Practical Technology

for practical people.

September 19, 2003
by sjvn01
0 comments

Linux Security: Good Enough

Linux is fundamentally more secure than Windows. There, I’ve said it.

ts not that Linux is some bulletproof wonder of security. Its not. If you want an operating system that really been built from the ground up to be secure what you want is OpenBSD. The crew behind it has made safe, sane security job number one before Bill Gates could spell security if you spotted him the s and the y.

But, to get back to the point, why is Linux more secure than Windows? First, its because Linux is open source. Yes, any cracker who wants can hunt for security holes all day long. Microsoft is closed source. If closed source is so much better for security, why is my virus detector still yelping every few minutes as the latest Windows virus, Swen, tries to e-mail it way in?
Indeed, what some security lunkheads claim is a flaw in Linux, its open source nature, has proven to be a security virtue. Potential security holes are spotted and fixed in Linux much faster than they are in Windows.

Don’t believe me? Consider, if you will, all of Linuxs security problems in the last year-and there has been lots-pile them all together and compare all the damage theyve done to real world productivity vs. the damage done in the last twelve months thanks to Blaster or SoBig or Bugbear or Badtrans or Elkern or Magistr or Sircam or Yaha or Nimda, and its clear that for all practical purposes, Linuxs security flaws are minor indeed.

Besides, Windows has always been insecure because of basic design flaws. Microsofts own fundamental operating system principles of enabling data and programs to work together at a low level has provided both the ability for programs to interoperate with each other over the network, from Windows for Workgroups dynamic data exchange (DDE) to Server 2003s ActiveX, while simultaneously giving crackers the ability to break into and corrupt Windows systems.
And, of course, thats exactly what theyve been doing. Over (ILOVEYOU), over (Melissa), and over (Blaster) again. Microsoft claims they want to do better. Indeed, Dave Aucsmith, Microsofts Security Business Unit CTO said back on April 18, 2003 if Windows 2003 was as vulnerable as previous versions of Windows, it meant that the companys security improvements approach “was wrong.”

Well, guess what, Microsoft was wrong. Dead wrong in the case of network administrators whove seen Server 2003 go down from one security exploit after another.

And, even now, after the worse summer ever for Windows security problems, after Ballmer has been humbled by Microsofts awful security, Microsoft is still up to its insecure tricks! What some find much to praise in Office 2003s collaboration features. I see bigger, badder security holes than ever. Yes, they are great features, but theyre also features that have hack me written all over them.

Linux simply never made this fundamental design mistake. In part, thats because Linux was always designed to work on a network and Windows, even now, is showing its desktop heritage of assuming that you can trust any data source. Of course, Microsoft has made some improvements like Enhanced Security Configuration (ESC) in the latest Internet Explorer and Server 2003, but, oh the irony of it all, to make such commonplace tasks as getting Windows own update patches, you have to amend and weaken your security policies to get work done.

With Linux security you dont have to play security games to make sure applications can work. Linux security is built on a foundation of stone, not sand.

Finally, there is no doubt that Windows is more popular than Linux. But, so what? Whining Windows defenders claim that its only because Windows is a bigger target that it gets hit so often. Nonsense. The real reason why Windows gets hit so often is because its an easier target. It it were popular and more secure, the script kiddies would be back playing computer games instead of games with Windows computers.

No, when push comes to shove, Linux has shown itself to be more secure than Windows in the real world. But, that said, the real secret to securing any operating system isnt the operating system itself. Its how its managers implement its built-in and third-party security tools.
For all of Windows recent woes, the simple truth is that most of them would have been mitigated has Windows administrators simply kept up with Microsofts security patches and used basic firewall measures. An unlocked door wont keep anyone else, but even a cheap lock will stop most petty online criminals.

Would Linux still be more secure? Yes, indeed. But, in the big bad real world, Windows could be doing a lot better.

To do security right, you have to be updating your programs and operating systems constantly. Windows, Linux, whatever. If you want your systems to be trouble-free, you need to take a lot of trouble. Hard work and constant diligence are the only real security answer. Its just that with Linux, you see, you dont have to work so hard.

