iStumbler News http://istumbler.net/ en-us Alf Watt alf@istumbler.net Alf Watt alf@istumbler.net 1440 iStumbler News and Releases Cisco Routers Face Possible Compromise http://news.com.com/Hackers+race+to+expose+Cisco+router+flaw/2100-1002_3-5812611.html?tag=nefd.top Security Mon, 1 Aug 2005 12:0:00 PST Cisco shot itself in the foot by trying to force a security researcher not to discuss a possible IOS (the operating system that powers Cisco routers) compromise. The result? Hackers have taken up arms to try and exploit that compromise, which would give them access to 60% of all internet traffic. <br><br> This perfectly illustrates my point to anyone advocating the use of encrypted wireless links: you can't trust the wired network either. Use secure protocols for personal information including mail, chat and file transfer if your provider does not offer them it's time to get a new one. Got Work? http://istumbler.net/resume-alf-watt.html Unemployment Mon, 1 Aug 2005 09:00:00 PST Open Source developer looking for Cocoa desktop development position in San Francisco, Portland or Seattle. More than 30,000 lines of example code are available on my web site, which attracts more than 20,000 visitors a month. Sadly, very few subscribe, so I'm looking for a full- time job to put my Mac skill to work. Hogwash... I like the sound of that.... http://wifinetnews.com/archives/005540.html Wireless Muniwireless Security Fri, 22 Jul 2005 20:00:00 PST "Hogwash. Securing the local link isn't the nightmare you're stating with modern equipment. You can't assume that residential users will use secure protocols. And secure protocols aren't enough." - GF <br><br> Continued from WiFi Net News... <br><br> I would argue that securing the local link has already been a nightmare. Surveying my network there are three generations of Wi-Fi base stations; two out of three have compromised versions of WEP. Any MAC layer encryption scheme used to secure municipal wireless networks is just as likely to be compromised in the future. So if it's not a nightmare on modern equipment it will be the day WPA/802.11i or whatever is broken. <br><br> As far as performance is concerned, processor speed is not the issue. While the bulk of traffic in, for e.g. a WPA network, is encrypted with the fast AES block cypher, key exchange must be done with a CBC stream cipher which, besides the added traffic increases the size of the encrypted data . See <a href="http://www.openxtra.co.uk/articles/wpa-vs-80211i.php"> http://www. openxtra.co.uk/articles/wpa-vs-80211i.php</a> for more info. Encryption is simply not free, and the kicker is that people already using encryption methods are doubly taxed. <br><br> On the user front, it is absolutely imperative that people understand the security issues surrounding their use of public networks. If as you suggest, we create a state of the art, fully encrypted and 'perfectly safe' municipal network which allows John Q. Public, not to mention Da Mayor, to use unsecured protocols for fetching his mail with his laptop at home, what happens when he leaves that safe network and goes to visit a cafe on a weekend getaway? If the cafe owner is running an open network to attract visitors he has no reason to use any security measures. John will check his email fro the cafe blissfully unaware that he is broadcasting his personal information and passwords because he has the perception of his internet connection is 'perfectly safe'. <br><br> Just like in real life, security on the internet is ultimately the individuals responsibility, and just like in real life there is no perfect security but you can take reasonable measure to protect yourself. Observe the same cautions you would in a public place when connecting to a public network. Close all network ports and services you're not using or have not properly secured, make sure that you use SSL/TLS or HTTPS for all sensitive information. For the love of God, Glenn NOOOOOO! http://wifinetnews.com/archives/005540.html Wireless Muniwireless Security Fri, 22 Jul 2005 12:00:00 PST Now, I usually agree with Glenn Fleishman, but when he writes about municipal network being deployed without MAC layer security (such as WEP or WPA): "This is a critical failing... [T]his giant breach in basic security is just a fact of the municipal networks that are deployed and deploying." I have to disagree. <br><br> You can never, never trust the network to keep your data secret. You can't trust wired networks, you can't trust wireless networks and you definatly cannot trust the open internet. Securing the link between you and you base station with MAC layer encryption only gives you the illusion of security. In reality, it reduces your available bandwidth and increase latency while providing no additional protection once your information leaves your network. Also note that all MAC layer encryption techniques have been broken either in principal or practice within two years of their introduction. <br><br> The good news is that you can protect your data by making use of Application layer security such as SSL or TLS for your email, web shopping and other online activities. Use chat clients such as Skype which automatically encrypt your voice and data. Whatever and however you secure your computer please, please. please don't cry for all network to be encrypted because you can't get it together to check a box in your mail configuration. Release 95 on the way. http://istumbler.net/subscribe.html Subscription