<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The Next Net</title>
	<atom:link href="http://patrick.vande-walle.eu/feed/" rel="self" type="application/rss+xml" />
	<link>http://patrick.vande-walle.eu</link>
	<description>Random thoughts about the Internet and life</description>
	<lastBuildDate>Wed, 25 Apr 2012 20:19:09 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
		<item>
		<title>Mac OS X Lion first impressions</title>
		<link>http://patrick.vande-walle.eu/real-life/mac-os-x-lion-first-impressions/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=mac-os-x-lion-first-impressions</link>
		<comments>http://patrick.vande-walle.eu/real-life/mac-os-x-lion-first-impressions/#comments</comments>
		<pubDate>Wed, 27 Jul 2011 10:00:49 +0000</pubDate>
		<dc:creator>Patrick Vande Walle</dc:creator>
				<category><![CDATA[Apple MacBook]]></category>
		<category><![CDATA[Real life]]></category>
		<category><![CDATA[Software]]></category>

		<guid isPermaLink="false">http://patrick.vande-walle.eu/?p=1319</guid>
		<description><![CDATA[I have been using Mac OS X Lion for two days now. This is fresh enough to remember the issues I encountered when installing. Installation It took me several tries to find an installation method that worked for me. In the end, the successful method was : Download the Lion image Open the image (right-click, [...]]]></description>
			<content:encoded><![CDATA[<p>I have been using Mac OS X Lion for two days now. This is fresh enough to remember the issues I encountered when installing.</p>
<h2>Installation</h2>
<p>It took me several tries to find an installation method that worked for me. In the end, the successful method was :</p>
<ol>
<li>Download the Lion image</li>
<li>Open the image (right-click, Show Package Contents) and extract installESD.dmg</li>
<li>With Disk Utility, burn installESD.dmg on a DVD disk. This makes it bootable.</li>
<li>Restart the Mac, press Command, Option, P, R at boot time to <a href="http://www.google.com/url?sa=t&amp;source=web&amp;cd=1&amp;ved=0CBcQFjAA&amp;url=http%3A%2F%2Fsupport.apple.com%2Fkb%2Fht1379&amp;rct=j&amp;q=Command%2C%20Option%2C%20P%2C%20R&amp;ei=jqwvTs2OEY-fOsX-7H4&amp;usg=AFQjCNGz7_mnBE0v5zuZ_JAS_ztiNlC-WA&amp;sig2=Xj5FL7HbJuk4aOPKoZ6H8Q&amp;cad=rja" target="_blank">reset the PRAM</a></li>
<li>Boot from the Lion DVD. It takes 5 minutes to load.</li>
<li>Go to the Disk Utility and Repair permissions</li>
<li>Reboot again from DVD</li>
<li>Install Lion from DVD and take a 35 minutes coffee break</li>
</ol>
<p>I followed <a href="http://holgr.com/blog/2011/02/creating-a-bootable-os-x-10-7-lion-disc/" target="_blank">this guide</a> to create the DVD. It could as well be put on a USB stick, but it needs to be one larger than 4Gb.</p>
<h2>Usage experience</h2>
<p>Quite strangely, it seems that the Java VM was not part of the standard installation. When I accessed a web site requring  Java, OS X kindly offered to download and install it. I restarted the browser and could continue.</p>
<p>Mail.app is an application which is central for me. On first launch, it took one hour to rebuild my (very large) mailboxes. The new three column display is most welcome. I used to use <a href="http://widemailplugin.com/">Widemail</a> to achieve this same result in earlier versions. At first, the folder list was hidden. When restored (click &#8220;Show&#8221; on the second button bar), it was displayed with large characters, pretty inconvenient with a 13&#8243; laptop screen. Quite strangely, this cannot be adjusted through the Mail.app preferences. You need to go to the System Preferences/General, and adjust the Sidebar icon size. This will also change the value for the Finder windows.</p>
<p>As I expected, <a href="http://www.gpgtools.org/" target="_blank">GPGTools</a>  does not work anymore with the new Mail.app. According to the developers, work is underway to restore the compatibility with the new Mail.app version.</p>
<p>Mission Control replaces the Spaces app for those virtual desktops. It works a bit differently, but it just requires getting used to.</p>
<p>The IPv6 stack has a new version number, dated 2009. The previous one was ten years old. I failed to notice any new feature, though. No DHCPv6, and no GUI option to set the IPv6 Privacy Extensions. By default, it is off. To turn it on requires<a href="http://www.whatismyipv6.com/blogs/macipv6/wordpress/?p=55" target="_blank"> editing a configuration file</a>. Whether those privacy extensions are a good or bad idea is another debate.</p>
<p>The mouse or trackpad behaves in the opposite direction than it used to. Scrolling to the top requires to slide you fingers down on the trackpad. This can be changed in the System Prefererences/Trackpad, first option.</p>
<p><a href="http://patrick.vande-walle.eu/uploads/2011/07/trackpad.png"><img class="wp-image-1325 aligncenter" title="trackpad" src="/uploads/2011/07/trackpad.png" alt="" width="625" height="44" /></a></p>
<p>Other than that, I did not notice major differences. This may explain why the new OS X version still runs happily on a 5 year old MacBook, with 2 Gb of RAM. Apple continues its strategy to make you a captive consumer. FaceTime and Apple Store are linked to your AppleID.</p>
<p>In the end, was the upgrade worth it ? Frankly, the new features in Lion are not something the world has been waiting for anxiously. There is  no compelling reason to upgrade.</p>
<p><em>Update: after 2 weeks of use, I notice that Lion is slower on the average than Snow Leopard was. After adding 2Gb of RAM to my Macbook, I regained most of the lost speed.</em></p>
]]></content:encoded>
			<wfw:commentRss>http://patrick.vande-walle.eu/real-life/mac-os-x-lion-first-impressions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Google Analytics for WordPress &#8211; IPv6 version</title>
		<link>http://patrick.vande-walle.eu/internet/google-analytics-injector-for-wordpress-ipv6-version/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=google-analytics-injector-for-wordpress-ipv6-version</link>
		<comments>http://patrick.vande-walle.eu/internet/google-analytics-injector-for-wordpress-ipv6-version/#comments</comments>
		<pubDate>Mon, 23 May 2011 11:12:04 +0000</pubDate>
		<dc:creator>Patrick Vande Walle</dc:creator>
				<category><![CDATA[Internet]]></category>
		<category><![CDATA[IPv6]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[APNIC]]></category>
		<category><![CDATA[Wordpress]]></category>
		<category><![CDATA[World IPv6 Day]]></category>

		<guid isPermaLink="false">http://patrick.vande-walle.eu/?p=1295</guid>
		<description><![CDATA[Ahead of the World IPv6 day,  APNIC has launched an useful initiative to collect statistics regarding IPv6 connectivity. If you are interested in testing your clients&#8217; IPv6 capabilities, you can use the APNIC Labs Google Analytics Tracking Code. This allows you to test your customers&#8217; experiences connecting to your website via IPv4, IPv6, and dual-stack. [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://patrick.vande-walle.eu/uploads/2011/05/world-ipv6-day1.png"><img class="alignleft size-thumbnail wp-image-1306" title="world-ipv6-day" src="/uploads/2011/05/world-ipv6-day1-150x150.png" alt="" width="90" height="90" /></a></p>
<p><a title="World IPv6 day" href="http://isoc.org/wp/worldipv6day">Ahead of the World IPv6 day</a>,  <a title="IPv6 Tracker" href="http://labs.apnic.net/index.shtml">APNIC has launched an useful initiative to collect statistics regarding IPv6 connectivity</a>. If you are interested in testing your clients&#8217; IPv6 capabilities, you can use the APNIC Labs Google Analytics Tracking Code. This allows you to test your customers&#8217; experiences connecting to your website via IPv4, IPv6, and dual-stack.</p>
<p>The APNIC code relies on Google Analytics. If you are using Google Analytics as a plugin in your WordPress blog, you might be interested in the versions I hacked together to integrate APNIC&#8217;s code into the following two popular plugins:</p>
<table>
<tbody>
<tr>
<td>-</td>
<td><a href="http://wordpress.org/extend/plugins/google-analytics-injector/">Google Analytics Injector for WordPress</a></td>
<td><a title="google-analytics-injector.zip" href="http://patrick.vande-walle.eu/upload/google-analytics-injector.zip">Download the updated version here</a> (version 1.0.1-ipv6)</td>
</tr>
<tr>
<td>-</td>
<td><a href=" http://yoast.com/wordpress/google-analytics/">Google Analytics for WordPress</a></td>
<td><a title="google-analytics-for-wordpress-ipv6.zip" href="http://patrick.vande-walle.eu/upload/google-analytics-for-wordpress-ipv6.zip">Download the updated version here</a> (version 4.2.4-ipv6)</td>
</tr>
</tbody>
</table>
<p>You will need a tracking code that you can obtain at the <a href="http://labs.apnic.net/tracker.shtml">APNIC</a> labs web site.</p>
<p>Note this is not a discussion on  whether Google Analytics is Big Brotherian. Many web sites rely on it to collect statistics. I thought it might be helpful if a WordPress plugin existed that supports the APNIC feature.</p>
]]></content:encoded>
			<wfw:commentRss>http://patrick.vande-walle.eu/internet/google-analytics-injector-for-wordpress-ipv6-version/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Fritz!Box WLAN 7390 review</title>
		<link>http://patrick.vande-walle.eu/hardware/fritzbox-7390/review/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=review</link>
		<comments>http://patrick.vande-walle.eu/hardware/fritzbox-7390/review/#comments</comments>
		<pubDate>Mon, 03 Jan 2011 09:32:17 +0000</pubDate>
		<dc:creator>Patrick Vande Walle</dc:creator>
				<category><![CDATA[Fritz!Box 7390]]></category>
		<category><![CDATA[7390]]></category>
		<category><![CDATA[Belgacom]]></category>
		<category><![CDATA[DNSSEC]]></category>
		<category><![CDATA[Fritz!Box]]></category>
		<category><![CDATA[IPv6]]></category>
		<category><![CDATA[VDSL2]]></category>

