Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

2026-04-05

The Problem of Passkeys

 The Problem of Passkeys

This is not a deep study of passkeys, I am interested in how useful and usable passkeys actually are.  In particular by trying them myself in a limited way.

I have many issues with passkeys.  Asymmetric encryption is hard, technical and not suitable or secure for most normal (ie non-technical) people.  But clearly it's possible to use it to make reasonably secure systems like Signal.

I had a brief look at passkeys a while ago.  When I found that I couldn't use passkeys on MacOS without having my passkeys (my secret keys) copied into the icloud, I decided to give that a miss.  I don't want my secret key on other people's servers.  Apple could have decided to allow passkeys to stay on a device, but no, apparently they wanted to make passkeys easier for people to use.  On all their Apple devices!  

Easy to use is the bane of IT security.

Anyway, since then there have been developments, so I decided to try again.  Apple still allows passkeys on its systems only if you allow it to copy your secret keys to the icloud.  But there are now alternatives.

Apparently Strongbox.app, two versions of which appear to be supplied with my MacOS Tahoe reads and stores password data in a standard Keepass database.  Strongbox appears to be integrated with the MacOS password systems.  Apparently Strongbox can store passkeys but the methods are complicated and oh, require a paid upgrade, that might even work!  Not really interested.  

I found that KeepassXC is yet another Keepass app that reads and writes Keepass format databases.  It also has binaries for MacOS, Windows, and Linux and is free and open source.  It doesn't have an Android or iPhone app yet, I think.  KeepassXC has some interesting new features.  For instance you can use it to generate passphrases.  KeepassXC can store passkeys and it has browser extensions for a number of browsers to autofill passkeys and other stuff. It has browser extensions for Firefox and Brave/Chrome and Edge.   Maybe more in the future? 

It's not exactly simple to get autofill working with KeepassXC.  You have to add the browser extensions to your browsers.  There are settings that need to be set.  I managed to get it to work on Firefox, but not Brave, even though Brave managed to use passkeys without it.

Oh yeah, did I mention: Brave browser can store passkeys internally.  Who knew?

I dislike password wallets that do autofill.  I'm sure that many people find it easy, but frankly easy in computers is the cause of many security vulnerabilities.  I guess you have to use autofill with passkeys.  We can't allow users to copy and paste or drag and drop or generally control their own secret keys.  Also I often need to use different browsers for different sites and to test stuff.  I don't necessarily want all of them to login as the same user or even to login at all.  I definitely don't want one overriding autofill system run by Apple or Microsoft with them deciding where to store my secret keys and personal info.  

After getting passkeys with KeepassXC to work in Firefox, on a test site, I tried it for a real site, ie google.  Somehow it just wouldn't work.  Some part of Firefox or MacOS decided I needed to store my passkey in Apple's icloud and since that was not enabled, no passkey.  The process appears to be controlled by the website and the operating system and is opaque to the user.  I tried another website and it worked.  Mysterious.

One of the problems with passkeys is that most systems appear to take all control away from users.  Websites apparently control how you create your passkeys, how you store them.  If you want to store your passkey in a browser and the browser allows it, you will only be able to use your passkey from that browser.  You may not be able to use other browsers, other devices.  It's hard to see your secret key, hard to move it around or not.  One solution of the problem of moving your passkeys around for yourself to other browsers, other apps, other devices is to put them in a cloud.  Apple's solution and maybe Google's too and possibly Microsoft's.  A cloud is other people's computers.  The big corporates, social media desperately want you to save your secret keys on their cloud, so they can get access to copies of your secret keys. And access to when and how you use your secret keys.  Bonus for them.

It would have been simple for the designers to allow more than one passkey per account.  This would have solved some of those problems.  They could have used just one secret key for all your accounts.  This could have solved some of those problems too.  Having just one secret key is not the same sort of security issue that having the same password is.  I mean, if someone gets your secret key, they can access all your accounts, but if you have all your secret keys on your cloud and they get that, they also have access to all your accounts.

Why can't any of these systems allow users themselves to move their own passkeys between systems?  Of course they might stuff it up.  Of course a compromised system would mean your passkeys would be compromised, but that would be the case if they were stored in a cloud.  