A version of this story was first published in eWEEK.

August 28, 2003
by sjvn01
0 comments

SCO: Inside the hurricane

Between hate mail from open source supporters and love notes from investors, life isn’t easy inside SCO. There have been more hated technology companies; IBM and Microsoft immediately come to mind. But they weren’t pounded earlier this week by a successful DDoS (Distributed Denial of Service) attack despite the efforts of open source leaders like Eric Raymond to stop it. And no one’s written a Nigerian spam parody for their CEOs. At the same time, though, some stock buyers love SCO’s aggressive Unix intellectual property stance and its Linux licensing schemes. Say what you will about the merits or demerits of the case, life at SCO is like being in the eye of the hurricane.

Darl McBride, SCO’s CEO, couldn’t agree more. “It’s interesting to wake up in the morning because you never know what will happen on a given day. You realize you’re in the middle of the hurricane. I was brought in to run this company, and then when we decided to start protecting our IP, our first decision was whether we were going to fight or get taken out early. Since we made that decision to fight for our property rights, as we unravel the yarn, it just becomes bigger than you thought it could possibly be going in.”

McBride also compares working at SCO to riding a roller coaster. “The highs and lows get you hardened and toughened and take on a steady tone. You realize that life may be really good today, it may be really bad the next day.” Eventually, he says, you learn to “hunker down and think like a fire fighter. Early on, it was fairly unnerving for employees, but now people are really tough on and see that SCO has taken an IP leadership position.”

You might think that employees would be leaving SCO, but according to McBride, despite everything, “there’s been no lawsuit-related turnover.” Indeed, “we get lots of people wanting to come aboard.” He also comments that 320 out of the 330 SCO people focus on SCO’s products, it’s the other ten who are the ones living in the middle of hurricane.

One of the storm-tossed wretches is Blake Stowell, SCO’s director of corporate communications, who just had his fifth child on August 25. He went to work that morning, joined his wife for the birth, then was back to work on the 26th. As he puts it, “I’ve never worked harder at a job in my life.”

He confesses that he’s “a bit tired,” but “for the most part, we’ve managed the communications pretty well over the last six months,” even though he believes that “there are some people — press, open source companies, and opinion leaders, like Eric Raymond, in the industry who don’t know what’s going on.”

Still, he says, “I don’t find it frustrating. It takes a lot of work and I look it as a challenge. Every time the open source community fires back with an issue I have to reply and that takes up bandwidth on my side. [But] I think it’s been a good exchange of opinions. I think each side understands the other’s viewpoint now even if they don’t agree with each other.”

McBride insists that IBM is the root of SCO’s Problems

McBride thinks that a lot of SCO’s public problems don’t stem from SCO’s actions, but from a loosely organized disinformation campaign masterminded by IBM. “IBM has a vast reach to a large number of people in open source. IBM doesn’t touch hundreds of thousands directly, but with their strong reach and influence to companies and people in the open source community, in particular Linus Torvalds and Eric Raymond, IBM gets its message out.” He goes on to say that “Novell is trying to get in [the attack] by trying to co-coordinating with IBM along with Red Hat and SuSE.”

Specifically, “companies have approached me and told me that IBM had tried to get them to stop working with us, even companies that are competitors to IBM. We’ve also had customers come up and say IBM will penalize us if we keep working with SCO.” McBride explains that, for the most part, these haven’t been SCO resellers or customers, but mostly software developers. He adds, “We’re in the discovery stage and this will be part of the filing and we will show direct information that IBM is the source of some of these attacks coming at us.”

What people don’t understand, McBride insists, is that SCO’s legal actions aren’t just about SCO’s IP, Unix, and the GPL anymore, it’s a broader issue that includes music, video, and anything that can be digitized and distributed on the Net. To McBride, the real issue is “the future of IP rights in the 21st century.”

