<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The Next Net &#187; Real life</title>
	<atom:link href="http://patrick.vande-walle.eu/category/real-life/feed/" rel="self" type="application/rss+xml" />
	<link>http://patrick.vande-walle.eu</link>
	<description>Random thoughts about the Internet and life</description>
	<lastBuildDate>Thu, 15 Jul 2010 12:49:53 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Faille de sécurité dans 500.000 modems Belgacom ?</title>
		<link>http://patrick.vande-walle.eu/internet/faille-de-securite-dans-500k-modems-belgacom/</link>
		<comments>http://patrick.vande-walle.eu/internet/faille-de-securite-dans-500k-modems-belgacom/#comments</comments>
		<pubDate>Tue, 19 Jan 2010 18:20:58 +0000</pubDate>
		<dc:creator>Patrick Vande Walle</dc:creator>
				<category><![CDATA[BBox-2]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[Real life]]></category>
		<category><![CDATA[BBox2]]></category>
		<category><![CDATA[Belgacom]]></category>
		<category><![CDATA[OpenRG]]></category>
		<category><![CDATA[VDLS2]]></category>

		<guid isPermaLink="false">http://patrick.vande-walle.eu/?p=741</guid>
		<description><![CDATA[Les modems BBOX2 qu&#8217;utilisent une majorité de clients de Belgacom TV comportent des failles de sécurité importantes. Belgacom revendiquait 589.000 clients pour sa plate-forme TV l&#8217;été dernier. Une majorité d&#8217;entre eux utilise ce fameux modem. Une combinaison de facteurs ouvre la porte à des actes malveillants, pouvant être commis par des personnes sans connaissances informatiques [...]]]></description>
			<content:encoded><![CDATA[<p>Les modems BBOX2 qu&#8217;utilisent une majorité de clients de <a target="_blank" href="http://www.belgacom.be">Belgacom</a> TV comportent des failles de sécurité importantes. <a target="_blank" href="http://www.belgacom.be">Belgacom</a> revendiquait <a href="http://trends.rnews.be/fr/economie/entreprises/12-1634-48592/belgacom---l-amende-de-proximus-fait-plonger-le-benefice-net.html" target="_blank">589.000 clients pour sa plate-forme TV</a> l&#8217;été dernier. Une majorité d&#8217;entre eux utilise ce fameux modem.   Une combinaison de facteurs ouvre la porte à des actes malveillants, pouvant être commis par des personnes sans connaissances informatiques particulières et pas seulement des &#8216;hackers&#8217;.</p>
<ol>
<li> Les modems BBOX2 sont tous livrés avec le même mot de passe d&#8217;administration. On peut très facilement le trouver via un moteur de recherche: <a href="http://www.google.com/search?hl=en&amp;q=BGCVDSL2 " target="_blank">http://www.google.com/search?hl=en&amp;q=BGCVDSL2 </a></li>
<li><a target="_blank" href="http://www.belgacom.be">Belgacom</a> prétend bloquer l&#8217;accès à distance de ces modems via Internet. C&#8217;est partiellement exact. Cependant, ces modems sont livrés d&#8217;origine avec une connexion WIFI active et non protégée.  N&#8217;importe qui passant dans la rue peut donc se connecter à une BBOX2 non protégée.</li>
<li>Muni de cet accès administratif, on peut télécharger le fichier de configuration du modem et décrypter les mots de passe qui s&#8217;y trouvent. Là aussi, on trouve le nécessaire sur Internet: <a href="http://www.webalice.it/zibri/Deobfuscate.html" target="_blank">http://www.webalice.it/zibri/Deobfuscate.html </a></li>
</ol>
<p>Après avoir récupéré les identifiants d&#8217;un abonné  à <a target="_blank" href="http://www.belgacom.be">Belgacom</a> TV (identifiants de la connexion PPPoE, pour être précis), un pirate peut utiliser ces informations pour perpétrer des actes malveillants en se faisant passer pour  cet abonné.</p>
<p>Toutes les informations ci-dessus sont en possession de <a target="_blank" href="http://www.belgacom.be">Belgacom</a> depuis longtemps. J&#8217;ai moi-même interrogé l&#8217;opérateur, qui n&#8217;a pas daigné accuser réception, et encore moins répondu ou proposé des solutions.</p>
<p>Notons également que si cela s&#8217;applique aux clients de <a target="_blank" href="http://www.belgacom.be">Belgacom</a> TV, certains abonnés Internet, chez <a target="_blank" href="http://www.belgacom.be">Belgacom</a> comme chez les opérateurs alternatifs qui utilisent le réseau VDSL2 de <a target="_blank" href="http://www.belgacom.be">Belgacom</a> sont également concernés. Le propriétaire du réseau impose en effet aux autres FAI l&#8217;utilisation d&#8217;un modem semblable au sien, également pourvu d&#8217;un mot de passe identique pour tous les abonnés.</p>
<p><span id="more-741"></span></p>
<p>Quelques détails additionnels pour les intéressés. Pour l&#8217;illustration, nous utilisons ici l&#8217;interface graphique du modem. Cependant, cette technique fonctionne également via une interface en mode textuel (telnet), qui permettrait à des pirates plus organisés de récupérer automatiquement ces données, sans intervention humaine.</p>
<h3>Mot de passe d&#8217;administration identique</h3>