Thu, 21 Jul 2005 20:00:00 PST iStumbler Release 95 is nearly done, I'll be sending out subscriptions early this weekend, and the final release will be next Tuesday. There are some great new features including a widget that will blow away the existing 'list of networks' hacks. There are also serious improvements to the Bonjour plugin including a new browse by hosts or service option, a database of more than 300 Bonjour service types and the ability to browse wide-area Bonjour domains. <br><br> If you don't already have a subscription, now's the time to signup. You'll get early access to Release 95 and a chance to check out the new features first! Trusted Computing Untrustworthy https://www.trustedcomputinggroup.org/downloads/TNC/ Trusted Computing Evil Sat, 16 Jul 2005 20:00:01 PST The "Trusted Computing Group" has released it's "Trusted Network Connect" specification (see article link). If you read between the lines you'll notice that the specification requires a software agent running on your computer to communicate the details of your system configuration to the network for vetting before you are allowed to connect. How much do you want to bet the first thing is checks for is a Windows license? iStumbler Release 94 Universal Updated http://istumbler.net/downloads/istumbler-94u.tgz Release Mac Sat, 11 Jun 2005 12:00:00 PST Updated Universal Binary for iStumbler Release 94. This build will only run on Mac OS 10.4 or greater and now Includes the fat binary for the Intel processor, the previous version was ppc only. Still looking for a screenshot on an Intel machine. -- alf@istumbler.net iStumbler Release 94 Universal http://istumbler.net/downloads/istumbler-94u.tgz Release Mac Mon, 10 Jun 2005 12:00:00 PST Universal Binary for iStumbler Release 94. This build will only run on Mac OS 10.4 or greater and should run property on a Mac with an Intel processor. I don't have the gear to test it, so a screenshot of it running on one of the developer machines would be great. -- alf@istumbler.net iStumbler Release 94 a Version Trackers Editors Pick http://www.versiontracker.com/php/gedPick.php?plt=macosx&perPage=200 News Mac Wed, 8 Jun 2005 09:00:00 PST We've gotten a few of these before, but it's always nice to earn the blue highlight. Swan song for the Power PC http://arstechnica.com/columns/mac/mac-20050607.ars/1 News Mac Tue, 7 Jun 2005 12:00:00 PST A sweet article about the why and how of the PPC to Intel transition. I really agree with the author about this being a sad turn of events... Shame on IBM for not even wanting to compete... iStumbler Release 94 http://istumbler.net/downloads/istumbler-94.tgz Release Mac Mon, 6 Jun 2005 12:00:00 PST Release 94 Focuses on stability and performance improvements with a few small user interface changes. Status displays are back, log messages are now formatted for improved readability and the AirPort plugin can now show the frequency a radio is using. Release 94 includes an important bug fix for users of Mac OS 10.4 (Tiger), earlier versions of iStumbler trigger a very large memory leak, all users are encouraged to upgrade in order to avoid excessive memory consumption. Leaks Patched, Release 94 On The Way! http://www.istumbler.net/subscribe.html News Mac Wed, 1 Jun 2005 18:00:00 PST After a week staring at the various memory debuggers I finally found the leak that was preventing iStumbler Release 94 from going out. After 16 hours running under the BigTop, iStumbler seems to be holding it's memory usage steady. If you don't already have a subscription this is your last chance to get early access to Release 94. Release 94 Delayed http://www.istumbler.net/ News Sat, 21 May 2005 13:00:00 PST I've got iStumbler 94 ready to go except a new bug for Tiger users. Unfortunately the bug is a large memory leak and has proven very difficult to track down. If you are using iStumbler with OS 10.4, you will want to restart iStumbler once a day to keep your swap file from filling up. iStumbler Release 93 is #1 Network & Security Download at apple.com http://www.apple.com/downloads/macosx/networking_security/ News Fri, 20 May 2005 12:00:00 PST Release 93 was featured by Apple in the Networking & Security section of their OS X download site. We are now the number one download in that section! Guerrilla Hi-Fi is Online http://www.guerrillahifi.info/ News Tue, 17 May 2005 10:00:00 PST Guerrilla Hi-Fi is online and waiting for you to come check it out. You can download three great dub albums in high quality mp3 format: for free! Developer Site Update: Framework Descriptions and Models http://istumbler.net/developer/ Developer Tue, 10 May 2005 11:30:00 PST Developer site now includes description of the iStumbler frameworks as well as class model diagrams produced with Xcode 2.0. Pretty snazzy stuff, though getting the arrangement *just right* can take some time... GPS Help Update: Setting up a Bluetooth GPS http://istumbler.net/help/btgps.html Help Tue, 26 Apr 2005 08:00:00 PST First pass at a tutorial for setting up a Bluetooth GPS to work with iStumbler. Please let me know if it's helpful and if anybody has gotten the GPS plugin working. iStumbler 93 Released http://istumbler.net/downloads/istumbler-93.tgz Release Sun, 20 Apr 2005 01:00:00 PST iStumbler says Hello to Bonjour! Apple's new name for the combination of multicast DNS and DNS Service Discovery which allows you to browse all the Bonjour enabled hosts on your network and connect to advertised services such as web servers or iChat