McBride isn’t the only SCO employee who feels that way. Communications director Stowell says, “I once worked for a company involved with the Open Source community. I enjoyed the time that I worked there trying to build a business around contributions from a development community. I joined that company when the 2.2 kernel was in wide distribution.” But, he says, “Since coming to SCO and reading over the contracts held with other licensees such as IBM, Sun, HP, and many others, I too have come to the realization that SCO intellectual property has indeed been contributed into Linux. I haven’t been just drinking the SCO Kool Aid. I understand the company’s case, I’ve read every word of each contract, every exhibit in our case, and I understand that there are people and organizations that have issues with our viewpoint. I believe in what we are doing in protecting our intellectual property. I hope at some point we can find a solution where SCO can be properly compensated for its IP and the Open Source community can move forward unhindered in creating great software.”

Drew Spencer, former CTO of Caldera from September 1998 to May 2002, who no longer has any interests in Caldera/SCO, sees it differently. “My sense of SCO’s action of late is that it has formulated a strategy by which it intends to extract the most value it possibly can from the IP it purchased when Caldera bought SCO in order to either liquidate it (as occurred with Caldera first generation) or re-launch the company as something totally different. With the R&D expense involved with trying to keep two operating systems up-to-date with the hardware development and what amounts to the destruction of any business development opportunities with the hardware vendors and ISVs, it’s probably pretty safe to say that SCO doesn’t want to be in the OS business anymore.”

One way in which some SCO employees are extracting value is from SCO’s lofty stock price. SCO was trading at a near 52-week high of $14.36 on August 27, and company executives have been selling stock. John Ferrell, founding partner of Carr & Ferrell, LLP, a Silicon Valley intellectual property and corporate law firm, “was interested to see that SCO insiders [the other] week were selling SCO stock at greatly inflated prices. If in fact IBM has misappropriated and infringed SCO code, SCO shareholders will deservedly be handsomely compensated. If, however, we come to learn that SCO management is falsely creating turmoil in this struggling tech economy for the purpose of jacking and dumping their stock; SCO’s legal troubles will be just beginning.”

Financial and IP issues aren’t the only ways SCO has been making headlines recently. Spencer thinks that SCO opponents who DDoSed SCO’s site are only hurting their cause. “In order to win in court, particularly with a jury trial in Utah, baiting the community into DoS attacks, protests, etc., merely serves to substantiate the case that the community wants to destroy SCO financially and the jobs that come with it. With the loss of jobs in the IT sector, particularly in Utah, where Novell, Caldera/SCO, and others have struggled as of late, a jury will likely be sympathetic to SCO’s problems even if the community is able to dispute SCO’s allegations of theft.” In short, “SCO is the ‘troll’ and the community has been keeping it well fed.”

That said, Spencer adds, “Could I or would I have taken the approach they are? No.”

Other former Caldera/SCO employees agree that they’re not happy with SCO’s current path, but SCO’s current staffers continue to stick to their position despite the slings and arrows of outraged open source advocates.

Additional reporting on this story was done by Joe Barr.

A version of this story first appeared in Linux.com.

June 26, 2003
by sjvn01
0 comments

The Mobile Phone Operating System Wars

It wasn’t so long ago that all you expected from your mobile phone was for it to let you talk to other people. Not any more! It’s not your dad’s cellular phone anymore; actually, it’s not even your old digital phone. Today, both mobile phone vendors like Ericsson and Nokia and network operators like Sprint and T-Mobile are eagerly pushing you to buy phones that double as personal digital assistants (PDA)s, digital cameras and mini-Internet consoles.

What’s driving this is a combination of ever-shrinking hardware components, which enable mobile phone OEMs to pack ever more processing power and RAM into a hand held device; the slow but steady growth of high speed wireless connections (2.5 and 3G); and network operators seeking new ways—such as simple messaging service (SMS), multimedia messaging service (MMS) and Wireless Access Protocol (WAP) for mobile Web viewing—to make income from their users.

As wireless devices and networks’ functionality and performance of have improved, their operating systems have also had to improve. According to David Wood, Symbian’s Executive Vice President for Technical Consulting, “the relentless increase in user requirements for mobile phones means that proprietary operating systems adopted by mobile phone manufacturers ten years ago are now at their limits.”

