-than-yours/</link>
	<description>&lt;p style=&quot;text-align: justify;&quot;&gt;&lt;img alt=&quot;Mine Is Bigger Than Yours&quot; class=&quot;alignleft  wp-image-21377&quot; height=&quot;227&quot; src=&quot;http://blog.rootshell.be/wp-content/uploads/2013/05/mine-s-bigger-than-yours.jpg&quot; width=&quot;227&quot; /&gt;Everybody already faced the same situation: Children like to compare with each others! Put kids in the same room and let them play. Comparisons will start soon: “&lt;em&gt;My dad has a bigger car than yours&lt;/em&gt;“, “&lt;em&gt;My plane flies better than yours&lt;/em&gt;“, “&lt;em&gt;I can run faster than you&lt;/em&gt;“, etc. Sometimes, I’m feeling exactly the same during conversations about infosec products and I’m pissed of this. My opinion is that infosec people also tend to be proud of their security solutions and compare them to others. Like in a kindergarten…&lt;/p&gt;
&lt;p style=&quot;text-align: justify;&quot;&gt;It’s a fact, humans don’t like to assume their errors. It’s not easy to concede a bad choice and say that your security solution does not fullfill its job. But why pretend to have the top-notch-killer-device on the other side?  Remember, years ago, the flame war between Linux and Windows users? (Honestly, I took part of this game when I was young)&lt;/p&gt;
&lt;p style=&quot;text-align: justify;&quot;&gt;Sometimes, colleagues or customers ask me what’s the best choice between “&lt;em&gt;x&lt;/em&gt;” or “&lt;em&gt;y&lt;/em&gt;“. It’s always difficult for me to answer such questions in a cold start situation. First of all because most of the time, I don’t have enough background to compare them. Of course, the market is full of studies and analyses like the well-known Gartner &lt;a href=&quot;http://en.wikipedia.org/wiki/Magic_Quadrant&quot; title=&quot;Link to Wikipedia&quot;&gt;magic-quadrant&lt;/a&gt;. Those can help you to make a first selection. Some vendors ask research firms to make a comparison of their product with direct competitors. If they “&lt;em&gt;asked&lt;/em&gt;“, it means they also “&lt;em&gt;paid&lt;/em&gt;” for these researches. In a customer – supplier relation, the customer must be happy. May we be certain that the results of the study are fully independent? I’m in doubt…&lt;/p&gt;
&lt;p style=&quot;text-align: justify;&quot;&gt;Personally, the best solution is the one which will solve YOUR issue and match YOUR requirements in terms of:&lt;/p&gt;
&lt;ul style=&quot;text-align: justify;&quot;&gt;
&lt;li&gt;&lt;span style=&quot;line-height: 13px;&quot;&gt;Budget&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;Features&lt;/li&gt;
&lt;li&gt;Integration in your environment&lt;/li&gt;
&lt;li&gt;Management &amp;amp; Support&lt;/li&gt;
&lt;/ul&gt;
&lt;p style=&quot;text-align: justify;&quot;&gt;Keep in mind that your information security is a big market place where all vendors would like their share of the cake… Select two or three solutions, ask for live demos, setup a PoC (“&lt;em&gt;Proof of Concept&lt;/em&gt;“). This could cost time and money but you will have all keys in your hand to make the right decision. Don’t buy a brand, buy a solution!&lt;/p&gt;
&lt;p&gt; &lt;/p&gt;
&lt;img height=&quot;1&quot; src=&quot;http://feeds.feedburner.com/~r/dev/rand/~4/LR5hSGdSeOQ&quot; width=&quot;1&quot; /&gt;</description>
	<pubDate>Mon, 06 May 2013 20:08:05 +0000</pubDate>
</item>
<item>
	<title>Lionel Dricot: La lettre d’Anton</title>
	<guid>http://ploum.net/?p=2835</guid>
	<link>http://ploum.net/post/la-lettre-danton</link>
	<description>&lt;img src=&quot;http://planet.grep.be/heads/ploum100&quot; alt=&quot;&quot; align=&quot;right&quot; style=&quot;float: right;&quot;&gt;&lt;p&gt;Il était une fois un enfant appelé Anton. Anton vivait dans une famille très pauvre. Le dimanche, la famille se partageait un artichaut et, le reste de la semaine, se contentait de faire infuser les feuilles de l’artichaut du dimanche, ajoutant parfois quelques pissenlits qu’Anton arrachait sur le chemin de l’école.&lt;/p&gt;
&lt;p&gt;Le père d’Anton travaillait à l’usine de nettoyage des pièces de monnaie. À la fin de chaque année, son patron le félicitait et lui octroyait une petite prime. Cette prime était intégralement dépensée à l’achat d’un cadeau de Noël pour Anton et d’un repas pour toute la famille.&lt;/p&gt;
&lt;p&gt;Cette année, lorsque le directeur de l’usine demanda à le voir, le père d’Anton se demanda s’il achèterait un livre illustré ou des crayons de couleur. Il emballerait le cadeau dans un papier argenté et le glisserait, la nuit, devant la cheminée. Il grignoterait un morceau d’artichaut qu’Anton aurait placé à l’intention des rennes du père Noël puis il irait se coucher, imaginant la joie pétillant dans les yeux de son fils.&lt;/p&gt;
&lt;p&gt;Mais le directeur n’avait pas l’air très souriant. Il mâchonnait nerveusement un gros cigare qui sentait mauvais.&lt;br /&gt;
— Les nouvelles ne sont pas bonnes, dit-il au père d’Anton. La crise nous fait perdre des intérêts sur les capitaux des placements dérivés. Nous devons améliorer la rentabilité globale. C’est pourquoi, nous enverrons désormais les pièces de monnaies en Chine, où l’usage de gants et de masques n’est pas obligatoire pour manipuler l’acide chlorydrique. Nous devons malheureusement nous défaire temporairement de nos nettoyeurs, jusqu’à ce que le coût du kérosène dépasse celui des masques et des gants.&lt;/p&gt;
&lt;p&gt;Le père d’Anton ne sut que répondre. Pour le repas de Noël ce soir là, ils se contentèrent du traditionnel artichaut. Tout la nuit, le papa d’Anton se retourna en tentant d’oublier le regard déçu qu’afficherait son fils le lendemain en ne découvrant aucun cadeau. Puis, pris d’un inspiration subite, il se leva, pris un crayon, une feuille de papier neuve et croqua l’artichaut. Il alla se coucher, rasséréné.&lt;/p&gt;
&lt;p&gt;Le lendemain, Anton se précipita hors de sa chambre mais ne trouva, au pieds de la cheminée, qu’une feuille de papier sur laquelle était écrit :&lt;/p&gt;
&lt;p&gt;« Cher Anton,&lt;/p&gt;
&lt;p&gt;Tu le sais, j’ai tendance à ne faire qu’un seul cadeau par an aux enfants qui ont été sages.&lt;/p&gt;
&lt;p&gt;Mais, cette année, tu as été particulièrement sage. Plutôt que de te faire un seul cadeau, j’ai décidé de t’en offrir pour le restant de ta vie.&lt;/p&gt;
&lt;p&gt;À chaque fois que tu seras heureux, à chaque fois que ta maman t’embrassera, que ton papa te caressera les cheveux, ce sera un cadeau que je te fais.&lt;/p&gt;
&lt;p&gt;Mais à chaque fois que tu te sentiras malheureux, réfléchis. Au fond de toi tu te rendras compte que tu n’as peut-être pas été assez sage.&lt;/p&gt;
&lt;p&gt;Sois sage et je te comblerai de bonheur,&lt;/p&gt;
&lt;p&gt;Père Noël »&lt;/p&gt;
&lt;p&gt;Anton tendit la lettre à son papa :&lt;br /&gt;
— Le père Noël m’a écrit. C’est vraiment lui papa ? C’est une véritable lettre du Père Noël ?&lt;br /&gt;
— De qui veux-tu que ce soit d’autre ? fit le papa d’Anton.&lt;br /&gt;
Tout en souriant, il passa sa main dans les cheveux de son fils. Anton sut alors au fond de lui que la lettre était vraie. Comme pour confirmer son intuition, Maman l’embrassa et lui souhaita un joyeux Noël. Ses yeux pétillèrent de joie.&lt;/p&gt;
&lt;p&gt;Mais la crise touchait durement toute la ville. Les intérêts s’effondraient, les bulles explosaient, les actions s’arrêtaient et les options disparaissaient. Toutes les familles se retrouvèrent en difficulté.&lt;/p&gt;
&lt;p&gt;Anton se trouvait à l’âge où, dans les cours de récréation, on se met à exercer son sens critique. Untel a surpris ses parents déposant les cadeaux. Un autre se demande comment le père Noël peut passer dans autant de cheminée en une seule soirée. Un troisième calcule la taille du traîneau nécessaire pour transporter assez de cadeaux. Mais Anton parait à tous ces arguments en exhibant sa lettre.&lt;/p&gt;
&lt;p&gt;Mis au courant par leurs enfants, les parents trouvèrent que c’était une très bonne idée pour faire des économies en temps de crise ou, comme le gouvernement l’appelait, en période d’austérité. Et comme le papier et le crayon commençaient eux-mêmes à manquer, les parents se contentèrent de répéter un message transmis par le Père Noël en personne qui était venu cette nuit mais n’avait pas voulu réveiller les enfants.&lt;/p&gt;
&lt;p&gt;Les parents vieillirent, les enfants grandirent et devinrent, à leur tour, des parents. À chaque veillée de Noël, on expliquait aux plus jeunes comment le père Noël récompensait les enfants sages. Et lorsqu’un enfant plus éveillé que les autres demandait si le père Noël existait, on lui racontait l’histoire d’Anton qui avait reçu une véritable lettre. La copie de cette lettre pouvait être trouvée dans n’importe quelle maison du pays. D’ailleurs, on l’apprenait par cœur à l’école, au grand dam de l’imprimeur qui avait fait fortune en éditant pour la première fois cette lettre.&lt;/p&gt;
&lt;p&gt;Dans les universités, des thèses de doctorat furent écrites pour savoir pourquoi Anton avait été choisi plutôt qu’un autre. D’autres affirmaient que si on traduisait la lettre en langage esquimau, qu’on mélangeait les lettres et qu’on lisait ensuite les lettres placées uniquement en position correspondant à un chiffre premier, on obtenait l’adresse du Père Noël. La faculté d’Aéronautique Du Traîneau fit son apparition et forma des générations de chercheurs scientifiques.&lt;/p&gt;
&lt;p&gt;Un jour, un étudiant affirma haut et fort qu’il ne pensait pas que le père Noël existait. D’ailleurs, disait-il, nous n’avons plus la moindre preuve de son existence. Dans les temps anciens, il apportait des cadeaux tangibles. Mais ce sont certainement des racontars. Comment aurait-il pu livrer autant de cadeau en une seule nuit ?&lt;/p&gt;
&lt;p&gt;Il lui fut rétorqué que s’il ne croyait pas au père Noël, il n’avait aucune raison d’être sage, qu’il serait donc malheureux. Que le fait qu’il lui arrive des évènements heureux était la preuve de l’existence du père Noël. Que cela revenait à traiter ses parents de menteurs pour lui avoir fait croire à quelque chose qui n’existait pas. Que lui, simple étudiant, osait traiter toute la faculté d’Aéronautique Du Traîneau de menteurs ?&lt;/p&gt;
&lt;p&gt;Mais que bon, ça le regardait. Que si il voulait, il pouvait ne pas croire et ne pas être sage. On n’allait pas le tuer, on n’est pas chez &lt;a href=&quot;http://ploum.net/post/le-platerrisme&quot; title=&quot;Le Platerrisme&quot;&gt;les platerristes&lt;/a&gt;. Mais qu’il était hors de question de le voir au souper de Noël familial ni à la soirée de Noël avec ses amis.&lt;/p&gt;
&lt;p&gt;Comme notre étudiant aimait ses parents, sa famille, ses amis et la faculté d’Aéronautique Du Traîneau, il répliqua que peut-être le père Noël ne voulait-il pas être vu justement pour tester ceux qui étaient vraiment sages.&lt;/p&gt;
&lt;p&gt;On considéra que c’était une très bonne explication. Et tout le monde applaudit en se disant que, au moins, les enfants étaient sages, que chacun avait des moments de bonheur et que le Père Noël devait être content d’eux.&lt;/p&gt;
&lt;p&gt; &lt;/p&gt;
&lt;p&gt;&lt;em&gt;Photo par &lt;a href=&quot;http://www.flickr.com/photos/27828336@N00/5247542532&quot;&gt;Robert Orr&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
 &lt;p&gt;&lt;a href=&quot;http://ploum.net/?flattrss_redirect&amp;amp;id=2835&amp;amp;md5=1ed9b7f6597cb502a20885a849cf710a&quot; target=&quot;_blank&quot; title=&quot;Flattr&quot;&gt;&lt;img alt=&quot;flattr this!&quot; src=&quot;http://ploum.net/wp-content/plugins/flattr/img/flattr-badge-large.png&quot; /&gt;&lt;/a&gt;&lt;/p&gt;</description>
	<pubDate>Mon, 06 May 2013 17:46:22 +0000</pubDate>
</item>
<item>
	<title>Wouter Verhelst: Oops, I did it again...</title>
	<guid>http://grep.be/blog/en/life/travel/debconf13</guid>
	<link>http://grep.be/blog/en/life/travel/debconf13</link>
	<description>&lt;img src=&quot;http://planet.grep.be/heads/wouter_verhelst&quot; alt=&quot;&quot; align=&quot;right&quot; style=&quot;float: right;&quot;&gt;&lt;p&gt;For (at least) the third time, I managed to register for &lt;a href=&quot;http://www.debconf.org/&quot;&gt;debconf&lt;/a&gt; before registration was
actually open. Oops.&lt;/p&gt;
&lt;p&gt;I found out that unfortunately, it's not quite certain yet that there
will actually be a debcamp this year—and if there is going to be a
debcamp, it won't be a full week. Pity. At any rate, I'll be there the
whole time, whatever the duration of debcamp.&lt;/p&gt;
&lt;p&gt;Since Vaumarcus is closer to Mechelen than Edinburgh (by about
250km), this is going to be the closest debconf for me, ever. And if I
could go to Banja Luka by car, I can certainly go to Vaumarcus by
car.&lt;/p&gt;
&lt;p&gt;Anyone care to join me?&lt;/p&gt;</description>
	<pubDate>Sat, 04 May 2013 00:26:00 +0000</pubDate>
</item>
<item>
	<title>Thomas Vander Stichele: If I was 16 years younger…</title>
	<guid>http://thomas.apestaart.org/log/?p=1533</guid>
	<link>http://thomas.apestaart.org/log/?p=1533</link>
	<description>&lt;p&gt;I’d totally try and be the &lt;a href=&quot;https://blog.pinboard.in/2013/04/seeking_a_summer_pintern/&quot;&gt;intern for pinboard&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;The money is great for a summer job, but that’s not the important part.  pinboard seems interesting, it’s a real service, and it’s (I assume) small enough to understand from top to bottom.  Contrary to, say, a Google Summer of Code project, you get to touch a real existing service, and from what I can tell from the blog you get to do it with a smart and funny guy.&lt;/p&gt;
&lt;p&gt;You’ve got five weeks left; even if you’re in the middle of exams right now, apply!&lt;/p&gt;
&lt;p&gt;(And if you do, why not add the features to merge and rename tags while you’re at it?)&lt;/p&gt;</description>
	<pubDate>Fri, 03 May 2013 21:30:48 +0000</pubDate>
</item>
<item>
	<title>Frank Goossens: Music from Our Tube; Seelenluft</title>
	<guid>http://blog.futtta.be/?p=8797</guid>
	<link>http://feedproxy.google.com/~r/futtta/~3/T_e918rOZmM/</link>
	<description>&lt;p&gt;&lt;img alt=&quot;seelenluft manila artwork&quot; class=&quot;alignright size-full wp-image-8799&quot; height=&quot;170&quot; src=&quot;http://blog-cdn.futtta.be/wp-content/uploads/2013/05/seelenluft-manila_smaller.jpeg&quot; width=&quot;170&quot; /&gt;Friday-evening, time to pretend you’re a young hipster! And this might help; a great (old, as in over 10 years old) track called “Manila” by Seelenluft in the Manitoba remix, as it was featured in &lt;a href=&quot;https://soundcloud.com/four-tet/essential-mix-january-2010&quot; title=&quot;2 hours of four tet, super mix, download NOW!&quot;&gt;Four Tet’s magnificent “Essential Mix”&lt;/a&gt; from way back in 2010;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;http://blog.futtta.be/2013/05/03/music-from-our-tube-seelenluft/&quot;&gt;&lt;img alt=&quot;YouTube Video&quot; src=&quot;http://i.ytimg.com/vi/ecHP4t8QdpM/0.jpg&quot; /&gt;&lt;/a&gt;&lt;br /&gt;Watch this video &lt;a href=&quot;http://youtu.be/ecHP4t8QdpM&quot;&gt;on YouTube&lt;/a&gt; or on &lt;a href=&quot;http://icant.co.uk/easy-youtube/?http://www.youtube.com/watch?v=ecHP4t8QdpM&quot;&gt;Easy Youtube&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;The vocals are by the Michael Smith, who apparently was only 12 years old when recording “Manila”. There’s multiple remixes of it (and &lt;a href=&quot;http://www.youtube.com/watch?v=mh2SiGuDT1A&quot; title=&quot;Ewan Pearson's remix of Manilla&quot;&gt;the official clip for the Ewan Pearson remix is pretty funny&lt;/a&gt;), but none are as wild as this one. Love those crazy horns, they remind me of (the more recent) &lt;a href=&quot;http://www.youtube.com/watch?v=hpXGIPv29QE&quot; title=&quot;Crazy horns with Neneh &amp;amp; The Thing&quot;&gt;Neneh Cherry &amp;amp; The Thing with their freaky cover of Springsteen’s “Dream Baby Dream”&lt;/a&gt; (which &lt;a href=&quot;http://www.youtube.com/watch?v=4VWvQSEbl5Y&quot; title=&quot;Four Tet goes Cherry&quot;&gt;Four Tet remixed as well&lt;/a&gt;).&lt;/p&gt;&lt;div class=&quot;yarpp-related-rss&quot;&gt;&lt;p&gt;Possibly related twitterless twaddle:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;a href=&quot;http://blog.futtta.be/2011/03/30/brian-eno-2-amerikanen-en-een-japanner/&quot; rel=&quot;bookmark&quot; title=&quot;Brian Eno, 2 Amerikanen en een Japanner&quot;&gt;Brian Eno, 2 Amerikanen en een Japanner&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://blog.futtta.be/2013/04/22/music-from-our-tube-laura-mvula/&quot; rel=&quot;bookmark&quot; title=&quot;Music from Our Tube; Laura Mvula&quot;&gt;Music from Our Tube; Laura Mvula&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://blog.futtta.be/2013/05/17/music-from-our-tube-modeselektor-essential-mix/&quot; rel=&quot;bookmark&quot; title=&quot;Music from Our Tube: Modeselektor Essential Mix&quot;&gt;Music from Our Tube: Modeselektor Essential Mix&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;/div&gt; &lt;div class=&quot;feedflare&quot;&gt;
&lt;a href=&quot;http://feeds.feedburner.com/~ff/futtta?a=T_e918rOZmM:c7z9ezc0IYQ:D7DqB2pKExk&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;http://feeds.feedburner.com/~ff/futtta?i=T_e918rOZmM:c7z9ezc0IYQ:D7DqB2pKExk&quot; /&gt;&lt;/a&gt; &lt;a href=&quot;http://feeds.feedburner.com/~ff/futtta?a=T_e918rOZmM:c7z9ezc0IYQ:yIl2AUoC8zA&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;http://feeds.feedburner.com/~ff/futtta?d=yIl2AUoC8zA&quot; /&gt;&lt;/a&gt; &lt;a href=&quot;http://feeds.feedburner.com/~ff/futtta?a=T_e918rOZmM:c7z9ezc0IYQ:qj6IDK7rITs&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;http://feeds.feedburner.com/~ff/futtta?d=qj6IDK7rITs&quot; /&gt;&lt;/a&gt; &lt;a href=&quot;http://feeds.feedburner.com/~ff/futtta?a=T_e918rOZmM:c7z9ezc0IYQ:I9og5sOYxJI&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;http://feeds.feedburner.com/~ff/futtta?d=I9og5sOYxJI&quot; /&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img height=&quot;1&quot; src=&quot;http://feeds.feedburner.com/~r/futtta/~4/T_e918rOZmM&quot; width=&quot;1&quot; /&gt;</description>