		<guid isPermaLink="false">http://patrick.vande-walle.eu/?p=1093</guid>
		<description><![CDATA[I finally got a AVM Fritz!Box WLAN 7390 modem/router to replace the Belgacom-provided BBOX-2, which gave me a few headaches and quite some frustration over the past year. I am happy to report that the Fritz works with Belgacom VDSL2, despite what Belgacom says about the mandatory use of their own broken modem.  Let&#8217;s get [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://patrick.vande-walle.eu/uploads/2010/12/fritz-7390-icon.jpg"><img class="alignleft size-full wp-image-1095" style="border: 0pt none; margin: 20px;" title="fritz-7390-icon" src="/uploads/2010/12/fritz-7390-icon.jpg" alt="" width="86" height="38" /></a><a href="http://patrick.vande-walle.eu/uploads/2011/01/Fritz-DSL2.jpg"><img class="alignright size-thumbnail wp-image-1118" style="margin: 10px;" title="Fritz-DSL2" src="/uploads/2011/01/Fritz-DSL2-150x150.jpg" alt="" width="150" height="150" /></a></p>
<p>I finally got a <a href="http://www.avm.de/en/Produkte/FRITZBox/FRITZ_Box_Fon_WLAN_7390/index.php" target="_blank">AVM Fritz!Box WLAN 7390</a> modem/router to replace the Belgacom-provided BBOX-2, which gave me a <a href="http://patrick.vande-walle.eu/internet/bbox-2/belgacoms-bbox-2/" target="_blank">few headaches</a> and quite <a href="http://patrick.vande-walle.eu/internet/bbox-2/belgacoms-bbox2-wastes-resources/" target="_blank">some frustration</a> over the past year.<strong> I am happy to report that the Fritz works with Belgacom VDSL2</strong>, despite what Belgacom says about the mandatory use of their own broken modem.  Let&#8217;s get to the real meat. Some background first.<span id="more-1093"></span></p>
<h3>AVM, the company</h3>
<p>AVM is the premier xDSL modem manufacturer in Germany. Besides the ones they sell under their own brand, they do quite a lot of OEM manufacturing for telcos:  <a href="http://dsl.1und1.de" target="_blank">1&amp;1</a>, <a href="http://www.telekom.de/is-bin/INTERSHOP.enfinity/WFS/EKI-PK-Site/-/-/-/ViewProductDetails-Start;sid=Q0C-20znCQm-2wHoWaOvb0fizR7dxNv-lYpXnNzG_gnnMgPX2NUpbU2jQ8Z5OA==?ProductRefID=0304021000172%40EKI-PK&amp;StageProductRefID=0304021000172_0002%40EKI-PK&amp;CatalogCategoryID=vPUFC7ITCHEAAAEd6oRTq_zF#" target="_blank">Deutsche Telekom</a> in Germany, <a href="http://www.pt.lu/portal/op/preview/lang/en/telecom/pid/543" target="_blank"><a target="_blank" href="http://www.pt.lu">P&amp;T</a></a> in Luxembourg and XS4ALL in the Netherlands.<a href="http://www.xs4all.nl/consument/internetbellen/fritzbox.php" target="_blank"> XS4ALL</a> launched earlier this year a native IPv6 service for their residential customers based on the Fritz 7340 modem, a scaled down version of the 7390.</p>
<p>The Fritz 7390 was first announced at <a href="http://www.avm.de/de/Presse/Informationen/2009/2009_01_21.php3" target="_blank">CEBIT 2009</a>. It seems that AVM suffers from the &#8220;CEBIT announcement&#8221; syndrome. At the time, the 7390 was merely vapourware, in that the actual delivery only started nearly a year later in Germany. It took them also a lot of time to deliver a firmware that actually lived up to the promises. The international version was only delivered in september 2010. It was only last December 2010 that a <a href="ftp://ftp.avm.de/fritz.box/fritzbox.fon_wlan_7390/firmware/english/" target="_blank">firmware version was released</a> that included &#8220;full support of IPv6&#8243; (announced two years earlier) and compatibility with Belgacom&#8217;s VDSL2 network.</p>
<p>Yet, the AVM company is quite serious in implementing standards. For example, they are the only CPE manufacturer I know that attends <a href="http://www.ripe.net/ripe/meetings/ripe-59/presentations/schoellhammer-v6-at-home.pdf" target="_blank">RIPE meetings</a>. The latest firmware implements DNSSEC in the local resolver, where most other CPE manufacturers could not care less.</p>
<h3>The Fritz!Box 7390</h3>
<p><a href="http://patrick.vande-walle.eu/uploads/2011/01/Fritz-overview.jpg"><img class="alignleft size-thumbnail wp-image-1111" style="margin: 10px; border: 0px solid black;" title="Fritz-overview" src="/uploads/2011/01/Fritz-overview-150x150.jpg" alt="" width="150" height="150" /></a><br />
As mentioned previously, the modem supports Belgacom&#8217;s VDSL2 network. At installation time, a wizard lets you select the right option according to your needs (Belgacom Internet or Belgacom Internet + TV).  Once you have added your PPoE credentials, the box is ready to go.<br />
The real power of the Fritz are the thousands options that allow you to customize it to your needs.</p>
<p>Integrated telephony has been a powerful feature of the AVM boxes over the years. This one does it again, only better. It features a built-in DECT base station. You can also place VoIP phone calls directly from an iPhone or Android phone, and use the built-in phone directory. The PABX inside the Fritz will forward the calls through PSTN or a number of VoIP providers based on the rules you set.</p>
<p>The support for IPv6 was the main reason I bought this modem.  Here again, the Fritz 7390 delivers. It can use native IPv6 (in the unlikely case your ISP supports it) and tunnels (6to4, SixXS, and others). <a href="http://patrick.vande-walle.eu/uploads/2011/01/fritz-ipv6-config.jpg"><img class="alignright size-thumbnail wp-image-1105" style="margin: 10px;" title="fritz-ipv6-config" src="/uploads/2011/01/fritz-ipv6-config-150x150.jpg" alt="" width="150" height="150" /></a> <a href="http://patrick.vande-walle.eu/uploads/2011/01/fritz-ipv6-config.jpg" target="_blank">Screenshot</a></p>
<p>WLAN can be both on the 2.4 Ghz and the 5 Ghz bands at the same time, with different SSIDs if you like. This may be helpful in an area with a crowded WLAN environment. It can do WIFI-N, up to 300 Mbps.  It makes a real difference. You can also setup a separate WLAN for the guests visiting your home, with a different SSID. Hence, you won&#8217;t have to give them the <a target="_blank" href="http://en.wikipedia.org/wiki/Wi-Fi_Protected_Access">WPA2</a> password to your home LAN. Further, the guests will get access to the Internet, but not to the local LAN.</p>
<p>The Fritz can also serve as a NAS for the local network. There are two USB ports. You can attach a hard disk or a memory stick and make them available to the LAN and/or the Internet. The BBox-2 also has a USB port, but it was castrated by Belgacom. You could also attach a USB printer to the Fritz, and share it among the users. Some restrictions may apply in this case. Not all USB printers can be used this way.</p>
<h3>Real life experience</h3>
<p>A small gotcha to begin with: When setting up the modem for the first time, tell the setup wizard that you use an Annex-B line (aka ISDN), even if you are actually using an analog telephone line. It seems Belgacom uses Annex-B signalling for VDSL2, irrespective of the actual type of the line.</p>
<p>After using the Fritz!Box for two weeks, I am happy to see it is much more stable than the BBox-2. The random disconnects I experienced on the WIFI are not happenning with the Fritz.  The random reboots of the BBox-2 too, obviously.</p>
<p>IPv6 works fine. The SixXS tunnel is stable. The Fritz uses router advertisements to allow <a href="http://www.ietf.org/rfc/rfc2462.txt" target="_blank">IPv6 autoconfiguration</a>. This works fine with Macs, Linux and  Windows boxes,  as well as Android phones. It can also announce DNS servers though RA (<a href="http://www.rfc-editor.org/rfc/rfc5006.txt" target="_blank">RFC 5006</a>).</p>
<p>One minor complaint about the Fritz!Boxes, that I also had with the previous models, is the inability to configure the DNS servers through the GUI. This would be most welcome. Most ISPs&#8217; DNS servers are broken in one way or another, and <a href="http://patrick.vande-walle.eu/internet/ipv6/belgacom-dns-resolvers-no-edns/" target="_blank">Belgacom&#8217;s are no different</a>.<br />
Changing from the default DNS servers assigned through the provider&#8217;s DHCP can be achieved  by editing the ar7.cfg file. I will post a more detailed HOWTO later on. Suffice to say that you should look for the  &#8220;overwrite_dns1[1,2]&#8221; values.  You can either</p>
<ul>
<li>start a telnet session to the box and edit the file with nvi</li>
<li>use a Java tool like FBEditor (<a href="http://patrick.vande-walle.eu/uploads/2011/01/FBEditor-0.5.2.zip">local mirror here</a>).</li>
</ul>
<p>Right now, it seems that IPv6 addresses for name servers are not supported by the Fritz.</p>
<p><em>Update April 2012: firmware version  84.05.21 now offers a GUI interface to change both IPv4 and IPv6 DNS servers.</em></p>
<p>All in all, the AVM Fritz!Box WLAN 7390 is a highly recommended CPE, worth every eurocent you paid for.</p>
]]></content:encoded>
			<wfw:commentRss>http://patrick.vande-walle.eu/hardware/fritzbox-7390/review/feed/</wfw:commentRss>
		<slash:comments>105</slash:comments>
		</item>
		<item>
		<title>GLD-NG, a greylisting daemon for Postfix</title>
		<link>http://patrick.vande-walle.eu/software/gld-ng-a-greylisting-daemon/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=gld-ng-a-greylisting-daemon</link>
		<comments>http://patrick.vande-walle.eu/software/gld-ng-a-greylisting-daemon/#comments</comments>
		<pubDate>Tue, 07 Dec 2010 06:31:12 +0000</pubDate>
		<dc:creator>Patrick Vande Walle</dc:creator>
				<category><![CDATA[Software]]></category>
		<category><![CDATA[GLD]]></category>
		<category><![CDATA[greylisting]]></category>
		<category><![CDATA[PostgreSQL]]></category>

		<guid isPermaLink="false">http://patrick.vande-walle.eu/?p=1077</guid>
		<description><![CDATA[GLD-NG is a new project I started on Sourceforge.  My goal was to aggregate the features I found most interesting in other greylisting software. Greylisting is a very effective technique to fight spam, especially the one originating from zombie PCs controlled by spambots. What is gld-ng ? gld-ng stands for GreyList Daemon, new generation. gld-ng [...]]]></description>
			<content:encoded><![CDATA[<div>
<p><a href="https://sourceforge.net/projects/gld-ng/" target="_blank">GLD-NG is a new project I started on Sourceforge</a>.  My goal was to aggregate the features I found most interesting in other greylisting software. <a href="http://en.wikipedia.org/wiki/Greylisting">Greylisting</a> is a very effective technique to fight spam, especially the one originating from zombie PCs controlled by spambots.</p>
<h2>What is gld-ng ?</h2>
<p>gld-ng stands for GreyList Daemon, new generation. gld-ng is a standalone policy delegation server for <a target="_blank" href="http://www.postfix.org">Postfix</a> that implements <a href="http://en.wikipedia.org/wiki/Greylisting">greylisting</a>. It is based on the <a href="http://www.gasmi.net/progs.php">GLD project</a>, originated by Salim Gasmi.<br />
<span id="more-1077"></span></p>
<h2>What makes gld-ng different from other greylisting servers ?</h2>
<p>gld-ng implements the author’s vision of how the ideal greylisting daemon. Obviously, this may or may not suit your needs.</p>
<p>Over the years, the author has used a variety of greylisting daemons.  All had different shortcomings. Which is why he tried to come up with  his own. The basic design requirements were the following:</p>
<ul>
<li><strong>It should handle IPv6 connections</strong>:  with the  complete exhaustion of IPv4 addresses arriving soon, mail servers will  need to support IPv6. Unfortunately, spambots will adapt, too. Hence,  the greylisting daemon needs to support IPv6.</li>
<li><strong>It should have a small memory footprint</strong>: let’s face  it, greylisting should not be using your server’s memory too much.  Daemons written in interpreted languages, like Perl, tend to use quite a  lot of memory. This one is written in C.</li>
<li><strong>It should use a database</strong>: While reviewing possible databases for this project, we settled with <a href="http://www.postgresql.org/"><a target="_blank" href="http://www.postgresql.org">PostgreSQL</a></a>.  The main reason is that PgSQL is unique in the way it can handle IP  addresses. It does feature data types for IP address and CIDR ranges and  has specific operators to work with them. Because it is network-based,  the database can be shared among multiple mail servers, making it  scalable. This is not to say that <a target="_blank" href="http://www.mysql.com">MySQL</a>, <a target="_blank" href="http://www.sqlite.org">SQLite</a> or other databases are  bad. However, PgSQL fits our needs best.</li>
</ul>
<p>As usual with FOSS, reusing what others have done previously is a good way of not reinventing the wheel. Credit is thus due to Salim Gasmi, the original author and Folkert Vanheusden, from whom I took the GUI layout of his web interface to SQLGrey.</p>
<p>Sourceforge offers a complete environment to manage this kind of projects, so I will not be blogging too much about GLD-NG here. If you are interested in enhancing the program,<a href="https://sourceforge.net/projects/gld-ng/"> join me on Sourceforge</a>.</p>
</div>
]]></content:encoded>
			<wfw:commentRss>http://patrick.vande-walle.eu/software/gld-ng-a-greylisting-daemon/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Belgacom DNS resolvers lack EDNS support</title>
		<link>http://patrick.vande-walle.eu/internet/ipv6/belgacom-dns-resolvers-no-edns/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=belgacom-dns-resolvers-no-edns</link>
		<comments>http://patrick.vande-walle.eu/internet/ipv6/belgacom-dns-resolvers-no-edns/#comments</comments>
		<pubDate>Sun, 15 Aug 2010 11:10:50 +0000</pubDate>
		<dc:creator>Patrick Vande Walle</dc:creator>
				<category><![CDATA[BBox-2]]></category>
		<category><![CDATA[Belgium]]></category>
		<category><![CDATA[DNS]]></category>
		<category><![CDATA[IPv6]]></category>

		<guid isPermaLink="false">http://patrick.vande-walle.eu/?p=986</guid>
		<description><![CDATA[The DNS resolvers used by default by Belgacom&#8217;s Internet customers lack EDNS support, according  to the test performed from OARC&#8217;s DNS Reply Size Test Server hiram$ dig +short rs.dns-oarc.net txt @195.238.2.21 rst.x476.rs.dns-oarc.net. rst.x485.x476.rs.dns-oarc.net. rst.x490.x485.x476.rs.dns-oarc.net. "195.238.24.113 DNS reply size limit is at least 490" "195.238.24.113 lacks EDNS, defaults to 512" "Tested at 2010-08-15 11:00:01 UTC" hiram$ [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://patrick.vande-walle.eu/uploads/2010/08/belgacom-logo.jpg"><img class="alignleft size-full wp-image-1040" style="margin: 10px;" title="belgacom-logo" src="/uploads/2010/08/belgacom-logo.jpg" alt="" width="50" height="50" /></a>The DNS resolvers used by default by Belgacom&#8217;s Internet customers lack EDNS support, according  to the test performed from <a href="https://www.dns-oarc.net/oarc/services/replysizetest" target="_blank">OARC&#8217;s DNS Reply Size Test Server</a></p>
<pre>hiram$ dig +short rs.dns-oarc.net txt @195.238.2.21
rst.x476.rs.dns-oarc.net.
rst.x485.x476.rs.dns-oarc.net.
rst.x490.x485.x476.rs.dns-oarc.net.
"195.238.24.113 DNS reply size limit is at least 490"
"195.238.24.113 lacks EDNS, defaults to 512"
"Tested at 2010-08-15 11:00:01 UTC"

hiram$ dig +short rs.dns-oarc.net txt @195.238.2.22
rst.x476.rs.dns-oarc.net.
rst.x485.x476.rs.dns-oarc.net.
rst.x490.x485.x476.rs.dns-oarc.net.
"195.238.25.113 DNS reply size limit is at least 490"
"195.238.25.113 lacks EDNS, defaults to 512"
"Tested at 2010-08-15 11:00:11 UTC</pre>
<p><span id="more-986"></span>Hence, if you expect correct DNSSEC or IPv6 responses, you would be better off using alternative DNS resolvers, like <a title="OARC's Open DNSSEC Validating Resolver " href="https://www.dns-oarc.net/oarc/services/odvr" target="_blank">OARC</a> . Obviously, the Belgacom DNS resolvers do not return RRSIG records and do not set the AD bit. This is very disappointing, given that <a href="http://www.root-dnssec.org/2010/07/16/status-update-2010-07-16/" target="_blank">the DNS root is now cryptographically signed</a> and so are several top level domains also. It is difficult to believe, a company claiming to be the number one ISP in Belgium is unable to implement a 11 year old standard defined in <a title="Extension Mechanisms for DNS (EDNS0) - August 1999" href="http://www.ietf.org/rfc/rfc2671.txt" target="_blank">RFC2671</a>, and a standard feature in all DNS resolver software since then.</p>
<p>The good news is that their BBOX-2 modem can proxy a EDNS query and response, when used with correctly configured DNS resolvers. As demonstrated below, the AD bit is set, meaning the DNSSEC response is valid.</p>
<pre>; &lt;&lt;&gt;&gt; DiG 9.6.0-APPLE-P2 &lt;&lt;&gt;&gt; +dnssec +multiline -t ns gov. @XXX.XXX.XXX.XXX
;; global options: +cmd
;; Got answer:
;; -&gt;&gt;HEADER&lt;&lt;- opcode: QUERY, status: NOERROR, id: 46617
;; flags: qr rd ra <strong>ad</strong>; QUERY: 1, ANSWER: 8, AUTHORITY: 0, ADDITIONAL: 1

