2013年7月28日 星期日

六色帽子 分辨各路黑客

蘋果日報

黑客人多勢眾又良莠不齊,就如魔法故事裏的巫師世界,因應黑客的品性和專長分成很多種類,黑帽黑客是奸惡罪犯、白帽黑客代表光明磊落的專家。道不同 有時也會走在一起,即將於美國召開的「黑帽大會」雖名為黑帽,但出席的不一定全是壞蛋,紅白藍灰綠各路黑客都會參與交流一番。

黑帽 奸惡罪犯

黑客界的壞人,非法入侵網絡盜取個人資料,為了金錢或純粹惡意搞破壞,屬電腦罪犯

白帽 道德專家

受聘於某公司專門測試網絡系統是否安全,或受聘於保安公司設計保安軟件,是道德黑客

灰帽 黑白之間

介乎黑帽與白帽之間,愛非法入侵網絡但沒有惡意,有時只為提醒該公司注意安全漏洞,事後會主動通知,收取象徵式費用後負責修復系統

紅帽 邀進分子

白帽黑客的「激進版」,多數受聘於政府部門,專門入侵其他政府的電腦主機網絡,癱瘓系統

藍帽 貪玩報復

通常不受僱於電腦保安公司,為了貪玩或者報復,針對特定人士或公司而入侵網絡。相對較被動,除非被招惹激怒,否則多數不會主動出手

綠帽 聽話新手

綠帽是黑客界的「菜鳥」,多數指缺乏經驗、技巧生澀的新手,他們熱衷學習,肯聽命於有經驗的黑客

2013年6月23日 星期日

Open Source Workshop #15 開源工作坊 (2013/07/06)

下一次 Open Source Hong Kong 和 HKLUG 合辦的開源工作坊,訂於 7 月 6 日 (星期六) 在城大舉行。

今 次除了新鮮開源消息分享外,你也可以跟我們一起透過連場 Lightning Talks 閃電講, 五分鐘內講解你的 open source projects, 程式開發, 用家經驗或 idea 等等,讓大家了解和學習不同 open source projects ,繼而在緊接的 Hacking / Discussion Session 進行有關實作或討論。

第 15 次開源工作坊 (2013年7月)

日期: 2013 年 7 月 6 日 (星期六)
時間: 14:30 - 17:45
地點: 香港城市大學一號教學樓 5/F Y5-203 課室。
報名: http://opensourcehk201307.eventbrite.hk/
聯絡: Sammy Fung sammy@opensource.hk

Agenda
  1. Open Source News & Updates.
  2. Lightning Talks - your open source project ideas / updates
  3. Open discussion and hacking session.
Lightning Talks
  • Sammy Fung - hk0weather open source weather data project
  • Wan Leung Wong - Raspberry Pi
  • Pockey Lam - Digital Freedom Foundation (DFF) (10 min)
  • 你也告訴我們你的題目吧
特別鳴謝: 香港城市大學電腦系. (場地提供)

(English)

Next Open Source Workshop co-organized by Open Source Hong Kong and HKLUG, will be hosted again at CityU in 2013/7/6 Saturday.

Open Source news updates will be shared by co-organizers.

At lightning talk session, you can demostrate or express your open source projects, user experiences, and brainstom ideas to others in 5 minutes, then we will form some hacking / discussion groups to continue  works or discussions on your topics after lightning talks.

Open
Source Workshop #15 (2013 July)


Date: 6 July 2013, Saturday
Time: 14:30 - 17:45
Venue: Classroom Y5-203, Academic 1, City University of Hong Kong, Tat Chee Road, Kowloon Tong.
RSVP: http://opensourcehk201307.eventbrite.hk/
Contact: Sammy Fung sammy@opensource.hk

Agenda
  1. Open Source News & Updates.
  2. Lightning Talks - your open source project ideas / updates
  3. Open discussion and hacking session.
Lightning Talks
  • Sammy Fung - hk0weather open source weather data project
  • Wan Leung Wong - Raspberry Pi
  • Pockey Lam - Digital Freedom Foundation (DFF) (10 min)
  • Tell us your topics if you got any.
Special Thanks: Department of Computer Science, City University of Hong Kong (Venue Provider)

--
Yours Sincerely,
Sammy Fung
Community Manager
Open Source Hong Kong
http://opensource.hk

2013年5月24日 星期五

Open Source Workshop #14 (2013/6/1)

開源工作坊 #14 (2013年6月)
日期: 2013 年 6 月 1 日 (六)
時間: 下午 2:30-5:45 (最早可在 2pm 到場)
地點: 香港城市大學一號教學樓 5/F Y5-303 課室
請到 http://registrano.com/events/01332d 登記

議程:
* Open Source News & Updates by sammyfung and haggen.
* Introduction of Mozilla Webmaker and Firefox OS by sammyfung.
* Kernel-based Virtual Machine (KVM) talk by wanleung.
* Open discussion and hacking session.