Those limits are being broken. Bad economy and all, smartphones are a growth market. According to IDC’s Ross Sealfon, research analyst for Smart Handheld Devices program, smartphones are taking off, with worldwide first quarter 2003 shipments growing by more than 400% to 1.71 million units. Specifically, IDC’s ranks Nokia (Symbian OS) as Q1 2003 market leader, based on units shipped, with 57.3% of the market, followed by Sony Ericsson (Symbian OS) with 11.1%, then Motorola, 7.4% (Symbian OS); Samsung 5.1% (Palm OS & Symbian OS); and Handspring 4.1% (Palm OS).

Carl Zetie, analyst with Forrester Research, believes, “that the rise of middleware for mobile devices, starting with mobile databases” which “suddenly it was much easier and cheaper to integrate a mobile app into the enterprise Infrastructure” is part of what’s drives the smartphone market.

Zetie also thinks that while, 2.5G, with its theoretical 115Kbps and practical 40 to 60Kbps throughput, “is certainly another important driver of adoption for PDAs as it provides dramatically better connectivity than its predecessor, I don’t think you can attribute the growth of mobile OSs to 2.5G for two reasons. First, the biggest beneficiary of 2.5G is the low end data-enabled smartphone such as J2ME or BREW-enabled phones. These devices have the least powerful OSs of all handheld devices, and in many cases no ‘real’ OS at all. Second, its important to remember that the majority of PDAs (ignoring the smartphone for a moment) in both the consumer and enterprise domains are mobile but not wireless—that is, they don’t make use of a wireless connection, 2.5G or otherwise.”

Instead, what’s really driving the market, he thinks, is the “constantly inflating enterprise demands for applications that are more and more comparable to what a laptop is capable of with consumer demand for rich media and games.”

Today, the most important mobile operating systems are Microsoft’s Smartphone 2002, Palm OS 5.x, and Symbian OS 7. Each has taken a different path to arrive at this point and each delivers services to their devices in uniquely different ways.

Still, each faces common problems. Each must work with small, mobile devices with limited screen space, memory and input options that usually used in short, frequent bursts of activity. In addition, they must support telephony communications standards and other networking services ranging from IrDA, Bluetooth, and TCP/IP over 2.5/3G and Wi-Fi all while restricting power consumption to the lowest possible level.

Besides doubling as a PDA, today’s smartphones operating systems are also asked to handle audio and video playback over MMS; take, save and send low-resolution digital photographs, and serve as an e-mail and instant messaging client. It’s not easy.

PalmOS: The PDA OS

The oldest of the trio, Palm OS started life in 1998 as an operating system for the first hugely successful PDA, the Palm Pilot. The 16-bit early versions of PalmOS supported the embedded Motorola 68000 chip series known as DragonBall. What set Palm OS apart from its competitors, says Carl Zetie, was that “unlike prior ‘organizers’ Palms could readily be programmed to add relevant enterprise or consumer applications.”

To handle today’s more demanding PDA and phone combinations; the recently released 32-bit PalmOS 5 supports ARM-based processors. With this combination, according to Albert Chu, Palmsource’s VP of Business Development, “the Palm OS has the horsepower to do sophisticated multimedia and security applications.” by supporting 128-bit Secure Socket Layer (SSL) and wireless connectivity options such as 801.11b Wi-Fi.

While Chu claims that Palm OS is the smartphone market leader, others disagree. Chris Preimesberger, wireless development analyst for Evans Data, says, “Palm OS has lost momentum in sales over the last couple of years; even though it has a steady market following. It needs to reestablish itself to developers, and potential new customers, somehow. Palm OS needs a new killer reasons for purchase.”

Isaac Ro, Senior Analyst for the Aberdeen Group, though, thinks that Palm OS’ problem is its hardware developers tend to devise their own ways to fit Palm OS to their phones. “This can lead to fragmentation of the operating system and leads to programmers constantly reinventing the wheel.”

Palm OS 6, according to Chu, which comes out at year’s end, seeks to bring Palm OS developers together and present everyone a killer reason to keep using Palm OS by making the OS support multitasking applications and adding still more telephony and wireless functionality.

