Category Archives: Computers

Windows 11

Part of the ongoing updating of things at work has been shifting to Windows 11 as a desktop OS, and now that the rest of the organisation is done, it was time to attend to my own laptop.

For the last 8-9 years I’ve had a Lenovo T470s, and it’s been nothing less than superb: one new keyboard thanks to me spilling tea on it, a tiny bit of screen delamination, and other than that it’s played a key part in keeping the infrastructure going. It’s been dropped onto concrete, balanced in precarious places in server rooms, carried around exhibitions, bounced about the boot of my car. It’s run Windows 10 all that time, with the occasional boot into Ubuntu.

It’s been replaced by a T14, and Windows 11. As a team we pushed for Lenovo: despite the claims that build quality isn’t what it was, it’s clearly better than the other tier 1 supplier (Dell) under consideration, and a world away from the no-name we were asked to look at.

I wasn’t looking forward to the change: The start button is in the wrong place, cut and paste have been moved, show desktop is in the wrong place too. All survivable, but years of muscle-memory is hard to change: despite the proper programmers mocking me for not using CTRl-C CTRL-V, there’s situations when the GUI and mouse work. The times when I’d had to support a Win11 machine a user was using had irritated me.

One thing I just had to do was remove the AI components and just generally remove some of the tat, and I found this did the task without too much bother.

A week in, and my deep hatred of 11 is subsiding: it works well enough once you turn off the tat. One nice thing: the new “terminal” shell accepts some bash commands, so all that problem of typing ls in a cmd shell is gone 🙂

Home Baked

A question on a Facebook group triggered this: someone asked about the Brennan B3. Is it hifi? Is it worth the nearly £800 price tag?

I’ll leave the latter to your judgement, but the Brennan devices have interested me for a while.

They’re a combined CD ripper and hard-disk music player, nicely packaged and with an easy to use interface. The advertising seems to be aimed at the older generation (well, the kids all stream now…), and at replacing your CD collection and old player with one box and adding a bit of convenience.

This is something I’ve been doing for a while with a Rasperry Pi and Moode, RuneAudio, Raudio or Volumio software: all similar concepts of a modified Linux distribution for playing media.

Can you see where this is going yet?

The Brennan box is unashamedly and openly the same thing, tidied up as a consumer appliance. The latest B3 unit is the most complete: it takes a Raspberry Pi, a hard drive, a CD drive, and a DAC and class D amplifier, puts them in a nice case with a nice display, and glues it all together with some software.

That software is freely downloadable if you’re so inclined, and if you write the image to a SD card you can mount it and poke about.

It looks to be based on Ubuntu 32 bit, and uses lighttpd to serve pages, and omxplayer to play media.

So: is it hifi?

I suppose, for certain definitions of hifi. It’s not high-end, but then that isn’t the target market.

Is it worth nearly £800?

Not for me. I’ll stick with the homebrew solution. But some people love them, and at the end of the day it’s a supported consumer product and the manufacturer is upfront and honest about it. You decide.

I’ve got a certain admiration for it: it’s a clever, well-executed idea, and it’s not like using a Raspberry Pi as the basis of a product is unusual.

Thunderbird is 20

I don’t often do open-source software stuff here these days, but it’s worth noting that the best email client (and one that works nicely cross-platform on Android, Linux, and Windows) has reached 20 years old: I think I’ve been using it most of that time., and as well as being as being good to use day-to-day, its flexibility makes it a valuable tool in my line of work.

Loss of Virginity

Since before this blog existed, I’d been a customer of Virgin Media or its predeccesor, Telewest/Blueyonder. Back when i took it out, in around 2001, it was the only option for broadband here, with no ADSL service, and I can still remember the blistering speed of 512Kbit/sec (that’s 0.5M, kids) that, actually did seem blistering compared to the 30-something K a so-called 56k dial-up could deliver.

We had TV too, with the demise of OnDigital, but not the phone: that came later with a package upgrade courtesy of a colleague’s sister that worked for VM at some point.

So, all in all, about 23 years of custom. The speeds have risen, and the price crept up, but overall, it’s been a reliable service.

Late last year, though, it wasn’t, and I started looking around. The relatively high cost, recently announced 8.8% price rise, and the arrival of fibre on the BT Openretch poles in the street convinced me it was time.

I’d heard great things of Andrews and Arnold: a small, UK-based, techie-friendly ISP who aim to be up front, simple, and clear. so i enquired, and got a real answer from a real human refreshingly free of marketing. They could also port my landline, an anachronism I’m not ready to lose yet, over to SIP with very cheap line rental and reasonable charges. I explained what my knowledge level was and what I wanted, they told me what to order and advised me against giving notice until the phone line port completed, as that can fail if a service is due to be ceased.

At the point of writing, the new connection is to be installed, but the phone port has happened- and thanks to a borrowed ATA, a config guide on A&A’s website, and prior experience with SIP means that the phone is working over the VM connection at the first attempt, despite the fact that SIP and NAT can be problematic, having ported in the timeframe given with no fuss whatsoever. Having the line in SIP with a tech-friendly provider means flexibility and features at no extra cost now, too. The end of POTS in the UK means all phones will move to IP in time, but moving to a more conventional ISP would leave me with less control and being forced to use their router if I wanted the landline phone. This gives me flexibility, at the cost of having to handle some tech myself.