<p>Pour une raison inexpliquée, <a target="_blank" href="http://www.belgacom.be">Belgacom</a> a choisi d&#8217;utiliser le même mot de passe sur tous ses modems. Il est très vite devenu un secret de polichinelle. Qui plus est, <a target="_blank" href="http://www.belgacom.be">Belgacom</a> ne donne pas d&#8217;indication sur la manière de le modifier. <a target="_blank" href="http://www.belgacom.be">Belgacom</a> ne fournit d&#8217;ailleurs aucun manuel avec le modem.  <a href="http://www.ripperjack.info/b-boxandco/spip.php?article52" target="_blank">D&#8217;autres s&#8217;en sont chargés, heureusement</a>. Ce qu&#8217;on retiendra, c&#8217;est la nécessité d&#8217;utiliser d&#8217;obscures commandes via une interface textuelle qui est peu compréhensible par le public que cible l&#8217;opérateur.</p>
<p><a target="_blank" href="http://www.belgacom.be">Belgacom</a> a également imposé aux opérateurs alternatifs qui passent par son réseau VDSL2 d&#8217;utiliser un mot de passe unique (OLOVDSL2, dans ce cas). Il est évident qu&#8217;il s&#8217;agit d&#8217;un problème majeur de sécurité.</p>
<h3>Accès à la configuration</h3>
<p>Suite aux menaces proférées il y a quelques par un pirate se faisant appeler Vendetta, <a target="_blank" href="http://www.belgacom.be">Belgacom</a> a décidé de bloquer l&#8217;accès à ses modems BBOX2 via l&#8217;Internet, en bloquant les accès sur les ports 80, 443 et 22. Ce faisant, <a target="_blank" href="http://www.belgacom.be">Belgacom</a> enlève également à l&#8217;abonné de gérer son modem à distance., ce qui retire pas mal de fonctionnalités. L&#8217;abonné à la possibilité de malgré tout ouvrir ces ports, <a target="_blank" href="http://www.belgacom.be">Belgacom</a> se contentant d&#8217;avertir qu&#8217;il y a un risque de sécurité, sans expliquer lequel. En tout état de cause, le remède est disproportionné par rapport au problème à traiter. Un peu comme si on confisquait les clés de voiture aux automobilistes au titre que cela diminuera leur empreinte carbone.</p>
<p>Les modems sont par contre très facilement accessibles via le WIFI, qui est actif et non protégé par défaut. En effet, <a target="_blank" href="http://www.belgacom.be">Belgacom</a> veut rendre la vie de ses clients <a target="_blank" href="http://www.belgacom.be">Belgacom</a> TV simple, y compris ceux qui ne sont pas férus de technologie.  En conséquence, le modem se configure de lui-même lors de la première connexion. Plus exactement, le modem est configuré à distance via le protocole <a href="http://fr.wikipedia.org/wiki/TR-069" target="_blank">TR-069</a>. L&#8217;utilisateur n&#8217;a rien à faire de son côté, sinon enficher le câble du décodeur TV dans le modem. Le reste est automatique.</p>
<p>Qui plus plus est, l&#8217;abonné à <a target="_blank" href="http://www.belgacom.be">Belgacom</a> TV a souvent souscrit à une offre qui comprend aussi l&#8217;accès Internet, même s&#8217;il n&#8217;en a pas ou peu l&#8217;usage, ce qui ne l&#8217;encouragera pas à prendre les mesures nécessaires pour sécuriser son WIFI. Ainsi donc, il y a possiblement des milliers de clients de <a target="_blank" href="http://www.belgacom.be">Belgacom</a> qui ont un modem grand ouvert à tout le monde, sans le savoir. J&#8217;ai personnellement identifié près d&#8217;une dizaine de modems BBOX2 non protégés dans mes environs immédiats.</p>
<h3>Déchiffrement des mots de passe</h3>
<p>La BBOX2 utilise un micro-logiciel nommé OpenRG, de la société <a href="http://www.jungo.com" target="_blank">Jungo</a>. Ce logiciel se retrouve dans de nombreux modems ADSL, et notamment la Livebox de France Télécom, également utilisée  par Mobistar en Belgique.</p>
<p>Jungo a utilisé une technique de chiffrement que les informaticiens appellent plutôt l&#8217;obfuscation. Elle consiste à rendre la lecture plus compliquée de prime abord, mais sans introduire réellement de chiffrement. C&#8217;est une technique qui est connue depuis l&#8217;Antiquité. En l&#8217;occurrence, on procède par remplacement d&#8217;un caractère par un autre. Ainsi, une fois identifié les 26 lettres minuscules et majuscules, en plus des 10 chiffres, on peut très facilement construire un tableau de concordance et codifier le tout dans une petite routine informatique. Le site mentionné ci-dessus utilise le très répandu Javascript, mais il existe d&#8217;autres implémentations, en <a href="/uploads/2010/01/openrg-decrypt.py.txt" target="_blank">Python notamment</a> (<a href="http://www.userbase.be/forum/viewtopic.php?p=307227#p306275" target="_blank">source</a>), ce qui permettait à un pirate de facilement créer un programme de récupération automatique de ces identifiants.</p>
<p>La première étape est de sauvegarder la configuration du modem. Il suffit d&#8217;aller dans le menu &#8220;Admin Settings/Backup and Update&#8221;</p>
<p style="text-align: center;"><a href="/uploads/2010/01/admin-settings-backup-.jpg"><img class="aligncenter" style="margin-top: 20px; margin-bottom: 20px;" title="admin-settings-backup" src="/uploads/2010/01/admin-settings-backup--300x211.jpg" alt="" width="300" height="211" /></a></p>