Microsoft’s Challenge: Smartphone 2002

Smartphone 2002, codenamed Stinger, has had a rocky start. Based on Windows CE 3.0, like Pocket PC, it is, a Microsoft representative explains, “the subset of the Windows CE that is appropriate for a mobile phone.” At the same time though, “Smartphone software is designed for those whose primary communication is done with voice, with an occasional need to access data information.” Users who want PDA functionality in their phones are directed to Pocket PC powered PDAs.

Thus, only one vendor, Orange, compared to dozens for both Palm OS and Symbian OS, is currently shipping a Smartphone-powered phone. Indeed, Microsoft’s Smartphone OEM partnering has gotten off to a very rocky start with a law suit from Sendo, the UK handset maker, over Microsoft’s business dealings with them.

Zetie observes though that “Microsoft quickly discovered that the brand-name handset makers were uninterested in or even hostile to its plans, so it has done an ‘end run’ around them. By facilitating contracts directly with carriers”—such as AT&T Wireless, Verizon Wireless, and Telefonica—“it has created a completely different value chain that cuts out the traditional tier one handset makers, for one that the carriers like because it puts their brand, along with Microsoft’s, front and center.”

Still one problem for Smartphone developers and users is, unlike the other two, even though Smartphone has a Windows-like interface, the display has no pointer interface meaning users must use the keypad to enter commands. As Preimesberger comments, the most popular Microsoft mobile OS is Pocket PC, which does support a touch screen. Microsoft’s explanation for Smartphone’s lack of a pointer to the desire to make devices that can be operated with one hand.

Isaac Ro, Senior Analyst Aberdeen Group, frankly thinks, “Smartphone is pretty poor” because of multiple technical and implementation problems. But, he’s not betting against Microsoft being a player. “Historically, Microsoft’s first products are always very rough, but their next version is much better” and their “developer tools are unparalleled.”

Symbian OS—the mobile phone OEMs OS of choice.

Symbian OS is beloved by mobile phone OEMs. And why shouldn’t it be? Symbian the company is wholly owned by some of the biggest names in its field: Ericsson, Nokia, Panasonic, Motorola, Psion, Samsung Electronics, Siemens and Sony. It also has the support of major programming tool vendors like Metrowerks.

Unlike the others, Symbian OS, since its rebirth from Psion’s EPOC operating system in 1998 has always been dedicated to be an operating system for mobile phones. Despite that though, and its very high market numbers, Preimesberger says, “I don’t see Symbian making as much progress in the development community as I had expected during the last year.”

Zetie explains, Symbian “likes to boast that its members account for “80% of all handset sales” – meaning that the member manufacturers sell 80% of the phones in the world, not that 80% of the phones sold have Symbian! Only a trickle of Symbian-powered phones have appeared and until Nokia’s Series 60 platform was launched they had very little impact in the market.”

Technically speaking, however, Ro is certain that “Symbian OS is the best” Why? “Because, it’s phone implementations are successful.” Mobile phones aren’t “PDAs and the like, for a voice-dedicated smartphone Symbian offers the best performance, while allowing developers and OEMs to differentiate their programs.”

With broad industry support, open standards, and the breakthrough of the first popular Symbian OS product line, with more to follow from Nokia and Ericsson, IDC predicts that by 2006, Symbian OS will own 53 % of the market with Microsoft’s operating systems placing second with 27 % and Palm lagging behind with 10%

Linux

While open standards may drive Symbian forward, open source, in the form of Linux, has been a mobile phone non-starter.

Part of the reason is technical. Rick Lehrbaum, LinuxDevices.com’s founder and editor-in-chief, believes that while a non-toy Linux can be squeezed into as little as 4MBs, “Linux probably requires double the RAM and flash memory of other embedded OSs,” for full mobile phone functionality.