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags: do; <strong>udp: 4096</strong></pre>
]]></content:encoded>
			<wfw:commentRss>http://patrick.vande-walle.eu/internet/ipv6/belgacom-dns-resolvers-no-edns/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Showing future posts in WordPress RSS feeds</title>
		<link>http://patrick.vande-walle.eu/software/showing-future-posts-in-wordpress-rss-feeds/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=showing-future-posts-in-wordpress-rss-feeds</link>
		<comments>http://patrick.vande-walle.eu/software/showing-future-posts-in-wordpress-rss-feeds/#comments</comments>
		<pubDate>Sun, 11 Jul 2010 15:04:03 +0000</pubDate>
		<dc:creator>Patrick Vande Walle</dc:creator>
				<category><![CDATA[Software]]></category>
		<category><![CDATA[Atom]]></category>
		<category><![CDATA[Future posts]]></category>
		<category><![CDATA[PHP]]></category>
		<category><![CDATA[RSS]]></category>
		<category><![CDATA[Wordpress]]></category>

		<guid isPermaLink="false">http://patrick.vande-walle.eu/?p=964</guid>
		<description><![CDATA[I have a web site which announces future events. In WordPress, you would adapt the publish date of the  post to suit the event&#8217;s start date. All is good on the web site itself. I use the c2c_get_upcoming_posts plugin to display them on the front page, but there are other ways. The RSS feed is [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://patrick.vande-walle.eu/uploads/2010/07/wp-logo.png"><img class="alignleft size-full wp-image-1038" style="margin: 10px;" title="WordPress Logo" src="/uploads/2010/07/wp-logo.png" alt="" width="32" height="32" /></a>I have a <a href="http://www.isoc.lu" target="_blank">web site which announces future events</a>. In WordPress, you would adapt the publish date of the  post to suit the event&#8217;s start date. All is good on the web site itself. I use the<a href="http://coffee2code.com/wp-plugins/get-upcoming-or-past-posts/" target="_blank"> c2c_get_upcoming_posts</a> plugin to display them on the front page, but there are other ways.</p>
<p>The RSS feed is another matter. By default, WordPress only shows those posts which are current to date. Later posts are not visible, which defeats a bit the purpose of announcing an event. If the readers following the RSS feed are only informed on the day of the event, it is of little help.</p>
<p>I added the following function to the functions.php file (in the WordPress theme folder) to show future posts.</p>
<pre class="brush: php">function include_calendar_posts($where) {
global $wpdb;
if ( is_feed() ){
// add SQL-syntax to default $where
$where .= &quot; OR $wpdb-&gt;posts.post_status = &#039;future&#039; &quot; ;
}
return $where;
}
add_filter(&#039;posts_where&#039;,&#039;include_calendar_posts&#039;);</pre>
]]></content:encoded>
			<wfw:commentRss>http://patrick.vande-walle.eu/software/showing-future-posts-in-wordpress-rss-feeds/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Belgacom&#8217;s BBOX2 wastes resources</title>
		<link>http://patrick.vande-walle.eu/hardware/bbox-2/belgacoms-bbox2-wastes-resources/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=belgacoms-bbox2-wastes-resources</link>
		<comments>http://patrick.vande-walle.eu/hardware/bbox-2/belgacoms-bbox2-wastes-resources/#comments</comments>
		<pubDate>Fri, 09 Apr 2010 11:58:22 +0000</pubDate>
		<dc:creator>Patrick Vande Walle</dc:creator>
				<category><![CDATA[BBox-2]]></category>
		<category><![CDATA[BBox2]]></category>
		<category><![CDATA[Belgacom]]></category>
		<category><![CDATA[VDSL2]]></category>

		<guid isPermaLink="false">http://patrick.vande-walle.eu/?p=831</guid>
		<description><![CDATA[Belgacom, we have (yet another ) problem with your BBox2 modem. A background management daemon like TR-98  just cannot be allowed to use 96% CPU all the time, even when doing nothing. Please fix this, or fire your supplier. Further, I do not use your SIP service, so please give me a way to disable [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://patrick.vande-walle.eu/uploads/2010/04/bbox-2-thumb.jpg"><img class="alignleft size-full wp-image-1031" style="margin: 10px;" title="bbox-2-thumb" src="/uploads/2010/04/bbox-2-thumb.jpg" alt="" width="60" height="45" /></a>Belgacom, we have (yet another ) problem with your BBox2 modem.</p>
<p>A background management daemon like TR-98  just cannot be allowed to use 96% CPU all the time, even when doing nothing. Please fix this, or fire your supplier.</p>
<p>Further, I do not use your SIP service, so please give me a way to disable the sipd process. It uses 48% of the available memory.</p>
<p>This is not an efficient use of resources and certainly not &#8220;green&#8221;.<span id="more-831"></span></p>
<p><a href="http://patrick.vande-walle.eu/uploads/2010/04/bbox2-tr98.png"><img class="aligncenter size-full wp-image-830" title="bbox2-tr98" src="/uploads/2010/04/bbox2-tr98.png" alt="" width="596" height="396" /></a></p>
<p>Update 19 June: After following Ced&#8217;s advice below, I killed the sipd, tr69 and tr98 processes and got the following results</p>
<p style="text-align: center;"><a href="http://patrick.vande-walle.eu/uploads/2010/04/BBOX2-screenshot21.png"><img class="size-full wp-image-923 alignnone" style="margin-left: 30px; margin-right: 30px;" title="BBOX2-screenshot2" src="/uploads/2010/04/BBOX2-screenshot21.png" alt="" width="538" height="402" /></a></p>
<p>As you can see, more memory is freed and the average load has been divided by two.</p>
<p style="text-align: left;">[Update  17/12/2010] Obviously, if you are using either Belgacom or another provider&#8217;s SIP service, do not kill the sipd processes.</p>
]]></content:encoded>
			<wfw:commentRss>http://patrick.vande-walle.eu/hardware/bbox-2/belgacoms-bbox2-wastes-resources/feed/</wfw:commentRss>
		<slash:comments>27</slash:comments>
		</item>
		<item>
		<title>HADOPI version belge, une fois</title>
		<link>http://patrick.vande-walle.eu/internet/hadopi-version-belge-une-fois/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=hadopi-version-belge-une-fois</link>
		<comments>http://patrick.vande-walle.eu/internet/hadopi-version-belge-une-fois/#comments</comments>
		<pubDate>Wed, 10 Feb 2010 13:49:54 +0000</pubDate>
		<dc:creator>Patrick Vande Walle</dc:creator>
				<category><![CDATA[Belgium]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[Belgique]]></category>
		<category><![CDATA[HADOPI]]></category>
		<category><![CDATA[MR]]></category>

		<guid isPermaLink="false">http://patrick.vande-walle.eu/?p=776</guid>
		<description><![CDATA[Dans un article précédent, j&#8217;analysais les faibles de la proposition ECOLO/Groen! de taxe forfaitaire  sur les connexions Internet pour &#8220;dédouaner&#8221; le téléchargement illégal.  Il y a aussi une autre &#8220;proposition de loi visant à promouvoir la création culturelle sur Internet&#8221; du sénateur MR Philippe Monfils, qui vise à instaurer un système semblable à la loi [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://patrick.vande-walle.eu/internet/une-taxe-sur-internet-non-merci/">Dans un article précédent</a>, j&#8217;analysais les faibles de la proposition ECOLO/Groen! de taxe forfaitaire  sur les connexions Internet pour &#8220;dédouaner&#8221; le téléchargement illégal.  Il y a aussi une autre <a href="http://patrick.vande-walle.eu/uploads/2010/02/Proposition-Monfils.pdf">&#8220;proposition de loi visant à promouvoir la création culturelle sur Internet&#8221;</a> du sénateur MR Philippe Monfils, qui vise à instaurer un système semblable à la loi HADOPI en France. Il semble que les Belges soient forts pour copier ce qui se fait de plus mal à l&#8217;étranger. <span id="more-776"></span></p>
<p>Notons tout d&#8217;abord que dans le préambule Mr Monfils se base uniquement sur les données provenant de l&#8217;<a href="http://en.wikipedia.org/wiki/International_Federation_of_the_Phonographic_Industry" target="_blank">IFPI</a>, lobby des producteurs de disques, ainsi qu&#8217;un sondage réalisé par la Karel De Grote Hogeschool, auprès d&#8217;un échantillon dont on peut contester la représentativité. D&#8217;autres études, citées dans un article précédent contredisent ces conclusions, mais le sénateur ne juge pas utile de s&#8217;y référer.</p>
<p>La proposition de Mr Monfils souffre de problèmes semblables à la loi HADOPI. Tout d&#8217;abord, il convient d&#8217;établir l&#8217;infraction. En cette matière, Mr Monfils, qui est juriste de formation, n&#8217;ignore pas qu&#8217;un indice ne constitue pas une preuve. Le fait de télécharger de gros volumes mensuels n&#8217;est pas la démonstration de l&#8217;infraction. La proposition du sénateur ne fait pas référence aux moyens mis en oeuvre pour établir l&#8217;infraction. Sans doute cela relève-t-il d&#8217;un arrêté royal, mais c&#8217;est pourtant le noeud du problème.  Il faudrait intercepter tous les contenus des paquets IP qui passent pour pouvoir les analyser. Comme l&#8217; a démontré le <a href="http://www.tjmcintyre.com/2008/10/sabam-v-scarlet-belgian-isp-released.html" target="_blank">conflit juridique entre Scarlet et la SABAM</a>, les moyens techniques pour interpréter le contenu des flux IP, tels <a href="http://www.audiblemagic.com/index.asp" target="_blank">Audible Magic</a>,  ne sont pas  infaillibles.   Par ailleurs, ce serait une atteinte au respect de la vie privée et du secret de la correspondance prévu par la Constitution.</p>
<p>Si le flux est chiffré, il faudrait casser la clé de chiffrement pour extraire une information utile. Compte tenu du volume de données à traiter, c&#8217;est impossible dans l&#8217;état actuel. Bien que l&#8217;on soit parvenu à <a href="http://eprint.iacr.org/2010/006.pdf" target="_blank">casser certaines clés de 768 bits</a>, ces même spécialistes avouent que casser une clé de 1024 bits demanderait 1.000 fois plus de ressources.   Techniquement impossible et hors de prix pour un gouvernement dont les finances publiques vont à vau l&#8217;eau. et si le gouvernement essaie de faire passer la facture aux des fournisseurs d&#8217;accès, ils devraient augmenter de manière drastique le prix de l&#8217;abonnement mensuel, donc perdre des clients et accentuer la fracture numérique.</p>
<p>Repérer l&#8217;internaute sur base de l&#8217;adresse IP est également exclu.  Les adresses IP sont très souvent partagées.  Dans de nombreux environnements professionnels, seules une ou deux adresses IP sont publiques. Tous les flux vers l&#8217;extérieur transitent par ces adresses. Il peut y avoir de très nombreuses personnes derrière une adresse. C&#8217;est le cas des PME qui utilisent une connexion ADSL partagée. Mais il y a aussi de grandes entreprises dans le même cas.</p>
<p>En ce qui concerne les particuliers, le fait que de très nombreux modems xDSL aient un <a href="http://patrick.vande-walle.eu/internet/faille-de-securite-dans-500k-modems-belgacom/" target="_blank">accès WIFI complètement ouvert</a> rend impossible la démonstration que c&#8217;est bien le titulaire de l&#8217;abonnement qui est effectivement responsable du téléchargement.</p>
<p>Dans le modèle proposé par le sénateur Monfils, c&#8217;est une autorité administrative qui établit le constat.  Si le constat se base sur l&#8217;équation simpliste &#8220;volume de téléchargement important = piratage&#8221;, on fonce droit dans le mur. Dans ce cas, ce sera à l&#8217;internaute de faire la démonstration de son innocence,  et non à la puissance publique de démontrer sa culpabilité. On renverse donc la charge de la preuve. Nous serons tous des Joseph K.  Cela ne semble pas être une bonne interprétation du concept d&#8217; &#8220;Etat de Droit&#8221;.</p>
<p>Ce qui particulièrement énervant, tant de le cas de la proposition de Mr Monfils que dans celles d&#8217;ECOLO, c&#8217;est la fixation sur les téléchargements de musique , et accessoirement de vidéos. Peut-on supposer que le lobby des éditeurs de logiciels, la <a href="http://www.bsa.org/country.aspx?sc_lang=nl-BE" target="_blank">BSA</a>, n&#8217;a pas fait suffisamment de travail  de lobbying envers les sénateurs ?</p>
<p>En résumé, on ne peut que conseiller à monsieur Monfils de s&#8217;entourer de meilleurs conseillers, au risque de voir promulger une loi inapplicable.  Le bon usage des ressources publiques, c&#8217;est aussi éviter le travail parlementaire inutile.</p>
]]></content:encoded>
			<wfw:commentRss>http://patrick.vande-walle.eu/internet/hadopi-version-belge-une-fois/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Une taxe sur Internet: non merci</title>
		<link>http://patrick.vande-walle.eu/internet/une-taxe-sur-internet-non-merci/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=une-taxe-sur-internet-non-merci</link>
		<comments>http://patrick.vande-walle.eu/internet/une-taxe-sur-internet-non-merci/#comments</comments>
		<pubDate>Wed, 27 Jan 2010 08:45:04 +0000</pubDate>
		<dc:creator>Patrick Vande Walle</dc:creator>
				<category><![CDATA[Belgium]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[Belgique]]></category>
		<category><![CDATA[Ecolo]]></category>
		<category><![CDATA[Groen!]]></category>
		<category><![CDATA[HADOPI]]></category>
		<category><![CDATA[téléchargement]]></category>