語言: 廣東話
(除了英語講者以英語演講外)

人數: 40.

主辦:
* Hong Kong Linux User Group.
* Mozilla Hong Kong Community.
* Open Source Hong Kong.

(English)
Next workshop will be hosted on June 1st at CityU.
Open Source Workshop #14 (June 2013)
Date: 1 June 2013 (Saturday)
Time: 2:30-5:45pm (door open at 2pm)
Venue: Classroom Y5-303, 5/F Academic 1, City University of Hong Kong, Tat Chee Road, Kowloon Tong.
Please RSVP at http://registrano.com/events/01332d

Agenda:
* Open Source News & Updates by sammyfung and haggen.
* Introduction of Mozilla Webmaker and Firefox OS by sammyfung.
* Kernel-based Virtual Machine (KVM) talk by wanleung.
* Open discussion and hacking session.

Language: Cantonese
(except English for English speakers if any)

Capacity: 40.

Organizers:
* Hong Kong Linux User Group.
* Mozilla Hong Kong Community.
* Open Source Hong Kong.





--
Yours Sincerely,
Sammy Fung
Community Manager
Open Source Hong Kong
http://opensource.hk

2013年5月17日 星期五

Skype with care – Microsoft is reading everything you write

www.h-online.com

Anyone who uses Skype has consented to the company reading everything they write. The H's associates in Germany at heise Security have now discovered that the Microsoft subsidiary does in fact make use of this privilege in practice. Shortly after sending HTTPS URLs over the instant messaging service, those URLs receive an unannounced visit from Microsoft HQ in Redmond.

A reader informed heise Security that he had observed some unusual network traffic following a Skype instant messaging conversation. The server indicated a potential replay attack. It turned out that an IP address which traced back to Microsoft had accessed the HTTPS URLs previously transmitted over Skype. Heise Security then reproduced the events by sending two test HTTPS URLs, one containing login information and one pointing to a private cloud-based file-sharing service. A few hours after their Skype messages, they observed the following in the server log:
65.52.100.214 - - [30/Apr/2013:19:28:32 +0200]
"HEAD /.../login.html?user=tbtest&password=geheim HTTP/1.1"
 
They too had received visits to each of the HTTPS URLs transmitted
over Skype from an IP address registered to Microsoft in Redmond. URLs
pointing to encrypted web pages frequently contain unique session data
or other confidential information. HTTP URLs, by contrast, were not
accessed. In visiting these pages, Microsoft made use of both the login
information and the specially created URL for a private cloud-based
file-sharing service.
In response to an enquiry from heise Security, Skype referred them to a passage from its data protection policy:
"Skype may use automated scanning within Instant Messages and SMS to (a) identify suspected spam and/or (b) identify URLs that have been previously flagged as spam, fraud, or phishing links."
A spokesman for the company confirmed that it scans messages to filter out spam and phishing websites. This explanation does not appear to fit the facts, however. Spam and phishing sites are not usually found on HTTPS pages. By contrast, Skype leaves the more commonly affected HTTP URLs, containing no information on ownership, untouched. Skype also sends head requests which merely fetches administrative information relating to the server. To check a site for spam or phishing, Skype would need to examine its content.
Back in January, civil rights groups sent an open letter to Microsoft questioning the security of Skype communication since the takeover. The groups behind the letter, which included the Electronic Frontier Foundation and Reporters without Borders expressed concern that the restructuring resulting from the takeover meant that Skype would have to comply with US laws on eavesdropping and would therefore have to permit government agencies and secret services to access Skype communications.
In summary, The H and heise Security believe that, having consented to Microsoft using all data transmitted over the service pretty much however it likes, all Skype users should assume that this will actually happen and that the company is not going to reveal what exactly it gets up to with this data.
 

2013年5月12日 星期日

International Space Station to boldly go with Linux over Windows

www.telegraph.co.uk

Computers aboard the International Space Station are to be switched from Windows XP to the Linux operating system in an attempt to improve stability and reliability. 