<p>On récupère alors un fichier texte, où l&#8217;on peut trouver les identfiants de l&#8217;utilisateur:</p>
<p style="text-align: center;"><a href="/uploads/2010/01/password-obfuscate.jpg"><img class="aligncenter" style="margin-top: 20px; margin-bottom: 20px;" title="password-obfuscate" src="/uploads/2010/01/password-obfuscate.jpg" alt="" width="262" height="87" /></a></p>
<p>Dans l&#8217;exemple, ci-dessus, le mot de passe est &#8216;testing&#8217;, et c&#8217;est très exactement la valeur que retourne  le <a href="http://www.webalice.it/zibri/Deobfuscate.html" target="_blank">site de déchiffrement</a> mentionné ci-dessus.</p>
<p>La plupart des modems ADSL permettent de créer une copie de sauvegarde de leur configuration, bien utile en cas de panne. Cependant, les autres fabricants créent un fichier de configuration binaire, et donc illisible par un être humain. Jungo a choisi de rendre le fichier compréhensible, introduisant de la sorte une faille de sécurité, et le manque de précautions prises par <a target="_blank" href="http://www.belgacom.be">Belgacom</a> rend evidemment le problème plus grave encore.</p>
<p>Pour information, j&#8217;ai signalé ce problème de sécurité tant à <a target="_blank" href="http://www.belgacom.be">Belgacom</a> qu&#8217;à son fournisseur Jungo. En l&#8217;absence de réponse, je mets donc ces informations en ligne.</p>
]]></content:encoded>
			<wfw:commentRss>http://patrick.vande-walle.eu/internet/faille-de-securite-dans-500k-modems-belgacom/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New ISP and lots of speed</title>
		<link>http://patrick.vande-walle.eu/internet/new-isp-and-lots-of-speed/</link>
		<comments>http://patrick.vande-walle.eu/internet/new-isp-and-lots-of-speed/#comments</comments>
		<pubDate>Fri, 25 Dec 2009 15:43:57 +0000</pubDate>
		<dc:creator>Patrick Vande Walle</dc:creator>
				<category><![CDATA[Belgium]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[Personal]]></category>
		<category><![CDATA[Real life]]></category>
		<category><![CDATA[Belgacom]]></category>
		<category><![CDATA[VDSL2]]></category>

		<guid isPermaLink="false">http://patrick.vande-walle.eu/?p=722</guid>
		<description><![CDATA[Santa has been kind to me. I just switched to a new ISP.  The results below speak for themselves. That&#8217;s the good news. The less good one is that this whole VDSL2 infrastructure deployed by the incumbent telecom operator has some major security holes, on which I will post later, once I have finished my [...]]]></description>
			<content:encoded><![CDATA[<p>Santa has been kind to me. I just switched to a new ISP.  The results below speak for themselves.</p>
<table align="center">
<tbody>
<tr>
<td>
<p><div id="attachment_721" class="wp-caption aligncenter" style="width: 310px"><a href="/uploads/2009/12/662631616.png"><img class="size-full wp-image-721" title="BGC-VDSL2" src="/uploads/2009/12/662631616.png" alt="BGC-VDSL2" width="300" height="135" /></a><p class="wp-caption-text">2009-12-25</p></div></td>
<td>
<p><div id="attachment_551" class="wp-caption aligncenter" style="width: 310px"><a href="/uploads/2009/07/521571818.png"><img class="size-full wp-image-551" title="521571818" src="/uploads/2009/07/521571818.png" alt="" width="300" height="135" /></a><p class="wp-caption-text">2009-07-20</p></div></td>
</tr>
</tbody>
</table>
<p>That&#8217;s the good news. The less good one is that this whole VDSL2 infrastructure deployed by the incumbent telecom operator has some major security holes, on which I will post later, once I have finished my research.</p>
]]></content:encoded>
			<wfw:commentRss>http://patrick.vande-walle.eu/internet/new-isp-and-lots-of-speed/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cher Scarlet</title>
		<link>http://patrick.vande-walle.eu/real-life/cher-scarlet/</link>
		<comments>http://patrick.vande-walle.eu/real-life/cher-scarlet/#comments</comments>
		<pubDate>Mon, 20 Jul 2009 20:22:05 +0000</pubDate>
		<dc:creator>Patrick Vande Walle</dc:creator>
				<category><![CDATA[Belgium]]></category>
		<category><![CDATA[Real life]]></category>
		<category><![CDATA[ADSL]]></category>
		<category><![CDATA[Belgique]]></category>
		<category><![CDATA[Scarlet]]></category>

		<guid isPermaLink="false">http://patrick.vande-walle.eu/?p=550</guid>
		<description><![CDATA[Une fois de plus, vous manquez à vos plus élémentaires obligations contractuelles en me fournissant le service ADSL le plus merdique de Belgique. Je n&#8217;ai pas l&#8217;habitude d&#8217;utiliser des gros mots en public. C&#8217;est vous dire combien je suis exaspéré. Vous m&#8217;avez reproché auparavant, et avec une mauvaise foi certaine, que je vous avais pas [...]]]></description>
			<content:encoded><![CDATA[<p>Une fois de plus, vous manquez à vos plus élémentaires obligations contractuelles en me fournissant le service ADSL le plus merdique de Belgique. Je n&#8217;ai pas l&#8217;habitude d&#8217;utiliser des gros mots en public. C&#8217;est vous dire combien je suis exaspéré.</p>
