LINUX JOURNAL (ISSN 1075-3583) Is Published Monthly by Belltown Media, Inc., 2121 Sage Road, Ste
Total Page:16
File Type:pdf, Size:1020Kb
™ HOW TO HARDEN YOUR SSH CONNECTIONS Since 1994: The Original Magazine of the Linux Community JANUARY 2014 | ISSUE 237 | www.linuxjournal.com SECURITY ENCRYPTED BACKUP SOLUTIONS With TrueCrypt and SpiderOak An Introduction to TAKING ADVANTAGE OF QUANTUM ENCRYPTION CRYPTOGRAPHY TIPS FOR USING TOR THE PAX Browse the Web ARCHIVING Anonymously UTILITY + SOLID-STATE DRIVES Are They Worth It? LJ237-Jan2014.indd 1 12/17/13 3:42 PM UPCOMING CONFERENCES For a complete list of USENIX and USENIX co-sponsored events, see www.usenix.org/conferences FAST ’14: 12th USENIX Conference on File and 23rd USENIX Security Symposium Storage Technologies August 20–22, 2014, San Diego, CA, USA February 17–20, 2014, Santa Clara, CA, USA www.usenix.org/conference/usenixsecurity14 www.usenix.org/conference/fast14 Submissions due: Thursday, February 27, 2014 2014 USENIX Research in Linux File and Storage Workshops Co-located with USENIX Security ’14 Technologies Summit EVT/WOTE ’14: 2014 Electronic Voting Technology In conjunction with FAST ’14 Workshop/Workshop on Trustworthy Elections February 20, 2014, Mountain View, CA, USA USENIX Journal of Election Technology Submissions due: January 17, 2014 and Systems (JETS) Published in conjunction with EVT/WOTE NSDI ’14: 11th USENIX Symposium on www.usenix.org/jets Networked Systems Design and Implementation Submissions for Volume 2, Issue 2, due: December 5, 2013 April 2–4, 2014, Seattle, WA, USA Submissions for Volume 2, Issue 3, due: April 8, 2014 www.usenix.org/conference/nsdi14 HotSec ’14: 2014 USENIX Summit on Hot Topics 2014 USENIX Federated Conferences Week in Security June 17–20, 2014, Philadelphia, PA, USA FOCI ’14: 4th USENIX Workshop on Free and Open Communications on the Internet USENIX ATC ’14: 2014 USENIX Annual Technical Conference HealthTech ’14: 2014 USENIX Workshop on Health www.usenix.org/conference/atc14 Information Technologies Paper titles and abstracts due January 28, 2014 Safety, Security, Privacy, and Interoperability of Health Information Technologies HotCloud ’14: 6th USENIX Workshop on Hot Topics in Cloud Computing CSET ’14: 7th Workshop on Cyber Security Experimentation and Test WiAC ’14: 2014 USENIX Women in Advanced Computing Summit WOOT ’14: 8th USENIX Workshop on Offensive Technologies HotStorage ’14: 6th USENIX Workshop on Hot Topics in Storage and File Systems OSDI ’14: 11th USENIX Symposium on Operating UCMS ’14: 2014 USENIX Configuration Systems Design and Implementation Management Summit October 6–8, 2014, Broomfield, CO, USA www.usenix.org/conference/osdi14 ICAC ’14: 11th International Conference on Abstract registration due April 24, 2014 Autonomic Computing Co-located with OSDI ’14: USRE ’14: 2014 USENIX Summit on Release Engineering Diversity ’14: 2014 Workshop on Diversity in Systems Research Do you know about the USENIX LISA ’14: 28th Large Installation System Open Access Policy? Administration Conference USENIX is the first computing association to offer free November 9–14, 2014, Seattle, WA, USA and open access to all of our conferences proceedings https://www.usenix.org/conference/lisa14 and videos. We stand by our mission to foster excel- Submissions due: April 14, 