Reiser4 file semantics: An opportunity for open source
Grok Headline matches for Reiser4 file semantics: An opportunity for open source
The Semantics of Free Software vs. Open
Source
The Semantics of Free Software vs. Open
Source
12/28/2004 04:54 PMOpen source opportunity, open source
risk
Open source opportunity, open source
risk
09/22/2004 10:44 AM
I've been traveling more than usual lately, and while on the road I've
been working my way through the
ITConversations audio
archive. It's full of gems, and one of them is Doug Kaye's
interview
with Philip Greenspun. While discussing the
ArsDigita flameout,
Greenspun offers insightful perspectives on the opportunity, and the
risk, of open source as a business model.
...Open source apps are seen as new
business opportunity
Open source apps are seen as new
business opportunity
04/05/2005 05:19 PMSAN FRANCISCO - The next wave in open source development is
applications, which presents opportunities for open source vendors to
focus on the small- and medium-sized businesses that established
commercial vendors cannot reach, said Larry Augustin, CEO of Medsphere
Systems and a founder of VA Linux Systems, on Tuesday.
Open source apps are seen as new
business opportunity (InfoWorld)
Open source apps are seen as new
business opportunity (InfoWorld)
04/05/2005 05:18 PMInfoWorld - SAN FRANCISCO - The next wave in open source development
is applications, which presents opportunities for open source vendors
to focus on the small- and medium-sized businesses that established
commercial vendors cannot reach, said Larry Augustin, CEO of Medsphere
Systems and a founder of VA Linux Systems, on Tuesday.
Web Security Errors and an Open Source
Revenue Opportunity
Web Security Errors and an Open Source
Revenue Opportunity
01/14/2003 06:32 PMWeb Security Errors
I normally wouldn't blog this much but so many of us here do web
development that its good for all of us to review these. Yes I know
we all know better but I'd virtually guarantee that we all have done
at least one of these in the last 24 months:
Unvalidated parameters: Information from Web requests isn't validated
before being used by a Web application. Attackers can use these flaws
to attack backside components through a Web application.
Broken access control: Restrictions on what authenticated users are
allowed to do aren't properly enforced. Attackers can exploit these
flaws to access other users' accounts, view sensitive files, or use
unauthorized functions.
Broken account and session management: Account credentials and session
tokens aren't properly protected. Attackers who can compromise
passwords, keys, session cookies, or other tokens can defeat
authentication restrictions and assume other users' identities.
Cross-site scripting flaws: The Web application can be used as a
mechanism to transport an attack to a user's browser. A successful
attack can disclose the user's session token, attack the local
machine, or spoof content to fool the user.
Buffer overflows: Web application components in some languages that
don't properly validate input can be crashed and, in some cases, used
to take control of a process. These components can include CGI,
libraries, drivers, and Web application server components.
Command injection flaws: Web applications pass parameters when they
access external systems or the local operating system. If an attacker
can embed malicious commands in these parameters, the external system
may execute those commands on behalf of the Web application.
Error-handling problems: Error conditions that occur during normal
operation aren't handled properly. If an attacker can cause errors
that the Web application doesn't handle, he or she can gain detailed
system information, deny service, cause security mechanisms to fail,
or crash the server.
Insecure use of cryptography: Web applications frequently use
cryptographic functions to protect information and credentials. These
functions and the code to integrate them have proven difficult to code
properly, frequently resulting in weak protection.
Remote administration flaws: Many Web applications let administrators
access a site using a Web interface. If these administrative functions
aren't very carefully protected, an attacker can gain full access to
all aspects of a site.
Web and application server misconfiguration: Having a strong server
configuration standard is critical to a secure Web application. These
servers have many configuration options that affect security and
aren't secure out of the box. [_Go_]
The full report is here. Nice job guys. Thank you.
And Just One More
Oh and I'd also kick in one other security glitch that's related to
these but not specifically mentioned: Installing Open Source
applications on the quick. You know the drill -- you grab some code,
install it and then poof! The client is running it and is happy so
you kinda ignore it. And you don't realize that the default
installation leaves the password in the clear! Think I'm kidding?
