home of the madduck/
madduck's droppings
blog debian git planet-debian planet-lca planet-lca2008 vcs-pkg

Welcome, visitor, to my weblog, or blog as they call it nowadays. This is my space to reflect, ramble, rant, ridicule, rampage, and relay about whatever or whomever I feel like; this is the one space where I can happily self-proliferate and merily make a fool of myself without any bad feelings.

I am aware that my blog is currently quite horrible to look at and that it lacks all sort of navigation abilities. I apologise. I hope to be able to fix this soon. In the mean time, please report any problems you may encounter. Thanks!

You may be interested in the full list of articles, or articles most recently modified.

Visual SSH fingerprints

Recently, people have picked up on OpenSSH’s new “feature”: visual SSH fingerprints.

It hurts to see this “feature” in a software like OpenSSH, which is so integral to everything we do, because it’s a waste. It’s additional code, and thus an additional risk of bugs, and it has a net security benefit of zero, NULL, zilch, nada, nothing, nix, nadje, oomph!

The theory is that you learn to recognise the general shape of the visual fingerprints of your hosts, which is easier for us to remember than strings of hexadecimal numbers. So, for instance, if you ssh to pony.debian.net, you get to see something that’s not entirely unlike a pony:

Host key fingerprint is 45:2f:a5:d8:13:95:ba:03:51:c4:8d:ac:82:a8:4c:6a
+--[ RSA 2048]----+
|         ==+o.   |
|        .++=o    |
|   . .  .o*..    |
| .. . . o..o     |
|+.     .S. .     |
|oE        o      |
|.          .     |
|                 |
|                 |
+-----------------+

Rejoice! Because now, should pony.debian.net ever present a new SSH fingerprint, when OpenSSH screams at you:

@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@    WARNING: REMOTE HOST IDENTIFICATION HAS CHANGED!     @
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
IT IS POSSIBLE THAT SOMEONE IS DOING SOMETHING NASTY!
Someone could be eavesdropping on you right now (man-in-the-middle attack)!
It is also possible that the RSA host key has just been changed.

then you can look at the picture and say: “yeah, I knew that”, because your pony has suddenly transformed into the visual representation of a giant fart.

On the other hand, the new “feature” makes day-to-day interactions a lot easier. Imagine you need to ssh into a new host. You take a piece of paper and call up the admin to ask for the fingerprint, but instead of a series of hexadecimal digits, he says “it looks like the easter bunny and a bit like southern Italy”.

Great “feature”. Thanks. I would appreciate if this sort of crap stayed out of important software. Dan Kaminsky might have some good ideas, but most of the time he’s on crack. Get a grip. Stop being a fanboy.

NP: Kinski: Alpine Static

Posted Fri 31 Oct 2008 09:01:07 CET Tags: ?nerds ?openssh ?ponies ?rant ?security
Fixing the credit crunch problems the wrong way

We’re all aware of the financial crisis due to credit default swaps shaking up the markets, media, politics, and what not. Some of us are feeling the pain, most of us aren’t yet.

A few days ago, politicians of the big, capitalist nations convened to agree on a way forward to stablise the financial market and set an end to the crisis. They are planning on doing this by throwing hundreds of billions at the market, buying all the subprime loan packages with the intention to create a new market for them, thus taking the weight off the shoulders of the countless barely-surviving banks and investors, who have written off billions in losses without an end in sight.

Where does this money come from? Taxes and newly printed money. You may not yet feel the effects of this, but you will: taxes will rise, and inflation soar to even higher levels.

Today is Blog Action Day with poverty as the focus, and it’s a good occasion for me to state what’s long been on my mind.

The strategy by our political leaders to combat the credit crunch is short-sighted, and it fights symptoms, not causes. In fact, it’s Robin Hood played in reverse: tax increases and inflation will hurt those most who cannot do anything against it: the poor. On the other side of things, those active in the financial markets will have their damages limited, and new CDS markets might even create more opportunities for those who can.

I strongly oppose the way our politicians are handling the issue, even though I do have small amounts of funds invested in financial products myself, and have already seen the positive effects of their actions.

Rather than throwing money at the markets, we really ought to put those away who have caused all this, those ruthless, greedy ones who have speculated way over their heads, underestimated the risks, and caused this crisis that killed many businesses, threatens to endanger entire countries, and hurts individuals who hardly ever had a choice. Think of it as a driver’s licence, and that should be revoked for those who screwed up so royally bad and got us into this situation in the first place. Don’t let them speculate again!

Update: Andreas Metzeler notes that he is (rightfully) missing a “what is to be done instead” section in my blog post. I don’t have anything to offer on that front, sadly.

I also realise I should have phrased my opposition differently.

Reading this interesting interview with Deutsche Bank ex-CEO Hilmar Kopper (German only) (thanks, Andreas!) helped me understand more that the politicians aren’t saving banks, they are saving the system, and that they have little other choice.

Another aspect I haven’t previously seen as clearly as now is that the governments are purchasing (and willing to carry) risk for others, to relieve the markets. Risk by itself doesn’t cost anything, so it might turn out that the billions they made available won’t actually be spent — though I always new that the governments might well come out of this with a profit even.

The whole affair still stinks, and what I truly miss are the actions to prevent those responsible for getting us into this mess in the first place from doing so again.

