Monday, December 14, 2015

5 open source web app alternatives to Google Drive

https://opensource.com/life/15/12/5-open-source-web-apps-self-hosted

Image of spider web

Last year, Kenton Varda and I ran a successful fundraising campaign that let us build Sandstorm. During the campaign, he published a treatise on how open source and indie software has proliferated on desktop and mobile, yet stagnated on the web because decentralized hosting has historically been so difficult.
Non-technical users comprise most of humanity, so that's where Sandstorm is setting the usability bar. We've come a long way since last year—we launched the App Market, managed hosting, and free automated dynamic DNS & SSL certs for self-hosters, to name a few milestones.
I'd like to take a moment to highlight some of my favorite open source web apps that have become part of my work and life routine. Before we dive into the apps, let's give a shoutout to the Sandstorm community, and in particular, the awesome folks who authored and/or packaged these apps. Be sure to check out the demos for each app. Demo accounts last for one hour, but you can sign into Oasis, our managed hosting, to keep your data in a free basic account or self-install on your own hardware.

1. Davros (personal file sync and storage)


Davros is essentially Dropbox or Google Drive style file sync and storage, but running on hardware that you control, wherever you want to install it. As soon as it came out earlier this month, I immediately 1) Installed it and created a grain for my Skitches, 2) Installed the ownCloud client on my laptop, and 3) Copy-pasted the key from my Davros instance ("grain"). In under a minute, I had everything working, and most of that minute was downloading the ownCloud client.
Since I capture and annotate screenshots for filing bug reports and other things almost every day, I've often felt a bit awkward about keeping those hosted by Evernote (who acquired Skitch in 2011). How can I really be sure if they've deleted a backup of someone else's bug (or some other potentially embarrassing photo)? Thanks to Michael Nutt's Davros, I can sync my files to my own server.

2. SandForms (Google Forms alternative)


SandForms is an open source alternative to Google Forms. It was developed by a team at ThoughtWorks that worked closely with the journalists and activists for whom Sandstorm's security features are of vital importance, as well as the Radical Librarians Collective and the Library Freedom Project.
That thing is beautiful. Seriously, give it a spin. I always love it when the open source apps are heads and shoulders above their conventional brethren in design, usability, and polish.

3. EtherCalc (real-time collaborative spreadsheet)

EtherCalc screenshot
EtherCalc is a real-time collaborative spreadsheet built by Audrey Tang. It does all the things you expect a collaborative spreadsheet like Google Spreadsheets to do, except you can install it on your own server and have control over your data.
Audrey has also written a fascinating history of EtherCalc (and its predecessors, WikiCalc and SocialCalc) for the book series The Architecture of Open Source Applications. These chapters are also available on the EtherCalc web site. It's a technically meaty read that does multiple deep dives into how each feature was implemented, optimizing for the performance of various features, the constraints they were solving for the environments in which each of these spreadsheet apps were designed to be deployed, and more. Great stuff!

4. HackerSlides (Minimalist presentation editor)

HackerSlides screenshot
HackerSlides lets you write your slides in Markdown into an Ace Editor while showing you a live preview on the right with Reveal.js. I've used it to write and present just about every presentation I've given since it came out (one exception for a conference that mandated a slide template). Personally, I prefer writing my slides in Markdown as I find it's so much faster to write without fussing about and moving boxes around with my mouse.
HackerSlides' author, Jack Singleton, gave a talk about it at Chaos Communication Camp earlier this year (video) and gathered a team of his colleagues to work on SandForms.

5. Etherpad (Real-time collaborative document editor)

Etherpad screenshot
Etherpad is a real-time collaborative document editor, like Google Docs, but running on your servers, not Google's. After Appjet (the original author) was acquired by Google, they open sourced the Etherpad code, where it is currently maintained for the community by John McLear and friends at the Etherpad Foundation.
Etherpad is one of the most popular open source web apps. Large groups like Mozilla and Wikimedia run instances, and so do small activist groups like La Quadrature du Net. By contrast, I self-host Etherpad on Sandstorm, where I get two practical advantages over using a shared instance: Sandstorm shows me a list of Etherpad documents I've created, and it adds security sandboxing to every app. The security features have mitigated a number of real Etherpad security issues.
This is the only app in the list maintained by someone on the Sandstorm core dev team, by the way. All four other apps are packaged for Sandstorm by the community that created them.