For example a lot of php applications use .inc for include files as
their extension so config.inc is viewable by anyone who knows it
exists.
A Chance for Open Source Revenues
Although I have no actual metrics on this I suspect it is quite
common. Now this makes me think that a possible revenue opportunity
for Open Source authors is something like "Security Check", for $99 or
$X (per server), I'll check over your installation and make sure you
don't have any holes. Given that a lot of Open Source applications
are rolled into hosting / consulting, it would be relatively easy to
pass this type of cost onto the ultimate customer.
NOSI, the Nonprofit Open Source
Initiative, announces the release of its
new guide "Choosing and Using Open
Source Software: A Primer for
Nonprofits."
NOSI, the Nonprofit Open Source
Initiative, announces the release of its
new guide "Choosing and Using Open
Source Software: A Primer for
Nonprofits."
02/17/2004 11:57 PMAs per a recent post, I love to see (and hope to one day do it myself)
Open Source Software in Non-Profits. Seems http://www.nosi.net found
my post:
http://thelostolive.net/tlo/comments.php?id=1786_0_1_0_C
And commented the release of its new guide "Choosing and Using Open
Source Software: A Primer for Nonprofits." And now in their own words:
___snip____
--
From: Katrin Verclas
Email: steering (a) nosi.net
Hi, Kevin -
NOSI actually just released a new...
Open-source activist Bruce Perens joins
open-source defense group
Open-source activist Bruce Perens joins
open-source defense group
05/07/2004 04:33 PMA key leader in the open-source software movement has been appointed
to the board of Open Source Risk Management, which is defending the
legal standing of open-source software.
Do You Suffer from Open Source Phobia? -
six reasons you might relent and be
ready for an extreme makeover - OPEN
SOURCE - Magazine - Darwin Magazine
Do You Suffer from Open Source Phobia? -
six reasons you might relent and be
ready for an extreme makeover - OPEN
SOURCE - Magazine - Darwin Magazine
03/08/2004 11:20 PMhttp://www.darwinmag.com/read/030104/open.html
ASK A GROUP OF corporate IT leaders whether they'd rather stick their
arms into a box of tarantulas or allow open source software (OSS) on
their networks, and odds are most would start rolling up their
sleeves. Not to do any downloading, either.
Slashdot on Open Source Ideas and Open
Source Life
Slashdot on Open Source Ideas and Open
Source Life
06/23/2004 08:27 PM As Canada protects the patents on genes, Download Aborted wonders
whether the genetic code should be considered Open Source. It's
slashdotted here. And as atonement for saying something positive about
the people at Microsoft — man, you folks are rough! —
here's some slashdottism about the anti-Open Source think tanks that
Microsoft is funding. (But I still like the Microsofties I've met. So
there.)...
Open source process for open source
development
Open source process for open source
development
04/05/2005 11:50 AM
Sun has given every possible indication that Open Solaris will be run as a true
open source project. The latest indication is the make-up of the board
of directors:
Casper Dik,
Roy Fielding,
Al Hopper,
Simon Phipps, and
Rich Teer.
(via Simon Phipps - congrats Simon!)
Getting a rise out of Reiser4
Getting a rise out of Reiser4
08/28/2004 01:03 AM
Last time I looked at ReiserFS
was, I think, at
least couple of years ago.It was a nice file system but I
didn't
find any use for it. Two years later, Reiser4 is released and
I still can't
find a good use for it, but it sure has some intriguing one
liner feature list
that would any geek a bit of excitement:
-
Reiser4 is the fastest filesystem, and
here are the benchmarks.
-
Reiser4 is an atomic filesystem, which means
that your filesystem
operations either entirely occur, or they entirely don't, and
they don't corrupt due
to half occuring. We do this without significant performance
losses, because we invented
algorithms to do it without copying the data twice.