Is it possible for a site to allow log in only with passkeys?  I don't think we are anywhere near to that.  How would we revoke a key then?

I just don't think passkeys are either ready nor has the design been thought through enough for the benefit of what we say in Australia: us mug punters.  Maybe it's almost OK for big companies.  Passkeys are great for a corporate network where the company controls everything.  Is that what we want for us ordinary people?  I think not.

 

2022-09-03

Browsing slightly more safely and privately

Companies and governments glean massive amounts of data from users on the web.  This data gets to huge data warehouses where it's matched together and used by many companies and not for your benefit.  Part of the issues are the secrecy and lack of oversight and control by the users themselves.  Often you are paying in multiple ways for them to collect your data.  Remember if it's free on the web, then you are the product, not the customer.  Just because you pay doesn't mean that changes either.

There are a number of things you can do to make web browsing safer and more private and give yourself more control.  I use Firefox because although it has issues, it is flexible and has lots of useful extensions that help make browsing safer.  Just remember that as you get more safety browsing, browsing can become more difficult.  Many sites use scripts from other places to do many things but those scripts often track you and snoop on you.

You can use other browsers but they all have issues.  Chrome is OK but it desperately wants you to sign in to Google and then once you do that, everything you do, every site you go to, every search you make, belongs to Google.  I can't really tell you about Edge as I usually don't use Windows.  I expect Edge browsing is part of the extensive Windows telemetry gathered by Microsoft.

Defaults:

Don't leave browsers on their default settings.  Although they make it hard, you can change important things like the default search engine.  Most browsers are paid in some way by search engines for the privilege to be the default search engine on that browser.  Or like Edge and Chrome they have a default from the company that supplies them.  I should mention here that you should try and avoid Google or Bing for your searches.  For a long time I used duckduckgo.com but I learned a while ago that they use a lot of data from bing although I think they have their own indexing, and some links redirect through bing.   It is still my fallback search engine and rarely I still use Google too.  Learn how to change your default search engine.  I prefer to have a separate navigation bar and search bar and not to allow searching from my navigation bar.  I actually sometimes type out full URLs.  That's all harder on a phone though.  Don't use google search if you're logged into google.  All that data goes straight into your Google history.   Remember you don't always have to use the same search engine.  Sometimes specialised search engines are much more useful, for example wikipedia, youtube, google maps, etc.

My favourite search engine at the moment is Searx Randomizer.  This sends your search to a random searx instance. Searx is an open source meta-search engine.  Official Searx website Searx Wikipedia Entry  Your search is relayed to many other search engines but without information about you, the searcher being relayed.  It often gives me unusual and interesting search results and useful, did I mention useful?  Google tends to show you results it thinks you want or it thinks you should have.  Also note that searx instances are quite fluid, coming and going occasionally.  In part, because the big search engines don't appear to like non-humans doing searches.  Google, who has robots trawling every web page on the planet, apparently doesn't like anyone doing Google searches without it knowing who is doing it.  Bing ditto but they have taken to using special Bing links that redirect through Bing.  Because of this, sometimes I'll have to repeat a searx search because it fails the first time.  Slow down. 

Fingerprinting.  Fingerprinting is a way tracking companies have of identifying you using features of your browser.  Things like languages, fonts, page size, operating system, IP address, colours of pixels on your monitor.  Why do browsers even give out this information?  Some of the extensions that follow make fingerprinting much harder.

Firefox extensions

Firefox has a number of useful extensions for safety and privacy.  

Adblockers

Apart from getting rid of objectionable and sometimes unsafe and even malware filled ads, these help lower your bandwidth.  There is a huge war between advertisers and adblockers that has been going on for a while.  

I use uBlock Origin. uBlock Origin website I'm sure there are many other adblockers that work. 

No Mining:

No Coin Stop scripts that use your browser to mine bitcoin for someone else. Sigh. 

Fingerprint Blocker:

CanvasBlocker  This add-on allows users to prevent websites from using some Javascript APIs to fingerprint them. Users can choose to block the APIs entirely on some or all websites (which may break some websites) or fake its fingerprinting-friendly readout API.

