Idioma

  • Português
  • Español
  • English

X Latin-American Free Software Conference

October 16 to 18, 2013 - Foz do Iguaçu | PR | Brazil

Ron Minnich and details of Coreboot

Em: October 15, 2012 as 9:58 por

Currently there is a great and controversial discussion over a new BIOS implementation. Known as UEFI Secure Boot, it provides for the deployment of a ‘Signed Boot’, i.e., an operating system that can be installed on your machine if previously signed.

 To comment a bit about this, one of the international attractions of Latinoware 2012 will be Google software engineer, Ron Minnich. Besides presenting Coreboot – a technology for implementing free BIOS created by him – he will discuss other topics in his lecture. Check out the full interview:

 What is the situation now? We heard that Microsoft will be releasing security keys for signing and market them with other operating systems vendors. Red Hat and Canonical have already bought. How this will impact a regular user or company or a government?

 The situation today is that PCs offer users the freedom to do anything they want. PCs have been this way since their inception in the ’70s – the original creators made every effort to keep them open as long as possible. Even IBM, when they standardized what we now call the PC, opened the project, including providing a list of BIOS that came with the machine – albeit under copyright, which made it necessary to reverse engineer the BIOS.

The “secure boot” UEFI is designed to restrict this freedom in the name of security. Since the beginning of the personal computer era until now, a PC owner could start any operating system he wanted. Even today, a user who wants to convert a PC from Windows to Linux need only insert a CD and push the button to do so. The newer PCs will not be as open. For x86 systems to “secure boot”, commercial PCs will almost certainly start the software only – bootloader or operating system – signed with the key property of Microsoft, unless the creator of the PC provides a way to disable “Safe Boot “- and the user knows how to disable it.

While it is possible to install certificates on PCs other than those created by Microsoft, I believe it is unlikely that vendors will go to all this trouble. While large distributions can get their accesses or bootloaders signed by Microsoft, the small ‘guys’  will have to find the $ 99 for subscribed services or try to convince users to disable the “Safe Boot” – which many users may be unwilling to do. We can expect campaigns trying to convince users not to “make their PCs less safe” by disabling the secure boot. In any case, this seems to be a barrier to entry. Returning to 1991, with these limitations, it would be difficult to see Linux happen in the same way.

 With ARM, it is much worse, because disable “Safe Boot” is not an option. ARM has traditionally been very open, but this opening can begin to change. You can find a summary here. http://mjg59.dreamwidth.org/13713.html

And, as was pointed out, the requirements of UEFI secure boot have implications on which modules can be loaded on Linux. This goes further than just starting. Simply put, with the UEFI secure boot, open PCs as we have known them for just over 30 year are overs.

 The actual implementation of the signed boot technology will allow governments to sign software on their own?

 I believe so. But is a complex process that many governments may not be willing to establish. Matthew explains much better than I could: http://mjg59.dreamwidth.org/9844.html. I doubt that governments do anything to make the closed system more open. It is not in their nature.

We have seen many attempts to protect devices such as tablets, smartphones, video game consoles, etc.. against the execution of arbitrary code with similar technology and they failed at some point. Do you believe that signed boot technology for the common PC will be able to avoid joining this list?

 I’m not sure. It certainly seems that many companies are trying to shut down the PC in the same way that these other products are closed. At the same time, I never thought that the Xbox 360 would work with unsigned code, however this: http://www.howtogeek.com/95339/new-xbox360-hack-works-on-all-360-models- 2 / works. I learned not to underestimate the ingenuity of a group of motivated hackers.

As far as we know, however, lack of community participation means that the UEFI secure boot has a fault and is the next WEP (http://en.wikipedia.org/wiki/Wired_Equivalent_Privacy), or can be broken as easily as the Clipper chip: http://en.wikipedia.org/wiki/Clipper_chip)

Will this technology really make a difference in relation to security, and who should have control of the secret key to sign other Operating Systems?