-
Reiser4 uses dancing trees, which obsolete the
balanced tree algorithms
used in databases (see farther down). This makes Reiser4 more
space efficient than
other filesystems because we squish small files together rather
than wasting space
due to block alignment like they do. It also means that Reiser4
scales better than
any other filesystem. Do you want a million files in a
directory, and want to create
them fast? No problem.
-
Reiser4 is based on plugins, which means that it will attract
many outside contributors,
and you'll be able to upgrade to their innovations without
reformatting your disk.
If you like to code, you'll really like plugins....
-
Reiser4 is architected for military grade
security. You'll find it
is easy to audit the code, and that assertions guard the
entrance to every function.
Dancing trees? I gotta look into that algorithm
sometimes. I wonder if
variations of the algorithms will be called Disco or Samba?
;-) Hmm.
One of the testimonials is LivingXML which is a native XML engine
built-on top of
Reiser. That's nice except LivingXML seems
to be, well, dead. Oh, well.

BE Conference 2005 Registration Now
Open; Go to www.be.org to Register for
Once-a-Year Learning Opportunity
BE Conference 2005 Registration Now
Open; Go to www.be.org to Register for
Once-a-Year Learning Opportunity
04/05/2005 06:16 AMZDNet India Apr 5 2005 10:24AM GMT
From open source to open services to
open information
From open source to open services to
open information
03/29/2005 12:00 PM
My
March
21 entry about upcoming.org turned out to be an odd juxtaposition
because, on the same day, a new events database called
EVDB was announced and shown at PC
Forum. It's due out shortly in public beta but I haven't seen it, so
for now I only know what you can also learn from reading, among
others:
Dan
Farber,
Ross
Mayfield,
Om Malik,
David
Weinberger, and
Paul
Kedrosky (whose recent archive is missing this morning, yikes).
The consensus seems to be that EVDB will be a Web-2.0-style,
Wiki-style, RSS-friendly, Flickr-and-del.icio.us-like thingy. Sounds
promising! I'll certainly check it out when it's public.
...Microsoft Depends On Shared Source, Dips
Toe In Open-Source Waters (TechWeb)
Microsoft Depends On Shared Source, Dips
Toe In Open-Source Waters (TechWeb)
04/08/2005 04:56 AMTechWeb - The software vendor will add to the 20 products it now
offers for source-code inspection under its Shared Source Initiative.
Microsoft releases source code to open
source community
Microsoft releases source code to open
source community
05/05/2004 04:06 AMAbout a month ago, Microsoft posted some of its source code to
SourceForge. SourceForge is a, if not the, major distribution point
for open source software. Microsoft's code was put there under the
terms of the Common Public License, which allows modification,
addition, redistribution - in short, it allows most of the rights and
privileges that we associate with open source software.
Advice to Microsoft: Open Source the
Leaked Source
Advice to Microsoft: Open Source the
Leaked Source
02/13/2004 02:37 PMWhat should Microsoft do, now that a chunk of its NT 4.0 and Windows
2000 source code have leaked onto the Web? Our guest columnist says
Microsoft should make lemonade out of lemons and just open source the
whole enchilada.
Open source process for closed source
development
Open source process for closed source
development
04/05/2005 11:50 AM IBM Adopts
Open Development Internally: "Following on the success of its
Eclipse open-source development platform, IBM has quietly been using a
form of open-source development internally to create technology the
company will sell commercially.
IBM calls its model Community Source, which it defines as a
collaborative, internal, open-source-style environment for developing
and testing new technology.
Danny Sabbah, vice president of strategy and technology for the IBM
Software Group, in Armonk, N.Y., said IBM is using its Community
Source model across 100 projects and 2,000 developers in the company.
These projects span the IBM Software Group, Systems Group, Research
and Global Services, he said."
Very interesting. I'd like to learn more about that. What parts of the
so called open source development process have they built into the
Community Source model? I've found that most developers have different
definitions of the open source development process (via
Ross
Gardler).
Pingtel Breaks Open VoIP Monopolies With
New Open Source Business Model.
Pingtel Breaks Open VoIP Monopolies With
New Open Source Business Model.