Tracker Blockers:

I tend to use a few of these.  There is just so much tracking at the moment. 

Privacy Badger by The Electronic Frontier Foundation.

Ghostery is a tracker blocker.  It is a commercial company but I've found it's quite good and easy to use.

Duckduckgo Privacy Essentials  A whole bunch of privacy features.  Also blocks fingerprinting.

Decentralize Protects you against tracking through "free", centralized, content delivery. It prevents a lot of requests from reaching networks like Google Hosted Libraries, and serves local files to keep sites from breaking. Complements regular content blockers.

AdNauseum not only blocks ads, it obfuscates browsing data to resist tracking by the online ad industry. To throw ad networks off your trail AdNauseam “clicks” blocked and hidden ads, polluting your data profile and injecting noise into the economic system that drives online surveillance. Just a bit of fun.

TrackMeNot An artware browser add-on to protect privacy in web-search. By issuing randomized queries to common search-engines, TrackMeNot obfuscates your search profile and registers your discontent with surreptitious tracking.  Just a bit of fun too.

Cookie Autodelete When a tab closes, any cookies not being used are automatically deleted. Keep the ones you trust (forever/until restart) while deleting the rest. Containers Supported. 

Facebook Container Prevent Facebook from tracking you around the web. The Facebook Container extension for Firefox helps you take control and isolate your web activity from Facebook.  Facebook is a surveillance company, it's not what you thought.

F.B Purity While you are logged onto Facebook, this lets you hide all the Facebook Ads, Suggested Posts / Related Posts / Sponsored Posts / Sponsored Posts / Upcoming Events / Games your Friends are playing / Games You May Like / Similar To / Related Articles / More Like / More From etc, etc.

Cross-site script blocking:

uMatrix Prevents cross-site scripting.  Warning: This extension can make it harder to use webpages.  You need to understand how to use it and you often have to enable scripts to get the page to work.  If you're prepared to deal with the hassle, it's very good.   Unfortunately even IT professionals find this one difficult to use, other alternative suffer from the same issues.

Smart Referer Every time you click on a link, your browser helpfully tells the website the link takes you to, what web page you came from.  This extension stops that. In tech speak: Automatically hide HTTP Referer and JavaScript document.referrer for cross-domain requests!

Redirector Some pages have links that redirect through their own site so they see what you click on.  Google and Bing both do this.  This extension might help with that, but it requires a bit of work.  May not be worth it.

Making pages more readable:

Remove/Crop to Selection Sometimes you may want to print or save only a part of a web page. With this add-on you can select a part of a web page (text, images, etc), right click on the selection.  Remove parts of a webpage (it's not permanent, just reload the page).  Remove annoying animations etc.

Kill Sticky Remove fixed headers or buttons that obscure or limit content on a web page.  Again, non-permanent but can be very useful.  Based on Alisdair McDermid's Kill Sticky.  This is a javascript bookmarklet not an extension as such.

Lots of tabs users:

Tab Session Manager Save all your tabs and restore them.

Tree Style Tab This extension provides the ability to work with tabs as "trees".  What can I say, I usually have a lot of tabs open.

Update (2025-04-12):

Since I wrote this post there are a couple of updates.  Apple has disallowed extensions on browsers other than Safari and Google has stopped adblocking extensions on Chrome.

iphones and ipads:

Unfortunately on IOS, Apple has forbidden browsers other than its own browser Safari to have extensions.  On iphones and ipads you can install Adguard extension for Safari.

Chrome:

Google has stopped extensions being able to block ads, use Brave instead.  Brave is based on Chrome and has an adblocker built in.  It works on IOS, MacOS, Windows and Linux. 








2016-07-12

randword: Generating memorable random passwords

This started when I decided to learn python by rewriting one of my old perl scripts in python.  randstring is a script to generate a random string of characters.  I use it sometimes to generate passwords, but password strings or random characters usually can't be remembered, at least not easily.  Passwords like that can be useful at times.  You need to store them in an encrypted password safe.