	<pubDate>Fri, 03 May 2013 15:04:22 +0000</pubDate>
</item>
<item>
	<title>Ruben Vermeersch: Mono is life improvement for mobile developers</title>
	<guid>http://savanne.be/?p=785</guid>
	<link>http://savanne.be/785-mono-is-life-improvement-for-mobile-developers/</link>
	<description>&lt;blockquote&gt;&lt;p class=&quot;lead&quot;&gt;Being a developer myself, I’m constantly looking at how to improve my way of working. When it comes to mobile development, the best way to improve your life is by using &lt;a href=&quot;http://xamarin.com/&quot;&gt;Mono (Xamarin.iOS and Xamarin.Android)&lt;/a&gt;.&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;That’s, in a nutshell, the talk I’ve given today at &lt;a href=&quot;http://www.appscity.be/&quot;&gt;Apps City&lt;/a&gt;: an introductory tour on Xamarin.iOS and Xamarin.Android.&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;http://savanne.be/wp-content/uploads/2013/05/mono-apps-city-2013.pdf&quot;&gt;Slides are over here&lt;/a&gt;, though they’re very light on details and &lt;a href=&quot;http://savanne.be/articles/deploying-node-js-with-systemd/&quot; title=&quot;Deploying Node.js with systemd&quot;&gt;unlike my previous talk&lt;/a&gt;, I haven’t had time to annotate them.&lt;/p&gt;&lt;p style=&quot;text-align: center;&quot;&gt;&lt;a href=&quot;http://savanne.be/wp-content/uploads/2013/05/mono-apps-city-2013.pdf&quot;&gt;&lt;img alt=&quot;mono-apps-city-2013&quot; class=&quot;aligncenter size-large wp-image-788&quot; height=&quot;375&quot; src=&quot;http://savanne.be/wp-content/uploads/2013/05/mono-apps-city-2013-500x375.png&quot; style=&quot;border: 1px solid black;&quot; width=&quot;500&quot; /&gt;&lt;/a&gt;&lt;/p&gt;</description>
	<pubDate>Fri, 03 May 2013 14:59:16 +0000</pubDate>
</item>
<item>
	<title>Les Jeudis du Libre: Mons, le 16 mai : Qui contribue à Wikipédia, et pourquoi ?</title>
	<guid>http://jeudisdulibre.be/?p=1262</guid>
	<link>http://jeudisdulibre.be/2013/05/02/mons-le-16-mai-qui-contribue-a-wikipedia-et-pourquoi/</link>
	<description>&lt;br /&gt;&lt;p&gt;&lt;a href=&quot;http://jeudisdulibre.be/2013/05/02/mons-le-16-mai-qui-contribue-a-wikipedia-et-pourquoi/photo_identite_nicolas2/&quot; rel=&quot;attachment wp-att-1264&quot;&gt;&lt;img alt=&quot;Nicolas Jullien&quot; class=&quot;alignright size-full wp-image-1264&quot; height=&quot;189&quot; src=&quot;http://jeudisdulibre.be/wp-content/uploads/2013/05/photo_identite_nicolas2.jpg&quot; width=&quot;189&quot; /&gt;&lt;/a&gt;Ce jeudi 16 mai 2013 à 19h se déroulera la dix-neuvième séance montoise des &lt;a href=&quot;http://jeudisdulibre.be&quot; rel=&quot;nofollow&quot; title=&quot;http://jeudisdulibre.be&quot;&gt;Jeudis du Libre de Belgique&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Le sujet de cette séance : &lt;strong&gt;Qui contribue à Wikipédia, et pourquoi ?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Thématique : &lt;strong&gt;Internet|communauté&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Public : &lt;strong&gt;Tout public&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;L’animateur conférencier : &lt;strong&gt;Nicolas Jullien&lt;/strong&gt; (LUSSI, M@rsouin. Institut TELECOM Bretagne &amp;amp; UEB)&lt;/p&gt;
&lt;p&gt;Lieu de cette séance : &lt;strong&gt;Mundaneum, 76 rue de Nimy à 7000 Mons&lt;/strong&gt; (cf. &lt;a href=&quot;http://www.openstreetmap.org/?mlat=50.4576&amp;amp;mlon=3.9555&amp;amp;zoom=18&amp;amp;layers=M&quot; rel=&quot;nofollow&quot; title=&quot;http://www.openstreetmap.org/?mlat=50.4576&amp;amp;mlon=3.9555&amp;amp;zoom=18&amp;amp;layers=M&quot;&gt;ce plan&lt;/a&gt; sur le site d’Openstreetmap)&lt;/p&gt;
&lt;p&gt;La participation sera gratuite et ne nécessitera que votre inscription nominative, de préférence préalable, ou à l’entrée de la séance. Merci d’indiquer votre intention (même incertaine) en vous inscrivant via la page &lt;a href=&quot;http://jeudisdulibre.fikket.com/&quot; rel=&quot;nofollow&quot; title=&quot;http://jeudisdulibre.fikket.com/&quot;&gt;http://jeudisdulibre.fikket.com/&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Cette séance sera suivie d’un verre de l’amitié, offert par l’A.S.B.L. &lt;a href=&quot;http://www.loligrub.be/&quot; rel=&quot;nofollow&quot; title=&quot;http://www.loligrub.be/&quot;&gt;LoLiGrUB&lt;/a&gt;, co-organisatrice des Jeudis du Libre.&lt;/p&gt;
&lt;p&gt;Si vous êtes intéressé(e) par ce cycle mensuel, n’hésitez pas à consulter l’&lt;a href=&quot;http://jeudisdulibre.be/grille-pour-mons/&quot; rel=&quot;nofollow&quot; title=&quot;http://jeudisdulibre.be/grille-pour-mons/&quot;&gt;agenda&lt;/a&gt; et à vous inscrire sur la &lt;a href=&quot;http://jeudisdulibre.be/news/lists/?p=subscribe&amp;amp;id=1&quot; rel=&quot;nofollow&quot; title=&quot;http://jeudisdulibre.be/news/lists/?p=subscribe&amp;amp;id=1&quot;&gt;liste de diffusion&lt;/a&gt; afin de recevoir systématiquement les annonces.&lt;/p&gt;
&lt;p&gt;Pour rappel, les Jeudis du Libre se veulent des rencontres autour de thématiques des Logiciels Libres. Les rencontres montoises se déroulent chaque troisième jeudi du mois, et sont organisées dans des locaux et en collaboration avec des Hautes Écoles et Facultés Universitaires du Pôle Hainuyer d’enseignement supérieur impliquées dans les formations d’informaticiens (&lt;a href=&quot;http://www.umons.ac.be/&quot; rel=&quot;nofollow&quot; title=&quot;http://www.umons.ac.be/&quot;&gt;UMONS&lt;/a&gt;, &lt;a href=&quot;http://www.hecfh.be/&quot; rel=&quot;nofollow&quot; title=&quot;http://www.hecfh.be/&quot;&gt;HECFH&lt;/a&gt; et &lt;a href=&quot;http://www.condorcet.be/&quot; rel=&quot;nofollow&quot; title=&quot;http://www.condorcet.be/&quot;&gt;Condorcet&lt;/a&gt;), et avec le concours de l’A.S.B.L. &lt;a href=&quot;http://www.loligrub.be/&quot; rel=&quot;nofollow&quot; title=&quot;http://www.loligrub.be/&quot;&gt;LoLiGrUB&lt;/a&gt;, active dans la promotion des logiciels libres.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Description&lt;/strong&gt; : Wikipédia est sans doute aujourd’hui l’exemple le plus connu d’une communauté ouverte, en ligne, qui autorise à chacun de contribuer pour améliorer le contenu des connaissances disponibles en ligne. Si tout le monde ne participe pas, comme dans d’autres projets en ligne, on peut se demander qui sont les personnes qui participent et pourquoi elles participent.&lt;/p&gt;
&lt;p&gt;Après une présentation générale de Wikipédia, et avant une discussion avec la salle, nous présenterons les résultats d’une enquête menée auprès des contributeurs au projet Wikipédia-fr (Wikipédia en langue française).&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Information complémentaire &lt;/strong&gt; : Nicolas Jullien donnera également une &lt;a href=&quot;http://www.ig.fpms.ac.be/content/seminaire-infortech-Nicolas-Jullien&quot; rel=&quot;nofollow&quot; title=&quot;http://www.ig.fpms.ac.be/content/seminaire-infortech-Nicolas-Jullien&quot;&gt;conférence dans le cadre du Séminaire InforTech&lt;/a&gt; à 17h00 (FPMS, rue de Houdain).&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Biographie courte de l’auteur&lt;/strong&gt; : Enseignant-chercheur à Télécom Bretagne, Brest, Nicolas Jullien étudie les communautés en ligne (logiciel libre, encyclopédie, communautés professionnelles) depuis le début des années 2000. Il s’intéresse aux raisons de participer à de telles communautés, aux différentes étapes dans la participation, à la façon dont les entreprises coopèrent avec les communautés, et au lien entre apprentissage communautaire et marché du travail.&lt;/p&gt;</description>
	<pubDate>Thu, 02 May 2013 12:11:24 +0000</pubDate>
</item>
<item>
	<title>Patrick Debois: The future of devops</title>
	<guid>http://www.jedi.be/blog/2013/05/02/The future for Devops - Devopsdays Austin 2013/</guid>
	<link>http://feedproxy.google.com/~r/jedi/IZwx/~3/QBP9CUceU_s/</link>
	<description>&lt;p&gt;I had a blast at &lt;a href=&quot;http://devopsdays.org/events/2013-austin&quot;&gt;Devopsdays Austin 2013&lt;/a&gt; . Here's my keynote on the 'future of devops'.&lt;/p&gt;

&lt;p&gt;My main point is that besides repeating the devops stories, we also need to seek diversity and make sure we keep adapting to situations.&lt;/p&gt;

&lt;p&gt;The slides are available on slideshare - &lt;a href=&quot;http://www.slideshare.net/jedi4ever/future-ofdevopsv2&quot;&gt;http://www.slideshare.net/jedi4ever/future-ofdevopsv2&lt;/a&gt;&lt;/p&gt;</description>
	<pubDate>Thu, 02 May 2013 08:35:34 +0000</pubDate>
</item>
<item>
	<title>Wim Leers: Practical WPO intro</title>
	<guid>http://wimleers.com/174 at http://wimleers.com</guid>
	<link>http://feedproxy.google.com/~r/WimLeers/~3/CYizz8dwVQA/practical-wpo-intro-2013</link>
	<description>&lt;p&gt;I was asked to do an introductory session on &lt;span class=&quot;caps&quot;&gt;WPO&lt;/span&gt; for the course “Network software and architectures” at &lt;a href=&quot;http://www.uhasselt.be&quot;&gt;Hasselt University&lt;/a&gt; and interweave that with my story (how my &lt;span class=&quot;caps&quot;&gt;WPO&lt;/span&gt;-related bachelor &lt;span class=&quot;amp&quot;&gt;&amp;amp;&lt;/span&gt; master thesis got me an &lt;a href=&quot;http://wimleers.com/tags/facebook&quot;&gt;internship at Facebook&lt;/a&gt;) to indicate this is not a far-fetched thing — any one of the students in the audience can do this, if they’re interested!&lt;/p&gt;

&lt;p&gt;Required background: general web development knowledge, general network knowledge, know &lt;a href=&quot;http://wimleers.com/article/key-properties-of-a-cdn&quot;&gt;what a &lt;span class=&quot;caps&quot;&gt;CDN&lt;/span&gt; is&lt;/a&gt;.&lt;/p&gt;
&lt;div class=&quot;field field-name-field-slideshare-link field-type-link-field field-label-inline clearfix&quot;&gt;&lt;div class=&quot;field-label&quot;&gt;Slides: &lt;/div&gt;&lt;div class=&quot;field-items&quot;&gt;&lt;div class=&quot;field-item even&quot;&gt;&lt;a href=&quot;http://wimleers.com/talk-practical-wpo-intro-2013/&quot;&gt;Practical WPO Intro&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;field field-name-field-location field-type-text field-label-above&quot;&gt;&lt;div class=&quot;field-label&quot;&gt;Location: &lt;/div&gt;&lt;div class=&quot;field-items&quot;&gt;&lt;div class=&quot;field-item even&quot;&gt;Hasselt, Belgium&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;field field-name-field-date field-type-date field-label-above&quot;&gt;&lt;div class=&quot;field-label&quot;&gt;Date: &lt;/div&gt;&lt;div class=&quot;field-items&quot;&gt;&lt;div class=&quot;field-item even&quot;&gt;&lt;span class=&quot;date-display-single&quot;&gt;May 2 2013 - 13:00&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;field field-name-field-duration field-type-number-integer field-label-above&quot;&gt;&lt;div class=&quot;field-label&quot;&gt;Duration: &lt;/div&gt;&lt;div class=&quot;field-items&quot;&gt;&lt;div class=&quot;field-item even&quot;&gt;60 minutes&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;ul class=&quot;tags&quot;&gt;
    &lt;li&gt;&lt;a href=&quot;http://wimleers.com/tags/wpo&quot;&gt;WPO&lt;/a&gt;&lt;/li&gt;
    &lt;li&gt;&lt;a href=&quot;http://wimleers.com/tags/hasselt-university&quot;&gt;Hasselt University&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;img height=&quot;1&quot; src=&quot;http://feeds.feedburner.com/~r/WimLeers/~4/CYizz8dwVQA&quot; width=&quot;1&quot; /&gt;</description>
	<pubDate>Wed, 01 May 2013 09:28:13 +0000</pubDate>
</item>
<item>
	<title>Frank Goossens: Ceremonies het monopolie van de (Katholieke) Kerk?</title>
	<guid>http://blog.futtta.be/?p=8782</guid>
	<link>http://feedproxy.google.com/~r/futtta/~3/6bVBQT31o_8/</link>
	<description>&lt;p&gt;De kerken lopen leeg, maar pakweg 5 keer in een mensenleven (doop, eerste communie, tweede communie, huwelijk en dood) speelt de Katholieke Kerk toch een onmiskenbaar grote rol in het leven van veel gelovige en zelfs ongelovige Belgen (en Fransmannen en Spanjaarden en …). Soit, &lt;a href=&quot;http://blog.zog.org/2013/04/communies.html&quot; title=&quot;Michel over vroeger, nu, communie en hypocrisie.&quot;&gt;Michel had het er al uitgebreid over&lt;/a&gt;, dus dat moet ik hier niet meer doen.&lt;/p&gt;&lt;p&gt;Maar “nee!”, de (Katholieke) Kerk heeft al lang geen monopolie meer op de grote levensmomenten. Want “ja!”, er zijn alternatieven; zeker voor ongelovigen. &lt;a href=&quot;http://blog-cdn.futtta.be/wp-content/uploads/2013/04/liezelente_binnenkant.jpg&quot;&gt;&lt;img alt=&quot;elise's lentefeestkaartje, met gedichtje van veerle!&quot; class=&quot;alignright size-medium wp-image-8772&quot; height=&quot;209&quot; src=&quot;http://blog-cdn.futtta.be/wp-content/uploads/2013/04/liezelente_binnenkant-300x209.jpg&quot; width=&quot;300&quot; /&gt;&lt;/a&gt;Het hangt er gewoon van af wat je er zelf van wilt maken, hoe je die grote momenten wilt vieren. Veerle en ik zijn diep-ongelovig en hebben in 2002, samen met een toffe madam van wat toen nog de Unie van Vrijzinnige Verenigingen heette, zelf &lt;a href=&quot;http://e-cafe.be/frankenveerle/plechtigheid.html&quot; title=&quot;tekst van de plechtigheid, op onze trouwsite&quot;&gt;onze trouwceremonie&lt;/a&gt; uitgewerkt. Met diezelfde vrouw hebben we &lt;a href=&quot;http://e-lise.blogspot.be/2006/07/1907-tekst-ceremonie-babyborrel_20.html&quot; title=&quot;onze babyborrel-ceremonie&quot;&gt;in juli 2006 de geboorte van onze dochter op een voor ons zinvolle manier gevierd&lt;/a&gt;. En &lt;a href=&quot;http://blog.futtta.be/2013/04/28/dochterken-wordt-te-groot/&quot; title=&quot;Dochterken wordt (te) groot&quot;&gt;Elise heeft net haar Lentefeest&lt;/a&gt; achter de rug.&lt;/p&gt;&lt;p&gt;Het is maar wat je er zelf van wilt maken, wat voor jou zinvol is. Indien je gelovig bent en geboorte, trouw en dood in en met de Kerk wilt vieren, fantastisch. Maar als dat niet écht zo is, denk dan even na over de alternatieven. En contacteer eventueel &lt;a href=&quot;http://www.demens.nu/nl/HuisVanDeMens/&quot; title=&quot;Huis van de Mens, vrijzinnig humanistisch ... dingens.&quot;&gt;het “Huis van de Mens”&lt;/a&gt; om te praten over hoe jij zelf zin kunt geven aan die grootse momenten in het leven?&lt;/p&gt;&lt;div class=&quot;yarpp-related-rss&quot;&gt;&lt;p&gt;Possibly related twitterless twaddle:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;a href=&quot;http://blog.futtta.be/2010/06/01/het-schrijven-verleerd/&quot; rel=&quot;bookmark&quot; title=&quot;Het schrijven verleerd&quot;&gt;Het schrijven verleerd&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://blog.futtta.be/2003/07/10/muziek-commercie-en-internet/&quot; rel=&quot;bookmark&quot; title=&quot;muziek, commercie en internet&quot;&gt;muziek, commercie en internet&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://blog.futtta.be/2010/09/10/tranen-om-stomme-regeltjes-in-center-parcs/&quot; rel=&quot;bookmark&quot; title=&quot;Tranen om stomme regeltjes in Center Parcs&quot;&gt;Tranen om stomme regeltjes in Center Parcs&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;/div&gt; &lt;div class=&quot;feedflare&quot;&gt;
&lt;a href=&quot;http://feeds.feedburner.com/~ff/futtta?a=6bVBQT31o_8:ICCzKD6nbbA:D7DqB2pKExk&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;http://feeds.feedburner.com/~ff/futtta?i=6bVBQT31o_8:ICCzKD6nbbA:D7DqB2pKExk&quot; /&gt;&lt;/a&gt; &lt;a href=&quot;http://feeds.feedburner.com/~ff/futtta?a=6bVBQT31o_8:ICCzKD6nbbA:yIl2AUoC8zA&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;http://feeds.feedburner.com/~ff/futtta?d=yIl2AUoC8zA&quot; /&gt;&lt;/a&gt; &lt;a href=&quot;http://feeds.feedburner.com/~ff/futtta?a=6bVBQT31o_8:ICCzKD6nbbA:qj6IDK7rITs&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;http://feeds.feedburner.com/~ff/futtta?d=qj6IDK7rITs&quot; /&gt;&lt;/a&gt; &lt;a href=&quot;http://feeds.feedburner.com/~ff/futtta?a=6bVBQT31o_8:ICCzKD6nbbA:I9og5sOYxJI&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;http://feeds.feedburner.com/~ff/futtta?d=I9og5sOYxJI&quot; /&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img height=&quot;1&quot; src=&quot;http://feeds.feedburner.com/~r/futtta/~4/6bVBQT31o_8&quot; width=&quot;1&quot; /&gt;</description>
	<pubDate>Tue, 30 Apr 2013 19:21:14 +0000</pubDate>
</item>
<item>
	<title>Wim Coekaerts: Oracle Secure Global Desktop 5.0</title>
	<guid>https://blogs.oracle.com/wim/entry/oracle_secure_global_desktop_5</guid>
	<link>https://blogs.oracle.com/wim/entry/oracle_secure_global_desktop_5</link>
	<description>We just released version 5.0 of Oracle Secure Global Desktop (for those that don't know what it is, formerly known as Tarantella...). It's a great product that I have been using every for a long time now. I have it installed at home on my servers so that I can get access to my home network from anywhere...without vpn.&lt;p&gt;
Anyway, a few nice things that I personally like in the new release : &lt;/p&gt;&lt;p&gt;
(1) html5 client support. In particular, at this time the ipad. So now, I can use my ipad to log into SGD and connect to my apps without having to download and install a client. It just works with the built-in Safari browser. We will expand this over time, right now it's ipad only. &lt;/p&gt;&lt;p&gt;
(2) the tta rpm will automatically pull in all dependencies on Oracle Linux 6. So all you need to do is download the tta (sgd) rpm from oracle.com and type  &lt;b&gt;yum install tta-5.00-907.i386.rpm&lt;/b&gt;. When Oracle Linux is configured to connect to ULN or just go to &lt;a href=&quot;http://public-yum.oracle.com&quot;&gt;http://public-yum.oracle.com&lt;/a&gt; it will grab all the required OS rpms. This makes it super easy to install and get going.
