Showing posts with label Technical Stuff. Show all posts
Showing posts with label Technical Stuff. Show all posts

Tuesday, 26 May 2015

Net Neutrality: The lifeline of the Internet




In this age of information i.e. where information is considered as the most important resource, Internet (or the Web) has emerged as a ubiquitous medium for getting access to all kinds of information. Because of the presence that the Internet (will be calling it the Net onwards in this article) has made in all sectors of life, it has become the primary medium for availing services to users remotely. As with any popular medium of information/services, Net also has its fare share of challenges and debates, the most popular right now being of Net neutrality. Let’s see why Net neutrality means, and why it is a hot topic of debate.


Net Neutrality
Over few decades of evolution that the Net has seen, it has maintained a very peculiar characteristic, as is the case with other public communication and information sharing mediums like telephone, radio etc. The characteristic is its Content and Service Neutralityi.e. the Net itself does not distinguish between the type of content and the service that is being delivered over it. The concept of Net is very loose here, because it essentially means the Internet Service Providers (ISPs) as it is the ISPs that act as the access points for users of the Net.
As already mentioned, the concept of neutrality towards content is not something unique to the Net; it hold for almost all mediums of communication/information delivery. Contrast this property with electricity, which is distributed as a commodity rather than as a medium, and is service aware (Electricity bills change based on commercial vs. household connections, peak load basis, use of special devices like air conditioners etc.)

Why are talking about this?
We are talking about Net neutrality due to the ongoing debate on violation of Net neutrality. Out the various such instances, some have been very popular:
1.     The first major incident was in December 2014 when Airtel announced that it will levy extra charges for making voice calls from it’s network over internet (VoIP).
2.     In February 2015, Facebook launched Internet.org in India with Reliance Communications which provides free access to a selected set of websites through an app. The commotion is about the criteria for selecting only these websites for free access, which is apparently biased and violates Net neutrality.
3.     In April 2015, Airtel came up with the Airtel Zero scheme, where it will provide free access to Internet to certain apps, if the app developer firm has already signed the Airtel zero contract.

Telecom Regulatory Authority of India (TRAI) has been under constant criticism for not being able to take action against these incidents and has not been able to ensure Net neutrality.
There have been many such incidents that potentially violate Net neutrality. I use the term “potentially” here because the notion of Net neutrality has never been fully formalized and it is still ambiguous as to what constitutes Net neutrality. For example, Facebook claims that Internet.org is an anthropologic initiative and thus does not violate Net neutrality. However, the experts’ opinions suggest something else. So, I will leave this interpretation to the reader, until a formal framework for Net neutrality comes into effect.

Is Net neutrality so critical?
In short, yes, it is. As aforementioned that Net has become the primary medium for exchange of information and facilitation of remote services, it holds utmost power in the sense that sentiment and information filtering on the Net can drastically change scenario of competition in the market and reduce quality of content and services. This will basically eliminate any new players from the cutthroat competition even before they make their online presence.
 Extrapolation of these impacts to a few years in the future paints a very horrific picture of the market where only an elite few (with deep pockets) will hold control of what reaches the end-users and basically manipulate their behavior at will.

Legal aspects
There are absolutely no laws for enforcing Net neutrality in India. TRAI has some guidelines for the Unified Access Service License, that promotes Net neutrality but don’t enforce it.  The IT Act 2000 also does not make any provisions regarding Net neutrality.

The way ahead…
The debate over Net neutrality is going to grow even more turbulent because of the importance of Internet and criticality of Net neutrality not just for large corporations but also for individual end users. Since, we have already established that access to unbiased information is critical for innovation and indiscriminate online presence is necessary for maintaining fair competition, Indian legal system needs to ensure that a formal legal framework is put into effect around the principles of Net neutrality.

Sunday, 24 May 2015

Big Data: Big Deal

In a world run by computers, and everything happening on the Internet, there is a giant, hidden and precious resource that is being generated every moment and every one of us is contributing to it. We know this resource by the name of information or data.  Big Data is one of the new hot terms in the jargon of Internet/Computer science literature.