		<guid isPermaLink="false">http://patrick.vande-walle.eu/?p=765</guid>
		<description><![CDATA[Ca devait arriver. Les Belges étant les champions du monde de la copie des mauvaises idées, voilà donc qu&#8217;arrivent deux propositions législatives sur le téléchargement illégal sur Internet. L&#8217;une des propositions émane du sénateur MR Philippe Monfils, et est basée sur le même concept que la loi HADOPI adoptée en France il y a quelques [...]]]></description>
			<content:encoded><![CDATA[<p>Ca devait arriver. Les Belges étant les champions du monde de la copie des mauvaises idées, voilà donc qu&#8217;arrivent deux propositions législatives sur le téléchargement illégal sur Internet. L&#8217;une des propositions émane du sénateur MR Philippe Monfils, et est basée sur le même concept que la loi HADOPI adoptée en France il y a quelques mois et entend combattre le téléchargement en criminalisant les usagers du Net. Je reviendrai sur les faiblesses de cette proposition dans un autre article.</p>
<p>Ce qui m&#8217;intéresse aujourd&#8217;hui, c&#8217;est la<a href="http://pra.im/648hwd" target="_blank"> proposition des sénateurs</a> Ecolo <a href="http://www.benoithellings.be/" target="_blank">Benoit Hellings</a> et Groen! <a href="http://www.freyapiryns.be/" target="_blank">Freya Piryns</a> pour l&#8217;instauration d&#8217;une &#8220;licence globale&#8221;, autrement dit une taxe sur les abonnements à Internet qui permettrait donc de télécharger des oeuvres protégées en toute impunité.</p>
<p>Notons que les deux propositions sont au départ basées sur la même constation dans le chef de leurs auteurs: le téléchargement illégal tue la création. Il faut saluer le travail remarquable effectué par les lobbyistes des majors du disque depuis des années.  A force de répétition tenant du lavage de cerveau version Révolution Culturelle, il sont parvenus à convaincre à peu près toute la planète du lien de causalité entre le téléchargement illégal et la chute de vente des CD et DVD.<span id="more-765"></span></p>
<p>Or, ce lien n&#8217;est pas établi. <a href="http://www.tno.nl/content.cfm?context=markten&amp;content=publicatie&amp;laag1=182&amp;laag2=1&amp;item_id=473" target="_blank">L&#8217;étude réalisée en 2009 par l&#8217;Institut de recherche néerlandais TNO</a> (enregistrement gratuit pour télécharger le rapport), dont la crédibilité est indiscutable, semble plutôt démontrer le contraire. En effet, selon le rapport &#8220;une chanson téléchargée ne correspond pas à une vente de moins. Les téléchargeurs ne pourraient se permettre d&#8217;acheter autant de CD au prix actuel, soit qu&#8217;ils n&#8217;en ont pas les moyens, soit qu&#8217;ils aient d&#8217;autres priorités budgétaires&#8221;. Le rapport montre aussi que &#8220;le téléchargement permet de découvrir de nouveaux artistes et peut donc conduire à l&#8217;achat de CD&#8221;. En ce sens, le téléchargement contribue donc à la mission de diffusion de la culture, au même titre que le service de prêt de la Médiathèque de la Communauté Française.</p>
<p>Un autre postulat majeur de la proposition de loi Ecolo/Groen! est que le téléchargement est majoritaire chez les utilisateurs d&#8217;Internet. Là encore, il s&#8217;agit d&#8217;un canard dont il faut tordre le cou. Un étude réalisé par le Professeur Esaki de l&#8217;Universite de Tokyo en 2007 montre que <a href="http://patrick.vande-walle.eu/uploads/2010/01/kjc-abs2007-2up.pdf" target="_blank">4% des utilisateurs génèrent 75% du trafic</a>.  En d&#8217;autres termes, une &#8220;licence globale&#8221;, appliquée à tous les abonnés à Internet signifierait que 96% des utilisateurs s&#8217;acquitteraient d&#8217;une taxe destinée à couvrir les agissements d&#8217;une minorité de 4%.  Cette étude notait également  que la tendance était à la baisse du trafic Peer-to-Peer, principalement utilisé pour le téléchargement de musique et de vidéo piratées, au profit du trafic vers des sites hébergant des vidéos, tels You Tube ou Daily Motion, où les droits intellectuels sont respectés.</p>
<p>On serait donc en train de légiférer sur un sujet qui n&#8217;est plus d&#8217;actualité, puisque le téléchargement se déplace vers des oeuvres légalement mises en ligne, et une &#8220;licence globale&#8221; rétribuerait de la sorte des créateurs mal à propos.</p>
<p>Plus encore, le fait de faire payer une majorité de bons citoyens pour le comportement d&#8217;une minorité de voyous n&#8217;est pas juste. Transposons cela dans le domaine de la circulation routière pour les besoins de la démonstration. Que penserions nous si on nous imposait  &#8220;Contravention globale&#8221; sur la taxe d&#8217;immatriculation des voitures, en compensation des excès de vitesse commis par quelques allumés ?</p>
<p>Un troisième postulat de la proposition Ecolo/Groen! est que le téléchargement se porte forcément sur des oeuvres piratées. Faux encore une fois. La<a href="http://www.mirrorservice.org/sites/cdimage.ubuntu.com/cdimage/releases/9.10/release/ubuntu-9.10-dvd-i386.iso " target="_blank"> dernière version complète de la distribution Linux <a target="_blank" href="http://www.ubuntu.com">Ubuntu</a></a>, par exemple, représente 3.9 <span style="text-decoration: line-through;">mega</span> gigabytes en téléchargement. La copie est non seulement autorisée, mais même encouragée. Le <a href="http://www.microsoft.com/downloads/details.aspx?familyid=874A414B-32B2-41CC-BD8B-D71EDA5EC07C&amp;displaylang=fr" target="_blank">Service Pack de Windows Vista</a> représente 726 megabytes, et est indispensable à tous les utilsateurs de Windows. Il existe sur Internet une mine inépuisable de contenus dont le téléchargement est autorisé.  Les logiciels libres en sont un, mais il y a aussi toutes les créations dans le domaine public ou libres de droits. Encore une fois, une taxe globale toucherait tous les utilisateurs d&#8217;Internet,  y compris ceux qui ne téléchargent pas de contenu illégalement.</p>
<p>Les écologistes avancent aussi que leur proposition ne vise que les gros téléchargeurs et que les abonnements pour les connexions à bas volume ne seraient pas affectées.  On manque içi de définitions. qu&#8217;est ce qu&#8217;un &#8220;haut débit&#8221;, alors que certains abonnés en Belgique ne diposent que de 1 Mbit/s et d&#8217;autres de 30 MBits/s ? Qu&#8217;est ce qu&#8217;un &#8220;bas volume&#8221;  ? 5 Gb par mois ? 10 ? 30 ? De nos jours, la moindre page sur un site web d&#8217;un journal par exemple comprend des animations Flash, des photos, voire même des flux vidéos.  Du contenu lourd, pour un usage courant.  A moins de se contenter de l&#8217; e-mail, 15 Gb par mois semblent un minimum pour un usage courant, sans téléchargement. Dans 2 ans, 30 Gb seront nécessaires. Or, les lois ont ceci de particulier qu&#8217;elles ne s&#8217;adaptent pas facilement à un monde en changement perpétuel.</p>
<p>Un autre argument avancé parles tenants de la proposition écolo prend comme référence le succès de la vente de lecteurs MP3 qui, d&#8217;après eux, serait la démonstration que le téléchargement illégal serait la norme. A nouveau, le lien de causalité n&#8217;est pas établi. Il y  30 ans, j&#8217;empruntais des disques vinyl à la Médiathèque, et j&#8217;en faisais des copies sur mini-cassette que j&#8217;utilisais dans mon Walkman. J&#8217;exercais mon droit à la copie privée. Le lecteur MP3  a remplacé le Walkman, mais cela ne change pas fondamentalement mon droit à la copie privée.</p>
<p>Quid aussi de la rétribution juste de tous les ayants droits dans un tel système ? Une perception forfaitaire de droits implique que la répartition se fera de manière statistique. En pratique, si je télécharge une oeuvre d&#8217;un jeune créateur inconnu qui n&#8217;a pas les honneurs du top 40, c&#8217;est Madonna et Sony Music qui empocheront les droits. C&#8217;est un reproche maintes fois invoqué vis-à-vis des sociétés de perception de droits telles la SABAM, SIMIM et autres. Ne confortons pas ce modèle qui spolie les jeunes créateurs.</p>
<p>Plus fondamentalement, une taxe sur les abonnements Internet au profit des créateurs légitimerait une pratique illégale. Cela semble moralement indéfendable.</p>
<p>Il est temps de faire preuve d&#8217;esprit critique et de discernement. Les arguments mille fois rabachés par les requins du showbiz ne résistent malheureusement pas à une analyse factuelle.</p>
]]></content:encoded>
			<wfw:commentRss>http://patrick.vande-walle.eu/internet/une-taxe-sur-internet-non-merci/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Faille de sécurité dans 500.000 modems Belgacom ?</title>
		<link>http://patrick.vande-walle.eu/internet/faille-de-securite-dans-500k-modems-belgacom/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=faille-de-securite-dans-500k-modems-belgacom</link>
		<comments>http://patrick.vande-walle.eu/internet/faille-de-securite-dans-500k-modems-belgacom/#comments</comments>
		<pubDate>Tue, 19 Jan 2010 18:20:58 +0000</pubDate>
		<dc:creator>Patrick Vande Walle</dc:creator>
				<category><![CDATA[BBox-2]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[Real life]]></category>
		<category><![CDATA[BBox2]]></category>
		<category><![CDATA[Belgacom]]></category>
		<category><![CDATA[OpenRG]]></category>
		<category><![CDATA[VDLS2]]></category>

