Wednesday, July 2, 2014

Web hosting for cheap on a virtual machine


The thing you have to remember about working in IT is that no two projects are ever alike.  Even if you're being asked to do the same thing for 10 different people you're still going to be surprised.  Sometimes even on the same project.

So it was with my latest foray into virtualization on the cheap.  The client could barely afford to pay me let alone invest thousands in licensing fees.  So we had to get creative without sacrificing stability. 

That can be a tall order especially when everything you're using is Open Source. 

Now I have my issues with the way the Open Source community does things but a good product is a good product regardless of who made it.

Of course, "good" is a relative term. 

It's always a trade off.  A bit of pain to save a lot of money is fair but too much pain can cost more than if you'd just went with a commercial option.  And I do mean "commercial" because I still firmly believe that any product that relies on a fractured support community or high priced "experts" to make a product work is just this side of an amateur effort. 

Not that all open source products are that way, however.  

Some communities are better than others and if they put together a solid package with "readable" documentation then I'm all for it.  If we're just stroking somebody's ego so they can get a guest spot on Floss Weekly I'll take a pass every time.

I put CentOS, the open source version of Red Hat Enterprise Linux, and Z-panel, the open source clone of C-panel squarely in the "good" category.

Together they offered a cost effective and relatively stable platform for web hosting.  Add in a virtual platform for them to live on and you've got a web host that could fit on a keychain.  Not bad...

Instead of bore you with 4000 words of text describing my latest open source virtualization adventure I've created a video that takes you from creating the virtual machine to administering your new web host. 

As you're watching you may miss a few of the links in the video.  I've provided them below.



Tuesday, April 22, 2014

Why Heartbleed Happened

Originally published on Kupeesh!


So what's up with all this HeartBleed nonsense?

What could possibly be behind the greatest crisis in Internet security since the invention of phishing emails?
How could this possibly happen?  What could possibly jeopardize the security of thousands of websites and secure services we take for granted like Google, Tumblr and even banking sites?

I have an easy answer and it points right back to the Achilles heel of Open Source. 

While proponents will argue the merits of solutions that don't come from commercial sources the one inescapable fact of Open Source software is that it's developed under mob rule.

Therein lies the problem. 

While nobody questions the benefits of Open Source software like cost and ease of customization, proponents tend to gloss over the fact that some projects are better managed than others.

Take the case of OpenSSL.  It's the foundation for thousands of web services like Google, Yahoo and even your bank.   Except that somebody wasn't minding the store and for two years the mechanism that was supposed to secure your communications...didn't.

The flaw was inadvertently discovered by Google's Neel Mehta during a routine security sweep but the flaw had been in existence for 2 years.  Overlooked by one of OpenSSL's core developers, Stephen N. Henson, the vulnerability came as the result of additional but apparently untested new functionality known as a Heartbeat for OpenSSL.  The functionality was supposed to function as little more than an "I'm still here!" beacon to whatever service you're connected to.  

The short of it is this...

The problem comes from not bothering to check that what's sent matches what was requested.  A crafty hacker can take advantage by continually sending heartbeat requests claiming to be of a certain size but not actually being that size.  The server dutifully responds by sending back a response of the claimed size to the client and inadvertently dumping the contents of its memory to fill the otherwise empty space of the response.  The contents of which have been shown to contain user credentials among other compromised information.

It's apparently a simple fix but it's taken two years for anyone to notice. 

Meanwhile, nobody knows how long the bad guys have been aware of the flaw.  How can something like this get by the supposed vigilance of security gurus and major corporations alike? 
I can tell you how, it's endemic, it's cultural and it's arrogance...

It's a misguided belief that oversight of a product is best left to a community regardless of its qualifications to do so.  A community that frequently finds itself more concerned with the technical wizardry of its products than the users who deploy them

It's the same mindset that's kept other Open Source offerings like Linux in the shadows of Windows.  Let's be honest here.  You can only stomach so many unintelligible whitepapers or narcissistic support forum posts before you just give up.  The inmates are indeed running the asylum...

Heartbleed shines a light on the failure of the Open Source community in that it lays open the lack of even the most basic oversight of a critical and widely used service.  It's not so much about the failure of OpenSSL but rather that nobody including its chief stewards noticed the problem for two years.


This is nothing less than a reality check on the entire Open Source community.  One that should be raising questions in anyone that relies on their wares.