Still, a few small Korean companies, like PalmPalm and Mizi, have developed Linux powered phones. “But,” Lehrbaum explains, “the real problem is that none of the embedded Linux vendors has the resources to attack that market, so it depends on the device and chip vendors to make the investment and partner with Linux OS and other technology players (e.g. Trolltech for Qtopia, Opera for browser.). In contrast, Microsoft has the muscle to make an entire stack come together. A company like MontaVista requires companies like Motorola, TI, Ericsson, and Nokia partnership to put the solution together without it, they’re just too small.”

Tomorrow

In the long run, most analysts think Symbian OS will win out. But, what does that really mean?

Zetie says that, “I would add a major caveat to anybody trying to read meaning into market numbers. First, the various reports often define their categories differently, and with so many different variations of voice and data devices, there is often little agreement. For example, is Handspring an unsuccessful PDA vendor or a successful “communicator” vendor? Given that low-end smartphone handsets sell tens of millions of units, PDAs sell millions, and communicators sell tens to hundreds of thousands, comparisons across categories are particularly misleading. Is a Motorola V60i J2ME handset really competing for the same buyer as a Handspring Treo? Probably not. In my view, the market is far too complex to be reduced to overall market shares and gains and losses.”

Ro sees the number of OEMs declining sharply. “It doesn’t make sense to have thirty phone vendors.” At the same time, though, the phones will become have more features. Even baseline machines will have high quality cameras and full PDA functionality. Simultaneously, “the business model in which mobile carriers buys phones from OEM vendors and then gives them away or sales them cheaply in order to gain subscribers will decline but not disappear. This will pressure phone vendors to build more cost effective and complex phones making even more demands of the mobile OSs.

In short, while it’s hard to see what mobile OS will become the most popular as the definition between phone, PDA, and laptop blur, what is clear is that mobile OSs will become increasingly more important to developers, and although they may no longer see the underlying structure as an operating system, end-users as well. The day of the mobile phone as computer is coming fast.

A version of this story was published in IEEE Computer.

June 16, 2003
by sjvn01
0 comments

SuSe Delivers Business Desktop Linux

SuSE has been planning its business around business-class Linux servers for years so it should come as no surprise that when they finally offer a Linux just for the desktop, SuSE Linux Desktop (SLD), it comes targeted at enterprises with a product price of $598 for the SLD installation kit and a 12-month SuSE maintenance program for up to five workstations. SLD also has a five-year support life cycle.

This is a desktop Linux for CIOs, not individual users.

Richard Seibt, CEO of SuSE Linux, makes this clear, ”We believe this is the product that will bring Linux to enterprise desktops across the whole world.”

But will CIOs buy it?

Dan Kusnetzky, IDC vice president for system software research, thinks SuSE has a ”reasonable plan” and ”a combination of desktop operating system and applications that’s good enough to do the job.”

Kusnetzky explains that businesses tend to have knowledge workers, who work with office applications, or transactional workers, who work with one or two business process applications like a DBMS or an accounting program. The key for a successful operating system for both has everything to do with the operating system supporting their application.

For the first group, SuSE supplies not only the free OpenOffice 1.0.2, but its big, commercial brother Sun’s StarOffice 6.0. But, perhaps more compelling for most offices, SLD also comes with CodeWeavers’ CrossOver Office 2.0.

With CrossOver Office, office workers can use the applications they already know from Windows such as Word, Excel and PowerPoint from Office 97 to XP as well as MS Outlook, Visio 2000, and non-Microsoft applications like Lotus Notes and Adobe PhotoShop.

As for transactional workers, Kusnetzky notes that many data-entry applications are now accessed by a Web browser. ”For users like this, any operating system that supports a Web browser, JavaScript, and any applets they might need, is good enough.”

Another plus, Kusnetzky notes, is that SLD may let offices run desktop machines for longer since Linux doesn’t demand the hardware upgrades needed to keep up with Windows desktop operating systems. For a company that’s counting IT pennies, this could be a real win.

SuSE’s Holger Dyroff, General Manager for the Americas, also makes a point of saying that SLD is ”optimized with the server for seamless integration and administration.” This is an important point, Kusnetzky observes, since ”many CIOs are afraid they don’t have staff that’s capable of managing Linux.”