&lt;/p&gt;&lt;p&gt;
To download the software, go to &lt;a href=&quot;http://edelivery.oracle.com&quot;&gt;http://edelivery.oracle.com&lt;/a&gt;, go to the &lt;b&gt;Oracle Desktop Virtualization Products&lt;/b&gt; product pack and click on &lt;b&gt;Oracle Secure Global Desktop 5.0 Media Pack&lt;/b&gt;.&lt;/p&gt;</description>
	<pubDate>Tue, 30 Apr 2013 16:21:33 +0000</pubDate>
</item>
<item>
	<title>Wouter Verhelst: Linux 3.9</title>
	<guid>http://grep.be/blog/en/computer/code/kernel</guid>
	<link>http://grep.be/blog/en/computer/code/kernel</link>
	<description>&lt;img src=&quot;http://planet.grep.be/heads/wouter_verhelst&quot; alt=&quot;&quot; align=&quot;right&quot; style=&quot;float: right;&quot;&gt;&lt;p&gt;... has been &lt;a href=&quot;https://lkml.org/lkml/2013/4/28/69&quot;&gt;released&lt;/a&gt; yesterday,
apparently. This wouldn't be very special, except that it carries &lt;a href=&quot;https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit?id=5e4b269bcd178ac9b066a69f17c253d2f3f6388a&quot;&gt;a
'patch'&lt;/a&gt; by yours truly. It isn't earthshattering, but hey, I can run
'git log' and find myself, now, in a released kernel.&lt;/p&gt;
&lt;p&gt;If that isn't nice.&lt;/p&gt;</description>
	<pubDate>Mon, 29 Apr 2013 22:50:00 +0000</pubDate>
</item>
<item>
	<title>Wouter Verhelst: New in wheezy: NBD named exports and installer support</title>
	<guid>http://grep.be/blog/en/computer/debian/newinwheezy/partman-nbd</guid>
	<link>http://grep.be/blog/en/computer/debian/newinwheezy/partman-nbd</link>
	<description>&lt;img src=&quot;http://planet.grep.be/heads/wouter_verhelst&quot; alt=&quot;&quot; align=&quot;right&quot; style=&quot;float: right;&quot;&gt;&lt;p&gt;Just after the release of squeeze, I released nbd 2.9.17, which had a
new feature that required some backwards-incompatible change: the
ability to specify an export by name, rather than by port number.
Obviously, that means that wheezy will be the first release to ship with
support for such named exports (although a backport was uploaded to
squeeze-backports with support for such a named export). After all,
names are that more obvious a way to specify an export than is a
meaningless number. The init scripts and root-on-NBD support was
updated, although a bugfix was denied for r0 (it will hopefully get into
r1).&lt;/p&gt;
&lt;p&gt;In addition, during the wheezy cycle I finally finished the
partman-nbd support in the installer. With this, it is possible to
install Debian to an NBD device on diskless systems, which is nice.&lt;/p&gt;</description>
	<pubDate>Mon, 29 Apr 2013 21:53:00 +0000</pubDate>
</item>
<item>
	<title>Wouter Verhelst: New in Wheezy: PMW</title>
	<guid>http://grep.be/blog/en/computer/debian/newinwheezy/pmw</guid>
	<link>http://grep.be/blog/en/computer/debian/newinwheezy/pmw</link>
	<description>&lt;img src=&quot;http://planet.grep.be/heads/wouter_verhelst&quot; alt=&quot;&quot; align=&quot;right&quot; style=&quot;float: right;&quot;&gt;&lt;p&gt;One of the things I do with computers is &quot;do stuff with music&quot;. I'm
not a professional musician by any means, but I do sometimes have a need
for some software to do some music editing.&lt;/p&gt;
&lt;p&gt;In the past, that meant using &lt;a href=&quot;http://lilypond.org&quot;&gt;GNU
LilyPond&lt;/a&gt;; and while that's certainly an interesting piece of
software, it has some idiosyncracies that have made me dislike it in the
past. So when I learned about &lt;a href=&quot;http://www.quercite.com/pmw.html&quot;&gt;PMW&lt;/a&gt;, written by Philip Hazel
(of PCRE and Exim fame) I was intrigued.&lt;/p&gt;
&lt;p&gt;PMW has several advantages over lilypond, in my opinion. To name but
two: its syntax is &lt;a href=&quot;http://grep.be/articles/pmw-vs-lilypond?css=plain&quot;&gt;less silly&lt;/a&gt;,
and it takes &lt;em&gt;far&lt;/em&gt; less time to convert something from source to
graphic, to the extent that I've considered creating an editor which
would update the result &lt;em&gt;after every keystroke&lt;/em&gt;, something that
just isn't possible with lilypond.&lt;/p&gt;
&lt;p&gt;The decision to upload pmw into Debian was just a no-brainer, and
it's saved me some time since, already. Enjoy!&lt;/p&gt;</description>
	<pubDate>Mon, 29 Apr 2013 13:47:00 +0000</pubDate>
</item>
<item>
	<title>Frank Goossens: Dochterken wordt (te) groot</title>
	<guid>http://blog.futtta.be/?p=8770</guid>
	<link>http://feedproxy.google.com/~r/futtta/~3/BVq6_qlCFgQ/</link>
	<description>&lt;p style=&quot;text-align: left;&quot;&gt;Gisteren vierden we dat ons dochterken geen onbeholpen kleuter, maar een zelfstandig denkend kind is geworden.&lt;a href=&quot;http://blog-cdn.futtta.be/wp-content/uploads/2013/04/liezelente_voorkant.jpg&quot;&gt;&lt;img alt=&quot;elise's lentefeest-kaartje&quot; class=&quot;size-medium wp-image-8771 aligncenter&quot; height=&quot;300&quot; src=&quot;http://blog-cdn.futtta.be/wp-content/uploads/2013/04/liezelente_voorkant-216x300.jpg&quot; width=&quot;216&quot; /&gt;&lt;/a&gt;&lt;a href=&quot;http://blog-cdn.futtta.be/wp-content/uploads/2013/04/liezelente_binnenkant.jpg&quot;&gt;&lt;img alt=&quot;binnenkant elise's lentefeestkaartje&quot; class=&quot;aligncenter size-medium wp-image-8772&quot; height=&quot;209&quot; src=&quot;http://blog-cdn.futtta.be/wp-content/uploads/2013/04/liezelente_binnenkant-300x209.jpg&quot; width=&quot;300&quot; /&gt;&lt;/a&gt;&lt;a href=&quot;http://blog-cdn.futtta.be/wp-content/uploads/2013/04/liezelente_achterkant.jpg&quot;&gt;&lt;img alt=&quot;achterkant van elise's lentefeestkaartje&quot; class=&quot;aligncenter size-medium wp-image-8773&quot; height=&quot;300&quot; src=&quot;http://blog-cdn.futtta.be/wp-content/uploads/2013/04/liezelente_achterkant-210x300.jpg&quot; width=&quot;210&quot; /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;Dat zelfstandig denken, we gaan dat ongetwijfeld nog vervloeken, maar het is een lief, slim en grappig prachtkind, ons Elise. Ze mag nu stoppen met groot worden, het is goed zo!&lt;/p&gt;&lt;div class=&quot;yarpp-related-rss&quot;&gt;&lt;p&gt;Possibly related twitterless twaddle:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;a href=&quot;http://blog.futtta.be/2006/06/09/elise/&quot; rel=&quot;bookmark&quot; title=&quot;elise&quot;&gt;elise&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://blog.futtta.be/2013/01/23/ik-slimmer-dan-toekomstige-leerkrachten/&quot; rel=&quot;bookmark&quot; title=&quot;Ik, slimmer dan (toekomstige) leerkrachten?&quot;&gt;Ik, slimmer dan (toekomstige) leerkrachten?&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://blog.futtta.be/2010/06/01/het-schrijven-verleerd/&quot; rel=&quot;bookmark&quot; title=&quot;Het schrijven verleerd&quot;&gt;Het schrijven verleerd&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;/div&gt; &lt;div class=&quot;feedflare&quot;&gt;
&lt;a href=&quot;http://feeds.feedburner.com/~ff/futtta?a=BVq6_qlCFgQ:gk2PUfsGBqk:D7DqB2pKExk&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;http://feeds.feedburner.com/~ff/futtta?i=BVq6_qlCFgQ:gk2PUfsGBqk:D7DqB2pKExk&quot; /&gt;&lt;/a&gt; &lt;a href=&quot;http://feeds.feedburner.com/~ff/futtta?a=BVq6_qlCFgQ:gk2PUfsGBqk:yIl2AUoC8zA&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;http://feeds.feedburner.com/~ff/futtta?d=yIl2AUoC8zA&quot; /&gt;&lt;/a&gt; &lt;a href=&quot;http://feeds.feedburner.com/~ff/futtta?a=BVq6_qlCFgQ:gk2PUfsGBqk:qj6IDK7rITs&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;http://feeds.feedburner.com/~ff/futtta?d=qj6IDK7rITs&quot; /&gt;&lt;/a&gt; &lt;a href=&quot;http://feeds.feedburner.com/~ff/futtta?a=BVq6_qlCFgQ:gk2PUfsGBqk:I9og5sOYxJI&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;http://feeds.feedburner.com/~ff/futtta?d=I9og5sOYxJI&quot; /&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img height=&quot;1&quot; src=&quot;http://feeds.feedburner.com/~r/futtta/~4/BVq6_qlCFgQ&quot; width=&quot;1&quot; /&gt;</description>
	<pubDate>Sun, 28 Apr 2013 05:56:49 +0000</pubDate>
</item>
<item>
	<title>Christophe Vandeplas: MISP - Malware Information Sharing Platform</title>
	<guid>tag:blogger.com,1999:blog-2016855433919117617.post-2645438456879725228</guid>
	<link>http://christophe.vandeplas.com/2013/03/misp-malware-information-sharing.html</link>
	<description>It took some time, but finally we were able to release &lt;a href=&quot;https://github.com/MISP/MISP&quot; target=&quot;_blank&quot;&gt;MISP&lt;/a&gt; as open source software.&lt;br /&gt;
This  MISP - Malware Information Sharing Platform has been developed in  collaboration between the Belgian Defence CERT and the NATO Computer  Incident Response Capability (NATO NCIRC) and is today actively  developed and used in production.&lt;br /&gt;
&lt;div&gt;&lt;br /&gt;
The  problem that we experienced in the past was the difficulty to exchange  information about (targeted) malwares and attacks within a group of  trusted partners, or a bilateral agreement.&lt;br /&gt;
Even today much of the information exchange happens in unstructured  reports where you have to copy-paste the information in your own  text-files that you then have to parse to export to (N)IDS and systems  like log-searches, etc...&lt;br /&gt;
&lt;br /&gt;
To facilitate the exchange of technical information we started to develop this tool, that :&lt;br /&gt;
- automates exchange of IOC&lt;br /&gt;
- enables you to have your internal IOC database accessible (include uploaded malwares and reports,...)&lt;br /&gt;
- correlates different malwares and events&lt;br /&gt;
- generates files in various export formats (snort/IDS, plain text, xml, ...)  (in the future MAEC and other IOC formats)&lt;/div&gt;&lt;div&gt;- synchronizes with instances of external trust-groups&lt;br /&gt;
&lt;br /&gt;
This results in faster detection of targeted attacks and improves the detection ratio while reducing the false positives. We also avoid reversing similar malware as we know very fast that others already worked on this malware.&lt;/div&gt;The Red October malware for example gives a similar view:&lt;br /&gt;
&lt;img border=&quot;0&quot; height=&quot;124&quot; src=&quot;http://4.bp.blogspot.com/-4Ibff5fC_6A/UXuFKbJk61I/AAAAAAAAAmw/7k_fNAqGNWk/s640/red-1.png&quot; width=&quot;640&quot; /&gt;&lt;br /&gt;
(...)&lt;br /&gt;
&lt;div&gt;&lt;img border=&quot;0&quot; height=&quot;278&quot; src=&quot;http://1.bp.blogspot.com/-_0xRAfWouQc/UXuFKhd6bII/AAAAAAAAAm0/zTWcdvcYHjA/s640/red-2.png&quot; width=&quot;640&quot; /&gt;&lt;/div&gt;&lt;div&gt;Feel free to have a look at the (pdf) documentation in the INSTALL directory.&lt;/div&gt;&lt;div&gt;For the future version (v2) this is the develop branch: &lt;a href=&quot;https://github.com/MISP/MISP/tree/develop/INSTALL&quot; target=&quot;_blank&quot;&gt;https://github.com/MISP/MISP/tree/develop/INSTALL&lt;/a&gt;&lt;/div&gt;&lt;div&gt;We are actively developing this tool and many (code, documentation, export formats,...) improvements are coming.&lt;/div&gt;&lt;div&gt;Feel free to fork the code, play with it, make some patches and send us the pull requests.&lt;/div&gt;&lt;div&gt;Feel free to contact me if you have questions or remarks.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div&gt;The project site is: &lt;a href=&quot;https://github.com/MISP/MISP&quot; target=&quot;_blank&quot;&gt;https://github.com/MISP/MISP&lt;/a&gt;&lt;/div&gt;&lt;div&gt;There are 2 branches: &lt;/div&gt;&lt;div&gt;- develop: future v2 with many many improvements&lt;/div&gt;&lt;div&gt;- main: current stable version, but it has some bugs in the synchronization functionality (we're fixing these)&lt;/div&gt;&lt;div&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div&gt;Some people might think about CIF, the collective intelligence  framework, however both tools are different. Perhaps integration might  be provided between those two in the future. &lt;/div&gt;&lt;div&gt;&lt;br /&gt;
&lt;/div&gt;</description>
	<pubDate>Sat, 27 Apr 2013 08:01:37 +0000</pubDate>
</item>
<item>
	<title>Stephane Delcroix: Decorating your Xamarin.iOS code with Behaviors</title>
	<guid>tag:blogger.com,1999:blog-1907372157232963850.post-368128578716580114</guid>
	<link>http://blog.reblochon.org/2013/04/decorating-your-xamarinios-code-with.html</link>
	<description>&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://4.bp.blogspot.com/-8w7eIRitFV0/UXo71Z8FX8I/AAAAAAAADow/-tOzPbYpMBU/s1600/photo.JPG&quot; style=&quot;clear: right; float: right; margin-bottom: 1em; margin-left: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;240&quot; src=&quot;http://4.bp.blogspot.com/-8w7eIRitFV0/UXo71Z8FX8I/AAAAAAAADow/-tOzPbYpMBU/s320/photo.JPG&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;i&gt;Note: this is the post in which I'm getting out of the closet and make it clear that I had an affair with Silverlight. I'm still thinking about it sometimes, and when I do, this is what happens...&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;Every time you have to ask your user &quot;What's your favourite colour&quot; or &quot;What is the air-speed velocity of an unladen swallow?&quot; from within your iOS application, you have to ask yourself &quot;Wait, will the field still be visible with the virtual keyboard displayed ?&quot;&lt;br /&gt;&lt;br /&gt;I don't know how &lt;b&gt;you&lt;/b&gt; do it (experience sharing is welcome), but me, I do it this way:&lt;br /&gt;&lt;br /&gt;&lt;pre&gt;public override void ViewDidLoad ()&lt;br /&gt;{&lt;br /&gt; base.ViewDidLoad ();&lt;br /&gt;&lt;br /&gt; //Set Bindings and Commands&lt;br /&gt; placeField.Bind (ViewModel, &quot;Place&quot;);&lt;br /&gt; sendButton.Command (ViewModel.SendCommand);&lt;br /&gt; busyIndicator.Bind (ViewModel, &quot;IsBusy&quot;);&lt;br /&gt;&lt;br /&gt; //Slide the view on keyboard show/hide&lt;br /&gt; placeField.EditingDidBegin += (sender, e) =&amp;gt; {&lt;br /&gt;  UIView.BeginAnimations (&quot;keyboardslide&quot;);&lt;br /&gt;  UIView.SetAnimationCurve (UIViewAnimationCurve.EaseInOut);&lt;br /&gt;  UIView.SetAnimationDuration (.3f);&lt;br /&gt;  var frame = View.Frame;&lt;br /&gt;  frame.Y = -100;&lt;br /&gt;  View.Frame = frame;&lt;br /&gt;  UIView.CommitAnimations();&lt;br /&gt; };&lt;br /&gt;&lt;br /&gt; placeField.EditingDidEnd += (sender, e) =&amp;gt; {&lt;br /&gt;  UIView.BeginAnimations (&quot;keyboardslide&quot;);&lt;br /&gt;  UIView.SetAnimationCurve (UIViewAnimationCurve.EaseInOut);&lt;br /&gt;  UIView.SetAnimationDuration (.3f);&lt;br /&gt;  var frame = View.Frame;&lt;br /&gt;  frame.Y = 20;&lt;br /&gt;  View.Frame = frame;&lt;br /&gt;  UIView.CommitAnimations();&lt;br /&gt; };&lt;br /&gt;&lt;br /&gt;}&lt;br /&gt;&lt;/pre&gt;&lt;br /&gt;&lt;a name=&quot;more&quot;&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;It works fine, but looks messy next to readable code setting bindings or commands (those come from a very light Binding library I'm working on). Then yesterday evening, I had a realisation. It looks very similar to Silverlight Behaviors, so this code could just be like:&lt;br /&gt;&lt;br /&gt;&lt;pre&gt; placeField.Attach (new SlideOnEditBehavior (View, defaultPosition:20, alternatePosition:-100));&lt;br /&gt;&lt;/pre&gt;&lt;br /&gt;And the SlideOnEditBehavior is kept aside (&lt;span style=&quot;font-size: x-small;&quot;&gt;&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;OnDetaching&lt;/span&gt; implementation left out for clarity&lt;/span&gt;):&lt;br /&gt;&lt;br /&gt;&lt;pre&gt;public class SlideOnEditBehavior : Behavior&lt;br /&gt;{&lt;br /&gt; UIView view;&lt;br /&gt; int defaultPosition;&lt;br /&gt; int alternatePosition;&lt;br /&gt;&lt;br /&gt; public SlideOnEditBehavior (UIView view, int defaultPosition, int alternatePosition)&lt;br /&gt; {&lt;br /&gt;  this.view = view;&lt;br /&gt;  this.defaultPosition = defaultPosition;&lt;br /&gt;  this.alternatePosition = alternatePosition;&lt;br /&gt; }&lt;br /&gt;&lt;br /&gt; protected override void OnAttached ()&lt;br /&gt; {&lt;br /&gt;  base.OnAttached ();&lt;br /&gt;  AssociatedObject.EditingDidBegin += (sender, e) =&amp;gt; {&lt;br /&gt;   UIView.BeginAnimations (&quot;keyboardslide&quot;);&lt;br /&gt;   UIView.SetAnimationCurve (UIViewAnimationCurve.EaseInOut);&lt;br /&gt;   UIView.SetAnimationDuration (.3f);&lt;br /&gt;   var frame = view.Frame;&lt;br /&gt;   frame.Y = alternatePosition;&lt;br /&gt;   view.Frame = frame;&lt;br /&gt;   UIView.CommitAnimations();&lt;br /&gt;  };&lt;br /&gt;&lt;br /&gt;  AssociatedObject.EditingDidEnd += (sender, e) =&amp;gt; {&lt;br /&gt;   UIView.BeginAnimations (&quot;keyboardslide&quot;);&lt;br /&gt;   UIView.SetAnimationCurve (UIViewAnimationCurve.EaseInOut);&lt;br /&gt;   UIView.SetAnimationDuration (.3f);&lt;br /&gt;   var frame = view.Frame;&lt;br /&gt;   frame.Y = defaultPosition;&lt;br /&gt;   view.Frame = frame;&lt;br /&gt;   UIView.CommitAnimations();&lt;br /&gt;  };&lt;br /&gt; }&lt;br /&gt;}&lt;br /&gt;&lt;/pre&gt;&lt;br /&gt;Cleaner. Simpler. Reusable. And it also supports BehaviorCollections:&lt;br /&gt;&lt;br /&gt;&lt;pre&gt; placeField.Attach (new BehaviorCollection {&lt;br /&gt;  new SlideOnEditBehavior (View, defaultPosition:20, alternatePosition:-100),&lt;br /&gt;  //Any other behavior here&lt;br /&gt; });&lt;br /&gt;&lt;/pre&gt;&lt;br /&gt;As expected, the code for all of this is trivial, but if you like the idea and save yourself the 30 minutes it takes to write it, it's on &lt;a href=&quot;https://github.com/StephaneDelcroix/MobileInception.Interactivity&quot;&gt;Github&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;[UPDATE: 2013-04-26] I updated the code as per Stuart Lodge suggestion (of MvvmCross) to use WeakReference to NSObjects. Doesn't change the API at all.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;</description>
	<pubDate>Fri, 26 Apr 2013 11:44:39 +0000</pubDate>
</item>
<item>
	<title>Mattias Geniar: Nginx: nginx: [warn] load balancing method redefined</title>
	<guid>http://mattiasgeniar.be/?p=3989</guid>
	<link>http://feedproxy.google.com/~r/mattiasgeniar/~3/0w83x9ilVrQ/</link>
	<description>&lt;p&gt;You may receive the following warning when reloading/configtesting an Nginx configuration that uses upstreams.&lt;/p&gt;
&lt;pre&gt;$ service nginx configtest
nginx: [warn] load balancing method redefined in /etc/nginx/conf.d/upstream.conf:5
nginx: the configuration file /etc/nginx/nginx.conf syntax is ok
nginx: configuration file /etc/nginx/nginx.conf test is successful&lt;/pre&gt;
&lt;p&gt;This can occur when you conflicting variables inside your upstream, like such:&lt;/p&gt;
&lt;pre&gt;$ cat upstream.conf 
upstream upstream_name {
  # Use max # keepalive connections
  keepalive 120;
  # Use the backend with least number of connections
  least_conn;
  # All upstream members defined below
  server 192.168.1.5:80  weight=24;
  server 192.168.1.6:80   weight=24;
}&lt;/pre&gt;
&lt;p&gt;The warning is causde by the mixing of 'keepalive' and 'least_conn', use either one but don't mix both.&lt;/p&gt;
&lt;img height=&quot;1&quot; src=&quot;http://feeds.feedburner.com/~r/mattiasgeniar/~4/0w83x9ilVrQ&quot; width=&quot;1&quot; /&gt;</description>
	<pubDate>Thu, 25 Apr 2013 14:57:18 +0000</pubDate>
</item>
<item>
	<title>Wouter Verhelst: Dear supplier,</title>
	<guid>http://grep.be/blog/en/life/supplier</guid>
	<link>http://grep.be/blog/en/life/supplier</link>
	<description>&lt;img src=&quot;http://planet.grep.be/heads/wouter_verhelst&quot; alt=&quot;&quot; align=&quot;right&quot; style=&quot;float: right;&quot;&gt;&lt;p&gt;I don't usually blog about work, but this time around, you maxed