<p>Vous m&#8217;avez reproché auparavant, et avec une mauvaise foi certaine, que je vous avais pas informé de la piètre qualité de vos services. Non seulement, je l&#8217;ai fait, <a href="http://forum.adsl-bc.org/viewforum.php?f=11" target="_blank">mais d&#8217;autres aussi</a>. Il y en a plein les forums de discussion. Mais puisque vous me prenez au mot, je vais effectivement me plaindre. Et que cela se sache.<span id="more-550"></span></p>
<p>Je vous propose donc de suivre en léger différé sur mon blog, les performances mesurées de vos services. On commence ce 20/7/2009:</p>
<table border="0">
<tbody>
<tr>
<td>
<p><div id="attachment_552" class="wp-caption aligncenter" style="width: 310px"><a href="/uploads/2009/07/521572635.png"><img class="size-full wp-image-552" title="521572635" src="/uploads/2009/07/521572635.png" alt="2009-07-20 22:10:28" width="300" height="135" /></a><p class="wp-caption-text">2009-07-20</p></div></td>
<td>
<p><div id="attachment_551" class="wp-caption aligncenter" style="width: 310px"><a href="/uploads/2009/07/521571818.png"><img class="size-full wp-image-551" title="521571818" src="/uploads/2009/07/521571818.png" alt="2009-07-20 22:08:45" width="300" height="135" /></a><p class="wp-caption-text">2009-07-20</p></div></td>
</tr>
</tbody>
</table>
<p>[Update 21/7 10:35]  Toute connexion est absolument impossible vers quelque service que ce soit. Web, e-mail, timeouts partout.</p>
<p>[Update 24/7 15:49] Envoyé un e-mail au help desk le 21/7. Réponse le 24/7 sur le thême &#8220;on n&#8217;a pas suffisamment d&#8217;information&#8221;. Entretemps, la vitesse est revenue à des valeurs normales, avec des chutes de temps à autre.</p>
<p>Restez branchés pour la suite. Je mettrai le post à jour de temps à autre.</p>
<p>Avant que votre help desk n&#8217;arrive avec sa check-list de questions préformatées, je precise que oui, ma ligne téléphonique fonctionne, que oui mon modem est bien configuré et que oui mon ordinateur aussi. Et je ne vous permets pas d&#8217;en douter. On s&#8217;évitera ainsi deux jours de questions/réponses inutiles.</p>
<p>Allons au fait: que se passe-t-il dans l&#8217;infrastructure de Scarlet qui justifie d&#8217;aussi piètres performances ? A la limite, le pourquoi n&#8217;est pas mon problème. Ce qui m&#8217;importe, c&#8217;est de savoir quand vous prendrez enfin les mesures nécessaires pour offrir un  service correct à vos clients.</p>
<p>Et si vous n&#8217;avez pas de réponse à cette question, que vous niez les évidences et que vous considérez que je vous échauffe les oreilles, il n&#8217;y a qu&#8217;une solution pour me faire taire: acceptez une  une résiliation anticipée de notre contrat,  que vous êtes de toute manière dans l&#8217;impossibilité d&#8217;honorer.</p>
<p>Allez, bonne journée quand même.</p>
]]></content:encoded>
			<wfw:commentRss>http://patrick.vande-walle.eu/real-life/cher-scarlet/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Lies, greediness and Belgian ISPs</title>
		<link>http://patrick.vande-walle.eu/real-life/lies-greediness-and-belgian-isps/</link>
		<comments>http://patrick.vande-walle.eu/real-life/lies-greediness-and-belgian-isps/#comments</comments>
		<pubDate>Wed, 04 Feb 2009 10:40:13 +0000</pubDate>
		<dc:creator>Patrick Vande Walle</dc:creator>
				<category><![CDATA[Belgium]]></category>
		<category><![CDATA[Real life]]></category>
		<category><![CDATA[ISP]]></category>
		<category><![CDATA[Scarlet]]></category>

		<guid isPermaLink="false">http://patrick.vande-walle.eu/?p=446</guid>
		<description><![CDATA[Some ISPs would do anything to gain a new customer. Last December, I switched ISPs. Although  my previous one, Dommel, provided a good and stable internet connection, their customer service staff was totally broken. They   seemed totally unwilling to answer any written question, be it in French, English or Dutch.  Further, they used the oldish [...]]]></description>
			<content:encoded><![CDATA[<p>Some ISPs would do anything to gain a new customer.</p>
<p>Last December, I switched ISPs. Although  my previous one, <a href="http://www.dommel.com" target="_blank">Dommel</a>, provided a good and stable internet connection, their customer service staff was totally broken. They   seemed totally unwilling to answer any written question, be it in French, English or Dutch.  Further, they used the oldish ADSL infrastructure from the incumbent, <a target="_blank" href="http://www.belgacom.be">Belgacom</a>, and thus could only provide a 4 Mbit/sec connection. With 6 computers at home, this proved to be slow at times.</p>
<p>Hence, I took the opportunity to move to another ISP, <a href="http://www.scarlet.be" target="_blank">Scarlet</a>, which promised 20 Mbit/sec.  I was aware that theorical speeds may not always be reached due to different factors like copper line length, etc.</p>