I have another script that generates more memorable passwords.  Some people I know, have found it useful.  There are always some passwords you need to be memorable.  For instance your login password and the password to your password safe.  randword generates a bunch of words from a dictionary.  XKCD style passwords, if you like.  In the process of examining it, I rewrote it in both perl and python, fixed some bugs and added some features.

In general a bunch of words can be much easier to remember and can be just as difficult or far more difficult  to crack.  I like to generate a bunch and choose a few at random.  4 or 5 or more words is OK.  Hint: misspellings are good but not if you can't remember what you did.  Passwords on websites are a bit mad at the moment with complicated rules, like: "there's an illegal character" or "you must have an upper-case letter and a number", or "that password is too short", or "too long" etc. 

New features of randword:
  • There's a couple of new options about output format, like camel case.   
  • randword can use any dictionary or word frequency lists as long as they have a fairly simple format - ie at least a word and an optional number at the start of each line. 
  • randword can also take a bunch of text and create dictionaries of words that it can use to generate random passwords.  
For word lists, I have used various texts, for instance Jane Austen's complete works, Shakespeare, Mark Twain, Chaucer.  There are many works that can be easily got from Project Gutenburg among other places on the net.  Also word lists and text that can be found at COCA or Lancaster University  etc.Since I only want ascii because I can't type non-ascii characters easily, I used unidecode (python or original perl version) to turn them into ascii.  Python unidecode comes with a command line script.  I wrote a very simple perl script to detect non-ascii characters, (not included) although working out what encoding a page is in is a kind of major headache and you need to know the encoding before unidecode will work, grrrr. 

The links below include word lists from Chaucer, Shakespeare, Mark Twain, and the linux word dictionary.

This is my original blog post on the scripts with all the links to the scripts and associated stuff.

Links:
randstring.pl randstring.py
randword.pl randword.py
some word lists
tarred and zipped archive of scripts and wordlists


2015-07-04

Detecting Rogue DHCP servers 2

So my script detecting rogue DHCP servers worked and worked well but having two or three DHCP servers covering the same scope is somewhat problematical.  So we eventually gave in and changed configuration to having a main DHCP server and failover servers.  I had to change the logic slightly to get the script to cover that.  The new version has a mode where it will only alert if it detects a rogue DHCP server it has not been told about, or gets no response from any of the servers in its valid server list.  One or more valid servers and all is right with the world.

As before, this script works in nagios.  I run nagios on ubuntu.  The scripts in the nagios package reside in /usr/lib/nagios/plugins.   Maybe there's a good place to put your own scripts but I put mine in there too (/usr/lib/nagios/plugins/check_rogue_dhcp.pl).

This script uses the nagios builtin DHCP checker: /usr/lib/nagios/plugins/check_dhcp.

Then you need a plugin command config file.  I edited the dhcp.cfg command file (/etc/nagios/plugins/) and added these lines:

# 'check_rogue_dhcp' command definition
define command{
   command_name check_rogue_dhcp
   command_line /usr/lib/nagios/plugins/check_rogue_dhcp.pl -f '$ARG1$' '$ARG2$' '$ARG3$'
}

Then to actually invoke the check you need to define a nagios object where you give the command the IP addresses of the servers (12.34.12.34 etc).  That may need a hostgroup or some other object depending on how you have nagios set up

#check that no rogue dhcp services are running
define service {
   service_description rogue-dhcp
   check_command check_rogue_dhcp!12.34.12.34!12.34.12.45
   use generic-service
   notification_interval 0 ; set > 0 if you want to be renotified
}

There's various ways to do this and I'm not great at strategic configuration of nagios, so I'll leave that to you.

The script can be downloaded from here.