One login, one workspace

When I used to use conventional SaaS apps from various developer-hosts, I had to log in separately into each service, entrust them with my data, and hope that they never pulled the plug on an app that I loved. These days, when I deploy apps I use on Sandstorm, I can have all my data in one place and share access with my collaborators. Most importantly, my data lives on hardware that I control.

Get involved

Want to make your own apps available to the Sandstorm community and self-hosters everywhere, regardless of their sysadmin skills? Check out this packaging tutorial, and drop a line to the sandstorm-dev mailing list with any questions. (Maybe even ask for a community review of your app before it goes live!) By default, your app will also get a one-click live demo to help your users try out a fresh instance of your app before installing it, and we'll even help you out with app icons if you need the help.
Want to try out new apps before they get into the App Market? Want to help app authors test their almost-ready apps? Join the sandstorm-dev mailing list to help out, and be sure to assist open source app authors by reporting bugs and edge cases on their repo. I love community-driven development because everyone gets to pitch in and participate, and we're all in this together, creating better technology for everyone.
Want to connect with other open source enthusiasts who like to self-host? Join or create a Sandstorm meetup group; it's a great opportunity to show and tell your latest and greatest open source app, or learn from local experts and get help on your work in progress. Put your city on the map via this SandForms survey, and I'd love to help you get started.
Stay tuned for my upcoming roundup of open source alternatives to other popular SaaS apps. Or explore the App Market and write about your favorites.

How to find out AES-NI (Advanced Encryption) Enabled on Linux System

http://www.cyberciti.biz/faq/how-to-find-out-aes-ni-advanced-encryption-enabled-on-linux-system

The Intel Advanced Encryption Standard (AES) or New Instructions (AES-NI) engine enables extremely fast hardware encryption and decryption for openssl, ssh, vpn, Linux/Unix/OSX full disk encryption and more. How do I check support for Intel or AMD AES-NI is loaded in my running Linux in my Linux based system including openssl?

The Advanced Encryption Standard Instruction Set (or the Intel Advanced Encryption Standard New Instructions - "AES-NI") allows certain Intel/AMD and other CPUs to do extremely fast hardware encryption and decryption. "AES-NI" is an extension to the x86 instruction set architecture for microprocessors from Intel and AMD. It increases the speed of apps performing encryption and decryption using the AES. Several server and laptop vendors have shipped BIOS configurations with the AES-NI extension disabled. You may need a BIOS update to enable them or change the BIOS settings. The following CPUs are supported:
  1. Intel Westmere/Westmere-EP (Xeon 56xx)/Clarkdale (except Core i3, Pentium and Celeron)/Arrandale(except Celeron, Pentium, Core i3, Core i5-4XXM).
  2. Intel Sandy Bridge cpus (except Pentium, Celeron, Core i3).
  3. Intel mobile Core i7 and Core i5.
  4. Intel Ivy Bridge processors All i5, i7, Xeon and i3-2115C only.
  5. Intel Haswell processors (all except i3-4000m, Pentium and Celeron).
    AMD Bulldozer/Piledriver/Steamroller/Jaguar/Puma-based processors.
  6. AMD Geode LX processors.
  7. VIA PadLock (a different instruction set than Intel AES-NI but does the same thing at the end of the day).
  8. ARM - selected Allwinner and Broadcom using security processor. There are few more ARM based processor.
Please note that the AES-NI support is automatically enabled if the detected processor is among the supported list as above. For a list of processors that support the AES-NI engine, see Intel ARK/AMD/ARM (vendor)/VIA padlock site and documentation.

How do I find out that the processor has the AES/AES-NI instruction set?

To find out cpu type and architecture type:
# lscpu
Type the following command to make sure that the processor has the AES instruction set and enabled in the BIOS:
# grep -o aes /proc/cpuinfo
OR
# grep -m1 -o aes /proc/cpuinfo
Sample outputs:
Fig.01: Linux Verify That Processor/CPU Has the AES-NI Instruction
Fig.01: Linux Verify That Processor/CPU Has the AES-NI Instruction

The aes output indicates that I have the AES-NI support enabled by Linux.