NP: This Will Destroy You: Young Mountain

Posted Wed 15 Oct 2008 13:05:35 CEST Tags: ?banks ?blog-action-day ?cds ?credit-crunch ?finance ?politics
Customer service how-not-to: Miles & More

I’ve previously ranted about the Lufthansa website. Trying to help out a blind friend obtain some assistance from Miles & More, the Lufthansa frequent flyer programme, I can confidently say that the two companies have a common origin and probably read the same customer service guidelines, which must be somewhat along the following lines:

If you follow the above guidelines carefully and possibly add a twist here or there, you can rest assured that you’ll fit in quite perfectly with most of your competitors and companies in many other fields. You’ll understand that the customer is evil and you have to protect your company and your customer service staff from them, by making it extraordinarily difficult and inconvenient to reach them, and ensuring that they won’t get any further than the computerised guard at the front door. It’s not like they are your most important asset.

Interestingly, neither Swiss, SAS, nor Thai have read these guidelines. I hope they will never find them.

NP: Porcupine Tree: The Sky Moves Sideways

Posted Tue 30 Sep 2008 11:53:47 CEST Tags: ?airlines ?customer-service ?customers ?lufthansa ?miles-and-more ?usability ?web
Ubuntu giving back

OpenExpo ended last night with a lovely dinner at Roter Turm, and I ought to thank Matthias Stürmer and his team for their efforts.

I especially would like to thank Myriam Schweingruber of the Ubuntu team! Debian.ch could not assemble enough manpower for a booth, and so Myriam took care of selling our new t-shirts at the Ubuntu booth — 29 of them.

That’s Ubuntu giving back to Debian! :)

NP: AC/DC: Stiff Upper Lip

Posted Fri 26 Sep 2008 14:44:34 CEST Tags: ?ch ?openexpo ?t-shirts ?ubuntu
35 years ago

Today, 35 years ago was a dark day for the human age. I mourn the deaths of 4 innocent children as a result of the 16th Street Baptist Church bombing.

Posted Mon 15 Sep 2008 20:19:54 CEST Tags: ?history ?ku-klux-klan ?racism ?satire ?terrorism ?world ?years-ago
Busting academics

As I crawl through the social science literature — a very painful endeavour, believe me — it fills me with disgust to see how much bullshit is being spread as authors randomly insert citations into their text to back up some claim they need to argue their case.

Often, the claim is something in which I am interested, so I go out and seek the reference they cite only to find that the referenced authors say nothing even remotely related to the claim for which they were cited. It is happening all over the place, and even in articles that appeared in “renowned” journals.

If we ever get to the point where all academic articles are properly interlinked so that references can be automatically checked — and I don’t mean just checked for correctness of the reference data, but for actual correctness of the reference — then the population of academics will probably shrink to single-digit percentages, at least for the social sciences; I don’t recall it being much different when I was researching artificial intelligence a few years ago though.

Until then, I am compiling a list. Whether I’ll publish it and point journal editors at, or just send it to the journals depends on my mood at the time.

NP: Guns ‘n’ Roses: Appetite for Destruction

Posted Mon 15 Sep 2008 18:54:05 CEST Tags: ?academia ?phd ?rant
x years ago

Inspired by Amaya, I would like to commemorate the thousands of people who died of hunger on any given 14th of September.

Posted Sun 14 Sep 2008 19:00:54 CEST Tags: ?history ?hunger ?satire ?world ?years-ago
9 years ago

Today, nine years ago, 13 September 1999 was a dark day for the human age: only a few days after more than a hundred of people were killed in bombings all over Russia, another bomb took the lives of 118 in an apartment complex in Moscow. Several other bombs were fortunately defused on the same day.

NP: Pulp: This is Hardcore

Posted Sat 13 Sep 2008 21:44:36 CEST Tags: ?history ?murder ?satire ?war ?world ?years-ago
Gazpacho are (finally) coming to Switzerland!

Gazpacho, one of my all-time favourite bands, are (finally) coming to Switzerland!!! On 17 October 2008, they’ll play a gig at the Z7 in Pratteln/Basel. Guess who’ll be there!?!

It makes me very happy that they have recently signed WiV Entertainment as event/tour managers, because it means I’ll probably get to see them more often in the future. To help a bit, I have agreed to be their Swiss “street team” (together with Tibor from Basel), which means I’ll be distributing flyers and posters when I return from Ireland, in exchange for free tickets for Penny and myself. You should join us! Tickets are €22 and can be ordered from the Z7 concert page (scroll down, I can’t link directly, unfortunately).

According to their news page (scroll down a bit), they are also playing in Oslo on 26 September, in Verviers, Belgium on 18 October, and in Den Bosch, The Netherlands on 19 October. Don’t miss them!

NP: Pulp: Freaks

Posted Sat 13 Sep 2008 20:58:55 CEST Tags: ?ch ?concerts ?gazpacho ?music
66 years ago

Sixty-six years ago was a dark day for the human age: thousands of innocent died when the RMS Laconia (1921) was (allegedly erroneously) torpedoed and the desperate rescue attempts by the offenders were (allegedly erroneously) foiled by a bomber plane.

NP: Gazpacho: Night

Posted Fri 12 Sep 2008 19:12:21 CEST Tags: ?history ?murder ?satire ?war ?world ?years-ago