		<guid isPermaLink="false">http://patrick.vande-walle.eu/?p=741</guid>
		<description><![CDATA[Les modems BBOX2 qu&#8217;utilisent une majorité de clients de Belgacom TV comportent des failles de sécurité importantes. Belgacom revendiquait 589.000 clients pour sa plate-forme TV l&#8217;été dernier. Une majorité d&#8217;entre eux utilise ce fameux modem. Une combinaison de facteurs ouvre la porte à des actes malveillants, pouvant être commis par des personnes sans connaissances informatiques [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://patrick.vande-walle.eu/uploads/2010/04/bbox-2-thumb.jpg"><img class="alignleft size-full wp-image-1031" style="margin: 10px;" title="bbox-2-thumb" src="/uploads/2010/04/bbox-2-thumb.jpg" alt="" width="60" height="45" /></a>Les modems BBOX2 qu&#8217;utilisent une majorité de clients de Belgacom TV comportent des failles de sécurité importantes. Belgacom revendiquait <a href="http://trends.rnews.be/fr/economie/entreprises/12-1634-48592/belgacom---l-amende-de-proximus-fait-plonger-le-benefice-net.html" target="_blank">589.000 clients pour sa plate-forme TV</a> l&#8217;été dernier. Une majorité d&#8217;entre eux utilise ce fameux modem.   Une combinaison de facteurs ouvre la porte à des actes malveillants, pouvant être commis par des personnes sans connaissances informatiques particulières et pas seulement des &#8216;hackers&#8217;.</p>
<ol>
<li> Les modems BBOX2 sont tous livrés avec le même mot de passe d&#8217;administration. On peut très facilement le trouver via un moteur de recherche: <a href="http://www.google.com/search?hl=en&amp;q=BGCVDSL2 " target="_blank">http://www.google.com/search?hl=en&amp;q=BGCVDSL2 </a></li>
<li>Belgacom prétend bloquer l&#8217;accès à distance de ces modems via Internet. C&#8217;est partiellement exact. Cependant, ces modems sont livrés d&#8217;origine avec une connexion WIFI active et non protégée.  N&#8217;importe qui passant dans la rue peut donc se connecter à une BBOX2 non protégée.</li>
<li>Muni de cet accès administratif, on peut télécharger le fichier de configuration du modem et décrypter les mots de passe qui s&#8217;y trouvent. Là aussi, on trouve le nécessaire sur Internet: <a href="http://www.webalice.it/zibri/Deobfuscate.html" target="_blank">http://www.webalice.it/zibri/Deobfuscate.html </a></li>
</ol>
<p>Après avoir récupéré les identifiants d&#8217;un abonné  à Belgacom TV (identifiants de la connexion PPPoE, pour être précis), un pirate peut utiliser ces informations pour perpétrer des actes malveillants en se faisant passer pour  cet abonné.</p>
<p>Toutes les informations ci-dessus sont en possession de Belgacom depuis longtemps. J&#8217;ai moi-même interrogé l&#8217;opérateur, qui n&#8217;a pas daigné accuser réception, et encore moins répondu ou proposé des solutions.</p>
<p>Notons également que si cela s&#8217;applique aux clients de Belgacom TV, certains abonnés Internet, chez Belgacom comme chez les opérateurs alternatifs qui utilisent le réseau VDSL2 de Belgacom sont également concernés. Le propriétaire du réseau impose en effet aux autres FAI l&#8217;utilisation d&#8217;un modem semblable au sien, également pourvu d&#8217;un mot de passe identique pour tous les abonnés.</p>
<p><span id="more-741"></span></p>
<p>Quelques détails additionnels pour les intéressés. Pour l&#8217;illustration, nous utilisons ici l&#8217;interface graphique du modem. Cependant, cette technique fonctionne également via une interface en mode textuel (telnet), qui permettrait à des pirates plus organisés de récupérer automatiquement ces données, sans intervention humaine.</p>
<h3>Mot de passe d&#8217;administration identique</h3>
<p>Pour une raison inexpliquée, Belgacom a choisi d&#8217;utiliser le même mot de passe sur tous ses modems. Il est très vite devenu un secret de polichinelle. Qui plus est, Belgacom ne donne pas d&#8217;indication sur la manière de le modifier. Belgacom ne fournit d&#8217;ailleurs aucun manuel avec le modem.  <a href="http://www.ripperjack.info/b-boxandco/spip.php?article52" target="_blank">D&#8217;autres s&#8217;en sont chargés, heureusement</a>. Ce qu&#8217;on retiendra, c&#8217;est la nécessité d&#8217;utiliser d&#8217;obscures commandes via une interface textuelle qui est peu compréhensible par le public que cible l&#8217;opérateur.</p>
<p>Belgacom a également imposé aux opérateurs alternatifs qui passent par son réseau VDSL2 d&#8217;utiliser un mot de passe unique (OLOVDSL2, dans ce cas). Il est évident qu&#8217;il s&#8217;agit d&#8217;un problème majeur de sécurité.</p>
<h3>Accès à la configuration</h3>
<p>Suite aux menaces proférées il y a quelques par un pirate se faisant appeler Vendetta, Belgacom a décidé de bloquer l&#8217;accès à ses modems BBOX2 via l&#8217;Internet, en bloquant les accès sur les ports 80, 443 et 22. Ce faisant, Belgacom enlève également à l&#8217;abonné de gérer son modem à distance., ce qui retire pas mal de fonctionnalités. L&#8217;abonné à la possibilité de malgré tout ouvrir ces ports, Belgacom se contentant d&#8217;avertir qu&#8217;il y a un risque de sécurité, sans expliquer lequel. En tout état de cause, le remède est disproportionné par rapport au problème à traiter. Un peu comme si on confisquait les clés de voiture aux automobilistes au titre que cela diminuera leur empreinte carbone.</p>
<p>Les modems sont par contre très facilement accessibles via le WIFI, qui est actif et non protégé par défaut. En effet, Belgacom veut rendre la vie de ses clients Belgacom TV simple, y compris ceux qui ne sont pas férus de technologie.  En conséquence, le modem se configure de lui-même lors de la première connexion. Plus exactement, le modem est configuré à distance via le protocole <a href="http://fr.wikipedia.org/wiki/TR-069" target="_blank">TR-069</a>. L&#8217;utilisateur n&#8217;a rien à faire de son côté, sinon enficher le câble du décodeur TV dans le modem. Le reste est automatique.</p>
<p>Qui plus plus est, l&#8217;abonné à Belgacom TV a souvent souscrit à une offre qui comprend aussi l&#8217;accès Internet, même s&#8217;il n&#8217;en a pas ou peu l&#8217;usage, ce qui ne l&#8217;encouragera pas à prendre les mesures nécessaires pour sécuriser son WIFI. Ainsi donc, il y a possiblement des milliers de clients de Belgacom qui ont un modem grand ouvert à tout le monde, sans le savoir. J&#8217;ai personnellement identifié près d&#8217;une dizaine de modems BBOX2 non protégés dans mes environs immédiats.</p>
<h3>Déchiffrement des mots de passe</h3>
<p>La BBOX2 utilise un micro-logiciel nommé OpenRG, de la société <a href="http://www.jungo.com" target="_blank">Jungo</a>. Ce logiciel se retrouve dans de nombreux modems ADSL, et notamment la Livebox de France Télécom, également utilisée  par Mobistar en Belgique.</p>
<p>Jungo a utilisé une technique de chiffrement que les informaticiens appellent plutôt l&#8217;obfuscation. Elle consiste à rendre la lecture plus compliquée de prime abord, mais sans introduire réellement de chiffrement. C&#8217;est une technique qui est connue depuis l&#8217;Antiquité. En l&#8217;occurrence, on procède par remplacement d&#8217;un caractère par un autre. Ainsi, une fois identifié les 26 lettres minuscules et majuscules, en plus des 10 chiffres, on peut très facilement construire un tableau de concordance et codifier le tout dans une petite routine informatique. Le site mentionné ci-dessus utilise le très répandu Javascript, mais il existe d&#8217;autres implémentations, en <a href="http://patrick.vande-walle.eu/uploads/2010/01/openrg-decrypt.py.txt" target="_blank">Python notamment</a> (<a href="http://www.userbase.be/forum/viewtopic.php?p=307227#p306275" target="_blank">source</a>), ce qui permettait à un pirate de facilement créer un programme de récupération automatique de ces identifiants.</p>
<p>La première étape est de sauvegarder la configuration du modem. Il suffit d&#8217;aller dans le menu &#8220;Admin Settings/Backup and Update&#8221;</p>
<p style="text-align: center;"><a href="http://patrick.vande-walle.eu/uploads/2010/01/admin-settings-backup-.jpg"><img class="aligncenter" style="margin-top: 20px; margin-bottom: 20px;" title="admin-settings-backup" src="/uploads/2010/01/admin-settings-backup--300x211.jpg" alt="" width="300" height="211" /></a></p>
<p>On récupère alors un fichier texte, où l&#8217;on peut trouver les identfiants de l&#8217;utilisateur:</p>
<p style="text-align: center;"><a href="http://patrick.vande-walle.eu/uploads/2010/01/password-obfuscate.jpg"><img class="aligncenter" style="margin-top: 20px; margin-bottom: 20px;" title="password-obfuscate" src="/uploads/2010/01/password-obfuscate.jpg" alt="" width="262" height="87" /></a></p>
<p>Dans l&#8217;exemple, ci-dessus, le mot de passe est &#8216;testing&#8217;, et c&#8217;est très exactement la valeur que retourne  le <a href="http://www.webalice.it/zibri/Deobfuscate.html" target="_blank">site de déchiffrement</a> mentionné ci-dessus.</p>
<p>La plupart des modems ADSL permettent de créer une copie de sauvegarde de leur configuration, bien utile en cas de panne. Cependant, les autres fabricants créent un fichier de configuration binaire, et donc illisible par un être humain. Jungo a choisi de rendre le fichier compréhensible, introduisant de la sorte une faille de sécurité, et le manque de précautions prises par Belgacom rend evidemment le problème plus grave encore.</p>
<p>Pour information, j&#8217;ai signalé ce problème de sécurité tant à Belgacom qu&#8217;à son fournisseur Jungo. En l&#8217;absence de réponse, je mets donc ces informations en ligne.</p>
]]></content:encoded>
			<wfw:commentRss>http://patrick.vande-walle.eu/internet/faille-de-securite-dans-500k-modems-belgacom/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>New ISP and lots of speed</title>
		<link>http://patrick.vande-walle.eu/internet/new-isp-and-lots-of-speed/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=new-isp-and-lots-of-speed</link>
		<comments>http://patrick.vande-walle.eu/internet/new-isp-and-lots-of-speed/#comments</comments>
		<pubDate>Fri, 25 Dec 2009 15:43:57 +0000</pubDate>
		<dc:creator>Patrick Vande Walle</dc:creator>
				<category><![CDATA[Belgium]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[Personal]]></category>
		<category><![CDATA[Real life]]></category>
		<category><![CDATA[Belgacom]]></category>
		<category><![CDATA[VDSL2]]></category>

		<guid isPermaLink="false">http://patrick.vande-walle.eu/?p=722</guid>
		<description><![CDATA[Santa has been kind to me. I just switched to a new ISP.  The results below speak for themselves. That&#8217;s the good news. The less good one is that this whole VDSL2 infrastructure deployed by the incumbent telecom operator has some major security holes, on which I will post later, once I have finished my [...]]]></description>
			<content:encoded><![CDATA[<p>Santa has been kind to me. I just switched to a new ISP.  The results below speak for themselves.</p>
<table align="center">
<tbody>
<tr>
<td>
<p><div id="attachment_721" class="wp-caption aligncenter" style="width: 310px"><a href="http://patrick.vande-walle.eu/uploads/2009/12/662631616.png"><img class="size-full wp-image-721" title="BGC-VDSL2" src="/uploads/2009/12/662631616.png" alt="BGC-VDSL2" width="300" height="135" /></a><p class="wp-caption-text">2009-12-25</p></div></td>
<td>
<p><div id="attachment_551" class="wp-caption aligncenter" style="width: 310px"><a href="http://patrick.vande-walle.eu/uploads/2009/07/521571818.png"><img class="size-full wp-image-551" title="521571818" src="/uploads/2009/07/521571818.png" alt="" width="300" height="135" /></a><p class="wp-caption-text">2009-07-20</p></div></td>
</tr>
</tbody>
</table>
<p>That&#8217;s the good news. The less good one is that this whole VDSL2 infrastructure deployed by the incumbent telecom operator has some major security holes, on which I will post later, once I have finished my research.</p>
]]></content:encoded>
			<wfw:commentRss>http://patrick.vande-walle.eu/internet/new-isp-and-lots-of-speed/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Hellotxt plugin update for WordPress</title>
		<link>http://patrick.vande-walle.eu/software/hellotxt-plugin-update-for-wordpress/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=hellotxt-plugin-update-for-wordpress</link>
		<comments>http://patrick.vande-walle.eu/software/hellotxt-plugin-update-for-wordpress/#comments</comments>
		<pubDate>Thu, 19 Nov 2009 10:03:00 +0000</pubDate>
		<dc:creator>Patrick Vande Walle</dc:creator>
				<category><![CDATA[Software]]></category>
		<category><![CDATA[Hellotxt]]></category>
		<category><![CDATA[Wordpress]]></category>

		<guid isPermaLink="false">http://patrick.vande-walle.eu/?p=645</guid>
		<description><![CDATA[This morning, I fixed an annoyance in the Hellotxt plugin I use on this WordPress blog that would resend a notification to hellotxt.com every time one updates a post (to correct a typo for example). I sent a tweet about this and, much to my surprise, I immediately received a series of direct messages on [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://patrick.vande-walle.eu/uploads/2010/07/wp-logo.png"><img class="alignleft size-full wp-image-1038" style="margin: 10px;" title="WordPress Logo" src="/uploads/2010/07/wp-logo.png" alt="" width="32" height="32" /></a></p>
<p>This morning, I fixed an annoyance in the <a href="http://code.google.com/p/hellotxt-wordpress/" target="_blank">Hellotxt plugin</a> I use on this WordPress blog that would resend a notification to hellotxt.com every time one updates a post (to correct a typo for example).</p>
<p>I sent a tweet about this and, much to my surprise, I immediately received a series of direct messages on Twitter asking for the code. So here it is:  <a href="http://patrick.vande-walle.eu/upload/hellotxt.php.txt" target="_blank">hellotxt.php.txt</a> , as well as the diff to the original file: <a href="http://patrick.vande-walle.eu/upload/hellotxtpress.php.diff">hellotxtpress.php.diff</a></p>
<p>There are actually <span style="text-decoration: line-through;">four</span> five changes:</p>
<ul>
<li>Added configuration option for URL shortener, so you can use your favourite URL shortener service. It defaults to <a href="http://www.pra.im" target="_blank">mine</a>.</li>
<li>Added configuration option for post prefix. By default, it is &#8220;New Blog post: &#8220;</li>
</ul>
<ul>
<li>Replace WP smart quotes by plain ones.  This is to prevent that some microblogging sites print out the HTML entities value, instead of the quotes themselves. Copied straight from <a href="http://bitbucketlabs.net/laconica-tools/" target="_blank">WP Laconica Tools</a>.</li>
<li>Don&#8217;t resend a post that was already submitted.  The inspiration came from the <a href="http://bitbucketlabs.net/laconica-tools/" target="_blank">WP Laconica Tools</a>.</li>
<li>Added configuration option for Twitter hash tags</li>
</ul>
<p>I will submit my changes to the plugin author, who may decide to incorporate them in a future release.</p>
]]></content:encoded>
			<wfw:commentRss>http://patrick.vande-walle.eu/software/hellotxt-plugin-update-for-wordpress/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Belgacom&#8217;s BBox 2 is brain dead</title>
		<link>http://patrick.vande-walle.eu/hardware/bbox-2/belgacoms-bbox-2/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=belgacoms-bbox-2</link>
		<comments>http://patrick.vande-walle.eu/hardware/bbox-2/belgacoms-bbox-2/#comments</comments>
		<pubDate>Mon, 16 Nov 2009 08:16:29 +0000</pubDate>
		<dc:creator>Patrick Vande Walle</dc:creator>
				<category><![CDATA[BBox-2]]></category>
		<category><![CDATA[AVM]]></category>
		<category><![CDATA[BBox2]]></category>
		<category><![CDATA[Belgacom]]></category>
		<category><![CDATA[Fritz!Box 7570]]></category>
		<category><![CDATA[VDSL2]]></category>