How do I verify that all my CPU supports AES NI?

The output of the following two commands should be same:
# lscpu | grep '^CPU(s):'
32

And:
# grep -o aes /proc/cpuinfo | wc -l
32

Is Intel AES-NI instructions optimized driver loaded for my Linux server/laptop/desktop?

Type the following command:
# sort -u /proc/crypto | grep module
Sample outputs:
module       : aesni_intel
module       : aes_x86_64
module       : crc32_pclmul
module       : crct10dif_pclmul
module       : ghash_clmulni_intel
module       : kernel

Is Intel AES-NI enabled for openssl enabled?

Now that we have verified support, it's time to test it. Is my AES-NI/VIA padlock engine supported?
$ openssl engine
Sample outputs from VIA based cpu that supports the AES:
(padlock) VIA PadLock (no-RNG, no-ACE)
(dynamic) Dynamic engine loading support
Another output from Intel based system that support the AES-NI:
$ openssl engine
(aesni) Intel AES-NI engine
(dynamic) Dynamic engine loading support

Test: AES-NI CPU vs Normal CPU without the AES-NI/Packlock support

In this example, serverA has the AES-NI and serverB has no support for hardware encryption:
$ dd if=/dev/zero count=1000 bs=1M | ssh -l vivek -c aes128-cbc serverA "cat >/dev/null"
Password:
1000+0 records in
1000+0 records out
1048576000 bytes (1.0 GB) copied, 10.6691 s, 98.3 MB/s

And:
$ dd if=/dev/zero count=1000 bs=1M | ssh -l vivek -c aes128-cbc serverB "cat >/dev/null"
vivek@localhost's password:
1000+0 records in
1000+0 records out
1048576000 bytes (1.0 GB) copied, 31.6675 s, 33.1 MB/s

Test: How do I benchmark my openssl performance?

Again run the following commands on both the systems:
# openssl speed
OR
# openssl speed aes-128-cbc

Popular Linux or Unix/BSD applications that can benefit from the AES-NI from high speed ecryption/decryption

  • dm-crypt for full-disk encryption on Linux.
  • 7-Zip app.
  • Google chrome and firefox browsers
  • FreeBSD's OpenCrypto API i.e aesni driver for zfs and other file systems.
  • OpenSSL 1.0.1 and above.
  • TrueCrypt 7.0 and above or VeraCrypt.
  • Citrix XenClient 1.0 and above.
  • Compilers such as GCC 4.4+, Intel C/C++ compiler 11.1+, Clang 3.3+ and more.
  • Libraries for golang, java, NSS, openssl and more.
  • Linux and BSD firewalls and vpn especially easy to use pfsense, ipcop and more.
  • Operating system based on Linux, *BSD, Unix, Microsoft, Android, iOS, Apple OS X and more.
References

Contribute Anonymously To Git Repositories Over Tor With Gitnonymous Project

http://fossbytes.com/contribute-anonymously-to-git-repositories-over-tor-with-gitnonymous-project

tor-githubShort Bytes: With gitnonymous project, now you can obfuscate your true identity while making Git commits and pushing to public repositories. Using the instructions given on the GitHub page, learn to setup your anonymous account.
Chris McCormick (aka chr15m) released an open source project called gitnonymous which can help you contribute to any public repository by obfuscating your true identity. You can follow the instructions given on the GitHub page to setup your anonymous account.It can be helpful for developers who are passionate about open source projects and willing to contribute but their corporates policies don’t allow them to contribute to open source projects.
Though this project doesn’t provide complete anonymity, the reasons below suggest that it is a good start. As more developers join the project, it will soon achieve maturity and complete anonymity.
@ryancdotorg on Hacker News pointed out following information leaks that may still be used to try to identify you –
  • Your timezone will appear in Git commits (narrows down location).
  • Commit times will be leaked (narrows down sleeping/working hours).
  • SSH client version will be leaked to servers you connect to (shows Linux distro version and patch level).
chr15m later called it pseudonymous method.
Read more about the gitnonymous on GitHub.
Do you think we need this project? Add your views in the comments below.