02/18/2004 10:41 PMPi
ngtel Breaks Open VoIP Monopolies With New Open Source Business
Model. Interesting.
Open Standards - Open Source. The
Business, Legal & Technical Challenges
Ahead.
Open Standards - Open Source. The
Business, Legal & Technical Challenges
Ahead.
10/28/2003 11:06 PM
The meeting comprised four panels: Business, Technical, Legal,
and Social and Ethical, each of which featured an introduction of the
issues and follow-up with an interactive discussion between the
speakers and the audience. The aim was to capture and publish the
issues discussed in order to raise the industry awareness of the
benefits of Open Source.
Open source hackers release open fixes
for MSFT vulnerabilityware
Open source hackers release open fixes
for MSFT vulnerabilityware
12/19/2003 11:45 AMMSFT's apparent incapacity for patching MSIE vulnerabilities hasn't
deterred open-source hackers, who have released a free software patch
for a well-known Explorer vulnerability.
Update: Andrew sez, "...it contains buffer overflow exploits that are wide open for hax0r5 to take
advantage of. In addition, it redirects weird URL requests to -it's
own website-."
Update: Yoz points out
that the patch has been patched.
Link
(via /.)
Open-Xchange Server 5 Blends
Proprietary, Open-Source Perks
Open-Xchange Server 5 Blends
Proprietary, Open-Source Perks
04/12/2005 08:07 PMAccessible through common Web browsers, the collaboration platform
lets users share e-mail, calendar, tasks, threaded discussions and
documents originating from both proprietary and open-source systems.
When Open Source doesn't open and source
doesn't matter
When Open Source doesn't open and source
doesn't matter
07/20/2004 11:14 AMOne frustration too many: time for a rant. When a bug in Mozilla
(keyboard focus is on the previously selected window) has remained
unfixed for at least 18 to 24 months, when XFree86 mouse interaction
with PS/2 or GPM remains hazardous and makes a system unusable and
that bug has been fobbed off to the kernel developers and not dealt
with for at least two years - when there are more examples like this
that make using Open Source software a pain, what do you do?
Are you one of the few people with the time and money and
expertise sufficient to delve into the source yourself to fix the
problem?
Do we have it "too good" and these niggles are, by comparison to
the rest of the world's computer users (Windows), absolute peanuts?
Linux Sees Open Field for Open Source
(washingtonpost.com)
Linux Sees Open Field for Open Source
(washingtonpost.com)
08/03/2004 10:28 AMwashingtonpost.com - Plenty of tech experts have spent years trying to
convince the general public that the Linux operating system is
becoming more of a threat to Microsoft's Windows. With the LinuxWorld
conference underway this week in San Francisco, there is finally a
sure-fire sign that this may be the case: Microsoft won't be there.
More Than Open Data at the 2004 O'Reilly
Open Source Convention
More Than Open Data at the 2004 O'Reilly
Open Source Convention
08/09/2004 12:52 AMWi-Fi Technology Forum Aug 9 2004 5:11AM GMT
Why open distribution is the real
promise of open source
Why open distribution is the real
promise of open source
06/16/2004 11:32 AM The White Rabbit has beckoned us down the wrong rabbit hole. Much has
been made about the open source revolution, and with good reason. The
open source development model produces superior software. But, in my
estimation, the real promise of open source lies not in open source,
but rather in open distribution. Here's why ...
Open source cracks publishing wide open
Open source cracks publishing wide open
06/17/2004 11:24 AMOnce upon a time, publishing was the domain of large corporations.
Then came desktop publishing and the tools to produce a book shrank
from the cost of an aircraft carrier to the price tag of a PT boat.
Now, small publishers on the bleeding edge of technology are fomenting
a revolution that may change the publishing market forever. Open
source publishing tools, long derided as not being ready for battle,
are proving themselves in the trenches of small publishing.
Why Microsoft Should Open Source the
Leaked Source
Why Microsoft Should Open Source the
Leaked Source
02/13/2004 02:37 PMANALYSIS: Redmond would be smart to make lemonade out of lemons by
releasing the rest of the Windows code and letting developers have at
it.