		<guid isPermaLink="false">http://patrick.vande-walle.eu/?p=629</guid>
		<description><![CDATA[In advance of a planned migration of my home Internet access to VDSL2, I received a Belgacom BBox2 modem. VDLS2 is actually a choice I had to make because ADSL technology is not really able to deliver in my area, due to the distance between my home and the phone exchange. On the other hand, [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://patrick.vande-walle.eu/uploads/2010/04/bbox-2-thumb.jpg"><img class="alignleft size-full wp-image-1031" style="margin: 10px;" title="bbox-2-thumb" src="/uploads/2010/04/bbox-2-thumb.jpg" alt="" width="60" height="45" /></a>In advance of a planned migration of my home Internet access to VDSL2, I received a Belgacom BBox2 modem.</p>
<p>VDLS2 is actually a choice I had to make because ADSL technology is not really able to deliver in my area, due to the distance between my home and the phone exchange. On the other hand, Belgacom has been installing these fiber cabinets in every block recently in the framework of their FTTC  project. Hence, a change of technology was needed for me if I wanted a faster Internet access.</p>
<p>The main issue with VDSL2 is the interoperability of equipment. The<a title="http://www.broadband-forum.org" href="http://" target="_blank"> Broadband Forum</a> is still working on this. As noted by the <a href="http://www.ibpt.be/GetDocument.aspx?forObjectID=3147&amp;lang=en" target="_blank">Belgian regulator IBPT in its latest consultation</a> : &#8220;Interoperability between DSLAM and CPE is not guaranteed by an ITU standard and it may be more difficult to achieve due to the differentiation possibilities of the VDSL2 technology&#8221;.</p>
<p>Belgacom decided to purchase its VDSL2 equipment from Alcatel-Lucent. That equipment is using <a href="http://www.ikanos.com/company/customers/" target="_blank">Ikanos Fusiv</a> chips. Consequently, Belgacom delivers CPE devices based on the same chipset. There were few at the time  when Belgacom  chose its platform, so they went for a <a href="http://www.sagem-communications.com/corporate/index.php?id=1226&amp;L=0" target="_blank">Sagem F@st 3464</a> modem, equipped with the Ikanos Fusiv Vx160 processor, which they repackaged (<a href="http://www.achilles.be/project,eng,143,100.php" target="_blank">it&#8217;s ugly</a>) and rebranded BBox2.</p>
<p>The Sagem box is not such a bad one, according to its specs. Unfortunately, Belgacom decided to design its own version of the firmware to adapt it to their commercial needs. Belgacom is agressively pursuing the triple play market. They wanted a modem that would be able to deliver two high definition TV streams at the same time it delivers Internet access.</p>
<p><span id="more-629"></span>The box uses Jungo&#8217;s  <a href="http://www.jungo.com/openrg/index.html" target="_blank">OpenRG firmware</a> , which is Linux-based. And although <a href="http://www.jungo.com/openrg/datasheets/OpenRG.pdf" target="_blank">OpenRG offers lots of features</a>, Belgacom managed to lobotomize it. Gone are the dynamic DNS, 802.11N, and IPv6  features, for example. While the dynamic DNS part is still there, although hidden, the IPv6 stack has been completely removed. Overall, this is the worst job of feature defacing I have seen in years.</p>
<p>As many new CPE devices, the BBox2 can be managed remotely by the telco using the TR-069 protocol. The good side is that it allows the telco to fix critical bugs, without user intervention. The bad side is that it also allows the telco to take complete control on your personal settings. For example, the BBox2 comes pre-configured to use the Belgacom VoIP service. While one can change the settings to use a competing offering, there is nothing that prevents Belgacom to reset the values remotely. Quite worrying from a competition point of view.</p>
<p>Which is why I foresee to move to a <a href="http://www.pt.lu/portal/op/preview/telecom/pid/543" target="_blank">AVM Fritz!Box 7570</a> in the near future. I have had several AVM Fritzes in the past and was always delighted with their features and also the fact that the company is doing real<a href="http://www.ripe.net/ripe/meetings/ripe-59/presentations/schoellhammer-v6-at-home.pdf"> innovation and development</a>, rather than just repackaging someone else&#8217;s work. They currently have projects with Dutch ISP <a href="http://www.fix6.net/archives/2009/05/05/xs4all-first-native-ipv6-adsl-connection/" target="_blank">XS4All</a> and <a href="http://ipv6council.lu/docs/J-M_Spaus.pdf" target="_blank">Luxembourg <a target="_blank" href="http://www.pt.lu">P&amp;T</a></a> to deploy IPv6.  The Fritz!Box 7570 has all you can expect. In addition to doing the basic work of connecting the home computers to the Internet, it also features a PABX with an integrated DECT base station, that will interact both with your landline but also with several VoIP providers, based on rules you set.  The<a href="http://www.avm.de/en/news/artikel/IPv6_Lab.html" target="_blank"> latest beta firmware for the box </a>features complete IPv6 support, which, judging from <a href="http://www.fix6.net/wp-content/uploads/2009/10/fritzbox.jpg" target="_blank">this screen shot</a> is fairly complete.</p>
<p>The Fritz!Box is based on the Infineon (now  Lantiq)  <a href="http://www.lantiq.com/products/broadband-customer-premises-equipment/vdsl/xwaytm-vinax/xwaytm-vinax-cpe/" target="_blank">XWay Vinax</a> chipset. It remains to be seen if  it is compatible with the Ikanos chips in my provider&#8217;s infrastructure. At worst, I could use the Belgacom provided modem as a bridge to the Fritz.</p>
]]></content:encoded>
			<wfw:commentRss>http://patrick.vande-walle.eu/hardware/bbox-2/belgacoms-bbox-2/feed/</wfw:commentRss>
		<slash:comments>141</slash:comments>
		</item>
		<item>
		<title>Voo, l&#8217;Internet et l&#8217;e-mail, ou comment se ridiculiser pour pas cher</title>
		<link>http://patrick.vande-walle.eu/internet/voo-internet/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=voo-internet</link>
		<comments>http://patrick.vande-walle.eu/internet/voo-internet/#comments</comments>
		<pubDate>Wed, 14 Oct 2009 08:40:02 +0000</pubDate>
		<dc:creator>Patrick Vande Walle</dc:creator>
				<category><![CDATA[Belgium]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[VOO]]></category>

		<guid isPermaLink="false">http://patrick.vande-walle.eu/?p=601</guid>
		<description><![CDATA[Il y a un mois et demi, je signalais à VOO, fournisseur d&#8217;accès Internet en Belgique, un problème de configuration de leurs serveurs e-mail et DNS. Les messages que je trouvais dans mes logs disaient: Sep 5 13:58:57 server Postfix/smtpd[30746]: NOQUEUE: reject: RCPT from mirapoint21.brutele.be[212.68.199.158]: 450 4.1.8 &#60;www-data@webvoo.voo.be&#62;: Sender address rejected: Domain not found; from=&#60;www-data@webvoo.voo.be&#62; [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://patrick.vande-walle.eu/uploads/2009/10/voo.png"><img class="alignleft size-full wp-image-1042" style="margin: 10px;" title="voo" src="/uploads/2009/10/voo.png" alt="" width="40" height="22" /></a>Il y a un mois et demi, je signalais à VOO, fournisseur d&#8217;accès Internet en Belgique, un problème de configuration de leurs serveurs e-mail et DNS. Les messages que je trouvais dans mes logs disaient:</p>
<pre>Sep 5 13:58:57 server <a target="_blank" href="http://www.postfix.org">Postfix</a>/smtpd[30746]: NOQUEUE: reject: RCPT from
mirapoint21.brutele.be[212.68.199.158]: 450 4.1.8 &lt;<a onclick="return rcmail.command('compose','www-data@webvoo.voo.be',this)" href="mailto:www-data@webvoo.voo.be">www-data@webvoo.voo.be</a>&gt;:
Sender address rejected: Domain not found;  from=&lt;<a onclick="return rcmail.command('compose','www-data@webvoo.voo.be',this)" href="mailto:www-data@webvoo.voo.be">www-data@webvoo.voo.be</a>&gt;
to=&lt;<a onclick="return rcmail.command('compose','xxx@xxx.xx',this)" href="mailto:xxx@xxx.xx">xxx@xxx.xx</a>&gt; proto=ESMTP helo=&lt;mirapoint21.brutele.be&gt;</pre>
<p>En pratique donc, le serveur de VOO à l&#8217;origne du message initial ne possède pas d&#8217;entrée dans le DNS, et se retrouve en conséquence blacklisté par mon serveur de mail. C&#8217;est une tactique courante pour rejeter une partie du spam qui abreuvent nos boîtes aux lettres.</p>
<p>En bon petit soldat de l&#8217;Internet, j&#8217;ai donc suivit les indications de <a href="http://www.ietf.org/rfc/rfc2142.txt" target="_blank">RFC 2142</a> concernant les adresess email de service, et qui précise que &#8220;<em> if a given service is offerred, then the associated mailbox name(es) </em><em><strong>must</strong> be supported&#8221;.<br />
</em></p>
<p>J&#8217;ai envoyé un message à<a href="mailto:postmaster@voo.be"> postmaster@voo.be</a> et à <span><a href="mailto:webmaster@voo.be">webmaster@voo.be</a> . Les messages me sont revenus avec un <em>non-delivery report</em>.  Le DNS de VOO est, en principe, géré par <a href="mailto:hostmaster@brutele.be">hostmaster@brutele.be</a> .  Du moins c&#8217;est ce qu&#8217;indique le SOA du DNS. Comme je devais m&#8217;y attendre, </span><span><a href="mailto:hostmaster@brutele.be">hostmaster@brutele.be</a> n&#8217;existe pas et les emails sont revenus itou. Bon, VOO ne respecte pas les standards et malheureusement, ils ne sont pas les seuls.</span></p>
<p><span id="more-601"></span></p>
<p><span>Troisième source d&#8217;information, le <a href="http://www.db.ripe.net/whois?form_type=simple&amp;full_query_string=&amp;searchtext=212.68.199.158&amp;submit.x=0&amp;submit.y=0&amp;submit=Search" target="_blank">WHOIS de RIPE NCC</a>, qui m&#8217;indique <a href="mailto:dnsmaster@brutele.be">dnsmaster@brutele.be</a> .  L&#8217;email a été accepté cette fois,  mais pas de réponse </span><span> </span>de l&#8217;humain se trouvant derrière cette adresse.  Et je constate qu&#8217;à ce jour, le problème n&#8217;est toujours pas réglé. Surprise aujourd&#8217;hui, je reçois un email standard du help desk me disant :</p>
<blockquote><p>dans le cas où la qualité du service mail est toujours à déplorer, je vous invite à contacter notre service Helpdesk au 078/50.50.50 choix technique, afin de déterminer l&#8217;origine de la panne et trouver une solution appropriée.</p></blockquote>
<p>Désolé VOO. Si vous ne disposez pas en interne des compétences nécessaires pour identifier &#8220;l&#8217;origine de la panne&#8221; et configurer votre DNS ou votre infrastructure e-mail, je ne puis que vous conseiller de faire appel à des professionnels. Il existe différentes solutions, prenant tout au plus 10 minutes à implémenter. En tout état de cause, devant cette démonstration d&#8217;incompétence, je ne puis que vous suggérer de vous focaliser sur votre métier originel, la télévision, avant de vous lancer dans un nouveau métier dont vous ne semblez pas maîtriser tous les paramètres techniques.</p>
<p>Update: il semble que abuse@ voo.be et postmaster@voo.be et hostmaster@brutele.be fonctionnent désormais. De là à dire que quelqu&#8217;un lira les messages &#8230;   Il ne  reste plus qu&#8217;à corriger le DNS.</p>
<p>Il apparaît par ailleurs que VOO sous-traite son assistance de premier niveau à une <a href="http://www.wbcc.eu/" target="_blank">société externe</a>, ce qui ne facilite pas la communication.</p>
]]></content:encoded>
			<wfw:commentRss>http://patrick.vande-walle.eu/internet/voo-internet/feed/</wfw:commentRss>
		<slash:comments>10</slash:comments>
		</item>
		<item>
		<title>Réunion de l&#8217;ICANN à Bruxelles en juin 2010</title>
		<link>http://patrick.vande-walle.eu/internet/reunion-de-licann-a-bruxelles-en-juin-2010/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=reunion-de-licann-a-bruxelles-en-juin-2010</link>
		<comments>http://patrick.vande-walle.eu/internet/reunion-de-licann-a-bruxelles-en-juin-2010/#comments</comments>
		<pubDate>Thu, 03 Sep 2009 12:37:00 +0000</pubDate>
		<dc:creator>Patrick Vande Walle</dc:creator>
				<category><![CDATA[Belgium]]></category>
		<category><![CDATA[ICANN]]></category>
		<category><![CDATA[Internet]]></category>