Dozens of laptops on the ISS's 'opsLAN' network - which provides the ship's crew with vital capabilities for day-to-day operations, from telling the astronauts where they are to interfacing with onboard cameras - will be switched, removing Windows entirely from the ISS.
“We migrated key functions from Windows to Linux because we needed an operating system that was stable and reliable – one that would give us in-house control. So if we needed to patch, adjust or adapt, we could," said Keith Chuvala of the United Space Alliance, which runs opsLAN for NASA.
Astronauts using the system were trained on specific courses tailored by the non-profit Linux Foundation.
Linux is already used to run various systems aboard the ISS, including the world's first 'Robonaut', sent to the Space Station in 2011. 'R2' can be manipulated by astronauts as well as ground controllers and is designed to carry out tasks "too dangerous or mundane" for astronauts in microgravity, according to the Linux Foundation.
Tailored versions of Linux are widely used in scientific projects, including CERN’s Large Hadron Collider.

“Linux Foundation had it all, and provided the trainer on-site at our headquarters, which was a huge plus,” said Chuvala. “On top of that, the cost was very good, so it was overall a great value.”
The ISS computers were previously infected by a virus while running Windows. In 2008 the W32.Gammima.AG worm was found aboard, having reportedly been carried on a Russian astronaut's laptop. The Windows-based worm was classed as low risk by anti-virus software manufacturer Symantec.
Reports from Russian officials today reveal that the ISS is suffering a "very serious" ammonia leak that may require astronauts to perform an emergency spacewalk

 

2013年4月28日 星期日

Open Source Workshop #13 (2013/5/4)

下個 HKLUG 和 OSHK 合辦的開源工作坊將於 5 月 4 日城大舉行,建議主題是 Web,歡迎交題目來分享任何 Open Source 有關的講題作 talk 或 workshop 等。

第 13 次開源工作坊 (2013年5月)

日期: 2013 年 5 月 4 日 (星期六)
時間: 14:30 - 17:45
地點: 香港城市大學一號教學樓 5/F Y5-205 課室。
報名: http://registrano.com/events/508972
Facebok 報名 (OSHK): https://www.facebook.com/events/280182835446159/
聯絡: Sammy Fung sammy@opensource.hk

程序:
14:00 Reception, Networking
14:30 Talks
- Opening by Sammy Fung.
- Joomla by Simon Ball.
- What's happening at Open Source Hackfest by Mathieu Bridon.
- And more, let tell us if u got anything would like to share.
16:00 Break
16:15 Workshop (Open Source Hackfest)
17:45 End


特別鳴謝: 香港城市大學電腦系. (場地提供)

台灣開源人年會 2013 海外徵稿和第一輪 keynote 講者公佈

(Keynote: 政委張善政,Greg Kroah-Hartman)

COSCUP 全稱為 Conference for Open Source Coders, Users and Promoters,COSCUP 是台灣最大型開放源碼年會,今年預期 1,800 人出席。

COSCUP 2013 將移師到更大場地的台灣國際會議中心 (TICC),2013/8/3-4 舉行。

話說今年台灣開源人年會 COSCUP 主題之一 OpenData,其中扮演相當重要的角色 — 當然就是政府囉!

而今年我們非常興奮的邀請到曾任 Google 亞太營運總監,數年來擔任政府雲端技術以及 OpenData 的推手 — 張善政行政院政務委員擔任 Keynote 講者!

另外,台灣開源人年會 COSCUP 辦得那麼龐大,聚集台灣本土超過 20 個社群,甚至香港、日本、大陸社群去出席,號稱開源「社群大拜拜」。

COSCUP 這個開源社群大拜拜要拜什麼呢?當然是「拜大神」了!

今年 COSCUP 邀請到了 Linux Kernel 「第一位交椅」- Linux Kernel stable branch maintainer、知名 Linux Kernel 開發者 Greg Kroah-Hartman 來台演講!

Greg Kroah-Hartman 是 Linux Kernel 相當多組件的維護者包括 Linux Kernel stable branch,USB, sysfs 等等,更撰寫了現在每個 Linux 使用者每天都會用到 udev 裝置管理系統!他亦是 Linus Torvalds 之外, 另一位 Linux Foundation 負責全職 Linux Kernel 開發的 Fellows。

OpenData 的開發者們怎麼能錯過跟政府直接交流的機會呢?跟大神一起在 COSCUP 演講的機會?趕快來投稿 COSCUP 吧! (5/3 截止)
你可以用英語、國語、甚至廣東話也可以.

