Smuggling USB Sticks
shkspr.mobi
shkspr.mobi
Last time in a Pycon conference in Beijing, 5/4 speeches were about new cloud offers (it was advertising actually). This makes no sense.
People should not do their stuff in free apps running on devices they don't really own, and these apps should not store that stuff in a cloud vaguely rented by the app maker.
Instead, people should use open tools, running on devices they own, storing things on some storage they own and control.
On my bed, I can use my tablet to browse pics I have taken with my phone, while listening to music I have ripped on my desktop long time ago. It seems necessary to be able to do so, but it is not necessary to hand over all your stuff to Apple or Google or Dropbox to do so. (And all your things should be right there even if you ISP is down.)
The obvious solution I used is a "local cloud" (just a samba server on a little Raspberry Pi actually). But on Android strangely only very few media players on devices acknowledge this need and let my slide pics, listen to music or watch video from the LAN. (I have no idea on iOS, I suppose it is even worse, do they have VLC on iOS?)
edit: clarify
http://obamapacman.com/2011/01/vicious-nokia-employee-gets-v...
DRM is fundamentally incompatible with open source licences like the GPL. You almost certainly cannot distribute other people's open source code with DRM. Other people wrote code and developed software that they'll give you the right to copy it under copyright law if you follow their rules. The AppStore does not meet those rules.
The largest example of this is probably CLANG. https://en.wikipedia.org/wiki/Clang
This is easy when you're the sole developer of an application, but almost impossible for existing GPL projects where you must track down all contributors and convince them to assign copyright to you.
http://stackoverflow.com/a/8694538
http://www.networkworld.com/community/blog/solving-apple-app...
The reason Apple does not allow GPL applications on the App Store is because it would be in violation of the GPL license for them to be there. The way the App Store model works requires static linking of both Apple and 3rd party libraries, which, amongst other things, is a violation of the GPL.
1. What do you do if your house burns down? What happens to the documents you care about most? Do you keep a USB drive in a safety deposit box and retrieve it regularly?
(I have a local USB backup, and I have a remote backup through the cloud.)
2. Do you have this local cloud poked out to the outside? How do you handle security? Is there a simple web interface that you can get to something when you're away from the house and your personal equipment?
1. fire safe. 200kg one. Usb stick in it, although I'm considering switching to DLT. USB stick in my bag. Both encrypted with truecrypt at moment.
2. Do without it. Got a moleskin with everything useful in it.
note: I use a film camera and have cds so my media load is quite low. Negatives live in the fire safe and I have a list of cds in a text file so will just buy them again. I also bin emails. My data volume is approximately 800mb. Not much.
I backup important stuff encrypted to S3 with a script.
> 2. Do you have this local cloud poked out to the outside? How do you handle security? Is there a simple web interface that you can get to something when you're away from the house and your personal equipment?
I use pfSense [0] as a router / security appliance running on a Atom based micro ATX board with a 4 ethernet ports. I connect remotely using OpenVPN terminated at the pfSense box and use Viscosity [2] on the client side. File storage is on a FreeNAS [1] server. Very easy to setup if you have basic networking knowledge. The only downside is that there is no built in support for OpenVPN in iOS. There is an app that handles it if your device is jailbroken.
Yes. Why don't you? It's not that hard, and a hell of a lot more reliable and secure than cloud storage.
2. Do you have this local cloud poked out to the outside? How do you handle security? Is there a simple web interface that you can get to something when you're away from the house and your personal equipment?
Blah, blah, blah. This isn't the 90s, you know. We do have things like Apache/Nginx with self signed SSL certs these days (not to mention SSH, rsync, VPNs, etc, etc), and it's not that hard to setup (used to be a right of passage for geeks; these days it's considered entrance exam to the equivalent of geek pre-school). Things are also getting better everyday with projects for "personal clouds" (aka, your own file server with a web interface).
And I did have a "local cloud" in the 90s. :) I find it a positive development that I don't have to do it today. I work enough that I would rather trade money for babysitting a box, checking for security updates, fighting incompatibilities with the scripts when an interface changes, and the other administrivia minutia.
I mean, for a personal uses, it probably won't come to haunt you that you're using an old piece of software with a security bug. But at this point, I have no problem paying for the privilege of thinking about other things.
iOS's built in players will play arbitrary media files as long as the codecs are supported, you just need to have a file browser application that can open it locally or on an SMB share. I use one named 'FileBrowser'[0] on my iPad that has worked well so far.