it.&lt;/p&gt;
&lt;p&gt;When I specifically ask you to &lt;em&gt;not&lt;/em&gt; ship goods, I have good
reasons for that. Specifically:
&lt;/p&gt;&lt;ul&gt;
&lt;li&gt;I'm not at my office &lt;em&gt;all the time&lt;/em&gt;. Yes, I'm often there,
but I'm also often at a customer's place (you know, so I can actually
&lt;em&gt;make money&lt;/em&gt;). When I'm not at a customer, I tend to be at the
office in a noon-through-evening schedule, rather than a
morning-through-late-afternoon one (I hate getting out of bed if I don't
have to). Since we don't have any employees, this likely means your
logistics partner will find a closed door with nobody answering the
bell.&lt;/li&gt;
&lt;li&gt;The result of that is that we'll often find that your shipments end
up at your logistics partner's warehouse. Since I have to drive to a
warehouse anyway, I might as well choose to drive to the warehouse that
is closest—yours.&lt;/li&gt;
&lt;li&gt;For this &quot;service&quot; of shipping goods away from interesting
locations, you charge €20+.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Not Happy(tm)&lt;/p&gt;</description>
	<pubDate>Thu, 25 Apr 2013 13:14:00 +0000</pubDate>
</item>
<item>
	<title>Xavier Mertens: BSidesLondon 2013 Wrap-Up</title>
	<guid>http://blog.rootshell.be/?p=21298</guid>
	<link>http://blog.rootshell.be/2013/04/24/bsideslondon-2013-wrap-up/</link>
	<description>&lt;p&gt;&lt;img alt=&quot;BSidesLondon Venue&quot; border=&quot;0&quot; class=&quot;alignleft  wp-image-9380&quot; height=&quot;150&quot; src=&quot;http://blog.rootshell.be/wp-content/uploads/2013/04/IMG_3108.jpg&quot; style=&quot;float: left;&quot; title=&quot;IMG_3108.jpg&quot; width=&quot;200&quot; /&gt;&lt;/p&gt;
&lt;p style=&quot;text-align: justify;&quot;&gt;This was already the third edition of &lt;a href=&quot;http://www.securitybsides.org.uk/&quot; title=&quot;Link to the website&quot;&gt;BSidesLondon&lt;/a&gt; today! Time flies! Being busy yesterday, I just reached London in the morning and arrived just in time for the administrative tasks (registration, pick-up a t-shirt, goodies), grabbing some coffee and shaking some hands. BSidesLondon is definitively growing in size and quality: A huge number of attendees, two tracks, a &lt;a href=&quot;http://blog.rootshell.be/2012/10/15/fresh-blood-wanted-for-bsideslondon/&quot; title=&quot;Link to the website&quot;&gt;rookie&lt;/a&gt; track, a job fair, workshops and lightning talks. Even the sun was present over London, no fog at all! Two tracks means you have to make choices! Here is the brief overview of my schedule.&lt;/p&gt;
&lt;p style=&quot;text-align: justify;&quot;&gt;&lt;span id=&quot;more-21298&quot;&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style=&quot;text-align: justify;&quot;&gt;The first presentation I attended was “&lt;em&gt;Pentesting like a Grandmaster&lt;/em&gt;” by &lt;a href=&quot;http://twitter.com/7a_&quot;&gt;Abraham Aranguren&lt;/a&gt;. The talk was split in two parts. FIrst, Abraham started with an interesting comparison: “&lt;em&gt;Pentesting == a chess game&lt;/em&gt;“. This can be resumed with the picture below:&lt;/p&gt;
&lt;p style=&quot;text-align: justify;&quot;&gt;&lt;img alt=&quot;Abraham on stage&quot; border=&quot;0&quot; height=&quot;225&quot; src=&quot;http://blog.rootshell.be/wp-content/uploads/2013/04/IMG_3104.jpg&quot; style=&quot;display: block; margin-left: auto; margin-right: auto;&quot; title=&quot;IMG_3104.jpg&quot; width=&quot;300&quot; /&gt;&lt;/p&gt;
&lt;p style=&quot;text-align: justify;&quot;&gt;How far can you go with “&lt;em&gt;your&lt;/em&gt;” intelligence? The success is always possible. They are many examples of great people who made awesome stuff with a normal IQ. Intelligence does not warranty success. One fact: it’s important to start early; this is an advantage. The talent is something natural and skills must be developed by hours and hours (days or months) of training. The comparison continues with the chess game. As reported by many chess champions: “&lt;em&gt;You can only be good at chess if you love the game&lt;/em&gt;“.  It’s exactly the same in information technology (generally speaking – not only security). Some quotes are so true:  ”&lt;em&gt;No pain, no gain&lt;/em&gt;” (Arnold Schwarzeneger), “&lt;em&gt;Pain is temporary&lt;/em&gt;” (Mohamed Ali). The next question could be how to stay motivated. Like in high level sports, your must remain healthy (in your body as well as in your mind). Another interesting quote I liked:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p style=&quot;text-align: justify;&quot;&gt;“&lt;em&gt;Smart people learn from their mistakes. But the real sharp ones learn from the mistakes of other people&lt;/em&gt;” (Brandon Mull)&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p style=&quot;text-align: justify;&quot;&gt;Abraham reviewed good tips to stay healthy and keep your attention.  In the second part of the talk, he explained why the game preparation is a key (again in chess and pen testing). Before the game: scope better, do better. Know the enemy but know yourself (strengths &amp;amp; weaknesses). Finally, some examples were reviewed of how a good preparation helps to pwn your target easily.. But keep in mind: When media report an exploit “&lt;em&gt;in seconds&lt;/em&gt;“, it took usually days or weeks to prepare it. The examples were demonstrated using Abraham’s project: &lt;a href=&quot;https://www.owasp.org/index.php/OWASP_OWTF&quot; title=&quot;Link to the website&quot;&gt;OWTF&lt;/a&gt;. I liked the comparison between the two worlds which initially have nothing in common. Great talk to start the day.&lt;/p&gt;
&lt;p style=&quot;text-align: justify;&quot;&gt;For the second talk, my choice was to follow &lt;a href=&quot;http://twitter.com/j4vv4D&quot;&gt;Javvad Malik&lt;/a&gt; about his own story “&lt;em&gt;How to build a personal security brand that will stop the hackers, save the world and get you the girl&lt;/em&gt;“. What a program! The room was crowded with people sitting on the ground! This is always a good sign. Javaad is a showman, have a look at his &lt;a href=&quot;http://www.youtube.com/user/InfosecCynic&quot; title=&quot;Link to the website&quot;&gt;Youtube&lt;/a&gt; channel about information security, a must see. His talk was a reflexion about people who are “&lt;em&gt;bankable&lt;/em&gt;” in information security. Starting with a fact: why everybody found Mother Theresa a personality? It’s the same in information security. Javvad showed a nice graph of knowledge vs fame. Then he defined three levels: echo chamber, industry, public and put famous people on it:&lt;/p&gt;
&lt;div class=&quot;wp-caption aligncenter&quot; style=&quot;width: 310px;&quot;&gt;&lt;img alt=&quot;Javvad on stage&quot; border=&quot;0&quot; height=&quot;225&quot; src=&quot;http://blog.rootshell.be/wp-content/uploads/2013/04/IMG_3106.jpg&quot; style=&quot;display: block; border: 0px;&quot; title=&quot;IMG_3106.jpg&quot; width=&quot;300&quot; /&gt;&lt;p class=&quot;wp-caption-text&quot;&gt;(Note: the hidden face is Gregory Evans &lt;img alt=&quot;;-)&quot; class=&quot;wp-smiley&quot; src=&quot;http://blog.rootshell.be/wp-includes/images/smilies/icon_wink.gif&quot; /&gt;&lt;/p&gt;&lt;/div&gt;
&lt;p style=&quot;text-align: justify;&quot;&gt;The key is the message you have to pass and how to deliver it. Today,  we have access to the same tools and services as professionals a few years ago to promote ourself. How to find the right idea to promote ourself? Via podcasts, blogs, mentors &amp;amp; continuous feedback.  Often security people act like the actors doing the promotion of Hollywood movies: they visit many places, are facing the same questions and constantly repeat the same sentences. Same message is broadcasted again &amp;amp; again. But what makes a good infosec guy? Javaad showed two pictures of Fish &amp;amp; Chips. Prepared with the same food but presented differently.  The same may apply with blogs: a blog post could be a very good research but badly presented. Also, the message we have to deliver is often bad news: “&lt;em&gt;you got owned&lt;/em&gt;“, “&lt;em&gt;you lost data&lt;/em&gt;“, etc. Then the procrastination and comfort zone are part of the game. Being a “&lt;em&gt;public&lt;/em&gt;” man forces you to remain visible. Question to the audience: Who has a blog and did not updated it for a long time”. I personally know this feeling. We make this on our free time but have wife, kids. Another tip: “&lt;em&gt;Do not feed the troll&lt;/em&gt;“. There is a difference between trolling and criticism. Javaad’s receipt was:&lt;/p&gt;
&lt;ul&gt;
&lt;li style=&quot;text-align: justify;&quot;&gt;He discovered himself&lt;/li&gt;
&lt;li&gt;He created his own rules&lt;/li&gt;
&lt;li&gt;He believed&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Excellent non-technical presentation but with true content and lot of fun.&lt;/p&gt;
&lt;p style=&quot;text-align: justify;&quot;&gt;The third talk was presented by my friend &lt;a href=&quot;http://twitter.com/chrisjohnriley&quot;&gt;Chris John Riley&lt;/a&gt;: “&lt;em&gt;Defense by Numb3r5&lt;/em&gt;” or “&lt;em&gt;Making problems for script k1d13s and scanner monkeys&lt;/em&gt;“. Chris started with a description of the use of HTTP return codes. You know the 2xx, 3xx, etc. Some are common, others less like 206 which means “&lt;em&gt;partial content&lt;/em&gt;“. Most of them are defined in the RFC &lt;a href=&quot;http://www.ietf.org/rfc/rfc2616.txt&quot; title=&quot;Link to the website&quot;&gt;2616&lt;/a&gt; and divided on five classes of response:&lt;/p&gt;
&lt;ul&gt;
&lt;li style=&quot;text-align: justify;&quot;&gt;1xx (info)&lt;/li&gt;
&lt;li&gt;2xx (success)&lt;/li&gt;
&lt;li&gt;3xx (redirection)&lt;/li&gt;
&lt;li&gt;4xx (client error)&lt;/li&gt;
&lt;li&gt;5xx (server error)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;img alt=&quot;Chris on stage&quot; border=&quot;0&quot; height=&quot;225&quot; src=&quot;http://blog.rootshell.be/wp-content/uploads/2013/04/IMG_3110.jpg&quot; style=&quot;display: block; margin-left: auto; margin-right: auto;&quot; title=&quot;IMG_3110.jpg&quot; width=&quot;300&quot; /&gt;&lt;/p&gt;
&lt;p style=&quot;text-align: justify;&quot;&gt;Personally, I like the 402 – “&lt;em&gt;payment required&lt;/em&gt;“. Chri’s question is why talk about numbers? For security reason of course. What can we do with them? Unpredicatability is at your advantage in your defense layer. Increase attacker costs, delay operations. There was already some ideas about this topic but not very deeply analysed. So, how to use this? Browsers have to be flexible. This leads to interpretation! But wait, there are RFC for that? They’re more than a guideline. What can possibly go wrong? Chris made some testing using a MitM proxy written in Python. Goal of this proxy: If the response code is not 200, respond with a 200 &lt;img alt=&quot;:-)&quot; class=&quot;wp-smiley&quot; src=&quot;http://blog.rootshell.be/wp-includes/images/smilies/icon_smile.gif&quot; /&gt; . A exampe of script is available on his blog:&lt;/p&gt;
&lt;p style=&quot;text-align: justify;&quot;&gt;&lt;a href=&quot;http://catch22insecurity.com/POC/respcode.php?code=200&quot; title=&quot;Link to the website&quot;&gt;http://catch22insecurity.com/POC/respcode.php?code=200&lt;/a&gt;&lt;/p&gt;
&lt;p style=&quot;text-align: justify;&quot;&gt;Chrome, Firefox and Internet Explorer were tested against all codes with HTML, Iframe &amp;amp; JavaScript pages. What a surprise: They interpret differently. Codes are often associated with headers. Ex: 302 &amp;amp; Location:. If headers are missing, what’s happening?  What can we do with this:&lt;/p&gt;
&lt;ul style=&quot;text-align: justify;&quot;&gt;
&lt;li&gt;Browser fingerprinting (UA can be spoofed but behaviour no)&lt;/li&gt;
&lt;li&gt;Proxy detection&lt;/li&gt;
&lt;/ul&gt;
&lt;p style=&quot;text-align: justify;&quot;&gt;Let’s put all the stuff together. Simply fuck with things and defeate attackers (slowing down, case false positives/negatives etc). By changing the answers to HTTP requests performed by crawlers and scanners, Chris demonstrated the different kinds of results with, depending on the cases, many false positives or false negatives. Finally, he had the idea to write an HTTP &lt;a href=&quot;http://en.wikipedia.org/wiki/Tarpit_(networking)&quot; title=&quot;Link to the website&quot;&gt;Tarpit&lt;/a&gt;: attacks detected by a WAF are send to a bad list to the server which rewrites all the responses to those IP’s. Even more funny, Metasploit performs attacks also based on HTTP response code (&amp;gt;800 occurrences found in the code). Chris’s concluion: “&lt;em&gt;No match, no shell&lt;/em&gt;“. Script kiddies go away! The MitM proxy code is available &lt;a href=&quot;https://github.com/ChrisJohnRiley/random_code&quot; title=&quot;Link to the website&quot;&gt;here&lt;/a&gt;.&lt;/p&gt;
&lt;p style=&quot;text-align: justify;&quot;&gt;After a sunny lunch break outside and some Club-Mate, my schedule continued with &lt;a href=&quot;http://twitter.com/stephenbonner&quot;&gt;Stephen Bonner&lt;/a&gt; and his “&lt;em&gt;Make cyber-love not cyber-war&lt;/em&gt;” talk. Based on slides with pictures only, Stephen reviewed the current situation of cyber-war and explained why he does not like this expressions. Very good speaker, good interactivity with the audience but I was not attracted by the topic.&lt;/p&gt;
&lt;p&gt;&lt;img alt=&quot;Stephen on stage&quot; border=&quot;0&quot; height=&quot;225&quot; src=&quot;http://blog.rootshell.be/wp-content/uploads/2013/04/IMG_3114.jpg&quot; style=&quot;display: block; margin-left: auto; margin-right: auto;&quot; title=&quot;IMG_3114.jpg&quot; width=&quot;300&quot; /&gt;&lt;/p&gt;
&lt;p style=&quot;text-align: justify;&quot;&gt;Then followed “&lt;em&gt;Pentest automation – Helping you to get to the pub on time&lt;/em&gt;” with &lt;a href=&quot;http://twitter.com/raesene&quot;&gt;Rory McCure&lt;/a&gt;. The goal of this talk was to review different ways to optimise your time during pentesting activities to go back early to home … or to the pub! Rory started with a general question: Why automate?&lt;/p&gt;
&lt;ul&gt;
&lt;li style=&quot;text-align: justify;&quot;&gt;To save time!&lt;/li&gt;
&lt;li&gt;Repetition is boring and we are all lazy people&lt;/li&gt;
&lt;li&gt;For accuracy: how to not miss interesting stuff?&lt;/li&gt;
&lt;li&gt;To encode your knowledge! If you script it, you won’t forget what you learned&lt;/li&gt;
&lt;/ul&gt;
&lt;p style=&quot;text-align: justify;&quot;&gt;It’s a fact, if you’re a pentester, you must be able to write some code. The next question which will arise is: In which language(s)? Rory’s recommendation is to pick up one and stick to it. How to choose? The language should be&lt;/p&gt;
&lt;ul&gt;
&lt;li style=&quot;text-align: justify;&quot;&gt;Dynamic&lt;/li&gt;
&lt;li&gt;Provide an Interactive shell&lt;/li&gt;
&lt;li&gt;Focus on development speed&lt;/li&gt;
&lt;li&gt;And have a good 3rd party library support (to easily add extra features to your scripts).&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;img alt=&quot;Rory on stage&quot; border=&quot;0&quot; height=&quot;225&quot; src=&quot;http://blog.rootshell.be/wp-content/uploads/2013/04/IMG_3116.jpg&quot; style=&quot;display: block; margin-left: auto; margin-right: auto;&quot; title=&quot;IMG_3116.jpg&quot; width=&quot;300&quot; /&gt;&lt;/p&gt;
&lt;p style=&quot;text-align: justify;&quot;&gt;Another tip: use source code control (subversion, git, etc), it will save you time and headaches. To better learn, find real examples you need to solve. Then Rory reviewed some nice scenarios where scripts can be helpful. His examples were written in Ruby:&lt;/p&gt;
&lt;ul&gt;
&lt;li style=&quot;text-align: justify;&quot;&gt;Expanding a subnet in an IP addresses list. Easy but so convenient&lt;/li&gt;
&lt;li&gt;Writing a template using the ‘&lt;a href=&quot;http://mechanize.rubyforge.org/&quot; title=&quot;Link to the website&quot;&gt;mechanize&lt;/a&gt;‘ Ruby library to automate a dual-steps authentication process.&lt;/li&gt;
&lt;li&gt;Parsing the output of tools like nmap.&lt;/li&gt;
&lt;/ul&gt;
&lt;p style=&quot;text-align: justify;&quot;&gt;Scripts can also be used to automate very boring tasks: reporting! Major security tools can be extended using plugins or extensions (whatever you name them). Think about Metasploit or Burpsuite. Contribute and add your own code to automate your tasks. A final remark to the presentation: If infosec guys complain about the bad quality of code delivered by customers, they are also writing bad code to automate their tasks. Try to write secure code yourself! The examples reviewed by Rory are available on his &lt;a href=&quot;https://github.com/raesene/&quot;&gt;github&lt;/a&gt; account.&lt;/p&gt;
&lt;p style=&quot;text-align: justify;&quot;&gt;The last talk was the one of Alex Polychronopoulos about “&lt;em&gt;Going Stealth: Staying off your AV  radar&lt;/em&gt;“. Again an interesting topic for pentesters who have to fight often with anti-virus programs and try to evade their detection mechanisms. Today’s AV features are:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Detection&lt;/li&gt;
&lt;li&gt;Identification&lt;/li&gt;
&lt;li&gt;Disinfection&lt;/li&gt;
&lt;li&gt;Some of them implement more funky stuff like built-in IDS, browser add-on, etc ($VENDORS have always plenty of ideas)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;img alt=&quot;Alex on stage&quot; border=&quot;0&quot; height=&quot;225&quot; src=&quot;http://blog.rootshell.be/wp-content/uploads/2013/04/IMG_3118.jpg&quot; style=&quot;display: block; margin-left: auto; margin-right: auto;&quot; title=&quot;IMG_3118.jpg&quot; width=&quot;300&quot; /&gt;&lt;/p&gt;
&lt;p style=&quot;text-align: justify;&quot;&gt;Anti-virus evasion sometimes can be quite easy (some files are simply not scanned like *.tmp or *.ocx files) and less than 5% of new threats are detected. Alex reviewed the different type of analysis. Static analysis is not efficient today. Detection based on signatures are out of business for new threats. The code can be easily obfuscated (via “&lt;em&gt;packers&lt;/em&gt;“). Today, dynamic analysis is better (it executes the malicious code and observes its behaviour) but the main weakness of emulators is… the emulation! The malware can slow down execution (using multiple sleep() calls), use uncommon CPU instruction sets or simply detect the emulator (and not perform any malicious activity). How to evade? First tip: See big! Most anti-virus have a file size limit for performance reasons. Second,  what about destroying the AV itself? After all it’s also a software like any other with bugs.  Research is always helpful to find new evasion techniques. What about packers? Their goal is to produce a new executable from… an executable and make it more difficult to be detected by AV. Problem: they do not like self modifying code! Better packers encrypt the code. The key can be randomised for each payload (polymorphism). If you don’t like encryption, use your math classes and implement other algebra transformations to build a better packer. Don’t forget to hide your strings! (can also be used a signatures). Don’t forget that any packer, best of all, will always become a signature at a time. What about metamorphism? Examples: Use random registers, substitute instructions, randomly add track code. Put all this techniques together to write your best packer. Interesting stuff but lacking of real examples. Some packed files passed through antivirus would be funny (with a low detection rate of course).&lt;/p&gt;