<p>Much to my surprise, I was informed after the contract was signed that I would only get 6Mbit. Scarlet&#8217;s tech support confirmed today that the local phone exchange to which I am connected has not been upgraded to ADSL2+.  This ISP knew at the time they presented the electronic contract to me  that they were unable to deliver what they promised.</p>
<p><a href="/uploads/2009/02/scarlet-adsl20.png"><img class="size-full wp-image-448 alignnone" title="scarlet-adsl20" src="/uploads/2009/02/scarlet-adsl20.png" alt="scarlet-adsl20" width="426" height="67" /></a></p>
<p>Their sign-in form stated &#8220;<em>Congratulations, you can be connected to the ADSL20 network [...] The maximum download speed is dependent on the distance  from the local exchange, your computer configuration and its cabling</em> &#8220;. Nowhere does it state that it is dependent on the exchange infrastructure.</p>
<p>The tech support guy was not able either to tell me when they expect the local exchange to be upgraded. This looks like ultra confidential information. Actually, we know more about battle plans in the Middle East, Iraq or Afganisthan than about an ISP&#8217;s infrastructure upgrade strategy.</p>
<p>Belgium once prided itself to be at the forefront of broadband deployment. If only it could be done by professionals who care about customers &#8230;</p>
<p>The next step will be to file a complaint to the telecom ombudsman. I do not expect much of a improvement, though.</p>
]]></content:encoded>
			<wfw:commentRss>http://patrick.vande-walle.eu/real-life/lies-greediness-and-belgian-isps/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Austrian Airlines are funny</title>
		<link>http://patrick.vande-walle.eu/real-life/austrian-airlines-are-funny/</link>
		<comments>http://patrick.vande-walle.eu/real-life/austrian-airlines-are-funny/#comments</comments>
		<pubDate>Thu, 06 Nov 2008 19:30:51 +0000</pubDate>
		<dc:creator>Patrick Vande Walle</dc:creator>
				<category><![CDATA[Real life]]></category>
		<category><![CDATA[austrian airlines]]></category>
		<category><![CDATA[Frank Zappa]]></category>
		<category><![CDATA[Miles Davis]]></category>

		<guid isPermaLink="false">http://patrick.vande-walle.eu/?p=376</guid>
		<description><![CDATA[In-flight magazines offered by airlines are usually the sort of thing one reads occasionally on boring long flights. So did I on my way from Vienna to Cairo last week. Just like any other airlines, Austrian Airlines gives names to its airplanes. Contrary to other airlines, Austrian tries to make an effort to innovate. They [...]]]></description>
			<content:encoded><![CDATA[<p>In-flight magazines offered by airlines are usually the sort of thing one reads occasionally on boring long flights. So did I on my way from Vienna to Cairo last week.</p>
<p>Just like any other airlines, <a href="http://www.aua.com" target="_blank">Austrian Airlines</a> gives names to its airplanes. Contrary to other airlines, Austrian tries to make an effort to innovate. They have a range of Boeing B737-800 named <a href="http://en.wikipedia.org/wiki/Frank_zappa" target="_blank">Frank Zappa</a>, <a href="http://en.wikipedia.org/wiki/Freddie_mercury" target="_blank">Freddie Mercury</a>, <a href="http://en.wikipedia.org/wiki/George_harrison" target="_blank">George Harrison</a>, <a href="http://en.wikipedia.org/wiki/Gregory_Peck" target="_blank">Gregory Peck</a>, <a href="http://en.wikipedia.org/wiki/Kurt_Cobain" target="_blank">Kurt Cobain</a> and <a href="http://en.wikipedia.org/wiki/Miles_davis" target="_blank">Miles Davis</a> . This is refreshing and much more original than using city names. Can I suggest the next plane be called <a href="http://tokyo.cool.ne.jp/deadpopstars/" target="_blank">The Dead Pop Stars</a> ?</p>
<p>But above all, it is good to see an airline mentioning in bold letters on page 3 of its &#8220;Skylines&#8221; magazine that it will not tolerate that passengers be offended by others because of ethnicity, religion or gender. It encourages to ask the cabin crew to intervene. It is good to see a company that places ethical values before commercial considerations.  They may have lost a few racist passengers because of this policy, but they have now gained a new customer.</p>
]]></content:encoded>
			<wfw:commentRss>http://patrick.vande-walle.eu/real-life/austrian-airlines-are-funny/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>This host is DNSSEC-enabled &#8211; Part 2</title>
		<link>http://patrick.vande-walle.eu/real-life/this-host-is-dnssec-enabled-part-2/</link>
		<comments>http://patrick.vande-walle.eu/real-life/this-host-is-dnssec-enabled-part-2/#comments</comments>
		<pubDate>Mon, 13 Oct 2008 20:23:24 +0000</pubDate>
		<dc:creator>Patrick Vande Walle</dc:creator>
				<category><![CDATA[DNS]]></category>
		<category><![CDATA[Real life]]></category>
		<category><![CDATA[DNSSEC]]></category>
		<category><![CDATA[linkedin]]></category>
		<category><![CDATA[NLNET Labs]]></category>
		<category><![CDATA[RESTENA]]></category>