Now the port is complete, I’ve told VM that I’m off. They did, of course offer to improve my package, but I have the same approach here as with car insurance: if you can offer me better, you should have done that, not waited for me to call and say I’m off. I now have a few weeks to play about with the new connection, while the old one still works. I have an ISP-supplied router and at least one alternative to try. The new connection will give me about 3 times the speed.

As to TV, we found that a lot of our watching was either Freeview, streaming from free-to-use services like All4, or a bit of Amazon prime, so the cost of VM’s TV seems excessive: we will try Freeview and consider other services if needed.

Flat Out

Warning: DNS/Email nerdery below.

For my sins, one of the things I had to do recently was complete DNS domain authentication, DKIM, and DMARC for some email domains at work in Mailchimp. Mailchimp is the spamming engine mass email system of choice, and to be fair, they’re responsible and force compliance with good practice. They also try to increase the chances of your spam legitimate mass email being deliverable, which is where this comes in.

The big email providers such as Yahoo, Hotmail/Outlook, and Gmail now insist that if you send over a certain threshold, you:

* Send from a domain you own
* Configure DKIM, SPF, and DMARC
* Don’t send shitloads of actual spam
* include a one-click unsubscribe

This is all part of the spam arms race: electronic means to detect spam are less effective, so this is an attempt to stop the problem at source by making sure the email is coming from where it claims to: spoofing email is trivial, so this effectively adds a signature.

Well, we already had the domain, and SPF, we don’t actually spam people, and Mailchimp handles the unsubscribe, so that left DKIM and DMARC. This actually isn’t that hard, just involving publishing a few records in DNS that match up with the email servers. The DMARC is little more than a published policy of what people should do if the mail seems to be unathenticated- and “take no action” is acceptable. The actual authentication is done by DKIM, where you publish a public key in DNS, and the email is signed by your outgoing server with a corresponding private key. If the encryption key matches, the mail is deemed as being legitimate.

So, I went ahead and did all this for our own infrastructure, as it seems silly to set it all up only for the mass mailing. Pretty simple, too, in the end.

Now, obviously, if someone (Mailchimp) is sending mail for you, you need to publish their key for DKIM. The logical way to do this is for them to publish it, and then for you to alias an entry in your DNS (with what is called a CNAME record). That way, if they change the key, it keeps working without changes to your DNS.
Continue reading Flat Out

rAudio

Following on from my forced evaluation of my Raspberry Pi audio player, as I’d got it in bits I went and looked at Runeaudio’s web site to see if there was a newer system image. There wasn’t, in fact there hasn’t been one since before this country lost its collective mind in 2016.

What I did find is that someone has forked and updated it, just like I mentioned here about all the other variants.

These players are all variations on a theme: a web interface, MPD, and a variety of other open-source things to provide connectivity and features like Apple Airplay or UPNP: the beauty is that if you have the skills and time, the components are all there for you to build it. If not, well, someone’s probably done a good enough match, which brings me to rAudio.

A proper open-source project this: no flashy website, just a Github and a concise set of instructions, but technically it’s great, with recent builds based on Arch Linux.

Booting it up, it just works: it reads the external disks just fine, recognises my Cambridge Audio DAC, it plays. There’s a few whistles and bells- you can do proper multi-room on a budget, and there’s Bluetooth and DAB if you have the hardware.

Best news is I’ve got rclone on to the machine, and a quick entry in crontab should see the music files automagically backed up to Google drive with no manual intervention.

In the Clouds

I briefly mentioned that the mirrored disks for my Runeaudio music player broke. I then compounded the issue by not RTFMing about the RAID enclosure- which also seems to have had a fault- with the result that I lost my FLAC collection.

I tried the excellent testdisk (which didn’t find any partitions) and photorec (which recovered files but no folder structure and with possible corruption), and decided I needed to bite the bullet, copy what I had on my phone back from there, and re-rip the rest. I’ve found as I have 2 CD drives, I can rip 2 together, and still use my laptop.

2 terminal windows showing 2 abcde rips running together
Ripping 2 CDs at once: that’s as many drives as I have.

This post is looking like an exercise is open-source software promotion: the files were originally ripped to open source FLAC (and MP3 for the car) with open source abcde, recovery was attempted with open-source tools, the player itself is open-source, and there’s one more thing to add: I don’t want to have to do this *again*, so I need a backup solution, and preferably something that requires minimum intervention.

I already use Google Drive for other backup, and pay for a decent amount of space, so that seems ideal. The idea now is to use rclone on the Runeaudio device so that whenever I transfer new music to it, it ends up on someone else’s computer in the cloud as well, automagically. Initial tests on my laptop are encouraging:

rclone copying my music
A test run of rclone, copying 5GB of music up to Google drive

So now it’s a case of installing rclone onto Runeaudio and seeing if it works.