Open Arms for Open-Source News
Open Arms for Open-Source News
07/22/2004 06:17 AMA California newspaper is turning over the news to the people: If you
think it's news, it probably is to somebody, so write it up. By Daniel
Terdiman.
Open-Xchange Server goes open source
Open-Xchange Server goes open source
08/04/2004 09:46 AMLINUXWORLD -- Open-Xchange Server, the Microsoft Exchange Server
workalike, is being released under the GPL at the end of August.
Open-Xchange Server is the engine behind Novell/SUSE's Openexchange
Server, and is produced by Netline Internet Service. Netline CEO Frank
Hoberg will be in the Novell booth during most of the LinuxWorld
Conference & Expo, displaying what a company press release
describes as "the industry's top-selling Linux-based groupware,
collaboration, and messaging application."
Open source and visible source
Open source and visible source
06/08/2004 09:11 AM
Zope Corp.'s layered strategy of engagement with open source and
visible-source communities is a compelling blend of the strengths of
free and commercial software development. In two previous columns, Open
source citizenship and Giving
back to open source, I explored the tendency of enterprises to
fork open source projects rather than join them. Pedhazur suggests
that a commercial entity supporting both an open source base and a
visible-source layered product can reduce the need to fork. By
outsourcing code enhancements, the argument goes, an enterprise can
enjoy single-throat-to-choke control without seceding from a project's
community. It remains to be seen how broadly this model can apply, but
in cases where it does, what's not to like? [Full story at
InfoWorld.com]
In this
two-minute
clip, Zope Corp.'s Chairman Hadar Pedhazur describes the visible
source model as a middle-ground option between the few large open
source projects, whose direction an enterprise cannot easily
influence, and the many smaller ones that enterprises can influence,
but typically fork in order to do so.
...Open season on open source
Open season on open source
05/21/2004 01:07 AMMicrosoft open to open source
Microsoft open to open source
06/24/2004 12:49 PMMicrosoft Corp. says it is looking to turn over more of its programs
to open-source software developers, playing a greater role in a
process that the Redmond company has criticized strongly at times in
the past.
Money-makers like the company's Windows operating system and Office
productivity suite aren't on the table -- or anywhere near it.
But the company has so far released two software-development tools to
the open-source community, and it wants to continue the practice, a
Microsoft platform manager told an industry group this week.
Microsoft open to open-source
Microsoft open to open-source
06/24/2004 08:17 AMNet file-swappers snap up Windows source
code
Net file-swappers snap up Windows source
code
02/13/2004 01:27 PMBoston Globe Feb 13 2004 5:14PM GMT
File Swappers Warned to Avoid Windows
Source Code
File Swappers Warned to Avoid Windows
Source Code
02/19/2004 06:19 AMExecutives Still Open File Attachments
Executives Still Open File Attachments
07/14/2004 03:21 PMTechWeb Jul 14 2004 7:01PM GMT
Pining For Open File Formats
Pining For Open File Formats
09/08/2004 04:52 AMI still seethe over all the extra work, and silly hoops I had to jump
through, because vendors feel compelled to create proprietary formats
for storing information, and make it hard for other people's software
to simply read and write the information to achieve whatever goals
their users might be pursuing. By James Elliott, O'Reilly Network (via
MyAppleMenu)
Wired News: Open Arms for Open-Source
News
Wired News: Open Arms for Open-Source
News
07/23/2004 03:07 AMturns content control to the people .. Open Arms for Open-Source
News
wired.com/news/culture/0,1284,64285,00.html
track this
site | 4 links
Second source, not open source, is the
key
Second source, not open source, is the
key
06/16/2004 09:56 AMZDNet UK Jun 16 2004 2:16PM GMT
Grok Description matches for Reiser4 file semantics: An opportunity for open source
GrokA matches for Reiser4 file semantics: An opportunity for open source
Reiser4 file semantics: An opportunity for open source