&lt;p style=&quot;text-align: justify;&quot;&gt;In parallel to the regular tracks, the rookie track given the stage to new coming speakers. There was some interesting topics like:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Blinking hell – Data extraction through keyboard lock states&lt;/li&gt;
&lt;li&gt;External assessments&lt;/li&gt;
&lt;li&gt;ICMP – The proxy your admin hates to block&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;I hope that slides will be released soon! Kudos to the BsidesLondon team for the great event!&lt;/p&gt;
&lt;p&gt;&lt;img alt=&quot;Main room&quot; border=&quot;0&quot; height=&quot;225&quot; src=&quot;http://blog.rootshell.be/wp-content/uploads/2013/04/IMG_3113.jpg&quot; style=&quot;display: block; margin-left: auto; margin-right: auto;&quot; title=&quot;IMG_3113.jpg&quot; width=&quot;300&quot; /&gt;&lt;/p&gt;
&lt;p style=&quot;text-align: justify;&quot;&gt;After some beers at the after party, I went out for a dinner with friends to discuss about security arround Italian food. Tomorrow, let’s dive into the $VENDORS jungle at InfoSecurity Europe before travelling back to Belgium!&lt;/p&gt;
&lt;img height=&quot;1&quot; src=&quot;http://feeds.feedburner.com/~r/dev/rand/~4/CeaPTgVT6TA&quot; width=&quot;1&quot; /&gt;</description>
	<pubDate>Wed, 24 Apr 2013 21:40:17 +0000</pubDate>
</item>
<item>
	<title>Lionel Dricot: Égalité pour tous !</title>
	<guid>http://ploum.net/?p=2827</guid>
	<link>http://ploum.net/post/egalite-pour-tous</link>
	<description>&lt;img src=&quot;http://planet.grep.be/heads/ploum100&quot; alt=&quot;&quot; align=&quot;right&quot; style=&quot;float: right;&quot;&gt;&lt;p&gt;Le 23 avril, Bernard et Jean-Pierre se sautaient dans les bras. Aujourd’hui, avec un petit groupe d’une centaine de personnes, ils manifestent devant l’Élysée en réclamant une solution. Des panneaux “Égalité” et “Pour tous” sont brandis.&lt;br /&gt;
— Nous ne pouvions y croire, murmure Jean-Pierre avec un brin de nostalgie. À l’époque j’étais réellement amoureux.&lt;/p&gt;
&lt;p&gt;Les deux amants ont donc immédiatement accompli les formalités nécessaires et, en juin 2013, ils comptaient parmi les premiers couples homosexuels mariés en France. Dans la foulée, ils achètent un appartement en banlieue parisienne.&lt;/p&gt;
&lt;p&gt;Mais, dès septembre, le couple bat de l’aile.&lt;br /&gt;
— Je ne connaissais pas Berrnard sous ce jour. Il est devenu colérique.&lt;/p&gt;
&lt;p&gt;À part, Bernard nous confie :&lt;br /&gt;
— Cette salope de Jean-Pierre est sorti avec Sabrina, ma meilleure amie, un soir où j’étais en voyage d’affaire. Il avait bien caché ses penchants hétéros.&lt;/p&gt;
&lt;p&gt;La situation devenant tendue, le couple décide de divorcer. Mais à la première audience, surprise : la loi n’autorise le divorce qu’entre un homme et une femme. Si le vote du 23 avril a rendu le mariage accessible aux couples de même sexe, il n’en est pas de même pour le divorce.&lt;/p&gt;
&lt;p&gt;Refusant chacun d’abandonner l’appartement qu’ils ont acheté ensemble, Bernard et Jean-Pierre sont donc forcé de cohabiter. Ce que Jean-Pierre considère comme très éprouvant.&lt;br /&gt;
— Comme je travaille essentiellement à domicile, cela me force de vivre 24h sur 24 avec une pédale comme Bernard. Sans compter que ma relation avec Sabrina en souffre énormément.&lt;/p&gt;
&lt;p&gt;Leurs amis ont bien essayé de trouver un arrangement.&lt;br /&gt;
— Je veux bien revendre mes parts de l’appartement, nous dit Bernard, mais j’exige la garde de Kiki, mon hamster.&lt;br /&gt;
— Hors de question que je laisse mon hamster à une tantouze, tempête Jean-Pierre.&lt;br /&gt;
— C’est mon hamster, espèce de vieux pervers !&lt;/p&gt;
&lt;p&gt;Les deux époux ont donc lancé le Divorce Pour Tous, un collectif qui a pour but de réclamer l’égalité devant le divorce. Kiki en est rapidement devenu l’icône, ainsi que nous confie une militante qui brandit un panneau à son effigie :&lt;br /&gt;
— Si je suis ici c’est parce que je trouve injuste qu’une pauvre bête comme Kiki souffre à cause de la bêtise des hommes. À cause d’une loi mal conçue, ce hamster est obligé de vivre dans une situation conflictuelle permanente, tiraillé entre ses deux papas. C’est affreux. Le parlement doit agir pour mettre fin à cette situation ! Pour sauver Kiki, nous réclamons le divorce pour tous.&lt;/p&gt;
&lt;p&gt;Et la centaine de militants de reprendre avec elle :&lt;br /&gt;
— Pour sauver Kiki, le divorce pour tous !&lt;/p&gt;
 &lt;p&gt;&lt;a href=&quot;http://ploum.net/?flattrss_redirect&amp;amp;id=2827&amp;amp;md5=e26f6672072189cdeeeb64fdf1882239&quot; target=&quot;_blank&quot; title=&quot;Flattr&quot;&gt;&lt;img alt=&quot;flattr this!&quot; src=&quot;http://ploum.net/wp-content/plugins/flattr/img/flattr-badge-large.png&quot; /&gt;&lt;/a&gt;&lt;/p&gt;</description>
	<pubDate>Tue, 23 Apr 2013 18:03:22 +0000</pubDate>
</item>
<item>
	<title>Frederic Hornain: JBoss Application Server has a new name…</title>
	<guid>http://fhornain.wordpress.com/?p=1646</guid>
	<link>http://fhornain.wordpress.com/2013/04/22/jboss-application-server-has-a-new-name/</link>
	<description>&lt;p&gt;&lt;a href=&quot;http://fhornain.files.wordpress.com/2013/04/screenshot-from-2013-04-22-184446.png&quot;&gt;&lt;img alt=&quot;Screenshot from 2013-04-22 18:44:46&quot; class=&quot;alignleft size-full wp-image-1647&quot; height=&quot;287&quot; src=&quot;http://fhornain.files.wordpress.com/2013/04/screenshot-from-2013-04-22-184446.png?w=460&amp;amp;h=287&quot; width=&quot;460&quot; /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;JBoss AS was renamed to &lt;b&gt;reduce confusion.&lt;/b&gt; The term JBoss commonly referred to: the JBoss Application Server project, the &lt;a href=&quot;http://www.jboss.org&quot; target=&quot;_blank&quot;&gt;JBoss Community&lt;/a&gt; or the Red Hat JBoss &lt;a href=&quot;http://www.jboss.org/products&quot; target=&quot;_blank&quot;&gt;product line.&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Ref :&lt;a href=&quot;http://www.wildfly.org/&quot; target=&quot;_blank&quot; title=&quot;JBoss AS becomes Wildfly&quot;&gt; http://www.wildfly.org/&lt;/a&gt;&lt;/p&gt;
&lt;br /&gt;  &lt;a href=&quot;http://feeds.wordpress.com/1.0/gocomments/fhornain.wordpress.com/1646/&quot; rel=&quot;nofollow&quot;&gt;&lt;img alt=&quot;&quot; border=&quot;0&quot; src=&quot;http://feeds.wordpress.com/1.0/comments/fhornain.wordpress.com/1646/&quot; /&gt;&lt;/a&gt; &lt;img alt=&quot;&quot; border=&quot;0&quot; height=&quot;1&quot; src=&quot;http://stats.wordpress.com/b.gif?host=fhornain.wordpress.com&amp;amp;blog=6345193&amp;amp;post=1646&amp;amp;subd=fhornain&amp;amp;ref=&amp;amp;feed=1&quot; width=&quot;1&quot; /&gt;</description>
	<pubDate>Mon, 22 Apr 2013 16:51:37 +0000</pubDate>
</item>
<item>
	<title>Frank Goossens: Music from Our Tube; Laura Mvula</title>
	<guid>http://blog.futtta.be/?p=8752</guid>
	<link>http://feedproxy.google.com/~r/futtta/~3/8blOsJ56XWg/</link>
	<description>&lt;p&gt;There’s real gems to be found on &lt;a href=&quot;http://www.youtube.com/user/kcrw?feature=watch&quot; title=&quot;kcrw on youtube&quot;&gt;KCRW’s YouTube channel&lt;/a&gt;, which features artists that perform live in the studio. &lt;a href=&quot;http://www.lauramvula.com/&quot; title=&quot;laura mvula dot com&quot;&gt;Laura Mvula&lt;/a&gt; is a upcoming UK vocalist and you can see her performing “Sing To The Moon” below. Enjoy!&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;http://blog.futtta.be/2013/04/22/music-from-our-tube-laura-mvula/&quot;&gt;&lt;img alt=&quot;YouTube Video&quot; src=&quot;http://i.ytimg.com/vi/ZZtO544g1J8/0.jpg&quot; /&gt;&lt;/a&gt;&lt;br /&gt;Watch this video &lt;a href=&quot;http://youtu.be/ZZtO544g1J8&quot;&gt;on YouTube&lt;/a&gt; or on &lt;a href=&quot;http://icant.co.uk/easy-youtube/?http://www.youtube.com/watch?v=ZZtO544g1J8&quot;&gt;Easy Youtube&lt;/a&gt;.&lt;/p&gt;&lt;div class=&quot;yarpp-related-rss&quot;&gt;&lt;p&gt;Possibly related twitterless twaddle:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;a href=&quot;http://blog.futtta.be/2010/05/18/lite-youtube-embeds-in-wordpress/&quot; rel=&quot;bookmark&quot; title=&quot;Lite YouTube Embeds in WordPress&quot;&gt;Lite YouTube Embeds in WordPress&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://blog.futtta.be/2012/06/28/wp-youtube-lyte-on-android-native-or-in-browser-playback/&quot; rel=&quot;bookmark&quot; title=&quot;WP YouTube Lyte on Android: native or in-browser playback?&quot;&gt;WP YouTube Lyte on Android: native or in-browser playback?&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://blog.futtta.be/2010/04/28/lite-youtube-embeds-free-for-all/&quot; rel=&quot;bookmark&quot; title=&quot;Lite YouTube embeds free for all!&quot;&gt;Lite YouTube embeds free for all!&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;/div&gt; &lt;div class=&quot;feedflare&quot;&gt;
&lt;a href=&quot;http://feeds.feedburner.com/~ff/futtta?a=8blOsJ56XWg:IoC9aPUMfD4:D7DqB2pKExk&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;http://feeds.feedburner.com/~ff/futtta?i=8blOsJ56XWg:IoC9aPUMfD4:D7DqB2pKExk&quot; /&gt;&lt;/a&gt; &lt;a href=&quot;http://feeds.feedburner.com/~ff/futtta?a=8blOsJ56XWg:IoC9aPUMfD4:yIl2AUoC8zA&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;http://feeds.feedburner.com/~ff/futtta?d=yIl2AUoC8zA&quot; /&gt;&lt;/a&gt; &lt;a href=&quot;http://feeds.feedburner.com/~ff/futtta?a=8blOsJ56XWg:IoC9aPUMfD4:qj6IDK7rITs&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;http://feeds.feedburner.com/~ff/futtta?d=qj6IDK7rITs&quot; /&gt;&lt;/a&gt; &lt;a href=&quot;http://feeds.feedburner.com/~ff/futtta?a=8blOsJ56XWg:IoC9aPUMfD4:I9og5sOYxJI&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;http://feeds.feedburner.com/~ff/futtta?d=I9og5sOYxJI&quot; /&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img height=&quot;1&quot; src=&quot;http://feeds.feedburner.com/~r/futtta/~4/8blOsJ56XWg&quot; width=&quot;1&quot; /&gt;</description>
	<pubDate>Mon, 22 Apr 2013 15:40:38 +0000</pubDate>
</item>
<item>
	<title>Xavier Mertens: Belgian Edition of The Hacknowledge Contest</title>
	<guid>http://blog.rootshell.be/?p=21268</guid>
	<link>http://blog.rootshell.be/2013/04/22/belgian-edition-of-the-hacknowledge-contest/</link>
	<description>&lt;p&gt;&lt;img alt=&quot;Hacknowlege Contest&quot; border=&quot;0&quot; class=&quot;alignleft  wp-image-9380&quot; height=&quot;150&quot; src=&quot;http://blog.rootshell.be/wp-content/uploads/2013/04/IMG_3090.jpg&quot; style=&quot;float: left;&quot; title=&quot;IMG_3090.jpg&quot; width=&quot;200&quot; /&gt;&lt;/p&gt;
&lt;p style=&quot;text-align: justify;&quot;&gt;&lt;span style=&quot;font-size: 14px; line-height: 21px;&quot;&gt;The last weekend, an ethical hacking event was organised in Belgium. The &lt;a href=&quot;http://www.hacknowledge-contest.org/&quot;&gt;Hacknowledge Contest&lt;/a&gt; joined Charleroi and was hosted at the &lt;a href=&quot;http://cpehn.be/&quot;&gt;CPEHN&lt;/a&gt;. This event was previously organised only in France thanks to the initiative of the &lt;a href=&quot;http://www.acissi.net/&quot;&gt;ACISSI&lt;/a&gt;. Last year, they decided to open their challenges to other countries. The current list of participating countries is: Côte d’Ivoire, Maroc, Benelux, Espagne and France. The organisers are already looking to extend their list with other countries. If you are interested, maybe contact them.&lt;/span&gt;&lt;/p&gt;
&lt;p style=&quot;font-size: 14px; text-align: justify;&quot;&gt;Initally, I registered a small team with a colleague and finally we were five ethical hackers/friends to participate as “&lt;em&gt;UID(0)&lt;/em&gt;“. So, we joined Charleroi Saturday afternoon to attend a bunch of small talks around information security. Small event and a relaxed atmosphere. The covered topics were:&lt;/p&gt;
&lt;div style=&quot;text-align: justify;&quot;&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span style=&quot;font-size: 14px; line-height: 14px;&quot;&gt;&lt;a href=&quot;http://www.zataz.com&quot; title=&quot;Link to the website&quot;&gt;Zataz.com&lt;/a&gt;, the well-known French website and the process in place to notify organizations of data breaches and/or security issues.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style=&quot;font-size: 14px; line-height: 14px;&quot;&gt;The security of our payment cards starting from old models based on a magstripe up to the state-of-the-art (but not from a security point of view) NFC chipsets.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style=&quot;font-size: 14px; line-height: 14px;&quot;&gt;A nice presentation about social-engineering with lot of funny examples (my preferred presentation by &lt;a href=&quot;http://twitter;com/cowreth&quot; title=&quot;Link to Twitter&quot;&gt;Seb Baudru&lt;/a&gt;, see the picture below)&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style=&quot;font-size: 14px; line-height: 14px;&quot;&gt;IPv6 &amp;amp; security&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style=&quot;font-size: 14px; line-height: 14px;&quot;&gt;An overview of the security landscape in Belgium (latest major security incidents and who contact in case of issues – &lt;a href=&quot;http://www.cert.be&quot; title=&quot;Link to the website&quot;&gt;CERT.be&lt;/a&gt;, &lt;a href=&quot;http://www.polfed-fedpol.be/org/org_dgj_FCCU_RCCU_fr.php&quot; title=&quot;Link to the website&quot;&gt;FCCU&lt;/a&gt;, etc)&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
&lt;div&gt;
&lt;div&gt;&lt;img alt=&quot;Social Engineering Talk&quot; border=&quot;0&quot; height=&quot;225&quot; src=&quot;http://blog.rootshell.be/wp-content/uploads/2013/04/IMG_3086.jpg&quot; style=&quot;display: block; margin-left: auto; margin-right: auto;&quot; title=&quot;IMG_3086.jpg&quot; width=&quot;300&quot; /&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div style=&quot;font-size: 14px;&quot;&gt;&lt;/div&gt;
&lt;p style=&quot;font-size: 14px; text-align: justify;&quot;&gt;After a break and the registration of all teams, the challenges started for a period of 12 hours (Saturday 10PM to Sunday 10AM). No CTF, no blue team nor read team but a list of challenges to solve similar to the SANS &lt;a href=&quot;http://www.sans.org/netwars&quot; title=&quot;Link to the website&quot;&gt;Netwars&lt;/a&gt;. Each challenge solved gives you points. Seventy challenges  were  categories were split in the categories like:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span style=&quot;font-size: 14px; line-height: 21px;&quot;&gt;Web technologies&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style=&quot;font-size: 14px; line-height: 21px;&quot;&gt;Crypto&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style=&quot;font-size: 14px; line-height: 21px;&quot;&gt;Network&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style=&quot;font-size: 14px; line-height: 21px;&quot;&gt;Forensics&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style=&quot;font-size: 14px; line-height: 21px;&quot;&gt;Hardware (lockpicking, Teensy, barcodes, …)&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p style=&quot;font-size: 14px;&quot;&gt;&lt;img alt=&quot;Our Team&quot; border=&quot;0&quot; height=&quot;225&quot; src=&quot;http://blog.rootshell.be/wp-content/uploads/2013/04/IMG_3089.jpg&quot; style=&quot;display: block; margin-left: auto; margin-right: auto;&quot; title=&quot;IMG_3089.jpg&quot; width=&quot;300&quot; /&gt;&lt;/p&gt;
&lt;p style=&quot;font-size: 14px; text-align: justify;&quot;&gt;It was very friendly with good times, music. We finished at the third position but very close to the second team… Only the first two teams won, too bad! The final contest will be organised in France and the winning team will receive a very nice price: a trip all-inclusive to Las Vegas to attend the DefCON security conference!&lt;/p&gt;
&lt;p style=&quot;font-size: 14px; text-align: justify;&quot;&gt;I don’t often participate to events like this one. I liked the limited number of teams (5) and the friendly atmosphere between the team. Not too small, not too big, well organized. The event was also covered by some Belgian &lt;a href=&quot;http://www.rtbf.be/video/detail_un-concours-de-hacking-a-charleroi?id=1817036&quot; title=&quot;Link to the RTBF website&quot;&gt;media&lt;/a&gt;.&lt;/p&gt;
&lt;img height=&quot;1&quot; src=&quot;http://feeds.feedburner.com/~r/dev/rand/~4/BfiayNRCgZo&quot; width=&quot;1&quot; /&gt;</description>
	<pubDate>Mon, 22 Apr 2013 13:11:11 +0000</pubDate>
</item>
<item>
	<title>Patrick Debois: What if Devops was invented by Coca Cola</title>
	<guid>http://www.jedi.be/blog/2013/04/22/What if Devops was invented by Coca Cola/</guid>
	<link>http://feedproxy.google.com/~r/jedi/IZwx/~3/GZk8KJ-F5FU/</link>
	<description>&lt;p&gt;Ever wondered what Devops would look like when it would be invented by Coca Cola?&lt;/p&gt;

&lt;p&gt;Enjoy my Ignite session from &lt;a href=&quot;http://devopsdays.org/events/2013-paris&quot;&gt;Devopsdays Paris 2013&lt;/a&gt;&lt;/p&gt;

&lt;center&gt;
  &lt;div style=&quot;margin-bottom: 5px;&quot;&gt; &lt;strong&gt; &lt;a href=&quot;http://www.slideshare.net/devopsdays/what-if-devops-was-invented-by-coca-cola&quot; target=&quot;_blank&quot; title=&quot;What if devops was invented by Coca Cola&quot;&gt;What if devops was invented by Coca Cola&lt;/a&gt; &lt;/strong&gt; from &lt;strong&gt;&lt;a href=&quot;http://www.slideshare.net/devopsdays&quot; target=&quot;_blank&quot;&gt;devopsdays&lt;/a&gt;&lt;/strong&gt; &lt;/div&gt;
&lt;/center&gt;</description>
	<pubDate>Mon, 22 Apr 2013 08:35:34 +0000</pubDate>
</item>
<item>
	<title>Wim Coekaerts: Importing Oracle VM templates through a proxy</title>
	<guid>https://blogs.oracle.com/wim/entry/importing_oracle_vm_templates_through</guid>
	<link>https://blogs.oracle.com/wim/entry/importing_oracle_vm_templates_through</link>
	<description>I am working on a little tool that makes it easy to import an Oracle VM template in a more automated fashion, using python's built-in SimpleHTTPServer. While working on this, I realized that in many environments the Oracle VM Servers might be in an isolated network so that they don't have direct access to the intranet. We're talking about the management network here.&lt;p&gt;
One simple way around this, is to take one server that's on the same network as the Oracle VM Server's management network, for instance, the Oracle VM Manager system... and install something like TinyProxy on that machine. Then, use that servername as the proxy in Oracle VM Manager when you import a VM, VM Template or VM Assembly. &lt;/p&gt;&lt;p&gt;
TinyProxy can be found in the &lt;a href=&quot;http://fedoraproject.org/wiki/EPEL&quot;&gt;EPEL repository&lt;/a&gt; (http://fedoraproject.org/wiki/EPEL). The tinyproxy RPM will install without issue on Oracle Linux. It is very easy/simple to configure and this can be a good workaround or solution to make it easy to import templates or VMs while the servers are on a more isolated network.