 This will ensure that you somehow cannot start an unauthorized operating system – assuming the EFI has not been hacked, which it has, several times. My concern is that UEFI secure boot seems to have more than one goal. Yes, it is limiting what can be started as the only “trustworthy” code. It is also making quite inconvenient to start anything other than Windows. The confusion of “starting a secure operating system” with “just starting Windows” is not desirable from my point of view.

Security experts (I’m not one of them) say that the real area of opportunity for the “bad guys” is the browser. UEFI secure boot naturally has no value for this problem. Restrict PCs to starting ” signed operating systems” seems to me to be the solution of a control problem for certain vendors, restricting the freedom to start any operating system, rather than solving a security problem. Anyhow, it must be possible to solve the signed operating system problem in a manner that is less inconvenient for users – who, after all, pay for hardware that will be restricted to use in certain ways. I believe that is not a good tradeoff. It could undoubtedly have been resolved in a better way if there was a more community involvement.

But community participation in their design and implementation has never been a priority of EFI as far as I know.

 * Ron Minnich is a software engineer at Google, inventor of LinuxBIOS in 1999, led the project in its first 10 years and recently returned to work in Coreboot.

Posted in: Uncategorized | Leave a comment

The International Hydroinformatics Centre (IHC) will disseminate its work in Latinoware

Em: October 15, 2012 as 9:55 por

As in the other editions of the Latin American Conference on Free Software (Latinoware), once again the work undertaken by the International Hydroinformatics Center (IHC) will be a stand out at the event, considered one of the largest of its kind on the continent.

 On the stand mounted in the exhibition space, participants can register to receive via e-mail information in connection with systems and projects developed by the Center, such as Web Radio Water, a collaborative space that allows the exchange of information and experiences related to our most precious commodity: water.

Last year, at the IHC stand, participants were able to share their knowledge and experience in various areas of free software.

 As one of the great specialties of IHC is the development of GIS systems, during the event, a participant with their geographical location registration system will be available to the public. In addition, presentations will be made of the systems at the stand during the event.

 On the 19th, at 11am, Cesar Habby and Jônathan This will give the talk ‘ Interactive Maps Systems Development Using Free Software’. The systems analysts will address the free tools used in WebMaps Territorial Management System, which allows the visualization of existing spatialized geographic data on IHC and public servers.

 Then, on the afternoon of the 19th, Luis Henrique Weiss – participant and contributor to the international gvSIG community – is promoting the short course ‘Geoprocessing using free platforms. MC4h’.

International Hydroinformatics Center

 The International Hydroinformatics Center is a bi-national center, a result of the partnership between Itaipu Binacional and the International Hydrological Programme (IHP) of the UNESCO. Besides being a bi-national center, it is a UNESCO Category II Center, i.e. its activities are approved by the United Nations Educational, Scientific and Cultural Organization.

 The IHC mission is to develop technological solutions for Land Management, using geo-technology for the development of free software systems for Web Platforms, with registration of information in geographic database and interactive maps applied to integrated watershed management.

 To learn more about the projects developed by IHC, visit http://www.hidroinformatica.org

 

Posted in: Uncategorized | Leave a comment

LPI certification cancelled

Em: October 15, 2012 as 9:50 por

Due to the low level of demand, 4Linux announces that the LPI certification exam, which was to be held during Latinoware, has been cancelled. People who had already enrolled, please contact company on website www.4linux.com.br.

Posted in: Uncategorized | Leave a comment

Latinoware program on your Android screen

Em: October 5, 2012 as 9:19 por

The app was developed by systems analysts Fernando Mantoan and Anderson Davi.

This is for you if you are one of those people who get lost with printed event schedules. Systems analysts Fernando Mantoan and Anderson Davi – of the Institute of Applied Technology and Innovation (ITAI **), located in Itaipu Technological Park (PTI) – recently launched a Latinoware app for the Android platform.

The app is available at Play Store (http://goo.gl/8Eh79) and allows participants to access on their mobile phones or tablets, the complete schedule of the three-day event. “I contacted the organization staff and they authorized the creation of a simple app to display the lecture grid,” said Mantoan.

As the conference is on free software, the idea of the pair was to build the application and provide the source code to developers to contribute towards achieving an application with more features. “This is just the kickoff. People interested in contributing to the app, can access the repository on GitHub *. All contributions are welcome, whether to report a bug, suggest a new feature or translate into other languages.”