香港朋友除左可向大會查詢外,還可以聯絡我 (Sammy Fung),我是今年 COSCUP 議程組成員之一。
http://coscup.org/2013
(English)

Hi,

Next Open Source Workshop co-organized by HKLUG and OSHK will be hosted again at CityU in 2013/5/4 Saturday. Suggested theme is Web, you are welcome to submit any open source related topics for talk or workshop, etc.

Open Source Workshop #13 (2013 May)

Date: 4 May 2013 Saturday
Time: 14:30 - 17:45
Venue: Classroom Y5-205, Academic 1, City University of Hong Kong, Tat Chee Road, Kowloon Tong.
RSVP: http://registrano.com/events/508972
Facebok RSVP (OSHK): https://www.facebook.com/events/280182835446159/
Contact: Sammy Fung sammy@opensource.hk

Agenda
14:00 Reception, Networking
14:30 Talks
16:00 Break
16:15 Workshop
17:45 End

Special Thanks: Department of Computer Science, City University of Hong Kong (Venue Provider)

--
Yours Sincerely,
Sammy Fung
Community Manager
Open Source Hong Kong
http://opensource.hk

2013年4月19日 星期五

Alert- US House of Representatives Passes CISPA Cybersecurity Bill

silverdoctors.com

The US House of Representatives has passed the controversial Cyber Intelligence Sharing and Protect Act (CISPA).
Lawmakers in the House voted 288-to-127 Thursday afternoon to accept the bill. Next it will move to the Senate and could then end up on the desk of US President Barack Obama for him to potentially sign the bill into law.

2013年4月7日 星期日

[ITFest] 自由及開源軟件在香港研討會 Seminar on Free and Open Source Software in Hong Kong

在香港,不論是個人或團體,
都有不少透過使用自由及開源軟件獲益的故事。藉著今次「國際IT匯」,香港Linux用家協會請了來自出版、資訊科技、長者服務和中學教育等的專業人士,分享他們參與自由及開源軟件的經驗。
 
自由及開源軟件在香港研討會
日期: 2013年4月20日(星期六)
時間: 下午3:00-6:00
地點: 九龍塘達之路,香港城巿大學,教學大樓四樓,LT-15演講廳
語言:廣東話 (部份附英文演示片)
聯絡人: 蘇孝恆博士 / info@linux.org.hk
參加者必須在 http://registrano.com/events/hklugitfest2013/ 登記。
議程內容:
  • 主辦單位致開幕詞
  • 立法會議員 (資訊科技界) 莫乃光致開幕詞
  • LinuxPilot – 亞洲唯一的中文Linux期刊 (麥經倫先生)
  • 開源軟件如何在香港協助推廣開放資料 (馮振華先生)
  • 開源硬件與教育 - Raspberry Pi和三維印刷 3D Printing (梁志宏老師)
  • 自由及開源軟件與長者 (梁敬文先生)
活動主辦:香港 Linux 用家協會 (HKLUG)
場地贊助及提供:香港城市大學電腦系
(English)
Different individuals and organisations in Hong Kong are enjoying the benefits of Free and Open Source Software. In the Hong Kong International IT Fest, professionals from area of publishing, information technology, elderly service and secondary education will share own experiences in Free and Open Source Software.Seminar on Free and Open Source Software in Hong Kong
Date: 20 April 2013(Sat)
Time: 3-6pm
Venue: LT-15, 4/F. Academic Building 1, City University of Hong Kong, Tat Chee Avenue, Kowloon Tong.
Language: Cantonese (English may be used in some slides)
Contact: Dr. Haggen So / info@linux.org.hk
Registration is required. Please register at http://registrano.com/events/hklugitfest2013/ .
Programme:
  • Opening by Organizer
  • Opening Remarks by Legislative Council member (ITFC) Hon. Charles Mok.
  • LinuxPilot – the Chinese Linux Magazine (Mr. Kenneth Mak)
  • How does Open Source Software helps Open Data in Hong Kong (Mr. Sammy Fung)
  • Open Hardware and Education - Raspberry Pi and 3D Printer (Mr. Parker Leung)
  • Free and Open Source Software and Elders (Mr. Kingman Leung)
This event is organized by the Hong Kong Linux User Group (HKLUG).
Venue is sponsored and supplied by the Department of Computer Science, City University Hong Kong.
--
Yours Sincerely,
Sammy Fung
Community Manager
Open Source Hong Kong
http://opensource.hk

2013年4月2日 星期二

Raspberry Pi 工作坊 (2013.04.06 PolyU)