All my TVs are DLNA enabled and on the network, and I just use NFS to access files from my desktop/laptop.
Was a breeze to setup on my file server (running Solaris for ZFS support; installing software is often unreasonably painful), actively updates its database as new files are added, and allows me to administer it remotely using the Serviio-Console GUI (e.g. to change the folders it scans, update profiles for clients, the directory structure it presents to clients)
For a barebones implementation, minidlna is a fantastic piece of software. I see MediaTomb recommended a lot, and I'm sure it's fantastic, but I've never managed to get it setup properly.
These USB stick stories tell us that, in fine, "existing" data has to have one physical location (or more). The cloud is not magically breaking this "existence principle". Instead, cloud user and data owners (or are they?) are just trusting a third-party service with the physical existence of their data.
The fast that people are able to smuggle slices of the Web in SD cards should remind us that issue, as much as the next big data loss or leak.
There are certain advantages when you "oursource" your basic infrastructure. As long as inter-device connections are still problematic (NAT, STUN, ...) and as long as harddrives die, I really enjoy being able to trade money for free time rather than setting up a redundant off-site backup system.
I mean there are certainly folks doing "off the grid" experiments that are moving this way, and I can certainly see a future where you create enough power for most of your home needs locally, including using some version of a 3D printer to build common items out of stock you have around the house (once they can also accept such). Things that are too costly to build at that scale or require special feedstock could be built by a neighborhood machine (much like mills used to service their neighborhoods), with the feedstock being ordered as needed.
Yes, as long as it is massively inconvenient there is a benefit for trading money for free time. But I would like to spend some of that free time making it possible for me to have a choice of my own - rather than a choice for my provider (who likely will eventually decide they need to make a profit).
It is cheaper per unit of energy to make a natural gas power plant and sell the power than it is to build a small-scale generator to power one home on natural gas. Once that model is established, there is resistance to local power generation. The same scale works at neighborhood level power generation. (Or construction, or manufacturing)
Cost is the difference now between using the cloud and running your own hardware. It is cheaper both in time and money to let a company like Google run your e-mail than to run your own server. So people do it. It is a very simple matter of convenience. I don't expect a backlash until people become mistreated to the point of breaking.
I am an enthusiast of 3D printing and I like the vision you've laid out, but I see it always being cheaper per unit to make 10,000 of something than 1 of something. So delegation will continue unless the underlying behavioral incentives, cost and convenience, change.
Such visions are the stuff of startups.
We barely have SLA standards for uptime, privacy, data breaches, etc.
It's cool to be a pioneer. But you're largely on your own. A trade off.
Give them time, and they will.
The power company only provides a "standard" volt and amp rated supply, and just like cloud computing, there are various standards to choose from[1]. You're probably thinking "120V 60Hz AC with type-b plugs", whereas for me the default assumption is "220V 50Hz AC with type-1 plugs". Fortunately, half my electronics doesn't actually care what voltage/frequency/current is available thanks to modern power supplies (I've seen my iMac happily keep running during a brown-out where the wall sockets were measuring just 90V AC, while all the routers/modems/harddrives with less capable power supplies were flickering and rebooting continuously.) Other devices I own I can use a transformer to change my 220V down to 120V, though still at 50Hz. If I needed to (and I never have) I could use a US targeted UPS or inverter to provide 120V AC @ 60Hz.
The "cloud" market is kinda the same. Cloud storage, for example, expects 8 bit bytes delivered over tcp (or perhaps udp). In general, "everything just deals with that", pretty much every modern-ish 8/16/32/64 bit device, regardless of native endianness, will happily emit and receive the same 8 bit bytes that S3 stores (converting on the fly, much like a switchmode power supply does for voltages). If you're an edge-case customer, perhaps wanting to use Amazon S3 to store data for your 12bit wide "bytes" from your PDP8, you just convert them on the way in and out. And much like the end result of electricity consumption is pretty much all the same, electricity is mostly just converted into heat - but with side effects varying from cooling your beer to blasting pixels onto your screen at 100fps to making your coffee machine hot; ultimately cloud storage is all just ordered bytes more-or-less reliably stored and retrieved - whether that's plain text passwords, or massively de-duped mp3s in Dropbox or Amazon/Apples cloud music storage, or cryptographically secure blobs which no-one can tell whether they contain your bank records or your secret research project data or child porn - it's all just bytes. There's no "vendor lockin" at the "it's just a bunch of ordered bytes" level. You might need to "change the plugs" if you want to switch you cloud storage from S3 to BigTable to Dropbox to Tahoe/LAFS, just like I need to switch cables or use a plug adaptor for US delivered electrical equipment. It's the same with cloud compute resources - sure EC2 and Linode and CloudNine and AppEngine have different interfaces, but you can view that as all just the plumbing on the way into the "remote universal turing mschine" which, much like the topologists who can't tell the difference between their coffee mug and their donut, in spite of their interface and language differences all the programmable remote computing offerings are identical - if you can compute anything on one of them, you can - in theory- compute it on any of them.