&lt;/p&gt;&lt;p&gt;&lt;/p&gt;</description>
	<pubDate>Mon, 22 Apr 2013 04:11:58 +0000</pubDate>
</item>
<item>
	<title>Christophe Vandeplas: Resolving DNS requests for malware analysis</title>
	<guid>tag:blogger.com,1999:blog-2016855433919117617.post-6855106218058559847</guid>
	<link>http://christophe.vandeplas.com/2013/04/resolving-dns-requests-for-malware.html</link>
	<description>&lt;a href=&quot;http://www.inetsim.org/&quot; target=&quot;_blank&quot;&gt;INetSim&lt;/a&gt; is an interesting tool for simulating common internet services. It's worth gold when you want to run an air-gaped network and still simulate &quot;the internet&quot; so that malicious software continue to work as they should be. While they do some activity you monitor their behavior on your victim machine, and on the INetSim server.&lt;br /&gt;
&lt;br /&gt;
One thing that was frustrating me was the default behavior of the DNS service within INetSim. When a client connects to INetSim to resolve a DNS name the service will always respond with the same fixed IP address.&lt;br /&gt;
&lt;br /&gt;
This is rather annoying when analyzing malwares that use multiple DNS names to connect to multiple command and control servers, or just performing test-connections. As the DNS service replies with the same IP, and the malware establishes a TCP connection to that IP you can't make the relation between the domain name and the communication. There is no clear way for you to know what tcp session, and what communication matches which command and control server.&lt;br /&gt;
&lt;br /&gt;
Except if you hardcode the different domain names in the configuration file of course. However, how do you encode a name in that configuration if you don't know the name yet? Basic static analysis could already have given you a name, however that is likely not the case if the malware was packed with a non-standard packer. So should I first spend loads of time to manually unpack the malware? Or should I run the malware, look at the DNS requests, encode these DNS names in my INetSim, restore from snapshot, re-infect the machine, see new domain names, re-encode them, etc... &lt;br /&gt;
&lt;br /&gt;
Being a lazy person this doesn't motivate me a lot, so when I was following &lt;a href=&quot;http://zeltser.com/reverse-malware/&quot; target=&quot;_blank&quot;&gt;Lenny Zeltser&lt;/a&gt;'s &lt;a href=&quot;http://learnrem.com/&quot; target=&quot;_blank&quot;&gt;SANS 610&lt;/a&gt; class some time ago I threw him this question. Fortunately I was not the first one with this frustration and another student if him wrote a python script to do incremental DNS responses and gave me a copy. However I didn't like the idea to use yet-another-additional-tool, so I looked into the code of INetSim and a hack looked easier than expected.&lt;br /&gt;
&lt;br /&gt;
So I wrote a simple patch that added this new functionality:&lt;br /&gt;
- for each dns request, a new IP is returned  (i++)&lt;br /&gt;
- requesting the same dns name twice returns the same IP of course (I save it in the temporary hash with the hardcoded hostnames)&lt;br /&gt;
- the start IP is the default IP&lt;br /&gt;
- functionality is activated by a configuration flag.&lt;br /&gt;
&lt;br /&gt;
There is however a limitation: once the x.y.z.254 IP is reached the DNS response will stay the same IP.&lt;br /&gt;
&lt;br /&gt;
This patch has been sent to the developers of INetSim, and they were going to look into it to integrate it when they would have a little bit more time. It seems I have forgotten to publish this 5 months old code here.&lt;br /&gt;
&lt;br /&gt;
You can apply the &lt;a href=&quot;http://documentation.vandeplas.com/inetsim/inetsim_incrementaldns.patch&quot; target=&quot;_blank&quot;&gt;patch&lt;/a&gt; using the following commands:&lt;br /&gt;
&lt;blockquote&gt;&lt;pre&gt;tar xzf inetsim-1.2.3.tar.gz
wget http://documentation.vandeplas.com/inetsim/inetsim_incrementaldns.patch
cd inetsim-1.2.3/
patch -p1 &amp;lt; ../inetsim_incrementaldns.patch&lt;/pre&gt;&lt;/blockquote&gt;This will output: &lt;span style=&quot;font-size: xx-small;&quot;&gt;(the fuzz is because the patch was for INetSim v1.2.2) &lt;/span&gt;&lt;br /&gt;
&lt;blockquote&gt;&lt;pre&gt;patching file conf/inetsim.conf
patching file lib/INetSim/Config.pm
patching file lib/INetSim/DNS.pm
Hunk #1 succeeded at 67 with fuzz 2.&lt;/pre&gt;&lt;/blockquote&gt;Now install INetSim and start it up and perform some DNS queries. We see the responses increment each time, while staying consistent when requesting the same name.&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://4.bp.blogspot.com/-wuAbLk88CM0/UXQevTziR3I/AAAAAAAAAmg/2BnxHjfELVM/s1600/inetsim_dns.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;http://4.bp.blogspot.com/-wuAbLk88CM0/UXQevTziR3I/AAAAAAAAAmg/2BnxHjfELVM/s1600/inetsim_dns.png&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;</description>
	<pubDate>Sun, 21 Apr 2013 17:19:58 +0000</pubDate>
</item>
<item>
	<title>LOADays Organizers: Post-LOADays Report</title>
	<guid>tag:www.loadays.org,2013-04-20:post-loadays-report.html</guid>
	<link>http://www.loadays.org/post-loadays-report.html</link>
	<description>&lt;p&gt;We survived a fourth edition of LOADays, we had a good turn-out and a lot of positive feedback.
We want to thank all the speakers, sponsors and visitors.
A special thanks goes to &lt;a href=&quot;http://www.donboscowilrijk.be/site/&quot;&gt;Don Bosco Werken en Leren Wilrijk&lt;/a&gt;, they provide us with the venue and a lot more.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;The slides of the presentations have been added.&lt;/strong&gt; Use the &lt;a href=&quot;http://loadays.org/pages/schedule.html&quot;&gt;Schedule&lt;/a&gt; to find the presentations.&lt;/p&gt;
&lt;p&gt;We would like people to subscribe to our &lt;a href=&quot;http://lists.loadays.org/mailman/listinfo/load&quot;&gt;mailing list&lt;/a&gt;.
This mailing list will be used to announce next events, related events or colocated events.
You can hang out on irc &lt;em&gt;FreeNode&lt;/em&gt; channel &lt;em&gt;#load&lt;/em&gt;, or just mail us on &lt;a href=&quot;mailto:info@loadays.org&quot;&gt;info(at)loadays(dot)org&lt;/a&gt; for any questions, suggestions or remarks.&lt;/p&gt;
&lt;p&gt;Here are some of the blogs about LOADays 2013 :&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;http://czanik.blogs.balabit.com/2013/04/czp-loadays/&quot;&gt;http://czanik.blogs.balabit.com/2013/04/czp-loadays/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;http://www.krisbuytaert.be/blog/initial-loadays-speakers-announced&quot;&gt;http://www.krisbuytaert.be/blog/initial-loadays-speakers-announced&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;http://toshaan.com/loadays-2013-report.html&quot;&gt;http://toshaan.com/loadays-2013-report.html&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;http://grep.be/blog/en/life/events/load2013&quot;&gt;http://grep.be/blog/en/life/events/load2013&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;http://blog.aeolusproject.org/aeolus-will-be-at-loadays-2013/&quot;&gt;http://blog.aeolusproject.org/aeolus-will-be-at-loadays-2013/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://blog.kumina.nl/2013/04/loadays-2013-and-kumina/&quot;&gt;https://blog.kumina.nl/2013/04/loadays-2013-and-kumina/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;http://www.openminds.be/nl/evenementen/detail/loadays&quot;&gt;http://www.openminds.be/nl/evenementen/detail/loadays&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;http://www.open-future.be/loadays-6-till-7th-april&quot;&gt;http://www.open-future.be/loadays-6-till-7th-april&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;http://www.openqrm-enterprise.com/community/project-blog/post/article/openqrm-tutorial-at-loadays-2013-in-antwerp-1.html&quot;&gt;http://www.openqrm-enterprise.com/community/project-blog/post/article/openqrm-tutorial-at-loadays-2013-in-antwerp-1.html&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;http://blog.opennebula.org/?p=4460&quot;&gt;http://blog.opennebula.org/?p=4460&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;http://blog.opennebula.org/?p=4421&quot;&gt;http://blog.opennebula.org/?p=4421&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;http://architects.dzone.com/articles/initial-loadays-speakers&quot;&gt;http://architects.dzone.com/articles/initial-loadays-speakers&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description>
	<pubDate>Fri, 19 Apr 2013 22:00:00 +0000</pubDate>
</item>
<item>
	<title>Kris Buytaert: Evolution Woes and yum magic</title>
	<guid>http://www.krisbuytaert.be/1079 at http://www.krisbuytaert.be/blog</guid>
	<link>http://www.krisbuytaert.be/blog/evolution-woes-and-yum-magic</link>
	<description>&lt;img src=&quot;http://planet.grep.be/heads/sdog&quot; alt=&quot;&quot; align=&quot;right&quot; style=&quot;float: right;&quot;&gt;&lt;p&gt;I`m an oldschool guy .. I still love pop3(s) to get my mails locally and read them with my fat email client.  Evolution.&lt;/p&gt;
&lt;p&gt;So when gmail breaks their pop/imap infra I`m screwed for a while. I hate reading mail from a web gui and the collapsed threading model gmail uses makes me nauseus.&lt;/p&gt;
&lt;p&gt;So I fiddled with my config .. disabled it.. deleted the account.. created it again. But even after gmail was up again . I couldn't  access my mail from my favourite client. Yet from other clients it seemed to work.&lt;/p&gt;
&lt;p&gt;This obviously is real fun when you are travelling and trying to keep an eye on a number of different email threads ..&lt;/p&gt;
&lt;p&gt;So I`m back home from Paris now and spend some 10 minutes figuring out what could be wrong.&lt;/p&gt;
&lt;p&gt;I ran into &lt;a href=&quot;https://bugzilla.redhat.com/show_bug.cgi?id=949180&quot; rel=&quot;nofollow&quot; title=&quot;https://bugzilla.redhat.com/show_bug.cgi?id=949180&quot;&gt;https://bugzilla.redhat.com/show_bug.cgi?id=949180&lt;/a&gt;  which points out that for newly created there is a problem with the keyring prompting&lt;/p&gt;
&lt;p&gt;And refers to &lt;a href=&quot;https://bugzilla.redhat.com/show_bug.cgi?id=953641&quot; rel=&quot;nofollow&quot; title=&quot;https://bugzilla.redhat.com/show_bug.cgi?id=953641&quot;&gt;https://bugzilla.redhat.com/show_bug.cgi?id=953641&lt;/a&gt; accounts   Which states that gcr-3.6.2-3 breaks password prompt/keyring unlocks.&lt;/p&gt;
&lt;p&gt;And indeed .. &lt;/p&gt;
&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;geshifilter&quot;&gt;&lt;pre class=&quot;text geshifilter-text&quot; style=&quot;font-family: monospace;&quot;&gt;&lt;ol&gt;&lt;li style=&quot;font-family: monospace; font-weight: normal;&quot;&gt;&lt;div style=&quot;font-family: monospace; font-weight: normal; font-style: normal;&quot;&gt;yum shell&lt;/div&gt;&lt;/li&gt;&lt;li style=&quot;font-family: monospace; font-weight: normal;&quot;&gt;&lt;div style=&quot;font-family: monospace; font-weight: normal; font-style: normal;&quot;&gt;Loaded plugins: langpacks, presto, ps, puppetverify, refresh-packagekit&lt;/div&gt;&lt;/li&gt;&lt;li style=&quot;font-family: monospace; font-weight: normal;&quot;&gt;&lt;div style=&quot;font-family: monospace; font-weight: normal; font-style: normal;&quot;&gt;&amp;gt; remove gcr&lt;/div&gt;&lt;/li&gt;&lt;li style=&quot;font-family: monospace; font-weight: normal;&quot;&gt;&lt;div style=&quot;font-family: monospace; font-weight: normal; font-style: normal;&quot;&gt;&amp;gt; install gcr-3.6.2-1.fc18&lt;/div&gt;&lt;/li&gt;&lt;li style=&quot;font-family: monospace; font-weight: normal;&quot;&gt;&lt;div style=&quot;font-family: monospace; font-weight: normal; font-style: normal;&quot;&gt;adobe-linux-x86_64                                       |  951 B     00:00     &lt;/div&gt;&lt;/li&gt;&lt;li style=&quot;font-family: monospace; font-weight: normal;&quot;&gt;&lt;div style=&quot;font-family: monospace; font-weight: normal; font-style: normal;&quot;&gt;fedora/18/x86_64/metalink                                |  31 kB     00:00     &lt;/div&gt;&lt;/li&gt;&lt;li style=&quot;font-family: monospace; font-weight: normal;&quot;&gt;&lt;div style=&quot;font-family: monospace; font-weight: normal; font-style: normal;&quot;&gt;google-chrome                                            |  951 B     00:00     &lt;/div&gt;&lt;/li&gt;&lt;li style=&quot;font-family: monospace; font-weight: normal;&quot;&gt;&lt;div style=&quot;font-family: monospace; font-weight: normal; font-style: normal;&quot;&gt;google-earth                                             |  951 B     00:00     &lt;/div&gt;&lt;/li&gt;&lt;li style=&quot;font-family: monospace; font-weight: normal;&quot;&gt;&lt;div style=&quot;font-family: monospace; font-weight: normal; font-style: normal;&quot;&gt;google-talkplugin                                        |  951 B     00:00     &lt;/div&gt;&lt;/li&gt;&lt;li style=&quot;font-family: monospace; font-weight: normal;&quot;&gt;&lt;div style=&quot;font-family: monospace; font-weight: normal; font-style: normal;&quot;&gt;rpmfusion-free-updates                                   | 3.3 kB     00:00     &lt;/div&gt;&lt;/li&gt;&lt;li style=&quot;font-family: monospace; font-weight: normal;&quot;&gt;&lt;div style=&quot;font-family: monospace; font-weight: normal; font-style: normal;&quot;&gt;rpmfusion-nonfree-updates                                | 3.3 kB     00:00     &lt;/div&gt;&lt;/li&gt;&lt;li style=&quot;font-family: monospace; font-weight: normal;&quot;&gt;&lt;div style=&quot;font-family: monospace; font-weight: normal; font-style: normal;&quot;&gt;updates/18/x86_64/metalink                               |  24 kB     00:00     &lt;/div&gt;&lt;/li&gt;&lt;li style=&quot;font-family: monospace; font-weight: normal;&quot;&gt;&lt;div style=&quot;font-family: monospace; font-weight: normal; font-style: normal;&quot;&gt;rpmfusion-free-updates/primary_db                          | 279 kB   00:01     &lt;/div&gt;&lt;/li&gt;&lt;li style=&quot;font-family: monospace; font-weight: normal;&quot;&gt;&lt;div style=&quot;font-family: monospace; font-weight: normal; font-style: normal;&quot;&gt;&amp;gt; run&lt;/div&gt;&lt;/li&gt;&lt;li style=&quot;font-family: monospace; font-weight: normal;&quot;&gt;&lt;div style=&quot;font-family: monospace; font-weight: normal; font-style: normal;&quot;&gt; --&amp;gt; Running transaction check&lt;/div&gt;&lt;/li&gt;&lt;li style=&quot;font-family: monospace; font-weight: normal;&quot;&gt;&lt;div style=&quot;font-family: monospace; font-weight: normal; font-style: normal;&quot;&gt;---&amp;gt; Package gcr.x86_64 0:3.6.2-1.fc18 will be installed&lt;/div&gt;&lt;/li&gt;&lt;li style=&quot;font-family: monospace; font-weight: normal;&quot;&gt;&lt;div style=&quot;font-family: monospace; font-weight: normal; font-style: normal;&quot;&gt;---&amp;gt; Package gcr.x86_64 0:3.6.2-3.fc18 will be erased&lt;/div&gt;&lt;/li&gt;&lt;li style=&quot;font-family: monospace; font-weight: normal;&quot;&gt;&lt;div style=&quot;font-family: monospace; font-weight: normal; font-style: normal;&quot;&gt; --&amp;gt; Finished Dependency Resolution&lt;/div&gt;&lt;/li&gt;&lt;li style=&quot;font-family: monospace; font-weight: normal;&quot;&gt;&lt;div style=&quot;font-family: monospace; font-weight: normal; font-style: normal;&quot;&gt; &lt;/div&gt;&lt;/li&gt;&lt;li style=&quot;font-family: monospace; font-weight: normal;&quot;&gt;&lt;div style=&quot;font-family: monospace; font-weight: normal; font-style: normal;&quot;&gt; ================================================================================&lt;/div&gt;&lt;/li&gt;&lt;li style=&quot;font-family: monospace; font-weight: normal;&quot;&gt;&lt;div style=&quot;font-family: monospace; font-weight: normal; font-style: normal;&quot;&gt;  Package       Arch             Version                Repository          Size&lt;/div&gt;&lt;/li&gt;&lt;li style=&quot;font-family: monospace; font-weight: normal;&quot;&gt;&lt;div style=&quot;font-family: monospace; font-weight: normal; font-style: normal;&quot;&gt; ================================================================================&lt;/div&gt;&lt;/li&gt;&lt;li