New Diagnosis

Back in 2005 I bought a VCDS cable for my then car, and because I bought the right, CAN-compatible cable, that’s done me well for 17 years, and pretty much copes with any VAG car up to 2018.

Then I bought a 2018 car, and started seeing this issue:


----------------------------------------------------------
Address 4B: Multifunc. Module
Interface not compatible.
Please upgrade to a current Ross-Tech interface.

----------------------------------------------------------

So a new interface is required.

The interfaces aren’t cheap, as they also act as a key for the software, and eligibility for lifetime upgrades and support. The original HEX+CAN USB was, i think, around £200 or so, and its replacement, the HEX V2, comes in at £225-£450, depending on how many cars you need to do the more advanced stuff on.

Interfaces can be traded in for upgrade, but after asking the nice people at Gendan about it, the only way to trade in against a 3 VIN or 10 VIN licence is to send my old cable back to the USA, with the associated hassle and carriage/customs charges that incurs, all for £100 trade-in.

Added to this is that the original cable works completely on cars up to 2018, and has no VIN limitation, and actually, the sane option is either to just keep it for older cars, or sell it. I think it’s most likely I’ll retain it for the older car in the household and for doing people favours, leaving me with 2 spare VIN slots for future use with the new cable.

[edit 2022-12-31]
Continue reading New Diagnosis

Simplification

After more than 15 years (I haven’t recorded exactly when I started with Red Hat) of running an active mail server here, I’ve decided now that I don’t need to.

When I started all that, broadband was slower, and Internet hosts had poorer anti-spam measures, so the combination of LAN-speed access to mail, leaving the server to send it in the background, and Spamassassin providing industrial strength spam scanning made it useful, and not having a network-connected printer or shared file storage meant Samba came in too.

It started as a cheap desktop PC, and since 2008 it’s been a laptop with a busted screen, sitting in a quiet cupboard, occasionally getting switched off my an exploring cat. Other than that, in typical Linux style, it’s just worked, almost 24x7x365 since then, with maybe a hard disk upgrade once.

This did, however, mean a bit of complexity: to have full, always-working email on a phone would have meant all sorts of tricks with PAT, and other stuff, and then there’s always the risk of blowing it up when you try an upgrade. I did have plans to build a new version, do it all again, and include that, when instead, I looked at how much spam is getting through.

The answer is: not much, so the hosting co must be doing a good job.

So with that, the “server” will be retired, and I think a Raspberry Pi will take it’s place (it is useful to have a shell-accessible Linux machine you’re superuser of at times).

The VPN Fallacy

It seems the next thing to get marketed to consumers is a VPN service. Nord VPN, for one, as well as our old friends Norton are busily pushing VPNs to all and sundry, and the inference is that is you don’t install their VPN product on your PC or phone, you might as well shout all your personal data out loud to all and sundry, because the hackers will listen in on all your traffic, and hack your device too.

This is, of course, bollocks. Most websites now use TLS, so website traffic is encrypted anyway, a sis most email, so unless you ignore certificate warnings, your data is encrypted, and in practical terms, unreadable to anyone listening in.

It’s important here to realise what a VPN actually does, and what it doesn’t. When you buy a VPN service, you buy a tunnel from your PC to an exit point the person you pay provides. They wrap up your traffic, carry it, then unwrap the other end.

As an analogy, Imagine you have a note on a piece of paper that you want to pass across a crowded room, but you can’t take it yourself: you have to hand it person to person. If you just pass the note, unencrypted, everyone might read it.

Now imagine that instead, there’s a person near to the recipient. You phone him, and say that you’re sending the note, inside a locked box that only he has the key to. This is your VPN. You place the note in the box, the box gets handed across the room, and the person unlocks the box, and hands over the note. This is great, because no-one sees the note on the way across- in fact, they don’t even know there’s a note- they just see a box- but there’s a key thing: you have to trust the person who unlocks the box. He could discard the note, replace it, or read it.

There’s the rub. A VPN exits somewhere, and you have to trust that exit, and there’s evidence it’s not always trustworthy.

Now imagine that you write the note in code, that only the recipient can decode and hand it across the room. Even if everyone looks at it, they can’t read it. When your recipient gets it, he decrypts it and reads it. Everyone in the room knows there was a note, but not what it says. That’s TLS.

Now, of course as TLS is in use anyway, your VPN provider probably can’t read the note, but, seeing as how no-one else can anyway, there’s little point putting it in a box, unless you’re looking to hide the fact there’s a note at all: to suggest that there’s a hacking potential if you don’t use the VPN product is highly dubious. TLS may be readable by governments, but if it is, the 3DES or whatever your VPN tunnel uses is probably readable too, and if the government is that interested in your traffic, you probably have bigger problems.

Things are different with a VPN that (for example) your employer might provide for you to access the company network from home: there your employer controls the endpoint, and deliberately places it inside their network, so that the stuff you send remains in the locked box until it gets to their server room. Similarly, you could set up a VPN to your home network from elsewhere: there you control the exit point, and get to hide your traffic from all the intermediate points.

In summary: Nord etc: give it a rest. It’s scaremongering.