Since SLD is built on the SuSE Linux Enterprise Server (SLES) 8, they share common code bases and administration and management tools. In addition, AutoYaST (Yet Another Setup Toolkit) and SuSE YOU (YaST Online Update), SuSE administrators can automatically update clients across the enterprise in a way that’s very similar to how Windows administrators maintain machines today.

Looking ahead, SLD uses KDE ”Desktop Sharing” for desktop remote control for remote management jobs. In the future, SuSE also plans to use a Smart Client (Web Service-based programs) framework and Ximian Red Carpet Enterprise to make remote management even easier.

SuSE has also gotten serious business hardware support behind SLD. IBM and SuSE are in the final stages of certifying the IBM ThinkPads A31 and T40 and IBM NetVista desktop for SLD. Dyroff also said that while these won’t be shipping with SLD at the moment-for now you must still install SLD yourself or have a reseller do it for you-he expects that pre-installed SLD business laptops and desktops will be arriving in the future.

IBM may not even be the first to sell SLD-equipped PCs. Martin Fink, HP’s vice president of Linux, says, ”SuSE Linux Desktop on HP desktops and workstations marks the next stage in the evolution of the Linux operating system. Users will get the price/performance advantage of Linux on one flexible and efficient platform to run enterprise-level applications on their desktops and one vendor — HP — to support them along the way.”

The one fly in SLD’s soup might be the battle between SCO and IBM and other Linux companies. Dyroff insists though that SuSE, which supports Univention GmbH’s injunction against SCO acting against Linux, will continue to support Linux come what may and that UnitedLinux, which provides SLD’s codebase, will go forward with or without other partners.

That matter aside though, SuSE may finally have the first winning corporate Linux desktop. Eventually, Dyroff says, there will be a consumer version of SLD-for now end-users have the SuSE Professional Linux 8.2, which is more of a ”all the bells and whistles” Linux distribution — but for now SuSE and SLD is focused on getting the Linux desktop in to business.

June 12, 2003
by sjvn01
0 comments

Cyber Cynic: SCO’s Hands in the Source Jar

I’ve known for about a week now-known, not assumed, not puzzled it out, known-that SCO had mixed Linux code into Unix. I know it because a source I trusted who was in a position to know had told me that had been the case.I haven’t written it up as news though because the person who’s told me this doesn’t want their name used and I haven’t been able to get anyone else who was at SCO in those days to confirm or deny the story.

For that matter, I can’t get anyone working at SCO today to confirm or deny that SCO did some code mixing of their own.

Those outside of SCO are reluctant because, quite frankly, they don’t want to be sued by SCO. Those inside either don’t want to lose their jobs, or at the top, they must not have a good explanation because they don’t have a good answer. And why should management want to answer it? SCO’s own public statements indicate that they were mixing Unix and Linux together. They can’t deny it but they can’t confirm it either without shooting their law suit in the foot.

Now, however, Peter Galli at eWeek has reported that “parts of the Linux kernel code were copied into the Unix System V source tree by former or current SCO employees.”

While no one yet has put their name behind these accusations, this news can’t come as any surprise to anyone who works on operating system compatibility issues.

SCO created the Linux Kernel Personality (LKP) to enable SCO OpenUnix, now back to its old name of UnixWare, users to run Linux binaries at the application binary interface (ABI) level. As SCO puts it, The LKP for UnixWare 7.1.3 and Open UNIX® 8 (UnixWare 7.1.2) provides a complete Linux system hosted on the UnixWare kernel.”

In laymen’s terms that means you could take a complied program for Linux, drop in on LKP-powered UnixWare and run it. No fuss, no muss, no recompiling from source code, you’d just run your Linux program on UnixWare.

Now, I’m not much of a coder, but if you want Linux binaries to run directly on Unix and not in a virtual machine mode-the way that VMware enables people to run Windows on Linux-you need to retrofit Linux code into Unix. Other programs, such as CodeWeavers CrossOverOffice and its open source ancestor Wine, work by emulating Windows’ application programming interface (API). Both are difficult tricks to pull off, but neither requires any Linux code to be placed in the Unix kernel. For LKP to do its job though you must merge some Unix and Linux code at the kernel level and that’s exactly what I’m told SCO did.