style=&quot;font-family: monospace; font-weight: normal;&quot;&gt;&lt;div style=&quot;font-family: monospace; font-weight: normal; font-style: normal;&quot;&gt;  Installing:&lt;/div&gt;&lt;/li&gt;&lt;li style=&quot;font-family: monospace; font-weight: normal;&quot;&gt;&lt;div style=&quot;font-family: monospace; font-weight: normal; font-style: normal;&quot;&gt;   gcr           x86_64           3.6.2-1.fc18           fedora             627 k&lt;/div&gt;&lt;/li&gt;&lt;li style=&quot;font-family: monospace; font-weight: normal;&quot;&gt;&lt;div style=&quot;font-family: monospace; font-weight: normal; font-style: normal;&quot;&gt;  Removing:&lt;/div&gt;&lt;/li&gt;&lt;li style=&quot;font-family: monospace; font-weight: normal;&quot;&gt;&lt;div style=&quot;font-family: monospace; font-weight: normal; font-style: normal;&quot;&gt;    gcr           x86_64           3.6.2-3.fc18           @updates           2.3 M&lt;/div&gt;&lt;/li&gt;&lt;li style=&quot;font-family: monospace; font-weight: normal;&quot;&gt;&lt;div style=&quot;font-family: monospace; font-weight: normal; font-style: normal;&quot;&gt; &lt;/div&gt;&lt;/li&gt;&lt;li style=&quot;font-family: monospace; font-weight: normal;&quot;&gt;&lt;div style=&quot;font-family: monospace; font-weight: normal; font-style: normal;&quot;&gt;    Transaction Summary&lt;/div&gt;&lt;/li&gt;&lt;li style=&quot;font-family: monospace; font-weight: normal;&quot;&gt;&lt;div style=&quot;font-family: monospace; font-weight: normal; font-style: normal;&quot;&gt; ================================================================================&lt;/div&gt;&lt;/li&gt;&lt;li style=&quot;font-family: monospace; font-weight: normal;&quot;&gt;&lt;div style=&quot;font-family: monospace; font-weight: normal; font-style: normal;&quot;&gt;  Install  1 Package&lt;/div&gt;&lt;/li&gt;&lt;li style=&quot;font-family: monospace; font-weight: normal;&quot;&gt;&lt;div style=&quot;font-family: monospace; font-weight: normal; font-style: normal;&quot;&gt;  Remove   1 Package&lt;/div&gt;&lt;/li&gt;&lt;li style=&quot;font-family: monospace; font-weight: normal;&quot;&gt;&lt;div style=&quot;font-family: monospace; font-weight: normal; font-style: normal;&quot;&gt; &lt;/div&gt;&lt;/li&gt;&lt;li style=&quot;font-family: monospace; font-weight: normal;&quot;&gt;&lt;div style=&quot;font-family: monospace; font-weight: normal; font-style: normal;&quot;&gt;    Total download size: 627 k&lt;/div&gt;&lt;/li&gt;&lt;li style=&quot;font-family: monospace; font-weight: normal;&quot;&gt;&lt;div style=&quot;font-family: monospace; font-weight: normal; font-style: normal;&quot;&gt;    Is this ok [y/N]: y&lt;/div&gt;&lt;/li&gt;&lt;li style=&quot;font-family: monospace; font-weight: normal;&quot;&gt;&lt;div style=&quot;font-family: monospace; font-weight: normal; font-style: normal;&quot;&gt;    Downloading Packages:&lt;/div&gt;&lt;/li&gt;&lt;li style=&quot;font-family: monospace; font-weight: normal;&quot;&gt;&lt;div style=&quot;font-family: monospace; font-weight: normal; font-style: normal;&quot;&gt;    gcr-3.6.2-1.fc18.x86_64.rpm                                | 627 kB   00:02     &lt;/div&gt;&lt;/li&gt;&lt;li style=&quot;font-family: monospace; font-weight: normal;&quot;&gt;&lt;div style=&quot;font-family: monospace; font-weight: normal; font-style: normal;&quot;&gt;    Running Transaction Check&lt;/div&gt;&lt;/li&gt;&lt;li style=&quot;font-family: monospace; font-weight: normal;&quot;&gt;&lt;div style=&quot;font-family: monospace; font-weight: normal; font-style: normal;&quot;&gt;    Running Transaction Test&lt;/div&gt;&lt;/li&gt;&lt;li style=&quot;font-family: monospace; font-weight: normal;&quot;&gt;&lt;div style=&quot;font-family: monospace; font-weight: normal; font-style: normal;&quot;&gt;    Transaction Test Succeeded&lt;/div&gt;&lt;/li&gt;&lt;li style=&quot;font-family: monospace; font-weight: normal;&quot;&gt;&lt;div style=&quot;font-family: monospace; font-weight: normal; font-style: normal;&quot;&gt;    Running Transaction&lt;/div&gt;&lt;/li&gt;&lt;li style=&quot;font-family: monospace; font-weight: normal;&quot;&gt;&lt;div style=&quot;font-family: monospace; font-weight: normal; font-style: normal;&quot;&gt;      Installing : gcr-3.6.2-1.fc18.x86_64                                      1/2 &lt;/div&gt;&lt;/li&gt;&lt;li style=&quot;font-family: monospace; font-weight: normal;&quot;&gt;&lt;div style=&quot;font-family: monospace; font-weight: normal; font-style: normal;&quot;&gt;      Cleanup    : gcr-3.6.2-3.fc18.x86_64                                      2/2 &lt;/div&gt;&lt;/li&gt;&lt;li style=&quot;font-family: monospace; font-weight: normal;&quot;&gt;&lt;div style=&quot;font-family: monospace; font-weight: normal; font-style: normal;&quot;&gt;      Verifying  : gcr-3.6.2-1.fc18.x86_64                                      1/2 &lt;/div&gt;&lt;/li&gt;&lt;li style=&quot;font-family: monospace; font-weight: normal;&quot;&gt;&lt;div style=&quot;font-family: monospace; font-weight: normal; font-style: normal;&quot;&gt;      Verifying  : gcr-3.6.2-3.fc18.x86_64                                      2/2 &lt;/div&gt;&lt;/li&gt;&lt;li style=&quot;font-family: monospace; font-weight: normal;&quot;&gt;&lt;div style=&quot;font-family: monospace; font-weight: normal; font-style: normal;&quot;&gt;           Removed:&lt;/div&gt;&lt;/li&gt;&lt;li style=&quot;font-family: monospace; font-weight: normal;&quot;&gt;&lt;div style=&quot;font-family: monospace; font-weight: normal; font-style: normal;&quot;&gt;              gcr.x86_64 0:3.6.2-3.fc18                                                     &lt;/div&gt;&lt;/li&gt;&lt;li style=&quot;font-family: monospace; font-weight: normal;&quot;&gt;&lt;div style=&quot;font-family: monospace; font-weight: normal; font-style: normal;&quot;&gt;           Installed:&lt;/div&gt;&lt;/li&gt;&lt;li style=&quot;font-family: monospace; font-weight: normal;&quot;&gt;&lt;div style=&quot;font-family: monospace; font-weight: normal; font-style: normal;&quot;&gt;             gcr.x86_64 0:3.6.2-1.fc18                                                     &lt;/div&gt;&lt;/li&gt;&lt;li style=&quot;font-family: monospace; font-weight: normal;&quot;&gt;&lt;div style=&quot;font-family: monospace; font-weight: normal; font-style: normal;&quot;&gt; &lt;/div&gt;&lt;/li&gt;&lt;li style=&quot;font-family: monospace; font-weight: normal;&quot;&gt;&lt;div style=&quot;font-family: monospace; font-weight: normal; font-style: normal;&quot;&gt;               Finished Transaction&lt;/div&gt;&lt;/li&gt;&lt;li style=&quot;font-family: monospace; font-weight: normal;&quot;&gt;&lt;div style=&quot;font-family: monospace; font-weight: normal; font-style: normal;&quot;&gt;                &amp;gt; quit&lt;/div&gt;&lt;/li&gt;&lt;li style=&quot;font-family: monospace; font-weight: normal;&quot;&gt;&lt;div style=&quot;font-family: monospace; font-weight: normal; font-style: normal;&quot;&gt;             &amp;gt; Leaving Shell&lt;/div&gt;&lt;/li&gt;&lt;/ol&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;&lt;/p&gt;
&lt;p&gt;Solved the problem&lt;/p&gt;</description>
	<pubDate>Fri, 19 Apr 2013 20:54:33 +0000</pubDate>
</item>
<item>
	<title>Xavier Mertens: Fixing SET 5.0.3 &amp; Metasploit 4.6.0</title>
	<guid>http://blog.rootshell.be/?p=21230</guid>
	<link>http://blog.rootshell.be/2013/04/19/fixing-set-5-0-3-metasploit-4-6-0/</link>
	<description>&lt;p style=&quot;text-align: justify;&quot;&gt;&lt;img alt=&quot;Social Engineering&quot; class=&quot;alignleft  wp-image-21231&quot; height=&quot;149&quot; src=&quot;http://blog.rootshell.be/wp-content/uploads/2013/04/social_engineering.jpg&quot; width=&quot;199&quot; /&gt;A quick post to share with you my feedback about an issue I faced after a &lt;a href=&quot;https://www.trustedsec.com/downloads/social-engineer-toolkit/&quot; title=&quot;Link to the website&quot;&gt;SET&lt;/a&gt; (“&lt;em&gt;Social Engineering Toolkit&lt;/em&gt;“) upgrade to the latest version (5.0.3). SET is a wonderful tool that you must master.  I’m using SET on a EC2 instance because it does not interfere with my other IP addresses and I can enable all ports without any issue (nothing else is running on this instance). Note that Amazon has a specific policy to make pentesting from their infrastructure, have a look &lt;a href=&quot;https://aws.amazon.com/security/penetration-testing/&quot; title=&quot;Link to the Amazon website&quot;&gt;here&lt;/a&gt;).&lt;/p&gt;
&lt;p style=&quot;text-align: justify;&quot;&gt;&lt;span id=&quot;more-21230&quot;&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style=&quot;text-align: justify;&quot;&gt;My current environment is:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span style=&quot;line-height: 16px;&quot;&gt;Ubuntu 12.04-LST (fully patched)&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;SET 5.0.2 (installed from the &lt;a href=&quot;https://github.com/trustedsec/social-engineer-toolkit/&quot; title=&quot;Link to github.com&quot;&gt;git&lt;/a&gt; repository)&lt;/li&gt;
&lt;li&gt;Metasploit 4.6&lt;/li&gt;
&lt;/ul&gt;
&lt;p style=&quot;text-align: justify;&quot;&gt;After the SET upgrade, I faced the following error when launching Metasploit from SET (full error dumped to allow the Google crawler to do its job)&lt;/p&gt;
&lt;pre&gt;set:phishing&amp;gt; Setup a listener [yes|no]:yes
/opt/metasploit/apps/pro/msf3/lib/fastlib.rb:374:in `fastlib_original_require': no such file to load -- active_support/concern (LoadError)
 from /opt/metasploit/apps/pro/msf3/lib/fastlib.rb:374:in `require'
 from /opt/metasploit/apps/pro/msf3/lib/msf/core/module_manager/cache.rb:4
 from /opt/metasploit/apps/pro/msf3/lib/fastlib.rb:374:in `fastlib_original_require'
 from /opt/metasploit/apps/pro/msf3/lib/fastlib.rb:374:in `require'
 from /opt/metasploit/apps/pro/msf3/lib/msf/core/module_manager.rb:27
 from /opt/metasploit/apps/pro/msf3/lib/fastlib.rb:374:in `fastlib_original_require'
 from /opt/metasploit/apps/pro/msf3/lib/fastlib.rb:374:in `require'
 from /opt/metasploit/apps/pro/msf3/lib/msf/core/framework.rb:66
 from /opt/metasploit/apps/pro/msf3/lib/fastlib.rb:374:in `fastlib_original_require'
 from /opt/metasploit/apps/pro/msf3/lib/fastlib.rb:374:in `require'
 from /opt/metasploit/apps/pro/msf3/lib/msf/core.rb:34 
 from /opt/metasploit/apps/pro/msf3/lib/fastlib.rb:374:in `fastlib_original_require'
 from /opt/metasploit/apps/pro/msf3/lib/fastlib.rb:374:in `require'
 from /opt/metasploit/apps/pro/msf3/lib/msf/ui/console/driver.rb:2
 from /opt/metasploit/apps/pro/msf3/lib/fastlib.rb:374:in `fastlib_original_require'
 from /opt/metasploit/apps/pro/msf3/lib/fastlib.rb:374:in `require'
 from /opt/metasploit/apps/pro/msf3/lib/msf/ui/console.rb:11
 from /opt/metasploit/apps/pro/msf3/lib/fastlib.rb:374:in `fastlib_original_require'
 from /opt/metasploit/apps/pro/msf3/lib/fastlib.rb:374:in `require'
 from /opt/metasploit/apps/pro/msf3/lib/msf/ui.rb:11
 from /opt/metasploit/apps/pro/msf3/lib/fastlib.rb:374:in `fastlib_original_require'
 from /opt/metasploit/apps/pro/msf3/lib/fastlib.rb:374:in `require'
 from /opt/metasploit/apps/pro/msf3//msfconsole:136&lt;/pre&gt;
&lt;p style=&quot;text-align: justify;&quot;&gt;Metasploit was running fine when started manually from the command line. Google found a thread on a forum about the same kind of problem. The suggestion was to setup the right environment for Metasploit using the setenv.sh script. Note: Be sure to execute the script using ‘&lt;em&gt;source&lt;/em&gt;‘ otherwise a new shell will be spawned and closed immediately without changing your environment:&lt;/p&gt;
&lt;p&gt;# source /opt/metasploit/scripts/setenv.sh&lt;br /&gt;
# se-toolkit&lt;/p&gt;
&lt;p&gt;Same issue, I tried to load ‘active_support/concern’ manually, it worked:&lt;/p&gt;
&lt;pre&gt;# ruby
require('active_support/concern')
^D
#&lt;/pre&gt;
&lt;p&gt;Finally, I upgraded the installed Ruby gems with the following command:&lt;/p&gt;
&lt;pre&gt;# gem update `gem list | cut -d ' ' -f 1`&lt;/pre&gt;
&lt;p style=&quot;text-align: justify;&quot;&gt;And the problem was solved! Don’t ask me why, I did not dive into the code and I’m not a Ruby guru it worked for me. If you are facing the same problem, think about upgrading your Gems. Just sharing…&lt;/p&gt;
&lt;p style=&quot;text-align: justify;&quot;&gt;Here is my list of installed Gems:&lt;/p&gt;
&lt;pre&gt;# gem list

*** LOCAL GEMS ***

actionmailer (3.2.13, 3.2.11)
actionpack (3.2.13, 3.2.11)
activemodel (3.2.13, 3.2.11)
activerecord (3.2.13, 3.2.11)
activeresource (3.2.13, 3.2.11)
activesupport (3.2.13, 3.2.11)
acts_as_list (0.2.0, 0.1.5)
arel (4.0.0, 3.0.2)
authlogic (3.3.0, 3.1.0)
bigdecimal (1.1.0)
bson (1.8.5, 1.6.4)
bson_ext (1.6.1)
builder (3.2.0, 3.0.4)
bundler (1.3.5, 1.1.2)
carrierwave (0.8.0, 0.7.0)
chunky_png (1.2.8, 1.2.6)
coderay (1.0.9, 1.0.8)
compass (0.12.2)
daemons (1.1.9, 1.1.8)
erubis (2.7.0)
eventmachine (0.12.10)
formtastic (2.2.1, 2.1.1)
fssm (0.2.10, 0.2.9)
hike (1.2.2, 1.2.1)
i18n (0.6.4, 0.6.1)
ice_cube (0.10.0, 0.9.1)
io-console (0.3)
journey (1.0.4)
jquery-rails (2.2.1, 2.1.3)
json (1.7.7, 1.6.6, 1.6.5, 1.5.4)
kaminari (0.14.1, 0.14.0)
libv8 (3.16.14.1, 3.11.8.17 x86_64-linux, 3.3.10.4 x86_64-linux)
liquid (2.5.0, 2.3.0)
mail (2.5.3, 2.4.4)
method_source (0.8.1)
mime-types (1.22)
minitest (4.7.2, 2.5.1)
msgpack (0.4.6 ruby)
multi_json (1.7.2, 1.5.0)
nokogiri (1.5.2 ruby)
pg (0.13.2 ruby)
polyglot (0.3.3)
pry (0.9.12, 0.9.10)
rack (1.4.5, 1.4.1 ruby)
rack-cache (1.2)
rack-ssl (1.3.3, 1.3.2)
rack-test (0.6.2)
rails (3.2.13, 3.2.11)
railties (3.2.13, 3.2.11)
rake (10.0.4, 10.0.3, 0.9.2.2)
rdoc (4.0.1, 3.12, 3.9.4)
ref (1.0.4)
robots (0.10.1)
sass (3.2.7, 3.2.1)
slop (3.4.4, 3.3.3)
sprockets (2.9.2, 2.2.2)
state_machine (1.2.0, 1.1.2)
therubyracer (0.9.10)
thin (1.3.1)
thor (0.18.1, 0.16.0)
tilt (1.3.7, 1.3.3)
treetop (1.4.12)
tzinfo (0.3.37, 0.3.35)&lt;/pre&gt;
&lt;img height=&quot;1&quot; src=&quot;http://feeds.feedburner.com/~r/dev/rand/~4/6j4xMUFLArI&quot; width=&quot;1&quot; /&gt;</description>
	<pubDate>Fri, 19 Apr 2013 15:44:21 +0000</pubDate>
</item>
<item>
	<title>Matt Casters: The Pentaho Big Data Forum</title>
	<guid>http://www.ibridge.be/?p=212</guid>
	<link>http://www.ibridge.be/?p=212</link>
	<description>&lt;p&gt;Dear friends,&lt;/p&gt;
&lt;p&gt;If you’re in the Washington DC area next Tuesday, April 23rd, why not drop in on our complementary Big Data Forum:&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://events.pentaho.com/Big-Data-Forum-Registration.html&quot;&gt;http://events.pentaho.com/Big-Data-Forum-Registration.html&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Come and listen to us and our partners Cloudera, 10gen and Unisys and see what we can do for you in the Big Data space.&lt;/p&gt;
&lt;p&gt;See you soon in DC!&lt;/p&gt;
&lt;p&gt;Matt&lt;/p&gt;</description>
	<pubDate>Thu, 18 Apr 2013 21:22:06 +0000</pubDate>
</item>
<item>
	<title>Frank Goossens: WP Caching plugin vulnerability debrief</title>
	<guid>http://blog.futtta.be/?p=8746</guid>
	<link>http://feedproxy.google.com/~r/futtta/~3/IeW0GBjp9dw/</link>