2014 lence and innovation while supporting research with a practical bias. Your membership fees play a major role in making this endeavor successful. Please help us support open access. Renew your USENIX membership and ask your colleagues to join or renew today! www.usenix.org/membership twitter.com/usenix www.usenix.org/youtube www.usenix.org/gplus Stay Connected... www.usenix.org/facebook www.usenix.org/linkedin www.usenix.org/blog LJ237-Jan2014.indd 2 12/17/13 3:42 PM coe_lj_10-29-13.indd 1 10/30/13 9:37 AM $UH\RXFRQVLGHULQJVRIWZDUHGHÀQHGVWRUDJH" zStax StorCore =)68QLÀHG6WRUDJH IURP6LOLFRQ ZFS Unified Storage 0HFKDQLFVLVWUXO\VRIWZDUHGHÀQHGVWRUDJH )URPPRGHVWGDWDVWRUDJHQHHGVWRDPXOWLWLHUHGSURGXFWLRQVWRUDJHHQYLURQPHQWWKHzStax StorCore =)6XQLÀHGVWRUDJHDSSOLDQFHVKDYHWKHULJKWPL[RISHUIRUPDQFHFDSDFLW\DQGUHOLDELOLW\WRÀW\RXUQHHGV zStax StorCore 64 January Case Study Feature zStax StorCore 104 8QLÀHG6WRUDJHLV&UXFLDO3DUWRI 6HDUFKDQG'LVFRYHU\IRUWKH&ORXG 7DONZLWKDQH[SHUWWRGD\ www.siliconmechanics.com/casestudies www.siliconmechanics.com/zstax LJ237-Jan2014.indd 3 12/17/13 3:42 PM JANUARY 2014 CONTENTS ISSUE 237 SECURITY FEATURES 68 Quantum 80 More Secure 94 Encrypted Backup Cryptography SSH Connections Solution “Home Classical cryptography Secure shell Paranoia Edition” may not be good connections can A solution for enough in providing be hardened for safeguarding your security in the extra security. personal information. near future. Federico Kereki Tim Cordova Subhendu Bera Cover Cover Image © Can Photo Stock Inc. / maxkabakov ON THE COVER /V^[V/HYKLU@V\Y::/*VUULJ[PVUZW ,UJY`W[LK)HJR\W:VS\[PVUZ^P[O;Y\L*Y`W[HUK:WPKLY6HRW (U0U[YVK\J[PVU[V8\HU\[T*Y`W[VNYHWO`W ;VY!)YV^ZL[OL>LI(UVU`TV\ZS`W ;HRPUN(K]HU[HNLVM,UJY`W[PVUW ;PWZMVY<ZPUN[OLWH_(YJOP]PUN<[PSP[`W :VSPK:[H[L+YP]LZ·(YL;OL`>VY[O0[&W 4 / JANUARY 2014 / WWW.LINUXJOURNAL.COM LJ237-Jan2014.indd 4 12/17/13 3:42 PM INDEPTH 108 Solid-State Drives—Get One Already! If you’ve been on the fence, this article should convince you to give SSDs a try. Brian Trapp COLUMNS 36 Reuven M. Lerner’s At the Forge 26 MANDELBULBER Talking to Twitter 44 Dave Taylor’s Work the Shell Easy Watermarking with ImageMagick 50 Kyle Rankin’s Hack and / A Bundle of Tor 56 Shawn Powers’ The Open-Source Classroom Encrypting Your Cat Photos 120 Doc Searls’ EOF Returning to Ground from the Web’s Clouds 50 TOR KNOWLEDGE HUB 106 Webcasts and White Papers IN EVERY ISSUE 8 Current_Issue.tar.gz 10 Letters 16 UPFRONT 34 Editors’ Choice 64 New Products 125 Advertisers Index 94 TRUECRYPT LINUX JOURNAL (ISSN 1075-3583) is published monthly by Belltown Media, Inc., 2121 Sage Road, Ste. 395, Houston, TX 77056 USA. Subscription rate is $29.50/year. Subscriptions start with the next issue. WWW.LINUXJOURNAL.COM / JANUARY 2014 / 5 LJ237-Jan2014.indd 5 12/18/13 10:15 AM Executive Editor Jill Franklin [email protected] Senior Editor Doc Searls [email protected] Associate Editor Shawn Powers [email protected] Art Director Garrick Antikajian [email protected] Products Editor James Gray [email protected] Editor Emeritus Don Marti [email protected] Technical Editor Michael Baxter [email protected] Senior Columnist Reuven Lerner [email protected] Security Editor Mick Bauer [email protected] Hack Editor Kyle Rankin lj@greenfly.net Virtual Editor Bill Childers [email protected] Contributing