The script:
------------check_rogue_dhcp.pl-------------------


#!/usr/bin/perl -w
# nagios: -epn
# the above line makes nagios run the script as a separately.
# rather than as part of nagios.
use POSIX;
use lib "/usr/lib/nagios/plugins";
use utils qw(%ERRORS);

sub fail_usage {
  if (scalar @_) {
    print "$0: error: \n";
    map { print "   $_\n"; } @_;
  }
  print "$0: Usage: \n";
  print "$0 [<options>] <server> [<server> [<server>]] \n";
  print "$0 [<options>] [-s <server> [-s <server> [-s <server>]]] \n";
  print "    options:  \n";
  print "      [-v [-v [-v]]] (verbose) \n";
  print "      [-t  <secs>] (wait this number of seconds)   \n";
  print "      [-f] (fuzzy - ok if one or more of the designated servers answer)   \n";
  print "      [-F] (force (default) - all the designated servers must answer)   \n";
  print " \n";
  exit 3 ;
}

my $verbose = 0;
my %servers=();
my $opt = "-t 5";
my $time = 5;
my $force=1;

## for some reason I can't test for empty ARGs in the while loop
@ARGV = grep {!/^\s*$/} @ARGV;

# examine commandline args
while ($ARGV=$ARGV[0]) {
  my $myarg = $ARGV;
  if ($ARGV eq '-s') {
    shift @ARGV;
    if (!($ARGV = $ARGV[0])) { fail_usage ("$myarg needs an argument"); }
    if ($ARGV =~ /^-/) { fail_usage ("$myarg must be followed by an argument"); }
    if (!defined($servers{$ARGV})) { $servers{$ARGV}=1; }
  }
  elsif ($ARGV eq '-t') {
    shift @ARGV;
    if (!($ARGV = $ARGV[0])) { fail_usage ("$myarg needs an argument"); }
    if ($ARGV =~ /^-/) { fail_usage ("$myarg must be followed by an argument"); }
    if ($ARGV !~ /^(\d+)$/) { fail_usage ("$myarg must be followed by an number"); }
    $time = $1;
    $opt = "-t $time";
  }
  elsif ($ARGV eq '-f' ) { $force=0; }
  elsif ($ARGV eq '-F' ) { $force=1; }
  elsif ($ARGV eq '-h' or $ARGV eq '--help' ) { fail_usage ; }
  elsif ($ARGV =~ /^-/ ) { fail_usage " invalid option ($ARGV)"; }
  elsif ($ARGV =~ /^\d+\.\d+\.\d+\.\d+$/)
    # servers should be ip addresses.  I'm not doing detailed checks for this.
    { if (!defined($servers{$ARGV})) { $servers{$ARGV}=1; } }
  else { last; }
  shift @ARGV;
}

if (scalar @ARGV) { fail_usage "didn't understand arguments: (".join (" ",@ARGV).")"; }  
my $serversn = scalar keys %servers;

if ($verbose > 2) {
  print "verbosity=($verbose)\n";
  print "servers = ($serversn)\n";
  if ($serversn) { for my $i (keys %servers) { print "server ($i)\n"; } }
}

if (!$serversn) { fail_usage "no servers"; }
my $responses=0;
my $responders="";
my @check_dhcp = qx{/usr/lib/nagios/plugins/check_dhcp -v $opt};
foreach my $value (@check_dhcp) {
  if ($value =~ /Added offer from server \@ /i){
    $value =~ m/(\d+\.\d+\.\d+\.\d+)/i;
    my $host = $1;
    # we find a server in our list
    if (defined($servers{$host})) { $responses++; $responders.="$host "; }
    else {
      # we find a rogue DHCP server.  Danger Will Robinson!
      print "SERVICE STATUS:CRITICAL: Rogue DHCP service running on $host";
      exit $ERRORS{'CRITICAL'}
    }
  }
}
if ($responses == $serversn) {
  # we saw all the servers in our list.  All is good.
  print "SERVICE STATUS:OK: $responses of $serversn Expected Responses to DHCP Broadcast";
  exit $ERRORS{'OK'};
}

if ($responses == 0) {
  # we found no DHCP responses.
  print "SERVICE STATUS:CRITICAL: no DHCP service responded";
  exit $ERRORS{'CRITICAL'}
}

# we found less DHCP servers than we should have. Oh Nos!
$responders =~ s/ $//;
if ($force == 1) {
  print "SERVICE STATUS:WARNING: $responses of $serversn Responses to DHCP Broadcast. Only ($responders) responded. ";
  exit $ERRORS{'WARNING'};
}
else {
  print "SERVICE STATUS:OK: $responses of $serversn Responses to DHCP Broadcast. Only ($responders) responded. ";
  exit $ERRORS{'OK'};
}

2014-05-07

ngraph: another random text generator.