		<guid isPermaLink="false">http://patrick.vande-walle.eu/?p=367</guid>
		<description><![CDATA[Last year, I started signing the DNS records for this domain (and isoc.lu). At the time, it was what is called an &#8216;island of trust&#8217; in DNSSEC-speak. Being a firm believer that one should eat his own dogfood, I took this now one step further. Both domains vande-walle.eu and isoc.lu are now added to ISC&#8217;s [...]]]></description>
			<content:encoded><![CDATA[<p>Last year, <a href="/internet/dnssec/" target="_blank">I started signing the DNS records for this domain</a> (and isoc.lu). At the time, it was what is called an &#8216;island of trust&#8217; in DNSSEC-speak. Being a firm believer that one should eat his own dogfood, I took this now one step further. Both domains vande-walle.eu and isoc.lu are now added to ISC&#8217;s DLV registry. In addition, they are also in UCLA&#8217;s <a href="http://secspider.cs.ucla.edu/isoc-lu--zone.html" target="_blank">Secspider DLV</a> repository. DLV stands for <a href="http://tools.ietf.org/html/rfc5074" target="_blank">Domain Lookaside Validation</a>, it &#8220;is a mechanism for publishing DNS Security (DNSSEC) trust anchors outside of the DNS delegation chain&#8221;, according to RFC 5074.</p>
<p>There are a few lessons to be learned from this experience. First and foremost, the tools are <span style="text-decoration: line-through;">now</span> not yet ready for a general audience. If the dnssec-signzone man page is your favourite late night reading and if you like Unix shell scripting, you will have plenty of fun. On the other hand, if you are an overworked system administrator being told by the boss to &#8216;By the way, please switch on DNSSEC before your leave this afternoon&#8217; , you are out of luck.  The best tool I found to make it a bit easier is <a href="http://www.hznet.de/dns/zkt/" target="_blank">ZKT</a>.  However, this is not the friendly Graphical User Interface you would expect.</p>
<p>Lesson 2 is &#8216;check you secondaries&#8217;. I had secondaries with <a href="http://www.xname.org" target="_blank">Xname.org</a>. Although these nice folks provide good and free DNS service, their machines do not answer DNSSEC queries. Hence, I had to switch to new secondaries.</p>
<p>Lesson 3 is that few DNS resolvers currently support DLV. <a href="http://www.isc.org/sw/bind/" target="_blank">Bind</a> does. <a href="http://www.unbound.net" target="_blank">Unbound</a> will in the next release (the current development code already does).</p>
<p>Lesson 4 is that the current system to register a domain in the DLV does not seem to scale and looks more like a proof of concept. It would need to be seriously industrialized to be helpful for a bigger deployment.</p>
<p>Lesson 5 stems from 4 above. The whole thing would be a bit easier to deploy if the root zone was signed. But this is <a href="http://blog.wired.com/27bstroke6/2008/10/feds-take-step.html" target="_blank">another debate</a>.</p>
<p>Many thanks to the folks at <a href="http://www.nlnetlabs.nl" target="_blank">NLNet Labs</a> and the <a href="http://www.restena.lu" target="_blank">RESTENA Foundation</a> for providing DNS secondary service, and <a href="http://www.isc.org" target="_blank">ISC</a> for running the DLV registry.</p>
]]></content:encoded>
			<wfw:commentRss>http://patrick.vande-walle.eu/real-life/this-host-is-dnssec-enabled-part-2/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>We need real paneuropean mobile operators</title>
		<link>http://patrick.vande-walle.eu/real-life/we-need-real-paneuropean-mobile-operators/</link>
		<comments>http://patrick.vande-walle.eu/real-life/we-need-real-paneuropean-mobile-operators/#comments</comments>
		<pubDate>Wed, 10 Sep 2008 07:39:39 +0000</pubDate>
		<dc:creator>Patrick Vande Walle</dc:creator>
				<category><![CDATA[Belgium]]></category>
		<category><![CDATA[Luxembourg]]></category>
		<category><![CDATA[Real life]]></category>
		<category><![CDATA[EU]]></category>
		<category><![CDATA[Europe]]></category>
		<category><![CDATA[GSM]]></category>
		<category><![CDATA[mobile]]></category>
		<category><![CDATA[Roaming]]></category>
		<category><![CDATA[Telecomunications]]></category>

		<guid isPermaLink="false">http://patrick.vande-walle.eu/?p=342</guid>
		<description><![CDATA[I got my mobile phone bill in the mail the other day and, again, I nearly got a heart attack.   It has been like this for over the last 10 years. Whatever I do, this bill is always way higher than expected. I tried everything from switching operators to  spending hours figuring out the [...]]]></description>
			<content:encoded><![CDATA[<p>I got my mobile phone bill in the mail the other day and, again, I nearly got a heart attack.   It has been like this for over the last 10 years. Whatever I do, this bill is always way higher than expected.</p>