Editors )BRAHIM (ADDAD s 2OBERT ,OVE s :ACK "ROWN s $AVE 0HILLIPS s -ARCO &IORETTI s ,UDOVIC -ARCOTTE 0AUL "ARRY s 0AUL -C+ENNEY s $AVE 4AYLOR s $IRK %LMENDORF s *USTIN 2YAN s !DAM -ONSEN Publisher Carlie Fairchild [email protected] Director of Sales John Grogan [email protected] Associate Publisher Mark Irgang [email protected] Webmistress Katherine Druckman [email protected] Accountant Candy Beauchamp [email protected] Linux Journal is published by, and is a registered trade name of, Belltown Media, Inc. PO Box 980985, Houston, TX 77098 USA Editorial Advisory Panel "RAD !BRAM "AILLIO s .ICK "ARONIAN s (ARI "OUKIS s 3TEVE #ASE +ALYANA +RISHNA #HADALAVADA s "RIAN #ONNER s #ALEB 3 #ULLEN s +EIR $AVIS -ICHAEL %AGER s .ICK &ALTYS s $ENNIS &RANKLIN &REY s !LICIA 'IBB 6ICTOR 'REGORIO s 0HILIP *ACOB s *AY +RUIZENGA s $AVID ! ,ANE 3TEVE -ARQUEZ s $AVE -C!LLISTER s #ARSON -C$ONALD s #RAIG /DA *EFFREY $ 0ARENT s #HARNELL 0UGSLEY s 4HOMAS 1UINLAN s -IKE 2OBERTS +RISTIN 3HOEMAKER s #HRIS $ 3TARK s 0ATRICK 3WARTZ s *AMES 7ALKER Advertising E-MAIL: [email protected] URL: www.linuxjournal.com/advertising PHONE: +1 713-344-1956 ext. 2 Subscriptions E-MAIL: [email protected] URL: www.linuxjournal.com/subscribe MAIL: PO Box 980985, Houston, TX 77098 USA LINUX is a registered trademark of Linus Torvalds. LJ237-Jan2014.indd 6 12/17/13 3:43 PM ® has the tools to keep you a!oat. Key Features: t Dual Intel® Xeon® Processors 5600 Series TrueNAS® Uni"ed Storage features the Intel® Xeon® Processor t Support for CIFS, NFS, iSCSI, and more 5600 series and supports high availability, remote replication, t Active Directory, LDAP, and NIS integration deduplication, encryption, compression, and snapshots. It has t Multi-Petabyte Scalability the tools to deal with any storage challenge you may face. Intel, the Intel logo, and Xeon Inside are trademarks or registered trademarks of Intel Corporation in the U.S. and other countries. Call iXsystems toll free or visit our website today! 1-855-GREP-4-IX | www.iXsystems.com LJ237-Jan2014.indd 7 12/17/13 3:43 PM Current_Issue.tar.gz Lapsang SHAWN POWERS Souchong! ack when we were kids, my BirdCam project (which you’ll hear “security” meant little more than more about in a month or so), I found Bhaving a secret password to keep his column particularly interesting. If you little siblings out of the treehouse. That’s need to work with photos, especially if still the case in some situations. Take the direct interaction isn’t possible, Dave’s title of this column, for instance. If you column will be interesting for you too. go to the #linuxjournal IRC channel on Kyle Rankin gets into the security FreeNode, saying “Lapsang Souchong” mindset this month by approaching will mark you as part of the inner circle. privacy. Specifically, he explains how (Note, this does not make you one of the to set up Tor in order to browse the cool kids...possibly the exact opposite!) Web in private. Tor is just as useful as When it comes to computer security, it once was, but thankfully, it’s gotten however, things are quite a bit more easier and easier to implement. I follow complex. Whether you want to encrypt Kyle’s column with The Open Source your data or lock down network Classroom, and this month, I talk access, Linux provides a wide variety of about file encryption.