Specifically, at a minimum SCO programmers have to take merge Linux code with the Unix kernel to deal with kernel threads, networking, and inter-process communication (IPC). In addition, vital system calls like clone, ipc, and socketcall, had to be cut, slightly modified and pasted for LKP to work. And, yes, LKP does work.

What all that means is that SCO’s intellectual property case against IBM and threats against Linux vendors has an LKP sized hole in it. I can’t make anyone talk to me; I can’t make anyone let me use their name. IBM’s attorneys can though and I’m sure they will if the case comes to court.

I still doubt that it will. SCO’s best chance, as it always has been, is to get bought out. I think they know they can’t win in court. But the longer they can drag matters out-and they can probably afford to do so for a long time with their contingency payment plan with their law firm and the money they got from Microsoft for IP rights-the more likely it is that they can get bought out by IBM or another company.

Technically speaking, I know that SCO is in the wrong, but from a purely pragmatic business viewpoint, the longer SCO can drag this out, the more Linux, and the companies that support it, will be hurt in the marketplace. And, of course, SCO’s management is gambling that this will pay off in big bucks for SCO’s current administration and owners. Of course, SCO’s current customers and Linux users everywhere are getting the short end of the stick, but SCO clearly doesn’t care about them. SCO’s in the law suit business now, not the IT business.

May 23, 2003
by sjvn01
0 comments

Cyber Cynic: Self Destructive DVDs and New Business Models

Walt Disney’s home video unit Buena Vista divsion, using Flexplay Technologies technology, is going to start selling DVDs that self-destuct after two days in August. It’s both an incrediblly good and an incredibly stupid idea

The technology, ez-D, is elegant and simple. The discs stop working because they change from a DVD-readable red to an unreadable black because of oxidation. You open them up, letting the oxygen in, watch them and in 48 hours you have a coaster instead of a DVD.

Buena Vista has two motives for these novel DVDs. The buisiness is that since buyers don’t have to return DVDs, they can sell DVDs pretty much anywhere. While Buena Vista isn’t telling, it’s clear from their language that they’re going to be pricing these disposible DVDs at close to current rental rates.

For idiots like me who waste money by being cogentially unable to get a DVD back to Blockbusters in time, ‘rental’ DVDs make perfect sense. Better still for Disney, there are enough people like me, or people who’d pick up a DVD as an impulse buy if it were three to five bucks at the local 7-11, that this technology will almost certainly give the financially struggling mouse a financial boost. That’s the good idea.

The bad idea, the incredibly stupid idea, that some people at Disney, not Flexplay, has is that ex-D is somehow an anti-cracker technology. Oh please!

The fact that the disc has a limited lifespan because of a chemical reaction instead of a software based Digital Rights Management (DRM) scheme somehow will stop hackers from getting at its contents is nonsense. With 48 hours to crack the DVD, and anti-cracking and DVD copying software commonplace, ez-D is no more a effective copy protection than the shrinkwrap the DVD comes in.

Besides, even though legal action against DVD encryption and copying software compaines like Internet Enterprises Inc., RDestiny LLC, HowtocopyDVDs.com, DVDBackupbuddy.com and DVDSqueeze.com is heating up with multiple law suits from Paramount and Twentieth Century Fox, the studios don’t seem to understand that breaking copy protection per se isn’t really the problem. The DVD copying companies claim that they’re simply enabling legal owners of a DVD ability to make backup copies of their DVDs. The studios reply that breaking a DVD’s copy protection under the 1998 Digital Millennium Copyright Act (DMCA) is illegal regardless of the copy’s use.

Of course, the real problem is that technology has fundamentally broken the business model of high-priced restricted access to copyright material. No copy protection scheme will stand against copy cracking efforts. No law suits will then stop the copy protection breaking software from spreading.

Technology has opened Pandora’s copyright protection box forever. Neither technology or the law can close it.

There is another way though. Embrace the new models. Sound impossible? Think again. Apple seems to have done pretty well with its iTunes Music Store haven’t they?