What is Big Data?
In the field of computer science, every piece of information/media constitutes data. However, for data to be called Big Data, it needs to satisfy the soft criteria of 3 Vs i.e. Volume, Velocity and Variety:
1.     Volume: As the name Big Data suggests, data size should be very large, generally of the order of Petabytes.
2.     Velocity: The data is generated at a very high rate, generally of the order of Gigabytes per second.
3.     Variety: Big Data generally consists of large variety data, mostly unstructured.



Who is generating Big Data?
We are. To understand how we generate big data, we need to know what actually constitutes big data. In most cases, big data is user profile, user preferences and user activity data, where a user means someone who is using a particular service on the web or outside of web. Billions of people are generating plethora of information every second through their interactions with different services that they use. With the advent of Internet of Things (IoT), a world where the vast majority of gadgets, machines and humans are connected to the internet, big data provides a promising future in terms of decisions based on big data.

Why all the fuss?
Data has lately emerged not only as a resource, but also as a precious commodity over past few years. We can only guess how precious this is as a commodity, I would not be wrong to say that it rivals all big commodities in the market like oil, gold etc. and has the potential to beat all these commodities (combined) in terms of gross global value in near future. Some people might think this is too bold of a statement, but let me give some pointers to think about:
Where do you think ALMOST ALL OF THE REVENUE of tech giants like Google and Facebook comes from, when they are not charging anything from the end user? Why do you think the government of India is so keen on investing in UID scheme, smart cities etc., when such basic problems likes illiteracy, discrimination etc. remain unsolved by a great margin? In fact, why do you think most of the services on the Internet are free for the end user?

The Big Data revolution: data never lies
Like every other precious commodity of such a wide impact, Big Data also has the potential to transform the world. If we really look closely, many of our decisions and our behavior are already being governed by data.
As the popular saying goes “Data never lies”, data is already being used by policy makers in progressive governance and big organizations to implement changes, attract people, transform behaviors and eliminate competitions. It would not be an exaggeration if I say that intelligent analysis of data is the key to a successful administration and a cutting edge business strategy in this age of information. In other words, we are going through a Big Data revolution, where data is one of the primary drivers of change, both positive (as we have already seen) as well as negative (as we will see in the next section).

Well there is a darker side too…
As some of the curious readers would have already guessed that, like any other commodity having an ability of such a huge impact on people’s lives, Big Data also comes with a cost and a set of challenges that can not be ignored.
1.    Greed vs Privacy: Since big data is a huge source of revenue, it is very tempting to cross boundaries of user privacy when it comes to using their personal data for filling pockets. As precious it is a commodity, it can not only be used by large corporations who already have a huge source of big data, but also can be sold for insane prices to malicious clients.

2.    Data Colonialism: As it happens with a commodity of such an impact, people with power over it don’t want to let it go.
Large corporations like Google and Facebook already have a soft monopoly over Big Data, but it remains to be seen whether they will use it (or are already using it) to not only generate revenues but also crush competition. However, the scenario here is not as bad as it used to be with oil, since the sources of big data as a commodity are not limited (at least as long as net neutrality is maintained, which is also a big issue of debate nowadays). The more worrisome phenomena is the colonization of the analog universe by the digital. The term Data Colonialism was given by Sorabji in 2013 to describe a scenario where the West has been mining African nations for health data without the African benefiting in any way. This was the case with raw materials extraction from colonies in 18th century- extraction of value.

3.    Transforming behavior: We have already entered the era where advertisements are powered by artificial intelligence which makes use of past user behavior to show advertisements that are more likely to impact user behavior towards a certain product, person, organization, campaign etc. That said, with the power that Big Data provides to large corporations and governments, it potentially provides a powerful tool to modify human behavior on a large scale for their benefits.

The problem of privacy violations can be solved to a large extent by imposing regulations regarding user privacy and performing audits whether those laws are adhered to. However, it is a big challenge since data often crosses national boundaries and there are technological limitations to imposing a law to such an effect.
Data colonialism is a very real possibility but not much can be done other than providing support to competing businesses to maintain an environment of open competition so that such situations do not arise. Although, use of data to transform human behavior for personal gains seems ethically wrong, but law cannot be used to counteract such a practice especially when it is done with user consent. All we can do is to make people aware of the potential risks and let them decide their courses of action.