<p>I tried everything from switching operators to  spending hours figuring out the optimal subscription plan. I do not place calls from my mobile if I can avoid it, especially abroad. I avoid SMS when e-mail is possible. I do not even <strong>dare</strong> to use the data services, although I have a 3G phone.  Still no luck. The main issue is that I work in a small country, live in the country nearby and often go to a two other countries for shopping and leisure. I am roaming on other networks than my home one 75% of the time. While this may sound unusual, actually this is what the whole European Union construction is all about: abolish borders.</p>
<p>I decided last year to subcribe to<a href="http://www.transatel.com" target="_blank"> Transatel</a>, a MNVO (Mobile Network Virtual Operator). In short, they do not have a network on their own, but buy capacity from other operators. It looked attractive because they cover several countries. They give you a local phone number in each country you choose. This makes it cheaper for the people calling you.  I can receive calls on my Luxembourg number while in Belgium and no roaming charges will apply. Sort of. Because, actually, you only get a limited number of minutes each month for call transfers across countries. Once you have reached the threshold, you are billed for the call transfers. This is just roaming charges by another name. At the time of subscription, they promised my monthly bill would be 50% lower. It looks like my usage profile was not part of their statistical sample&#8230;</p>
<p>The European mobile market is very fragmented. Each country has 3 or 4 mobile operators. Even those self labelled paneuropean networks like Vodaphone or Orange are actually alliances of different national operators, loosely tied by a similar logo.  All the rest of their offerings is different: subscription plans, services, phone numbers and roaming charges.  As for roaming charges, I noticed on several occasions in the past that if your home network operator is a Vodaphone partner, it may sometimes be cheaper to select a non-Vodaphone network abroad.</p>
<p>Those alliances are another way to make the offers more opaque to better fool the customer. On the economics of the mobile market, there is this interesting post from <a href="http://www.kurtis.pp.se/blog/2008/07/the_cost_of_walledgarden_desig.html" target="_blank">Kurtis Linqvist</a> (thanks to Patrik Fältström for the link) . Just like Kurtis, I agree that there is no such thing as free and open mobile markets  in Europe.  I, too, hope the European Commission will continue to regulate the market until such time that it will cost the same price to call a mobile in Stockholm from Madrid that it is to place call from Los Angeles to Washington.  <a href="http://www.wireless.att.com/cell-phone-service/cell-phone-plans/index.jsp" target="_blank">At&amp;T in the US</a> has a subscription plan for unlimited voice calls throughout the US for USD99.99/month. Unfortunately, given the current market conditions, I do not see a similar paneuropean offer any time soon.</p>
]]></content:encoded>
			<wfw:commentRss>http://patrick.vande-walle.eu/real-life/we-need-real-paneuropean-mobile-operators/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Gartner on new Generic Top Level Domains</title>
		<link>http://patrick.vande-walle.eu/internet/gartner-on-new-generic-top-level-domains/</link>
		<comments>http://patrick.vande-walle.eu/internet/gartner-on-new-generic-top-level-domains/#comments</comments>
		<pubDate>Fri, 11 Jul 2008 18:25:04 +0000</pubDate>
		<dc:creator>Patrick Vande Walle</dc:creator>
				<category><![CDATA[ICANN]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[Real life]]></category>

		<guid isPermaLink="false">http://patrick.vande-walle.eu/?p=296</guid>
		<description><![CDATA[Gartner, the well known IT consulting company, has published a report on the new top level domains that will appear some time next year. The report totally misses the mark. In a pure US centric vision, it focuses on &#8220;.com&#8221; as the must-have TLD, totally overlooking the fact that a &#8220;.com&#8221; is mostly worthless e.g. [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.gartner.com" target="_blank">Gartner</a>, the well known IT consulting company, has <a href="http://gartner.com/DisplayDocument?doc_cd=159489" target="_blank">published a report on the new top level domains</a> that will appear some time next year.</p>
<p>The report totally misses the mark. In a pure US centric vision, it focuses on &#8220;.com&#8221; as the must-have TLD, totally overlooking the fact that a &#8220;.com&#8221; is mostly worthless e.g. in Germany, where &#8220;.de&#8221; is the TLD one must have to succeed locally. There are many countries where the local TLD has much more value than a &#8220;.com&#8221;.</p>
<p>The report is also clueless in that it states that &#8220;<em>proposals previously rejected by ICANN, such as the creation of “.xxx” for adult-oriented sites, are also likely to be commercially successful</em>&#8220;, when everybody but Gartner knows that the newly adopted rules were designed to precisely avoid the &#8220;.xxx&#8221; debacle to happen again.</p>