sessions. The GPS Plugin is substantially updated adding the ability to put down virtual pins and record the location of Notes and AirPort Networks it also fixes a hanging bug for people with Bluetooth phones, Infrared Ports and other serial devices. New icons throughout make Release 93 the best looking version of iStumbler yet. Why would you think your cell phone would work at home? http://sfgate.com/cgi-bin/article.cgi?file=/chronicle/archive/2005/04/16/BUGJ1C9R091.DTL News Mon, 18 Apr 2005 09:30:00 PST Ivan Seidenberg, Verizon's CEO, shows his true colors in this interview with the SF Cronic's Todd Wallack. I've always suspected that phone companies hated their customers, but it's something else hear a CEO actually say it. iStumbler Release 93 available to subscribers http://istumbler.net/subscribe.html Release Mon, 18 Apr 2005 09:00:00 PST iStumbler Release 93 is available to subscribers. If you don't already have a subscription please visit our subscriber page and you'll get the latest version of iStumbler before it's public release on Wed, the 20th of April 2005. Seattle Bans Free Wi-Fi After Coffeehouse Explosion http://istumbler.net/ News Fri, 1 Apr 2005 07:00:00 PST "Seattle's City Council has passed an emergency measure to ban free Wi-Fi access within city limits, following testimony from experts and fire officials regarding their investigation of last week's explosion at the popular "Beans, Beans, The Magical Fruit" coffeehouse. The measure takes effect immediately; individuals or businesses found to be operating unregulated Wi-Fi access will be subject to misdemeanor charges, confiscation of Wi-Fi equipment, and fines of up to $5,000. Seattle will also create a Wi-Fi Testing Foundation (WTF) to assess and regulate Wi-Fi access within city limits. The WTF will consider a proposal in which users of Wi-Fi would be required by law to limit their use in coffeehouses to email and text-only Web sites (or Web browsing which images turned off)." iStumbler in MacWorld Magazine http://www.macworld.com/ News Thu, 31 Mar 2005 17:00:00 PST Brief mention, no review, no rating. Sigh. iStumbler in Mac Home Magazine http://www.machome.com/issue/index.lasso News Tue, 29 Mar 2005 15:00:00 PST They wrote us up for the April 2005 issue, and iStumbler is ON THE COVER of Mac Home this month, there's a great screen shot of Release 90 on page 28: "Alf Watt's iStumbler is a slick utility that sniffs out wireless networks in your immediate surroundings. [If] you are having intermittent connection issues with your own wireless network, you can troubleshoot the problem with your new best friend, iStumbler. It reveals the wireless channel each network is using, allowing you to choose a free [one.]" NY Times on bluejacking http://www.nytimes.com/2005/03/24/technology/circuits/24blue.html News Thu, 24 Mar 2005 12:00:00 PST NY Times has an article on Bluejacking today, worth reading. iStumbler 92 Bugs http://istumbler.net/help/bugs.html Release Tue, 22 Mar 2005 12:00:00 PST Several users are describing bugs with the GPS plugin. There are two general issues: people with bluetooth phones or pda's will have trouble when quitting the application, they will also have trouble when trying to get the GPS plugin to work with their existing hardware. In both cases the culprit is a known bug in the GPS plugin: it can only select the first serial device. A fix is in the works, please stand by. iStumbler 92 Released http://istumbler.net/downloads/istumbler-92.tgz Release Sun, 20 Mar 2005 12:00:00 PST Release 92 reintroduces the GPS plugin which works with any NMEA Serial or Bluetooth GPS device. This release also includes new preferences for setting the font size and toolbar style as well as improvements to the plugin system and better support for help. The new Subscribe plugin makes it easy to subscribe to iStumbler and get early access to new releases and help support further development of cutting edge wireless tools. iStumbler 91 released to Subscribers http://istumbler.net/subscribe.html Release Fri, 11 Feb 2005 12:00:00 PST Release 91 gives iStumbler a thorough face-lift. The AirPort, Bluetooth and mDNS plugins now display icons for various items. Menus for the AirPort and Bluetooth plugins have been greatly improved and resize behavior was tuned up. Behind the scenes improvements in stability, memory and processor usage make this the most reliable release of iStumbler yet. iStumbler Release 90 downloaded over 15,000 times http://blackbox.istumbler.net/cgi-bin/awstats.pl?config=istumbler.net Stats Wed, 26 Jan 2005 12:00:00 PST They come, they download, they leave... istumbler-90.tgz 15,052 downloads... iStumbler Release 90 a Version Tracker Editor's Pick http://www.versiontracker.com/macosx/ep Press Tue, 25 Jan 2005 12:00:00 PST iStumbler Release 90 was named a Version Tracker Editors's Pick! iStumbler 90 released http://istumbler.net/ Release Mon, 24 Jan 2005 12:00:00 PST Release 90 introduces the mDNS (Multicast-DNS, AKA Rendezvous) plugin which allows you to browse published services on the local network and connect to them with a single click. The Bluetooth plugin enables the 'Pair' and 'Browse' features while the preferences have been updated for all plugins. iStumbler 90 released to subscribers http://istumbler.net/ Release Sat, 22 Jan 2005 15:43:12 PST iStumbler 90 was released to subscribers today, general downloads will be available Monday Jan 24 2004. You can subscribe for as little as one dollar to get iStumbler now!