In short…


In short, Big Data is a very precious commodity and a powerful tool to drive positive changes and lead to a world that runs on intelligent decisions rather than whims and fancies of people. However, this power comes with it’s own set of risks which we need to be aware of as the primary producers of this resource and be vigilant about how this data is being used.

Sunday, 20 April 2014

Heartbleed Bug Explained


The biggest recent fuss in the field of computer science gains notoriety day by day. Online references to the bug have multiplied over time. Anyone having basic understanding of the field of computer science and programming would know that bugs in software are very common and they come and go daily. So, what is Heartbleed and what makes it unique and so notorious?

To skip all the background and technical details skip to the section Simplified explanation of the Heartbleed bug.


What is Heartbleed?
It is a serious vulnerability (a software bug) in the popular cryptographic software library OpenSSL. This bug allows a malicious user (commonly called hacker) to steal protected information over a communication channel secured by the SSL/TLS encryption, which has OpenSSL lying at its implementation.
Specifically, this bug lies in the Heartbeat extension of OpenSSL.


What is SSL/TLS?
Transport Layer Security (TLS) and its predecessor, Secure Sockets Layer (SSL) are cryptographic protocols designed to provide security for communication over Internet.  SSL/TLS protocols essentially are a set of specifications that define the mechanism for a secure communication.


Where do we see SSL/TLS?
Secure communication over Internet uses the SSL/TLS protocols. Most of the confidential information over Internet is communicated using the HTTPS application protocol that utilizes SSL/TLS protocols. Nearly all websites, web servers, chat servers, network appliances where confidential and private information can be exposed use SSL/TLS; examples include Bank websites, payment gateways, email providers, social networking websites and numerous other websites.


What is OpenSSL?
OpenSSL is a cryptographic software library that provides an implementation of the SSL and TLS protocols too. It is considered the de facto library used for incorporating SSL/TLS security on a website. So, if a website uses SSL/TLS security, there are very high chances that it uses OpenSSL implementation.


If there are vulnerabilities associated with using SSL/TLS security, why use it at all?
The vulnerabilities are not associated with the SSL/TLS protocols; the vulnerabilities exist in specific implementations. It is like saying, if items from my house can be stolen; why not leave them out in the open?  :)


Okay, if the vulnerabilities exist in specific implementations; are there other implementations of the SSL/TLS protocols?
Yes, there are a host of other implementations of the SSL/TLS protocols. See A Comparison of TLS Implementations for a comparison of such implementations. That said, OpenSSL is a very popular cryptographic library that has proven to be highly reliable and efficient over time. A bug does not make it a bad choice (since the bug has already been fixed); it is natural for other implementations to have their own set of problems too.


What is the heartbeat extension?
OpenSSL introduced an extension called Heartbeat around December 2011, with its 1.0.1 build release.  The extension’s task was to help avoid reestablishing sessions so that the SSL sessions could be kept alive for longer durations.


How does the Heartbeat extension work?
Without going into the intricate details of the headers formats, we can have a simple understanding of the Heartbeat extension. 

When a session is established, the server and the client (or the two peers) establish session keys. However, after regular intervals, the client and the server need to verify each other’s identities because of a variety of security reasons (like  session hijacking). 

One approach is to establish another session. Since, establishing a session requires multiple steps, this is considered inefficient.

Another approach (the one that the heartbeat extension follows) is to setup two code words in the beginning, one for the client and one for the server. Now, after some time (called a Heartbeat), the server asks the client back for its code word (of course, encrypted by the session key). If the client replies with the correct answer, server knows that the client is authentic. If the client cannot reply, or gives an incorrect reply, the server asks for reestablishment of session (asks again for the password).

Similarly, the client verifies the server’s identity by requesting the client’s code word. If server is unable to reply correctly, the client asks for re-verification of its certificate.


Okay, then, what exactly is the Heartbleed bug? 
As we already saw, an exchange of secret code words is performed during a persisting session to verify the identity of two communicating peers.

However, due to the Heartbleed bug, the client not only has access to the session key but also an arbitrary chunk of memory on the server side (similarly server has access to client’s memory).

The client, while verifying session, send a request to the server to return back the client's secret code word that was established earlier. In the request, client also sends the size of the data it expects the server to return. Even if the secret code was a few bytes long, the client can always request a bigger chunk of memory (an upper limit of 64 KB in one heartbeat). The server fulfills the request giving that amount of memory data back to the client (starting from the key’s location in the memory). 