In my series of scripts to generate random text for fun and for helping create secure passwords this is my latest.  This new set of scripts generate text based on frequency weighted random choice of ngraphs.  I use it sometimes to generate word-like things  to create passwords.  There may be other uses, for instance creating random text with English characteristics.

ngraph:  Generating text from frequency weighted letter combinations

An ngraph is a group of n consecutive letters occurring in a language.  (This is my definition, there may be another word for it but I couldn't find it.) A set of ngraph frequencies is a set of the number of times each ngraph is used in a group of texts.  So for instance for n=1 we have the frequencies of the letters.  For n=2 we have the set of frequencies of the digraphs, for n=3, the trigraphs etc.  Because it is easy to do on a computer, I include some punctuation (space return - ' , . ; ! ? &).  I use these files among others:
The complete works of Jane Austen and the complete works of William Shakespeare.
Any texts would do.  Gutenburg texts have a few oddities that the script is designed to work with.

There are two main scripts and a subsidiary script.  (ngraph.pl, dbfill.sh and ngraph-db.pl)

The first script is "ngraph.pl": this script has two separate functions.
Firstly it reads a series of files with presumably text in a human language and generates a set of ngraphs for an "n" you specify.
Then ngraph.pl will generate a random set of text based on the ngraphs and their frequency.

Alternatively it can just output the set of ngraph frequencies as text or sql.  The reason for this is that reading the files and creating ngraph frequency tables is a resource intensive process so I decided to create a database of ngraphs and to generate text from that database.  I found a database with n = 1 to 5 to be most useful and above 5 the amount of data gets massive and more actual words are generated. 

The second script "dbfill.sh" is a subsidiary script.  It creates the database and populates it with ngraphs using the first script.

The third script is "ngraph-db.pl"
This uses the database and generates text based on the ngraphs in the database.  Because it has access to a database with ngraphs of say n = 1 to 5 it can generate text from random sized ngraphs as well as a single ngraph.

The generated text can include words but it mostly has word-like things that are a bit memorable but not actual words.  I never use the generated text directly to create passwords but pick and choose bits and let parts of the text inspire a password.

The scripts are available under the GPL here.

Here is a sample output:
$ngraph-db.pl -W -c 1000 -2 -g 1-4

2013-07-11

Detecting Rogue DHCP servers

I don't know why there aren't more simple ways to detect rogue DHCP servers.  It can have nasty effects on a network and can be difficult to diagnose and it's easy for it to happen. Someone can plug in a machine set to share its internet connection and bam.

I wrote a perl script to detect rogue DHCP servers in nagios.  I found one on the web here but I wanted it a bit more flexible so the hosts it was testing were in the nagios config files rather than in the script itself.  It's a debian policy thing I like.

So I adjusted the script.  It requires the check_dhcp plugin which for me was part of my ubuntu nagios install.  It takes options "-v" and a list of servers.   In your nagios-plugins/configure file the command looks like:

/usr/lib/nagios/plugins/check_rogue_dhcp.pl!$ARG1$!$ARG3$!$ARG3$
  
The script can be downloaded from here. (Sorry the link is corrected now!)

Post on new version can be found here.

-----check_rogue_dhcp.pl-------------

#!/usr/bin/perl -w
# nagios: -epn
# the above makes nagios run the script separately.
use POSIX;
use lib "/usr/lib/nagios/plugins";
use utils qw(%ERRORS);

sub fail_usage {
  if (scalar @_) {
    print "$0: error: \n";
    map { print "   $_\n"; } @_;
  }
  print "$0: Usage: \n";
  print "$0 [-v [-v [-v]]] (server-ip) [(server-ip) (server-ip) ....] \n";
  print "$0 [-v [-v [-v]]] [-s] (server-ip) [[-s] (server-ip) (server-ip)....] \n";
  print " \n";
  exit 3 ;
}

my $verbose = 0;
my %servers=();