*** 本活動名額有額,必需經由 Registrano 報名。 ***
報名表格:http://registrano.com/events/32be70
*** 優先接納中學生報名 ***


Raspberry Pi 工作坊
日期2013 年 4 月 6 日 ( 星期六 )
時間下午 2:00-5:00
地點香港九龍紅磡,理工大學六樓,CD634
語言:廣東話 ( 部份附英文演示片 )
內容:
  • 什麼是Raspberry Pi?
  • 如何使用 Raspberry Pi 學習
  • Raspberry Pi 電子實驗習作 (以小組進行)
報名程序:
  • 先經 Registrano 表格報名,等待主辦單位人手接納報名。
  • 中學生將被優先接納。
報名表格http://registrano.com/events/32be70

人數:20 人
主辦單位:香港 Linux 用家協會
場地贊助及提供:香港理工大學電子及資訊工程學系
協助單位:Open Source Hong Kong
(English)
This is a workshop conducted in Cantonese. Local secondary school students are primary targeted participants in this workshop, and they will have first priority to get a seat after registration.
Raspberry Pi Workshop
Date: 2013.4.6 Saturday
Time: 2:00-5:00 pm
Venue: PolyU
Language: Cantonese
Program:
  • What is Raspberry Pi?
  • How to learn with Raspberry Pi ?
  • Practical Raspberry Pi workshop (in groups)
Registration Procedure:
  • Register thru Registrano is a must, and wait for confirmation / reply from organizer.
  • Students of local secondary school will be accepted in first priority.
Registration Form: http://registrano.com/events/32be70

Capacity: 20
Organizor: Hong Kong Linux User Gruop (HKLUG)
Venue Sponsor and Provder: Department of Electronic and Information Engineering, Hong Kong Polytechic University.
Supporting Organisation: Open Source Hong Kong
--
Yours Sincerely,
Sammy Fung
Community Manager
Open Source Hong Kong
http://opensource.hk

2013年3月7日 星期四

太混賬 政府踢走iProA

蘋果日報

【本報訊】獲政府撥款逾億元推行上網學習支援計劃的「信息共融基金會」,因推行計劃以來管理混亂及向政府提供失實資料,近日被政府罕有地以違反撥款和營運 協議為由,宣佈將於今年5月中解約。基金會原本由小童群益會及唐營的互聯網專業協會(iProA)合組。政府現要求小童群益會接手「爛攤子」。

點名暗批前會長

本報取得一封由政府資訊科技總監賴錫璋於上月19日發給信息共融基金會署理主席鍾志平的信件,力數基金會四宗罪,包括至今仍未提交去年11月至今年4月的 工作計劃書,交代推行上網學習支援計劃的人手與開支;至今無法確保上網學習支援計劃使用一個獨立於iProA的銀行戶口。

信 中又形容,信息共融基金會由去年11月底至今年2月初,先後七次向政府提供不盡不實的資料,並點名暗批基金會前會長鄧淑明,包括指鄧去年7月去信政府聲稱 已使用獨立銀行戶口,但事實並非如此;又指鄧去年12月曾去信政府聲稱已有嚴格措施去核實開支,但同樣事不符實。所以決定根據合約條款於今年5月19日終 止合約。

據了解,政府已委託小童群益會繼續執行在香港東推行上網學習支援計劃,並向立法會資訊科技及廣播事務委員會滙報事件。

資訊科技總監辦公室回覆表示,鑑於小童群益會一直參與上網學習支援計劃,相信由小童群益會繼續兼負項目對受眾影響最細,故不打算將計劃的香港東部份重新招標,現時信息共融基金會已展開上網計劃交接程序,細節稍後公怖。

小童群益會總幹事羅淑君回覆稱,會繼續執行上網學習支援計劃,並密切留意有關發展。
信 息共融基金會由iProA與小童群益會合組,於2011至12年度獲政府撥款2,980萬元,按合約要求,執行機構獲撥款後,要立即開設獨立銀行帳戶。現 任iProA會長洪為民昨回應時推說,他於去年5月才上任,「iProA一年才開四次會,5月開董事大會時,冇人喺agenda加入要開銀行 account。」

信息共融基金會則稱,去年底已決定由小童群益會全面執行上網計劃,iProA已不再參與前線服務,反指政府終止合約是多此一舉,又稱政府未能提供受眾資料,令推行計劃遇到很大困難。

被政府暗批的信息共融基金會前會長鄧淑明(圖)表示,今年初已退出基金會及iProA,不便回答。