[1] http://en.wikipedia.org/wiki/Mains_electricity_by_country
* Use a vendor specific extension - e.g. EBS + snapshots to mount customer data volumes - make sure you can work around it easily if you move to another provider. * Backup data inside the same cloud provider? - make sure you backup the backups in case of catastrophic cloud provider failure - not doing that? then you need to understand what your risk profile is? * Only use 1 provider? What is your strategy if they fail, temporarily or permanently? Where is your data? How do you fail if they fail?
So on and so on - these are standard considerations in a business risk analysis / disaster recovery plan - but I many IT shops in the cloud are staffed by people who are great at code, but have never dealt with the vagaries of business practice - not their "fault" - but it is a blind spot I see quite often.
I agree with your sentiment that "we shouldn't let others control our stuff." However, that doesn't mean you have to completely forego the advantages of cloud services.
For example, you can encrypt your data before backing it up to a storage providers. You haven't lost any freedom there; the worst case scenario is that they don't provide the reliability you paid them to provide. You can mitigate that risk by using more than one provider.
Of course, unofficially you just had to pop down to the souks where you could get anything (pornography included) burnt to DVD. I used my time there as an excuse to digitise my DVD collection, since they certainly weren't going to let me get away with bringing them into the country, whereas a USD hard-drive went pretty much un-noticed.
It seems to me that whilst there are a few countries which enforce a totalitarian approach to censorship (like North Korea), others really just do it for 'appearances', because to not do so would be culturally unacceptable. Certainly pretty much everyone I met was circumventing censorship (both in net and print).
A related interesting effect with respect to corruption: any official is corrupt, and can be brought down at anytime because of that. Squeaky clean officials are not trusted because the "nuclear option" won't work on them, so they aren't promoted, leading to a downward spiral in quality.
A reasonable fair legal system is very important, I feel like we take it for granted in the west that things could be much worse.
The US isn't too different from this, especially if you include all the contractual agreements that a typical person enters into.
In China, if someone wants you out of your apartment, they can have you out almost overnight. Can you imagine how stressful a midnight move is?
The courts in the United States of America regard resisting arrest as a separate charge or crime in addition to other alleged crimes committed by the arrested person. It is possible (and has happened) to be charged, tried and convicted on this charge alone.
https://www.youtube.com/watch?v=WFd5_YtbScs
(not-so-good English subtitles available)
http://www.amazon.com/Three-Felonies-Day-Target-Innocent/dp/...
Another angle in the US is are situations where you cannot be charged with a crime, but your property can. For example, if you are travelling on an airplane with a "large" quantity of cash, the authorities can (and have) essentially "arrest" your cash via asset forfeiture. You have rights, but your property does not.
(and the modern version of that calculation, a station wagon fill of microsd cards, is calculated at 500gig per second here: http://www.dansdata.com/gz105.htm )
I think there's only one real reference to this in the movie. It's supposed to be a super-secure way to transfer data. However, personally if the data was that important I'd just say "you come to me", because honestly if I got the cash I wouldn't care if you got shot 5 feet outside my building.
Not if they're encrypted well enough and the data is somewhat time-sensitive!
....have we just found the solution to this XKCD? http://xkcd.com/538/
However, the sender would likely phone/email/deliver the password on notification of arrival, which IIRC was what was supposed to happen in Johnny Mnemonic, but the Yakuza attacked and Johnny gets a portion of the password, which incidentally ties in with frame 2 of that comic.
I guess the lesson here is that a $5 wrench and a $50 mix of acid/shrooms/K applied to the right person would beat any cyrpto known to man.
Point being that movie files are still quite huge.
Also, transferring 32GB over fairly modest 10Mbps line takes roughly 7 hours, far less time than what it'd take via post service.
If you're talking about countries where this censorship is common, even a 10/1 line is probably not affordable by anyone except an elite.
Cable supports up to 100Mbs down (at least I'm pretty sure that Virgin has started to roll that out, if not then 50Mbs), though contention might be an issue at peak times.