So, if a client is a malicious client, it can keep sending heartbeat requests to the server potentially accessing up to 64 KB of arbitrary memory every time. That portion of memory can contain highly confidential data, including the server’s private key (access to which gives unrestricted access to the server), other user’s data etc.


Can you skip the technical details and explain in simple terms?
Okay, let’s skip all the encryption stuff. Let us imagine a scenario where you visit a bank. The receptionist asks you for your secret key (the password) to enter the bank. You also ask the receptionist for her identification. Once, you are satisfied with her credentials, you tell her the password. She verifies the password and lets you access the inside of the bank.

However, you two also setup code words for further communication. You tell the receptionist your code word and the receptionist tells you her code word. Receptionist passes these code words to all the bank’s employees, so that anyone who knows them is an employee and anyone who doesn’t is not.

Now, you are sitting in the waiting room waiting to be assisted. Now, an employee comes to assist you. However, instead of asking your password again (having to verify it from the system), he simply asks for the bank’s code word. You ask him your code word first. He tells you your code word and establishes that he is an authentic employee of the bank.

However, the employee is infected by the deadly heartbleed bug. So, while asking your code word, you tell him how many words you are expecting.  He tells you the correct code word but also tells other visitors' code words, and the bank’s code words for other visitors too, depending on the number of words you said you were expecting.

This knowledge gives you unnecessary access to private information related to other visitors. You can even impersonate as one of them.

To throw in a little technicality, the situation with OpenSSL is not as bad as the bank’s, because code words are not stored as plain texts. They are encrypted using session keys. So, just to decipher the code word, or any part of memory that was leaked, a hacker would first have to hijack a session (basically know who to attack).


Bugs in software come and go, what makes Heartbleed so unique?
The severity and ease of exploitation of the bug makes it so notorious.


The bug is very easy to exploit, does it leave the Internet insecure to all hackers?
No, it doesn’t.  The reason is, a hacker has access to arbitrary chunk of memory but he doesn’t know what part of memory (or what information) he is getting. Essentially, all he might be getting could be garbage or could be the bank account’s password of a user. It takes a mediocre hacker to exploit the bug but someone very good to get important information out of the leaked data.


How do I know that I was attacked?
You don’t. The exploitation of the bug leaves no traces, so there is no way to know if someone has already accessed your confidential information. However, if something bad hasn’t happened yet, there are pretty good chances that you weren't attacked.


How do I ensure that Heartbleed no longer affects me?
The OpenSSL developer community promptly fixed the bug, and fixes have been pushed by most operating systems. All you have to do is update your OpenSSL with the latest set of updates. After that, ask your users to change their passwords to protect from any future information theft due to an earlier password leak.



For background information on the Heartbleed bug, visit the Wikipedia article on Heartbleed.

Most of the explanations in the post are oversimplifications intended to be understandable by most readers. Please feel free to report any mistakes and give your invaluable suggestions. 

Thursday, 6 March 2014

Extension must for smooth internet surfing

Google Chrome browser
Options->Extensions

Adblock plus
Blocks the advertisements on the websites
Speeds up browsing
Get rid of unnecessary advertisements

FastestChrome- Browse Faster
Browsing Flawless and quick
Automatically adds extra pages to the first page for eg. For search results- just need to scroll up and down to access

Google dictionary
You can easily select a word, and particular definition is popped up

Skip Ad on Youtube
Escaping ads in youtube

YouTube Downloader
Download a youtube video at desired resolution

Youtube Options
Set default setting for youtube videos(size of the window, visibility of ads and annotations etc.)

Black Menu for Google
Get easy one click access to google menu(maps, translate, web, images)

Chime
Fed up of opening facebook, gmail , twitter to check notifications. Try this. It aggregates the notifications for Gmail, Facebook, Twitter and more.
Feedly
Similar to google reader to read the content of your favorite sites.

Media hint
Access videos banned outside the country.

P.S.- not available in the chrome web store. Goto mediahint.com and get free from there.

Humility and the Cosmos: How Realizing Our Insignificance Can Lead to Goodness

       The vastness of the universe can be overwhelming and awe-inspiring. When we take a step back and consider the countless stars, planet...