		<guid isPermaLink="false">http://patrick.vande-walle.eu/?p=589</guid>
		<description><![CDATA[Ainsi donc, l&#8217;ICANN tiendra une réunion à Bruxelles en juin 2010. Toutes mes félicitations à Marc Van Wesemael et l&#8217;équipe d&#8217;Eurid. Lors de la conception du projet de la réunion ICANN à Luxembourg qui se déroula en 2005, j&#8217;avais un temps envisagé de l&#8217;organiser à Bruxelles, tant il me semblait logique que la capitale de [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://patrick.vande-walle.eu/uploads/2010/06/icann-thumb.jpg"><img class="alignleft size-full wp-image-1050" style="margin: 10px;" title="icann-thumb" src="/uploads/2010/06/icann-thumb.jpg" alt="" width="60" height="49" /></a>Ainsi donc, l&#8217;I<a href="http://www.icann.org/en/minutes/prelim-report-27aug09.htm" target="_blank">CANN tiendra une réunion à Bruxelles en juin 2010</a>. Toutes mes félicitations à Marc Van Wesemael et l&#8217;équipe d&#8217;<a href="http://www.eurid.eu/" target="_blank">Eurid</a>.</p>
<p>Lors de la conception du projet de la réunion ICANN à Luxembourg qui se déroula en 2005, j&#8217;avais un temps envisagé de l&#8217;organiser à Bruxelles, tant il me semblait logique que la capitale de l&#8217;Europe accueille une telle manifestation. Le contexte était cependant différent.</p>
<p>A l&#8217;époque, le coût de la manifestation était entièrement supporté par l&#8217;organisateur local et ses partenaires. Le fractionnement institutionnel de la Belgique, avec ses multiples niveaux de pouvoirs aux compétences redondantes et en concurrence directe rendait tout simplement la participation des pouvoirs publics impossible. De nos jours, l&#8217;ICANN a compris qu&#8217;elle ne pouvait plus compter sur des tiers pour ouvrir leur portefeuille et finance elle-même la majeure partie des coûts.</p>
<p>Il n&#8217;en reste pas moins qu&#8217;il sera intéressant de voir qui seront les orateurs lors de la séance inaugurale. Aura-t-on un ministre fédéral ? Les télécoms sont une compétence largement régionalisée. On pourrait donc avoir un ministre bruxellois. Oui mais, Bruxelles est aussi la capitale de la Flandre. Aura-t-on peut être un ministre flamand ? Le responsable  du protocle va s&#8217;arracher les cheveux.</p>
]]></content:encoded>
			<wfw:commentRss>http://patrick.vande-walle.eu/internet/reunion-de-licann-a-bruxelles-en-juin-2010/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Cher Scarlet</title>
		<link>http://patrick.vande-walle.eu/real-life/cher-scarlet/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=cher-scarlet</link>
		<comments>http://patrick.vande-walle.eu/real-life/cher-scarlet/#comments</comments>
		<pubDate>Mon, 20 Jul 2009 20:22:05 +0000</pubDate>
		<dc:creator>Patrick Vande Walle</dc:creator>
				<category><![CDATA[Belgium]]></category>
		<category><![CDATA[Real life]]></category>
		<category><![CDATA[ADSL]]></category>
		<category><![CDATA[Belgique]]></category>
		<category><![CDATA[Scarlet]]></category>

		<guid isPermaLink="false">http://patrick.vande-walle.eu/?p=550</guid>
		<description><![CDATA[Une fois de plus, vous manquez à vos plus élémentaires obligations contractuelles en me fournissant le service ADSL le plus merdique de Belgique. Je n&#8217;ai pas l&#8217;habitude d&#8217;utiliser des gros mots en public. C&#8217;est vous dire combien je suis exaspéré. Vous m&#8217;avez reproché auparavant, et avec une mauvaise foi certaine, que je vous avais pas [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://patrick.vande-walle.eu/uploads/2009/07/scarlet.jpg"><img class="alignleft size-full wp-image-1044" style="margin: 10px;" title="scarlet" src="/uploads/2009/07/scarlet.jpg" alt="" width="48" height="48" /></a>Une fois de plus, vous manquez à vos plus élémentaires obligations contractuelles en me fournissant le service ADSL le plus merdique de Belgique. Je n&#8217;ai pas l&#8217;habitude d&#8217;utiliser des gros mots en public. C&#8217;est vous dire combien je suis exaspéré.</p>
<p>Vous m&#8217;avez reproché auparavant, et avec une mauvaise foi certaine, que je vous avais pas informé de la piètre qualité de vos services. Non seulement, je l&#8217;ai fait, <a href="http://forum.adsl-bc.org/viewforum.php?f=11" target="_blank">mais d&#8217;autres aussi</a>. Il y en a plein les forums de discussion. Mais puisque vous me prenez au mot, je vais effectivement me plaindre. Et que cela se sache.<span id="more-550"></span></p>
<p>Je vous propose donc de suivre en léger différé sur mon blog, les performances mesurées de vos services. On commence ce 20/7/2009:</p>
<table border="0">
<tbody>
<tr>
<td>
<p><div id="attachment_552" class="wp-caption aligncenter" style="width: 310px"><a href="http://patrick.vande-walle.eu/uploads/2009/07/521572635.png"><img class="size-full wp-image-552" title="521572635" src="/uploads/2009/07/521572635.png" alt="2009-07-20 22:10:28" width="300" height="135" /></a><p class="wp-caption-text">2009-07-20</p></div></td>
<td>
<p><div id="attachment_551" class="wp-caption aligncenter" style="width: 310px"><a href="http://patrick.vande-walle.eu/uploads/2009/07/521571818.png"><img class="size-full wp-image-551" title="521571818" src="/uploads/2009/07/521571818.png" alt="2009-07-20 22:08:45" width="300" height="135" /></a><p class="wp-caption-text">2009-07-20</p></div></td>
</tr>
</tbody>
</table>
<p>[Update 21/7 10:35]  Toute connexion est absolument impossible vers quelque service que ce soit. Web, e-mail, timeouts partout.</p>
<p>[Update 24/7 15:49] Envoyé un e-mail au help desk le 21/7. Réponse le 24/7 sur le thême &#8220;on n&#8217;a pas suffisamment d&#8217;information&#8221;. Entretemps, la vitesse est revenue à des valeurs normales, avec des chutes de temps à autre.</p>
<p>Restez branchés pour la suite. Je mettrai le post à jour de temps à autre.</p>
<p>Avant que votre help desk n&#8217;arrive avec sa check-list de questions préformatées, je precise que oui, ma ligne téléphonique fonctionne, que oui mon modem est bien configuré et que oui mon ordinateur aussi. Et je ne vous permets pas d&#8217;en douter. On s&#8217;évitera ainsi deux jours de questions/réponses inutiles.</p>
<p>Allons au fait: que se passe-t-il dans l&#8217;infrastructure de Scarlet qui justifie d&#8217;aussi piètres performances ? A la limite, le pourquoi n&#8217;est pas mon problème. Ce qui m&#8217;importe, c&#8217;est de savoir quand vous prendrez enfin les mesures nécessaires pour offrir un  service correct à vos clients.</p>
<p>Et si vous n&#8217;avez pas de réponse à cette question, que vous niez les évidences et que vous considérez que je vous échauffe les oreilles, il n&#8217;y a qu&#8217;une solution pour me faire taire: acceptez une  une résiliation anticipée de notre contrat,  que vous êtes de toute manière dans l&#8217;impossibilité d&#8217;honorer.</p>
<p>Allez, bonne journée quand même.</p>
]]></content:encoded>
			<wfw:commentRss>http://patrick.vande-walle.eu/real-life/cher-scarlet/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Linksys != Cisco</title>
		<link>http://patrick.vande-walle.eu/internet/linksys-cisco/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=linksys-cisco</link>
		<comments>http://patrick.vande-walle.eu/internet/linksys-cisco/#comments</comments>
		<pubDate>Sun, 28 Jun 2009 13:21:56 +0000</pubDate>
		<dc:creator>Patrick Vande Walle</dc:creator>
				<category><![CDATA[Internet]]></category>
		<category><![CDATA[Cisco]]></category>
		<category><![CDATA[Linksys]]></category>
		<category><![CDATA[Nokia E61i]]></category>

		<guid isPermaLink="false">http://patrick.vande-walle.eu/?p=541</guid>
		<description><![CDATA[I just bought a Linksys WAG160N ADSL modem/router that I am going to bring back to the retail store. The main reason it that it will not connect to my Nokia E61i phone on anything more than the old-fashioned (and insecure) WEP. My phone works fine with WPA2 on real Cisco APs; it also works [...]]]></description>
			<content:encoded><![CDATA[<p>I just bought a Linksys WAG160N ADSL modem/router that I am going to bring back to the retail store.  The main reason it that it will not connect to my Nokia E61i phone on anything more than the old-fashioned (and insecure) <a target="_blank" href="http://en.wikipedia.org/wiki/Wired_Equivalent_Privacy">WEP</a>. My phone works fine with <a target="_blank" href="http://en.wikipedia.org/wiki/Wi-Fi_Protected_Access">WPA2</a> on <strong>real</strong> Cisco APs; it also works with competing products, including the AVM Fritz!Box that was using earlier &#8211; and was partially destroyed by a thunder strike on the street telephone cabinet where my DSL phone line connects.  My phone just does not work with the Linksys WAG160N. This is actually a <a href="http://forums.linksys.com/linksys/board/message?board.id=Wireless_Routers&amp;message.id=119023&amp;query.id=60817#M119023" target="_blank">known issue</a> that I found out too late. however, it does not seem to be solved and no indication shows that it was acknowledged, even less on the way to be fixed.</p>
<p>I work with a lot of Cisco products in my day job. I have the pleasure to know many folks at Cisco. Most of  them were telling me that Linksys somehow usurpts the Cisco label with inferior quality products. How right they were.  I should have listened to what  Cisco&#8217;s own staff was telling me.</p>
<p>My online chat with the Linksys support staff did not resolve the issue. <a target="_blank" href="http://en.wikipedia.org/wiki/Wired_Equivalent_Privacy">WEP</a> works, but who dares to use <a target="_blank" href="http://en.wikipedia.org/wiki/Wired_Equivalent_Privacy">WEP</a> these days ? My advice to John Chambers and all those at Cisco who care about the company image is to stop your subsidiary from using the Cisco name.</p>
]]></content:encoded>
			<wfw:commentRss>http://patrick.vande-walle.eu/internet/linksys-cisco/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>New Top Level Domains and software implications</title>
		<link>http://patrick.vande-walle.eu/internet/icann/new-top-level-domains-and-software-implications/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=new-top-level-domains-and-software-implications</link>
		<comments>http://patrick.vande-walle.eu/internet/icann/new-top-level-domains-and-software-implications/#comments</comments>
		<pubDate>Thu, 25 Jun 2009 11:51:15 +0000</pubDate>
		<dc:creator>Patrick Vande Walle</dc:creator>
				<category><![CDATA[DNS]]></category>
		<category><![CDATA[ICANN]]></category>
		<category><![CDATA[New Top Level Domains]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[ASP.NET]]></category>
		<category><![CDATA[C]]></category>
		<category><![CDATA[ColdFusion]]></category>
		<category><![CDATA[Javascript]]></category>
		<category><![CDATA[perl]]></category>
		<category><![CDATA[PHP]]></category>