I've got BT Infinity, which is fibre to the cabinet rather than all the way to the home. Since the distance to the cabinet is likely to be pretty minimal you can get pretty high bandwidth over the last length of telephone wire. For reference, I get 76Mbs down and 20+Mbs up - more than fast enough for plently of thing to feel instant, such as downloading movies which now takes in the order of minutes.
I think the premise of the article is flawed, because I have a 16/2 connection. I recently express mailed an envelope across country (GTA to Vancouver) and it took approximately 4 business days and cost me ~$12. To do this through the internet, we're looking at 1.5 days for my internet connection (assuming upload is the speed issue). Even at the average 10/1 connection, we're talking 3 days. Still beats mail, and god forbid you mail on a thursday and it takes 6-7 days to get the mail through. What about from Canada to Australia? Well an express letter, you're looking at 2 weeks if you're lucky.
Remember, this is only a product of our lazy ISPs happy to keep service where it is whilst bumping up prices. If Google Fibre has an effect on the market this discussion is meaningless. Up to 1gbps up and down. This discussion is meaningless if it only attains 10mbps upload, it won't even leave the post office in the time it would take to transfer.
The notion that SOPA et al will destroy the internet is a little absurd, all it will do is expand the darknet, which will cause rapid expansion.
Think what Tor would be if every computer in the world was on it and acting as a proxy. This is what governments will force to happen with restrictive legislation and our "controlled freedom" will become uncontrollable freedom.
edit: and it's worth noting that these small video files will typically strip the multi-channel audio and favor a remixed stereo-only sound track. saves more bytes.
edit: kudos to poster below for clarifying my half-baked explanation.
DVD does use MPEG2. Blu-ray supports a variety of algorithms for video and audio with the BDAV container (.m2ts), commonly MPEG2, H.264 (AVC) and VC1 for video and DTS-HD MA, Dolby TrueHD and garden-variety LPCM for lossless audio.
Today, most Blu-rays are being authored with H.264 or VC1 encoding for video. That being said, space savings are achieved by trans-coding the raw .m2ts to much lower bitrate H.264 and downmixing the audio to, say, 620kbps DD5.1 or even just stereo.
Also, multi-channel is rarely downmixed to stereo in case of HD content - for Blu-ray rips, however, only the core from Dolby TrueHD (640kbps AC3) or DTS-MA (1536kbps DTS) is generally used (at least in case of western content) instead of the full lossless audio (and in cases where lossless audio is used it is generally converted to FLAC because it compresses better).
Just because rips have drastically smaller filesizes doesn't mean that they're going to have drastically lower quality, though - Blu-ray has limitations in the amount of H.264 features that can be used, and encoding applications also matter. x264, which is a FOSS H.264 encoder, is generally recognized as the best H.264 encoder in the world. If you use x264 and go above Blu-ray limits, hell even H.264 level 4.1 limits, or even encode in 10-bit, it's not uncommon that you'll be able to shave off over 50% of the file's original size or more (compared to the original .m2ts file on the BD) with no discernible loss in video or audio quality. In case of western content, people tend to mostly stick to level 4.1 8-bit H.264, though, because of hardware compatibility. 5.1 DTS/AC3 core is used instead of say, 5.1 AAC is used for compatibility reasons as well - because S/PDIF can't do 24-bit 5.1 LPCM.
There is one scene that cares very little about hardware compatibility, though: the anime scene. You can find pretty much the most advanced video, audio and subtitle formats in use there, with 10-bit H.264 video going up to level 5.1, AAC/FLAC audio, very complex ASS subtitles, Matroska ordered chapters... it's quite fascinating, really.
But you completely missed the point the article is trying to make...
I'd certainly hope that they already have a copy of that, given that an entire dump is <32 GB[1], depending on how much meta-info (edit history, etc.) you want to include.
From there, all you have to do is smuggle in the diffs every now and then, which should be minuscule.
For the technically savvy, yes. But by enacting these changes, governments and other interests can dramatically alter the mainstream discourse and culture negatively. Having a difficult technical means for a few to work around the damage won't prevent the overall harm.
Well, not a SD card, but you can mail Amazon a HD and they'll transfer it over for you. It may not suit your particular use case, but people do use it.
Internet without cables? Dead drops started as an art experiment...
(Everyone's being pedantic about the numbers, so I felt entitled to be pedantic about something else.)
Also, you completely missed the point of the article.