Modification to webserver

February 27th, 2010

Privacy just got a lot better when you visit this website. According to an article in the german magazine "C't magazin fĂr Computer technik" (2010 Edition 5, page 154), the storage of IP data is illegal. Specifically the correlation between IP and access time. So what I've done is patch my webserver (lighttpd) accordingly to throw out the last last 2 octets from the dotted quad. I can now roughly see which region you're from in my logs but not who exactly you were, I'm not interested in that anyhow but if someone wants my logs it won't give them much.

Here is the patch:

--- mod_accesslog.c..orig       2010-02-27 17:31:49.000000000 +0100
+++ mod_accesslog.c     2010-02-27 17:38:01.000000000 +0100
@@ -742,8 +742,12 @@
                        case FORMAT_REMOTE_HOST:
                                /* handle inet_ntop cache */
+                               {
+                                       sock_addr myaddr = con->dst_addr;
+                                       myaddr.ipv4.sin_addr.s_addr &= 0x0000fff
-                               buffer_append_string(b, inet_ntop_cache_get_ip(s
rv, &(con->dst_addr)));
+                                       buffer_append_string(b, inet_ntop_cache_
get_ip(srv, &myaddr));
+                               }
                        case FORMAT_REMOTE_IDENT:

A typical log looks like this then: solarscale.de - [27/Feb/2010:17:46:46 +0100] "HEAD /public/rfc2516nc.
mp3 HTTP/1.1" 200 0 "http://www.deezer.com" "Mozilla/4.0 (compatible; MSIE 6.0; 
Windows NT 5.1; SV1; .NET CLR 1.1.4322)"

The other VPS I have in Panama I'm not going to do this patch because I'm unsure of what the legalities there are there. This should only affect the centroid.eu domain though and if you wish to read only from the german server use solarscale.de. Cheers!


The Internet Meltdown

February 18th, 2010

Yesterday I watched a Google Tech Talk on IPv6 and specifically what transition technologies exist today. The speaker basically thinks we'll have a meltdown near the end of 2011 but seemed very calm about it. I yahoo'ed for it and found this article as well. Over here I've got IPv6 connectivity but I'm wishing that my VPS would have it as well and I've asked about it repeatedly. Maybe by next year, I'm hoping, as being available in both IPv4 and IPv6 land is a must after we run out of addresses.


OpenSMTPD bug (DoS) fixed

February 17th, 2010

Yesterday I found this bug with Mouring on IRC. Basically if you have a very long string for an email address the smtpd will quit with a truncation error in lowercase(). Gilles Chehade put in this fix, revision 1.99 of lka.c, this morning (it should be noted it's Gilles fix, we only identified the bug and wrote to him). Everyone should update to this version or their smtpd will cease working when the DoS comes around that came around to Mouring.


Bruce Schneier has a new book out!

February 15th, 2010

Bruce Schneier has written a new book. I've already ordered this and it should be delivered by march 30th, it'll be released march 15th.


Winter Star Sky

February 8th, 2010

Yesterday for the first time this year the cloudy sky went away and I was able to use my dads camera to make photos of the star sky.

Check out more processed photos here.


The American Manned Space Program

February 4th, 2010

Well so much for the American Manned Space Program, of which I'm a big fan I must add. But let's review what happened in the last 10 years. 12 years. NASA built the International Space Station together with the Russians and other major contributors, starting in 1998. Then GW Bush announced the Moon to Mars program, probably because going to the moon was easier than going to mars. Then President Obama just recently cancelled the Moon-to-Mars program and what we're left with is a formidable space station in orbit and a space shuttle that's retiring at the end of this year (4 more flights).

So what has happened behind the scenes, elsewhere? Well we had the Spaceship One win the Ansari X-Prize and Virgin founded Virgin Galactic so that Spaceship Two can take passengers to a non-orbiting 5 minute view of the rim of space. Also scram-jet engines have been tested in Australia but I didn't find any conclusive evidence that they are building a scram-jet just yet. Also there is a company out in the US that proposes to shoot resources into orbit out of a cannon. They are promising cheaper launch rates than what the shuttle cost by a factor of 10 or so. Then there is the space elevator that everyone dreams of but the material isn't quite strong enough for it yet. And then there have been a number of private space companies that have launched payloads into orbit, these are fairly new.

Anyhow the president of the United States probably has more insight on what technologies are best and cheapest and makes his decision based on that. So perhaps one of these things appealed to him causing NASA to lose their manned space program. Obama must be convinced that there is a better way and we'll see in time what that may be, perhaps he thinks it's too soon to tell the world . Meanwhile I read somewhere, that Europe wants to go to the Moon by 2030 which is in 20 years time. But a lot can happen in just a decade. The original moon program of the US managed to land a man on the moon in 1969 in a decade of preparation with no experience on how to do so, but the cost was so tremendous that they had to give it up. So for this situation I can only look to myself when I was a boy and wanted something real bad. When I didn't get it, after a while I didn't want it anymore and I was glad I didn't make that decision. Perhaps this is what America faces today and they'll be glad they didn't go ahead with a moon program just yet. Time will tell.