	<description>&lt;p&gt;Now that both &lt;a href=&quot;http://wordpress.org/extend/plugins/wp-super-cache/changelog/&quot; title=&quot;WP Super Cache changelog&quot;&gt;WP Super Cache&lt;/a&gt; and &lt;a href=&quot;http://wordpress.org/extend/plugins/w3-total-cache/changelog/&quot; title=&quot;W3 Total Cache changelog&quot;&gt;W3 Total Cache&lt;/a&gt; developers &lt;strong&gt;have released a new version of their respective plugins&lt;/strong&gt; (upgrade first, continue reading after) it seems time for a small “&lt;strong&gt;post mortem&lt;/strong&gt;“.&lt;/p&gt;&lt;p&gt;The problem was in the &lt;strong&gt;interpretation of&lt;/strong&gt; &lt;a href=&quot;http://wordpress.org/extend/plugins/wp-super-cache/faq/&quot; title=&quot;wp super cache faq with info on dynamic snippets (scroll down)&quot;&gt;dynamic snippets&lt;/a&gt;, that are contained inside a number of &lt;strong&gt;specific HTML-comment tags&lt;/strong&gt;. These snippets allow both plugins (and their predecessor WP Cache) to &lt;strong&gt;cache pages&lt;/strong&gt; while keeping a limited amount of &lt;strong&gt;dynamic, PHP-generated content&lt;/strong&gt; in them that can be executed on the fly. Think &lt;a href=&quot;https://www.varnish-cache.org/docs/3.0/tutorial/esi.html&quot; title=&quot;varnish esi doc &quot;&gt;ESI in e.g. Varnish&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;The vulnerability, which was &lt;a href=&quot;http://wordpress.org/support/topic/pwn3d&quot; title=&quot;kisscsaby reports vuln on wp.org support forum&quot;&gt;originally discovered by kisscsaby and reported 3 weeks ago on the wordpress.org plugins support forum&lt;/a&gt;, had multiple causes:&lt;/p&gt;&lt;ol&gt;&lt;li&gt;Unlike ESI’s, dynamic snippets can &lt;strong&gt;not only be includes (mclude) but also PHP-code (mfunc)&lt;/strong&gt;. Whereas one could consider includes of known files more or less safe, inclusion of PHP-code introduces a risk.&lt;/li&gt;&lt;li&gt;As WP Super Cache &amp;amp; W3 Total Cache keep entire pages in cache and as pages can contain comments, that &lt;strong&gt;user generated content is parsed for dynamic snippets as well&lt;/strong&gt;.&lt;/li&gt;&lt;li&gt;&lt;strong&gt; WordPress core&lt;/strong&gt; by default only allows a limited set of HTML in comments (“a blockquote code em strong ul ol li”), but it also &lt;strong&gt;leaves HTML comments in place&lt;/strong&gt;.&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;As a result, blogs with WP Super Cache (before version 1.3) and W3 Total Cache (before version 0.9.2.9) were at risk of &lt;strong&gt;PHP code injection&lt;/strong&gt;. Blog comments could contain dynamic snippets (in HTML-comments) and WordPress core did not them filter out. Upon a such a malicious comment having been submitted, a new cached version of the page was created that included the injected PHP-code. Upon the first request of the cached page, that code was successfully executed.&lt;/p&gt;&lt;p&gt;I stumbled on &lt;a href=&quot;http://wordpress.org/support/topic/pwn3d&quot; title=&quot;original report on wordpress.org forum&quot;&gt;the vulnerability report&lt;/a&gt; about a week and a half ago, while researching why dynamic snippets weren’t executing when &lt;a href=&quot;http://blog.futtta.be/category/autoptimize/&quot; title=&quot;autoptimize, my adopted plugin&quot;&gt;Autoptimize&lt;/a&gt; was active (simple really, Autoptimize by default removes HTML comments, the upcoming 1.6.3 will leave mfunc/mclude in place). As this &lt;strong&gt;seemed like a pretty severe security hole&lt;/strong&gt; and as there was no feedback from developers in the support thread, &lt;a href=&quot;http://blog.futtta.be/2013/04/10/wp-safer-cache-stopgap-for-wordpress-cache-plugins-vulnerability/&quot; title=&quot;WP Safer Cache: stopgap for WordPress Cache plugins vulnerability&quot;&gt;I &lt;strong&gt;created a small “stopgap plugin”&lt;/strong&gt;&lt;/a&gt; to mitigate the threat on April 10th, &lt;strong&gt;mailed security@wordpress.org and plugins@wordpress.org&lt;/strong&gt; and requested &lt;a href=&quot;http://wordpress.org/extend/plugins/wp-safer-cache/&quot; title=&quot;stopgap plugin soon to be retired&quot;&gt;WP Safer Cache being published on wordpress.org&lt;/a&gt; on the 11th. A &lt;strong&gt;couple of hours later WP Super Cache’s Donncha O Caoimh contacted me&lt;/strong&gt; and the same day he &lt;strong&gt;released a version (1.3) that fixed this vulnerability&lt;/strong&gt; by parsing out potential exploits from comments as they are posted and as they are rendered. On April 12th&lt;strong&gt; W3 Total Cache’s Frederick Townes confirmed&lt;/strong&gt; they were working on a fix. Version &lt;strong&gt;0.9.2.9 got released on April 17th,&lt;/strong&gt; disabling dynamic snippets by default and when these are enabled, they require a secret alphanumeric key to be included in the snippet which is checked against one that is defined in wp-config.php.&lt;/p&gt;&lt;p&gt;Conclusions; The fact that this &lt;strong&gt;didn’t generate any fuss&lt;/strong&gt; (as opposed to &lt;a href=&quot;https://www.google.be/search?q=w3+total+cache+vulnerability+database&quot; title=&quot;w3 total cache database has usernames and password hashes&quot;&gt;W3 Total Cache’s widely published information disclosure vulnerability in December 2012&lt;/a&gt;) is surprising. PHP Code injection clearly is a more&lt;strong&gt; severe &lt;strong&gt;security risk &lt;/strong&gt;&lt;/strong&gt;that must have been there&lt;strong&gt;&lt;strong&gt; for a long time already&lt;/strong&gt;. &lt;/strong&gt;The fact that this only got discovered recently is &lt;strong&gt;baffling&lt;/strong&gt;. And &lt;strong&gt;why WordPress core doesn’t filter out HTML-comments&lt;/strong&gt; from submitted blog comments, others seem to understand, but to me that remains the biggest mystery of all.&lt;/p&gt;&lt;div class=&quot;yarpp-related-rss&quot;&gt;&lt;p&gt;Possibly related twitterless twaddle:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;a href=&quot;http://blog.futtta.be/2013/04/10/wp-safer-cache-stopgap-for-wordpress-cache-plugins-vulnerability/&quot; rel=&quot;bookmark&quot; title=&quot;WP Safer Cache: stopgap for WordPress Cache plugins vulnerability&quot;&gt;WP Safer Cache: stopgap for WordPress Cache plugins vulnerability&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://blog.futtta.be/2011/07/30/quick-dirty-cdn-in-wordpress/&quot; rel=&quot;bookmark&quot; title=&quot;Quick &amp;amp; dirty “CDN” in WordPress&quot;&gt;Quick &amp;amp; dirty “CDN” in WordPress&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://blog.futtta.be/2012/04/13/wp-donottrack-0-6-0-and-beyond/&quot; rel=&quot;bookmark&quot; title=&quot;WP DoNotTrack 0.6.0 and beyond&quot;&gt;WP DoNotTrack 0.6.0 and beyond&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;/div&gt; &lt;div class=&quot;feedflare&quot;&gt;
&lt;a href=&quot;http://feeds.feedburner.com/~ff/futtta?a=IeW0GBjp9dw:07nh13JUgmQ:D7DqB2pKExk&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;http://feeds.feedburner.com/~ff/futtta?i=IeW0GBjp9dw:07nh13JUgmQ:D7DqB2pKExk&quot; /&gt;&lt;/a&gt; &lt;a href=&quot;http://feeds.feedburner.com/~ff/futtta?a=IeW0GBjp9dw:07nh13JUgmQ:yIl2AUoC8zA&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;http://feeds.feedburner.com/~ff/futtta?d=yIl2AUoC8zA&quot; /&gt;&lt;/a&gt; &lt;a href=&quot;http://feeds.feedburner.com/~ff/futtta?a=IeW0GBjp9dw:07nh13JUgmQ:qj6IDK7rITs&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;http://feeds.feedburner.com/~ff/futtta?d=qj6IDK7rITs&quot; /&gt;&lt;/a&gt; &lt;a href=&quot;http://feeds.feedburner.com/~ff/futtta?a=IeW0GBjp9dw:07nh13JUgmQ:I9og5sOYxJI&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;http://feeds.feedburner.com/~ff/futtta?d=I9og5sOYxJI&quot; /&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img height=&quot;1&quot; src=&quot;http://feeds.feedburner.com/~r/futtta/~4/IeW0GBjp9dw&quot; width=&quot;1&quot; /&gt;</description>
	<pubDate>Thu, 18 Apr 2013 20:49:38 +0000</pubDate>
</item>
<item>
	<title>Lionel Dricot: Récit de voyage</title>
	<guid>http://ploum.net/?p=2818</guid>
	<link>http://ploum.net/post/recit-de-voyage</link>
	<description>&lt;img src=&quot;http://planet.grep.be/heads/ploum100&quot; alt=&quot;&quot; align=&quot;right&quot; style=&quot;float: right;&quot;&gt;&lt;p&gt;Il fait chaud. Dans un nuage de poussière nauséabonde, le vieux bus bringuebalant s’arrête devant nous. D’un revers de la main, j’essuie la goutte de sueur qui perle au dessus de mes lunettes de soleil. Une foule criarde s’engouffre dans l’antique tacot en fer blanc, me pressant, me collant et me dévisageant avec amusement.&lt;/p&gt;
&lt;p&gt;Je jette un coup d’œil inquiet à mon téléphone : montez dans le bus 42 et insérez 200 chtongs dans le récepteur à côté du chauffeur. Attention, le symbole suivant indique que le paiement se fait au débarquement et non à l’embarquement.&lt;/p&gt;
&lt;p&gt;Relevant la tête, je constate que le chauffeur m’invective. Sa bouche édentée mâche une matière brunâtre tandis que, d’un geste insistant, il m’indique alternativement le fond du bus et un symbole illuminé au dessus de sa tête. Le symbole de paiement à la sortie. Derrière moi, la foule s’impatiente. Je murmure une excuse en patois local, si je dois en croire ce que mon téléphone m’a inculqué dans les semaines précédent le départ, et je m’élance vers le fond de l’engin où j’ai à peine le temps d’empoigner ce qui fut une poignée de cuir avant que le démarrage ne me projette sur mes compagnons de voyage.&lt;/p&gt;
&lt;p&gt;Durée de trajet estimée : 18 minutes, toujours selon mon téléphone. De toutes façons, il me préviendra quelques minutes avant mon arrêt de destination, au cas où je m’assoupirais.&lt;/p&gt;
&lt;p&gt;Je n’ai jamais été très aventurier dans l’âme. Mais la technologie m’a permis de découvrir le monde en chair et en os. Depuis trois ans, j’investis annuellement deux ou trois bitcoins dans un grand voyage de découverte. Et je n’ai jamais eu à le regretter. Sauf la première fois lorsque, dans une étape, j’ai découvert un cafard dans mes draps de lit. Ma note de 0 sur cet hôtel a fait comprendre à &lt;a href=&quot;http://wikitravel.org/fr/Accueil&quot;&gt;Wikitravel&lt;/a&gt; que si j’étais assez souple sur le confort, j’avais néanmoins une certaine exigence de propreté.&lt;/p&gt;
&lt;p&gt;Mais le système d’apprentissage a fonctionné à merveille : je n’ai plus que des hôtels honorables tout en restant relativement typiques et dans ma limite de budget.&lt;/p&gt;
&lt;p&gt;Cette année, j’ai fait entièrement confiance. J’ai simplement déclaré que je voulais visiter le Zizikistan Oriental, j’ai donné mes dates approximatives et mon budget. Wikitravel a fait le reste, en minimisant les escales et allant jusqu’à réserver le taxi et le payer à l’avance pour m’amener de mon domicile à l’aéroport. À chaque étape, je n’ai qu’à suivre mon téléphone. J’ai des rappels pour tous les événements importants, il me signale les bus, les arrêts. Il m’avertis lorsque je dois presser le pas car je me suis trop éloigné et affiche un QR code pour franchir les portes d’embarquement à l’aéroport. Même les places dans l’avion sont choisies selon mes goûts.&lt;/p&gt;
&lt;p&gt;Dans les semaines qui précèdent, je peux m’entraîner à prononcer les phrases usuelles dont je vais avoir besoin : bonjour, au revoir, merci, pardon. Et laissez-moi vous dire que le Zizikistanais, ce n’est pas une sinécure.&lt;/p&gt;
&lt;p&gt;Bzzzz ! Mon téléphone vibre. C’est ici que je descends du bus. Je dépose deux pièces de 100 chtongs dans le réceptacle et murmure un remerciement au conducteur. Derrière moi, le bus redémarre dans un vrombissement de vieux gazoil brûlé. Après quelques dizaines de mètres sur les cailloux brûlants, j’arrive à un antique panneau délavé, placé en des temps antédiluviens par un office de tourisme bien intentionné mais manifestement fâché avec l’anglais.&lt;/p&gt;
&lt;p&gt;Ce qui ne m’incommode pas le moins du monde, mon téléphone me fournissant toutes les informations utiles ou simplement intéressantes. Dans le cas présent, il me signale de suivre les symboles jaunâtres placés sur des piquets de bois. Nul besoin de rester rivé sur mon téléphone : il m’avertira si je m’éloigne de plus de cent mètres de mon itinéraire, me laissant le choix de marquer cet écart comme volontaire ou non.&lt;/p&gt;
&lt;p&gt;Le planning initialement proposé par Wikitravel tenait compte de mes préférences : monuments historiques, ballades dans la nature et un jour ou deux sur une plage pour terminer. Comme les plages du Zizikistan Oriental sont particulièrement célèbres, j’ai ajusté le voyage pour y passer 3 jours. Tant pis pour la visite du village aborigène. Mais aujourd’hui, j’ai enfilé mes chaussures pour une randonnée de 10 km à travers la forêt tropicale. Une ballade jusqu’à un petit temple perdu dans les brumes de la jungle marquée, par Wikitravel, comme à ne pas manquer car elle permet une immersion dans la faune et la flore locale.&lt;/p&gt;
&lt;p&gt;Encore un panneau jaune ! Décidémment, cette randonnée est bien balisée. Je m’arrête un instant pour prendre des photos d’une splendide libellule. J’enregistre également une séquence son des bruits de jungle. C’est magique ! Tout cela est génère automatiquement un diaporama avec la carte de mes déplacements, mes notes personnelles, les sons, vidéos, photos. Ce diaporama est partagé en temps réel avec mes amis proches et ma famille car, oui, même dans la jungle Zizikistanaise il y a du 3G.&lt;/p&gt;
&lt;p&gt;Chaque soir, j’édite mon “carnet de voyage” en supprimant les photos marquées comme inutiles ou ratées par mes amis. Je décide également de rendre public certaines notes, surtout les appréciations, et les images les plus jolies. Le tout agrémente WikiTravel et sera certainement utile aux voyageurs suivants.&lt;/p&gt;
&lt;p&gt;Alors qu’ils avaient une avance certaine avec Latitude et Maps, l’hégémonie de &lt;a href=&quot;http://ploum.net/post/le-monde-selon-google&quot; title=&quot;Le monde selon Google&quot;&gt;l’omniprésent Google&lt;/a&gt; est pour une fois remise en question. Qui plus est par la fondation Wikimedia !&lt;/p&gt;
&lt;p&gt;D’ailleurs, j’ai toujours répugné à confier mon budget à Google. L’un des points forts de Wikitravel est justement la gestion totale du budget. Les hôtels et les vols sont bien entendu réservés à l’avance mais Wikitravel va jusqu’à prévoir le prix du bus local, me suggérer la quantité de monnaie locale à retirer, me conseiller le petit restaurant typique pas cher sans aucun intérêt publicitaire autre que s’adapter à mes goûts et mes désirs de découverte.&lt;/p&gt;
&lt;p&gt;Le 1% du prix total versé automatiquement comme “donation” à la fondation Wikimedia n’est donc que justice. Surtout depuis qu’elle s’occupe également d’OpenStreetMap, qui est une pierre angulaire de WikiTravel. D’ailleurs, on peut configurer ce pourcentage et choisir &lt;a href=&quot;http://ploum.net/post/the-disruptive-free-price&quot; title=&quot;The Disruptive Free Price&quot;&gt;un prix libre&lt;/a&gt;. Un business model assez intéressant et qui a donné une bouffé d’oxygène à la fondation dont le produit phare reste Wikipédia.&lt;/p&gt;
&lt;p&gt;La jungle bruisse de mille bruits. C’est merveilleux. Moi qui n’ai jamais été un débrouillard, moi qui n’ai jamais réussi à organiser correctement une semaine dans un camping de la Costa Brava et dont le sens de l’orientation est inexistant, je découvre enfin le monde. Je ne sais même pas dans quelle ville je vais loger ce soir ni comment je vais m’y rendre. Je me laisse guider et je savoure chaque instant.&lt;/p&gt;
&lt;p&gt;Tiens, le sentier se divise et un piquet esseulé m’indique que, un jour, un symbole jaune a du guider des touristes comme moi, perdu à 5 km de la lisière de la forêt.&lt;/p&gt;
&lt;p&gt;Je sort mon téléphone de ma poche. L’écran est noir. J’appuie sur la touche plusieurs fois mais sans succès. Un oiseau tropical pousse un cri strident. Je sursaute, pose un regard inquiet autour de moi avant de replonger sur mon téléphone.&lt;/p&gt;
&lt;p&gt;Hier soir, après avoir trié les photos de la journée vautré dans mon lit, j’ai eu la flemme d’aller le mettre à charger sur la seule prise de la chambre. Je m’étais dit que, étant donné sa vitesse de charge, je ferai ça durant le petit déjeuner.&lt;/p&gt;
&lt;p&gt;Je crois que j’ai oublié. Ma batterie est morte. Les feuilles bruissent autour de moi. Un nouveau cri de l’oiseau me fait frisonner l’échine…&lt;/p&gt;
&lt;p&gt; &lt;/p&gt;
&lt;p&gt;&lt;em&gt;Photo par moi-même (tout arrive)&lt;/em&gt;&lt;/p&gt;
 &lt;p&gt;&lt;a href=&quot;http://ploum.net/?flattrss_redirect&amp;amp;id=2818&amp;amp;md5=8486ae0eca2a4cae53872485bc116b82&quot; target=&quot;_blank&quot; title=&quot;Flattr&quot;&gt;&lt;img alt=&quot;flattr this!&quot; src=&quot;http://ploum.net/wp-content/plugins/flattr/img/flattr-badge-large.png&quot; /&gt;&lt;/a&gt;&lt;/p&gt;</description>
	<pubDate>Thu, 18 Apr 2013 16:34:20 +0000</pubDate>
</item>

</channel>
</rss>