According to Mantoan, the application is divided into two parts. The first built in PHP, targeted directly at reading the HTML on LAPSI and provide the grid through a webservice in JSON format (this application is hosted on Heroku) and the second part is the Android client, which gets data from the webservice and displays the grid on the device.

Starting with this “beta” release, next steps planed are: building a database locally on the device, avoiding querying the backend; implement the feature of ticking lectures that will be attended, add information about the speakers and the detailed description of lectures; and enable exchange of e-mails via Bluetooth or other mechanism.

“The new features are in progress. The main difficulty is to read the HTML directly from the site Latinoware, making it not simple to create these features. But I believe that with the help of the community we will be able to reach a pretty cool app”, he added.

* For those interested in contributing, the entire source code is available on GitHub: https://github.com/fernandomantoan/android-latinoware

** To learn about the work of the ITAI, visit www.itai.org.br

Posted in: Uncategorized | Leave a comment

Nerds de Batom (Nerds in Lipstick) have also confirmed attendance at Latinoware

Em: October 5, 2012 as 9:11 por

Eliane Domingos, Carol Souza, Cris Geyer, Viviane Sousa and Desireé Santos are five confessed “nerds” who decided to get together to represent women in the area of Information Technology. Similar to Women in Technology (Mulheres na Tecnologia – MNT), their idea also stemmed from the realization of the lack of female presence in free software encounters.

“Our endeavor was for a space targeted at women, where we might explore the dilemmas and difficulties found, in addition to searching for and proposing remedies for the purpose of improving the feminine scenario in the area of IT”, stressed Desireé Santos, coordinator of the group and active participant of the Rio de Janeiro Arduino group.

Four representatives of this group will participate in Latinoware 2012, including in a round table together with MNT where issues in relation to the feminine cause will be debated. To actively participate in the group, women interested should send an e-mail to desisant@gmail.com or elianedomingos@gmail.com.

 

Posted in: Uncategorized | Leave a comment

Possibilities for PHP on social media

Em: October 5, 2012 as 9:09 por

The importance and forms of interaction of programming language PHP with the different social networks – in particular Facebook – will be shown in one of the lectures given by Jota Junior – a young enthusiast of PHP and free software in general and founder of the Lyla project, software that uses the networks to publish data of missing people – at Latinoware 2012. Check out the complete interview:

- How does PHP interact with social media and how are they important?

There many different forms of interaction. Services como o Facebook Developers make available SDKs (specific libraries in PHP), Open Graph (REST Api) among other possibilities, including in the tools (in Facebook PHP SDK requests can be sent to the server in different forms, and one very interesting one is Facebook Query Language, similar to Data Base SQL).

Other software, like Twitter do not allow so much freedom, but even so make available a library (tmhOauth) and a REST Api which make development very easy, once their form of operation is understood. And OAuth, in separate, is a resource used by most libraries enabling interaction with these sites in a standardized and secure way.

- What are the functionalities of OAuth? Is it easy to implement?

The important thing in order to use this resource powerfully is, initially, to understand the power of socil networks. They have opened up a totally new and incredibly broad horizon, where businesses and different tools can take advantage of this potential to grow. Today, people do not just read an article; they read them and show them to your friends , recommending they read it too! Understanding this is the first step.

After going through this nearly ‘phylosophical’ (hehe) portion, understanding well the concepts for basic for REST Apis, Permissions, what can and cannot be done, what is convenient and what is not – gives you nearly all you need . Then, it is just a matter of starting to write code and test the libraries! At times there may be a challenge in terms of performance, number of requests, but it is all tangible.

- What can the audience expect from your presentation?

Well, the audience can expect a very elucidating presentation! After a few complex projects involving interaction with social media , I thrashed about some, lost a lot of the little hair I had with some of the problems that I will alert to and show how to work around , and if they understand what I will explain, they will not even be problems. Definitively, this is the first step for people wishing to enter this promising market!

Posted in: Uncategorized | Leave a comment

Apoio