<p>Going further down the path of ignorance, Gartner also states that : &#8220;<em>we would expect that an extension such as “.movie” would have similar value</em>&#8220;. I am afraid &#8220;.movie&#8221;, just like &#8220;.travel&#8221; or &#8220;.name&#8221; will only have modest success, because they are focused on the English speaking market, and have little value outside North America. In this specific case, my British colleagues usually use the word &#8220;film&#8221; rather than &#8220;movie&#8221;. Looks like &#8220;.movie&#8221; will not even be able to cross the Atlantic.</p>
<p>How much credit you give to this report depends on the credit you give to Gartner, of course. I am afraid this one is not going to help the company&#8217;s track record. Sometimes, silence is better.</p>
]]></content:encoded>
			<wfw:commentRss>http://patrick.vande-walle.eu/internet/gartner-on-new-generic-top-level-domains/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Missing Firefox, badly</title>
		<link>http://patrick.vande-walle.eu/internet/missing-firefox-badly/</link>
		<comments>http://patrick.vande-walle.eu/internet/missing-firefox-badly/#comments</comments>
		<pubDate>Sat, 17 May 2008 14:50:06 +0000</pubDate>
		<dc:creator>Patrick Vande Walle</dc:creator>
				<category><![CDATA[Internet]]></category>
		<category><![CDATA[Real life]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Spam]]></category>

		<guid isPermaLink="false">http://patrick.vande-walle.eu/?p=272</guid>
		<description><![CDATA[I recently switched to a new position in my day job. I moved to another campus and office, where I found on my desk a computer with the default standard configuration. The default browser in this configuration is Internet Explorer 6. I am still in a state of shock. Over the last four years in [...]]]></description>
			<content:encoded><![CDATA[<p>I recently switched to a new position in my day job. I moved to another campus and office, where I found on my desk a computer with the default standard configuration. The default browser in this configuration is Internet Explorer 6.</p>
<p>I am still in a state of shock. Over the last four years in my previous position, I had been using <a target="_blank "href="http://www.mozilla.com/en-US/firefox/">Firefox</a> as my main browser, mostly because of <a target="_blank href="https://addons.mozilla.org/en-US/firefox/addon/1865">AdblockPlus</a>, a remarkably efficient advertisement blocker.  </p>
<p>With IE6, I have rediscovered how advertising on web sites can be distracting and invading. Suddenly, the pop-up windows, Flash animations and other nasties are there again.  Unlike a paper magazine, when you only need to turn the page to ignore them, advertisements on web sites really prevent you to work until you close the pop-up window, stop the animation, turn off the volume, etc. </p>
<p>I guess one could say that Wladimir Palant, the developer of Adblock Plus,  is one of the greatest benefactors to computer productivity over the last few years. Thanks, mate. Great job. I am forever grateful.</p>
]]></content:encoded>
			<wfw:commentRss>http://patrick.vande-walle.eu/internet/missing-firefox-badly/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Luxembourgish humor</title>
		<link>http://patrick.vande-walle.eu/real-life/luxembourgish-humor/</link>
		<comments>http://patrick.vande-walle.eu/real-life/luxembourgish-humor/#comments</comments>
		<pubDate>Wed, 19 Dec 2007 19:26:28 +0000</pubDate>
		<dc:creator>Patrick Vande Walle</dc:creator>
				<category><![CDATA[Luxembourg]]></category>
		<category><![CDATA[Real life]]></category>

		<guid isPermaLink="false">http://patrick.vande-walle.eu/real-life/luxembourgish-humor/</guid>
		<description><![CDATA[Found in an office of the Luxembourg Ministry of Finance: For those who do not read French, it says: &#8220;The seat opening is 29 X 23 cm wide. If you miss the hole, please use the brush to clean. This brush is not a toothbrush&#8221; &#160; &#160;]]></description>
			<content:encoded><![CDATA[<p>Found in an office of the Luxembourg Ministry of Finance:</p>
<p><a href="http://patrick.vande-walle.eu//uploads/2007/12/19122007-small.jpg" title="19122007-small.jpg"></a></p>
<p style="text-align: center"><a href="http://patrick.vande-walle.eu//uploads/2007/12/19122007-small.jpg" title="19122007-small.jpg"><img src="http://patrick.vande-walle.eu//uploads/2007/12/19122007-small.jpg" alt="19122007-small.jpg" border="0" /> </a></p>
<p>For those who do not read French, it says: &#8220;The seat opening is 29 X 23 cm wide. If you miss the hole, please use the brush to clean. This brush is <strong>not</strong> a toothbrush&#8221;</p>
<p align="left">&nbsp;</p>
<p style="text-align: center">&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://patrick.vande-walle.eu/real-life/luxembourgish-humor/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