		<guid isPermaLink="false">http://patrick.vande-walle.eu/?p=532</guid>
		<description><![CDATA[Many software applications rely on validation routines to check the validity of domain names. By validation, I mean here to test the string submitted by the user and see if it matches a pre-defined pattern. A typical example are web forms that need to validate e-mail addresses. This is by no means a new issue. [...]]]></description>
			<content:encoded><![CDATA[<p>Many software applications rely on validation routines to check the validity of domain names. By validation, I mean here to test the string submitted by the user and see if it matches a pre-defined pattern. A typical example are web forms that need to validate e-mail addresses.</p>
<p>This is by no means a new issue. It first appeared with the introduction of the .info TLD. Before that TLDs were only two or three letters long, and many validation routines could not cope with the 4 letters of .info. At the time, ICANN had developed a testing tool which allowed developers to test if their code took into account the requirement for 4 letters. Still, you find today on the Internet tons of library routines that do not support 4 or more letter TLDs.</p>
<p>Some of these routines also rely on a hard-coded list of TLDs. Even today, I sometimes find that some web sites cannot deal with my .eu domain, which was introduced 4 years ago.There are hundreds of thousands of these routines written in Javascript, <a target="_blank" href="http://www.php.net">PHP</a>, Perl, ColdFusion, ASP and just about any programming or scripting language you can think of.</p>
<p><span id="more-532"></span>In the Draft Applicant&#8217;s Guidebook to new gTLDs, ICANN has clearly indicated that it does not guarantee universal acceptance of the new TLD, and rather place the burden on the registry operator to educate its customers. This made sense during the previous new TLD rounds, where there were only a few added, one at a time and with long intervals between them.</p>
<p>With the new gTLD round, ICANN plans to add a lot of TLDs, potentially at very close intervals, if not at the same time. The figure most often heard is 500. That is a quantum leap forward. All those hard-coded lists deeply buried in software will need to be updated. It will not happen overnight. It may take years. This time also, we are throwing into the mix TLDs which could be long strings, like .coca-cola. We are also adding IDN (internationalized Domain Names) in non-ASCII characters, which will be a real issue with all environments that do not process double-byte strings. There are tons of legacy applications that do not support that, and some never will.</p>
<p>The good news is that programmers do not need to worry about their job. There is plenty of work ahead. The bad news is that most of them are not aware of these upcoming TLDs, let alone the implications it will have on the code they wrote, or the code they use and written by someone else.</p>
<p>So, it does not make sense now for ICANN  just to say it is someone else&#8217;s problem. If the new gTLDs cannot be processed on the client platforms, this will mean their acceptance by the user community will be low. This means less revenue for registries, registrars and finally ICANN. This would also mean a partial failure of the whole new gTLD program, for which ICANN will be accountable for. It could cost ICANN much of its credibility, because it would not be the failure of one specific TLD for which the registry could be blamed, it would mean the failure of several, all for the same reasons.</p>
<p>Hence, I suggested today to ICANN to plan a workshop at the Seoul meeting to help identify these issues, so that clear guildelines can be given to the software community and an awareness campaign can be launched. It is absolutely crucial to identify the issues, the amount of work they represent and the time it will take to fix the code before the introduction of these new top level domains.</p>
]]></content:encoded>
			<wfw:commentRss>http://patrick.vande-walle.eu/internet/icann/new-top-level-domains-and-software-implications/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>IRT Final Report on Trademark Protection in new Top Level Domains &#8211; Part 1 &#8211; Uniform Rapid Suspension System</title>
		<link>http://patrick.vande-walle.eu/internet/icann/irt-final-report-on-trademark-protection-in-new-top-level-domains-part-1-uniform-rapid-suspension-system/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=irt-final-report-on-trademark-protection-in-new-top-level-domains-part-1-uniform-rapid-suspension-system</link>
		<comments>http://patrick.vande-walle.eu/internet/icann/irt-final-report-on-trademark-protection-in-new-top-level-domains-part-1-uniform-rapid-suspension-system/#comments</comments>
		<pubDate>Wed, 03 Jun 2009 09:40:47 +0000</pubDate>
		<dc:creator>Patrick Vande Walle</dc:creator>
				<category><![CDATA[ICANN]]></category>
		<category><![CDATA[trademarks]]></category>

		<guid isPermaLink="false">http://patrick.vande-walle.eu/?p=512</guid>
		<description><![CDATA[The ICANN IRT working group has published its final report, which I decided to analyze a bit further. I already made a few comments last month, both in the At-Large Advisory Council framework and on my own.   There are several issues raised by the recommendations of this report. The URS is one. Reliance on e-mail [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://patrick.vande-walle.eu/uploads/2010/06/icann-thumb.jpg"><img class="alignleft size-full wp-image-1050" style="margin: 10px;" title="icann-thumb" src="/uploads/2010/06/icann-thumb.jpg" alt="" width="60" height="49" /></a>The ICANN <a href="http://vhva8m.s.isoc.lu" target="_blank">IRT working group has published its final report</a>, which I decided to analyze a bit further. I already made a few comments last month, both in the <a href="http://forum.icann.org/lists/irt-draft-report/msg00061.html" target="_blank">At-Large Advisory Council framework</a> and on <a href="http://forum.icann.org/lists/irt-draft-report/msg00003.html" target="_blank">my own</a>.   There are several issues raised by the recommendations of this report. The URS is one.</p>
<h3>Reliance on e-mail</h3>
<p>Among the issues is the fact that most of the URS process relies on e-mail for notifications to the registrant, to the registry operator, etc.  Let&#8217;s face it: e-mail has become unreliable for critical applications. With more than 90% of e-mail being catalogued as spam, identifying the one important e-mail that you are not expecting is like searching a needle in a haystack.  Some techniques like DKIM, S/MIME signing, etc might help getting through the spam filters, if only the latter are well-configured. Most users do not have fine-grained control on the configuration of their spam filter, and none at all on the one used by their ISP.</p>
<p>Where this matters is that &#8220;<em>A Registrant has fourteen (14) calendar days from the date of the initial email notification to submit an Answer</em>&#8220;.  If the e-mail was caught by your spam filter, or if you are on vacation, travelling or more simply not reading your e-mail on a regular basis, you are out of  luck. You might lose your domain name without you even noticing it before it is too late.</p>
<p>The language issue is also an important one. It may be that English is the<em> lingua franca</em> of the business community. However, it may not be a language understood by the domain name registrant and he may, in good faith,  discard the notification message.<span id="more-512"></span></p>
<h3>Collateral damage</h3>
<p>The IRT working group is focusing on  the web. To provide evidence, the complainant &#8220;<em>must include PDF copies of [...]  the website showing the alleged violation(s)</em>&#8220;.  If the domain name is indeed found to infringe on someone else&#8217;s IP rights by the third-party complaints examiner,  &#8220;<em>The third-party provider will post a standard page on the domain name</em>&#8220;. No mention is made of other services, although, as one of my friends says &#8220;there are <span class="toctext">65534 other ports&#8221;. </span></p>
<p>The URS proposal does not explain how other services, like e-mail, DNS, etc would be treated. E-mail is  problematic in this context. There could be a privacy issue with the third party provider intercepting correspondence originally addressed to the domain name registrant. Or, if the registrant had indicated a contact e-mail address under the domain name being suspended, he might not receive any notifications on his case any more.</p>
<p>DNS is another issue.  If the suspended domain name was running a DNS server for other, unchallenged domain names, those other domain names may not be accessible anymore.</p>
<p><span class="toctext">What the IRT group is proposing is technically close to the controversial <a href="http://en.wikipedia.org/wiki/Sitefinder" target="_blank"> Sitefinder &#8220;service&#8221;</a> , and this proves again that the IRT group would have benefitted to have a broader base of participants, especially from the technical community, in this case.</span></p>
<h3><span class="toctext">Legal uncertainty</span></h3>
<p><span class="toctext">The fact a registrant has successfully passed a URS examination does not mean he is certain to keep his domain name. He could still face a UDRP complaint and a legal action. There is not much that can be done to prevent a legal action. However, one could expect the complainant to have to choose between a URS complaint or a UDRP complaint, but not both.<br />
</span></p>
<p><span class="toctext">On other factor is that the registrant should be guaranteed some peace of mind regarding the use of his domain name. A URS complaint can be filed at any time.  If the registrant has been using a domain  name for several months or years, he could still face a URS complaint. This creates a high level of uncertainty. Would you dare to launch an  Internet-based business if your domain name can be taken down at any time ?<br />
</span></p>
<p><span class="toctext">The extensive use of  e-mail in the URS process creates a real issue regarding the production of  l</span><span class="toctext">egal evidence in law suits following URS cases.  Like it or not, most judicial system use written evidence to examine civil cases, and do not consider e-mails or faxes as legal evidence.<br />
</span></p>
<h3>Individual domain name registrants</h3>
<p>The IRT proposal does not make any difference between domain names registrants which are either  businesses or individuals. Unlike businesses which are &#8220;open all day&#8221;, individuals cannot be expected to be glued to their computer screen waiting for an  e-mail regarding a potential issue with a domain name they have registered. As mentioned above, the 14 day period for answering after the  notification may be impossible to keep for an individual, especially if he is not well-versed into the intricacies of the IP framework regarding domain names.</p>
<p>The language issue mentioned above is even more problematic for individuals.</p>
<h3>Potential suggestions for improvement</h3>
<p>I am told I should suggest possible improvements rather than just whining. So:</p>
<ul>
<li>Use certified/registered paper mail for notification. This is expensive, yes, but will provide indisputable evidence to both parties. Further, because of the cost involved, it will help eliminate frivolous complaints only designed to hurt competitors.</li>
<li>Draft notifications in the registrant&#8217;s native language. This is expensive, again, but will make sure that the registrant actually understands what is going on.  And again, it will greatly help in possible later law suits.</li>
<li>Differentiate between individual private persons and legal entities. The process applying to the former would be more relaxed in terms of  time schedules.</li>
<li>Make the suspended domain names unresolvable by the DNS. Web users, will get a 404 error. E-mail users will get a non-delivery receipt. This would be RFC-compliant and solve the privacy issues.</li>
<li>Put a time limit on the introduction of a URS complaint, for example 3 months. After that time, the domain name owner should be guaranteed he will not face a URS complaint anymore.</li>
<li>In line with the above, a complainant should be requested to elect for a URS or a UDRP but not both.  This will guarantee that the domain name registrant will not be harassed.</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://patrick.vande-walle.eu/internet/icann/irt-final-report-on-trademark-protection-in-new-top-level-domains-part-1-uniform-rapid-suspension-system/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Belgian incumbent ISP not dominant operator says appeals court</title>
		<link>http://patrick.vande-walle.eu/internet/belgian-incumbent-isp-not-dominant-operator-says-appeals-court/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=belgian-incumbent-isp-not-dominant-operator-says-appeals-court</link>
		<comments>http://patrick.vande-walle.eu/internet/belgian-incumbent-isp-not-dominant-operator-says-appeals-court/#comments</comments>
		<pubDate>Fri, 15 May 2009 10:53:21 +0000</pubDate>
		<dc:creator>Patrick Vande Walle</dc:creator>
				<category><![CDATA[Belgium]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[Belgacom]]></category>
		<category><![CDATA[IBPT]]></category>
		<category><![CDATA[ISP]]></category>

		<guid isPermaLink="false">http://patrick.vande-walle.eu/?p=505</guid>
		<description><![CDATA[Picture this: the still state-owned (51% of shares) Belgian incumbent telecom and Internet operator, Belgacom, is not a dominant player on the ISP market, according to the Brussels appeals court (see also here). It is obvious to every inhabitant of Belgium that the incumbent is everywhere. It owns all the copper pairs to homes and  [...]]]></description>
			<content:encoded><![CDATA[<p>Picture this: the still state-owned (51% of shares) Belgian incumbent telecom and Internet operator, <a href="http://www.belgacom.be" target="_blank">Belgacom</a>, is not a dominant player on the ISP market, <a href="http://s.isoc.lu/yhpnta" target="_blank">according to the Brussels appeals court</a> (see also <a href="http://s.isoc.lu/3x8maw" target="_blank">here</a>).</p>
<p>It is obvious to every inhabitant of Belgium that the incumbent is everywhere. It owns all the copper pairs to homes and  a good deal of the fibre. No single Internet or telephony operator can get into the business without transiting through the Belgacom network at some stage. As expected, the infrastructure owner is not keen to open up its infrastructure to competitors and has used every trick in the book to slow down competition. As a result, alternative operators, be it in telephony or Internet access,  have a ridiculous market share. Belgacom has a more than<a href="http://s.isoc.lu/4fehag" target="_blank"> 70% share of the residential Internet access market</a>.  Belgium has one of the most expensive Internet access offer in Europe, nearly twice the price of France, for example.</p>
<p>The telecoms regulator, <a href="http://www.ibpt.be" target="_blank">IBPT</a>,    is often depicted as a weak one and often accused of favouring Belgacom.  It came with some surprise a few months back that the <a href="http://s.isoc.lu/6zm486" target="_blank">regulator ruled that Belgacom had to open up its ADSL and VDSL infrastructure </a>to the competition. Under the EU competition rules, it is foreseen that the infrastructure owner and dominant operator has to open its infrastructure to allow competitors to offer their services, too.</p>
<p>Belgacom wishes to diversify its income sources and launched an ambitious project to deliver <a href="http://www.belgacomtv.be/" target="_blank">triple play services</a>. This includes high definition and pay TV.  For this to happen they needed to upgrade their DSL network. They embarked in an infrastructure project to lay  fibre optic cabling up to street cabinets (<a href="http://en.wikipedia.org/wiki/FTTC" target="_blank">FTTC</a>) and deliver <a href="http://en.wikipedia.org/wiki/VDSL2" target="_blank">VDSL2</a> connectivity from there to the customers premises.   This has actually proven very successful. Belgacom was greatly helped by the fact that the cable TV operator in the Southern part of Belgium, <a href="http://www.voo.be" target="_blank">Voo</a>, has an outdated and poor quality network.</p>
<p>It may be that IBPT  did not make a rigorous enough study of the marketplace. Still, I cannot understand judges refuse to see what is obvious to all. The net result is that Belgacom&#8217;s competitors will have even less opportunities to offer quality services and that the incumbent&#8217;s market share will grow even more. For customers, this will mean less choice and higher prices. This is sad news in a country where the unemployment rate have risen quite sharply due to the global economic downturn. It is nearly impossible these days to apply for a job if you do not have an Internet connection and e-mail address.  The most vulnerable part of the population will be the first victim.</p>
]]></content:encoded>
			<wfw:commentRss>http://patrick.vande-walle.eu/internet/belgian-incumbent-isp-not-dominant-operator-says-appeals-court/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