# examine commandline args
while ($ARGV=$ARGV[0]) {
  my $myarg = $ARGV;
  if ($ARGV eq '-s') {
    shift @ARGV;
    if (!($ARGV = $ARGV[0])) { fail_usage ("$myarg needs an argument"); }
    if ($ARGV =~ /^-/) { fail_usage ("$myarg must be followed by an argument"); }
    if (!defined($servers{$ARGV})) { $servers{$ARGV}=1; }
  }
  elsif ($ARGV eq '-v' ) { $verbose++; }
  elsif ($ARGV eq '-h' or $ARGV eq '--help' ) { fail_usage ; }
  elsif ($ARGV =~ /^-/ ) { fail_usage " invalid option ($ARGV)"; }
  elsif ($ARGV =~ /^\d+\.\d+\.\d+\.\d+$/)
# servers should be ip addresses.  I'm not doing detailed checks for this.
    { if (!defined($servers{$ARGV})) { $servers{$ARGV}=1; } }
  else { last; }
  shift @ARGV;
}

# for some reason I can't test for empty ARGs in the while loop
@ARGV = grep {!/^\s*$/} @ARGV;
if (scalar @ARGV) { fail_usage "didn't understand arguments: (".join (" ",@ARGV).")"; }  

my $serversn = scalar keys %servers;

if ($verbose > 2) {
  print "verbosity=($verbose)\n";
  print "servers = ($serversn)\n";
  if ($serversn) { for my $i (keys %servers) { print "server ($i)\n"; } }
}

if (!$serversn) { fail_usage "no servers"; }
my $responses=0;
my $responders="";
my @check_dhcp = qx{/usr/lib/nagios/plugins/check_dhcp -v};
foreach my $value (@check_dhcp) {
  if ($value =~ /Added offer from server \@ /i){
    $value =~ m/(\d+\.\d+\.\d+\.\d+)/i;
    my $host = $1;
    # we find a server in our list
    if (defined($servers{$host})) { $responses++; $responders.="$host "; }
    # we find a rogue DHCP server.  Danger Will Robinson!
    else {
      print "SERVICE STATUS:CRITICAL: DHCP service running on $host";
      exit $ERRORS{'CRITICAL'}
    }
  }
}
# we saw all the servers in our list.  All is good.
if ($responses == $serversn) {
  print "SERVICE STATUS:OK: $responses of $serversn Expected Responses to DHCP Broadcast";
  exit $ERRORS{'OK'};
}
# we found no DHCP responses.
if ($responses == 0) {
  print "SERVICE STATUS:CRITICAL: no DHCP service responded";
  exit $ERRORS{'CRITICAL'}
}
# we found less DHCP servers than we should have. Oh Nos!
$responders =~ s/ $//;
print "SERVICE STATUS:WARNING: $responses of $serversn Responses to DHCP Broadcast. Only ($responders) responded. ";
exit $ERRORS{'WARNING'};


 

2007-11-07

47 days to replace a car door lock

In the continuing story of the car break-in.

So yesterday, 2007-11-07, finally I was able to get all the documentation and my wife (the owner of the car) to Hauswagen and we have ordered the new lock which will take an estimated 20 days to arrive. If it arrives on time, it would make 47 days since the car was broken into. Hauswagen were good and helpful but the fact remains that the whole process with Volkswagen is effectively helping thieves.

In order to make my car secure I had to seal the lock and make it completely unusable. The fox only has one side door lock and a lock on the hatch. It is possible to open the car with the radio key but the problem is that the radio key is very unreliable. Occasionally I have dropped it and the batteries move and the circuit loses power and I have to take it apart and reseat the batteries and then the key has to be "resynchronised" with the car. Easy if you have a working door lock. Climbing in through the hatch with the alarm going off is going to be interesting.

So my question still is: "why is Volkswagen policy deliberately making it easy for thieves to steal my car?"

I should say here that it would be very simple to make a lock that can't be opened by a screw driver. Why aren't these used by car companies?

Perhaps this might explain some of it: Who owns car companies?

The story continues here ...