Building a Blog with Org Mode

As regular readers know, Irreal posts begin as Org Mode files that are subsequently published to WordPress with org2blog. This works very well for me but not everyone wants to run WordPress. For those of you who want to build your own blog, Bastien Guerry has a great post that shows you how to build and publish a blog from Emacs Org Mode.

It’s astounding how easy it is. Guerry walks you through the process from your first post to adding an RSS feed. What you end up with is a static blog and the associated RSS feed. In the spirit of eating his own dog food, Guerry publishes his blog this way. You can see the result by clicking on the home button at the linked post.

Guerry is an interesting guy and one of the heroes of Org Mode. For anyone interested in some background, I’ve written about him here, here, and here.

Posted in General | Tagged , | 2 Comments

Hating Apple

My friend Watts has a perspicacious tweet concerning those who hate Apple:

At times I suspect hating Apple is at least as much of a fashion
statement as buying them is.

That’s right, I think. How else to reconcile the near universal panning of the new iPhones by the technical press with Apple’s announcement that weekend sales of the new iPhones set a new record of nine million units? Apple also revealed, in the same announcement, that over 200 million iOS devices are now running iOS 7, which was mostly panned by the press as well.

Posted in General | Tagged | Leave a comment

The New York Times on Encryption Backdoors

In a bit of good news, The New York Times has published an editorial Calling on the NSA to close their backdoors. There’s nothing in the editorial that will be news to Irreal readers but it’s useful because it educates the public at large as to the issues at stake. It’s easy for us geeks, who sometimes seem to understand these things at the DNA level, to forget that to most people encryption backdoors (and even the associated massive surveillance) is (1) an esoteric technical issue not understandable by normal folks and (2) something that has no impact on their lives.

The advantage to having mainstream publications like the NYT weigh in on the situation is that it can help educate the man on the street about the risks these activities bring to all of us. The article mentions that Representative Rush Holt of New Jersey has introduced legislation that would bar the government from demanding that software makers build in backdoors to their products. If you’re a US citizen, this might be a good time to let your representatives know that you support Holt’s measure.

Posted in General | Tagged | Leave a comment

Code Snippets in Org Mode

Everyone who’s hung around Irreal for a while knows that I’m a big fan of Org mode and that I use it to, among other things, write all my blog posts. One of the really nice things about it is the way it handles the embedding of code snippets in the text.

Matthew Keeler has posted an excellent video on embedding code snippets in Org mode. He starts with a simple document and exports it to PDF through LaTex. Then he adds a bit of Python to the document and demonstrates the Org features that support embedding code in documents. Even this short video serves to demonstrate what you can do in Org mode.

If you write documents that include code you really should watch this video. It will make your work much easier. It’s just a little over 6 minutes long so you can watch it while you’re waiting for the coffee to brew.

Posted in General | Tagged , | 3 Comments

Safe Password Hashing

I have written several times about the absolute necessity to properly hash passwords. The tricky part is that properly. It’s a bit subtle to get it right. Happily the folks over at Defuse Security have an excellent guide that

  • Tells you what to do
  • Tells you what not to do
  • Provides source code to proper implementations in PHP, Java, C#, and Ruby

If you’re a developer tasked with the customer authentication system, be sure to read this. There’s lots of good advice in it. And whatever you do, don’t store the passwords in plain text. If you do, you’re going to end up here and be the object of universal derision and scorn.

Posted in General | Tagged | 1 Comment

Dual_EC_DRBG

One of the recently released Snowden documents mentions the NSA’s success at weakening a 2006 NIST encryption standard and getting it accepted as an international ISO standard. While the standard isn’t named, it is widely assumed to be NIST Special Publication 800-90A with the DualECDRBG random number generator being the weakened algorithm. Indeed, the algorithm was weakened to such an extent that it can be said to have a backdoor.

Matthew Green, a John Hopkins research professor, has a great post on DualECDRBG and its flaws. He explains what the flaw is and how it is exploited. The article is fairly technical but not overly mathematical so interested Irreal readers should be able to follow it without problems.

Ironically, DualECDRBG is very slow (about 3 orders of magnitude slower than the other RNGs in SP 800-90A) so there is no reason to use it except these types of algorithms can be proved to be secure and the cautious implementer may be willing to sacrifice the performance for the security. Unfortunately, NIST neglected to include such a proof in SP 800-90A and when cryptographers took a close look they discovered many problems with the algorithm. Read Green’s post for the details.

Incredibly, despite these problems having been known since 2007, there are still implementations using the algorithm. Meanwhile, NIST has reopened public comment on SP 800-90A and is strongly recommending that DualECDRBG not be used until the standard is reissued.

Posted in General | Tagged | Leave a comment

Tracking Emacs Packages

Via Xah Lee’s blog, I came across a really interesting project. Artur Malabarba’s EAT (Emacs Archive Tracker) project checks the Gnu, Marmalade, and Melpa archives every couple of hours and displays a graph showing the number of packages added recently. The data shows that about 75 news packages are being added every month. That’s pretty impressive and shows how active the Emacs community is.

Of course, EAT is written in Emacs Lisp. That shows not just that the community is willing to eat its own dog food but that Elisp really can be used as a general purpose computing platform.

Update: the → the community

Posted in General | Tagged | 1 Comment

Emacs Startup Packages

Xah Lee has a roundup of emacs Starter Kits on his blog. He’s got a list of 5 such kits so there’s a lot to choose from.

Lee also notes that you can just install Emacs and add things as you need them. That’s the approach I took, probably because there weren’t any starter kits when I first came to Emacs. That approach has worked well for me. When a user of one of the starter kits writes about some wonderful feature in his setup, I just add it to mine. Of course, I’m a programmer so this is natural for me. If you’re a bit less technically inclined, one of the starter kits may be the right answer for you. I’ve heard good things about all the kits that Lee lists so pick one and start building your own configuration from there.

Posted in General | Tagged | Leave a comment

Apple and Fingerprints

Anyone who’s been following Irreal lately is painfully aware that the NSA scandals have kicked my paranoia into hyperdrive. Still, there are limits. Apple’s recent announcement of their fingerprint reader on the iPhone 5S has provoked those poor souls even more inflicted than I into paroxysms of suspicion that the NSA is plotting to steal their fingerprints.

Fortunately, my pal Watts has an excellent post that assuages their concerns and debunks the whole foolish notion. Watts explains how the system actually works and why this really is tinfoil hat thinking. If you’re an Apple user and worried about the technology or you just want an entertaining read, head over to Coyote Tracks and enjoy.

If you want some additional technical details, which corroborate what Watts says, there’s a nice description of the technology over at Quora.

Update: have → has

Posted in General | Tagged | Leave a comment

Trusting Microsoft

If you’re a Microsoft user and at all concerned about the security of your computers, you need to read this BoingBoing story about Microsoft’s cooperation with numerous 3-letter government agencies. If ever there were an argument for open source, here it is.

I love my Apple systems and I haven’t seen much about Apple doing this sort of thing but it does give me pause. If nothing else, it makes sense to use third party (open source) applications for full disk encryption and other security measures. It’s pretty clear that it’s foolish to trust any vendor large enough to be worth the government’s attention. If this sort of thing worries you too, check out Prism Break for some alternatives.

Posted in General | Tagged | Leave a comment