Monday, February 25, 2008

Using Truecrypt to protect your data

In Hong Kong the "pron" photos topic is still very hot. It showed the limitation and contradiction between ethics, Law system and Information Technology. As a so called "IT person", I just want to point out that, if the photo owner had kept the photos well, nothing could have happened. Hence, it is very important for us to protect our personal data.

So how to protect and secure our data? At least we have to achieve the following things:
1. Only the owner can access the data
2. Even the data was stolen, the data still need to be decrypted

In order to implement the above points, the simplest way is to zip the data files with a password. In normal case other people would not access the access so easily. However, if you have a lots of data, just like Mr. Chan who owners thousands of photos, zipping files will be quite trouble. So it is recommended to use a free encryption tool "truecrypt", which can protect your data in an easy and secure way.

Truecrypt is different from Zip, we have to create a blank file and encrypt it (Using password or a keyfile), then mount it as a Windows drive or Linux mount point for storing your sensitive data. That encrypted file can be named or sized as you like, very flexible. Even though your hard disk is stolen, nobody will know which file can be mounted. In addition, you can also encrypt a partition rather than a file, which makes the hackers have a hard time.

There is also a "hidden mode", which is a encrypted area inside the file or partition, but with another password or keyfile. So in some situation you are forced to tell the password, you can just give the password of the "outer" part. As nobody can ensure the existence of the hidden part, your most important data will not be exposed.

Remember, do protected your important data !

Ref:
Truecrypt offical site
Truecrypt Tutorial in Chinese

Friday, November 23, 2007

AIX - Change IP with one command

chdev -l -a netaddr= -a state=

e.g.
chdev -l en0 -a netaddr='192.168.1.1' -a state='up'

That's all. Simple?

Friday, September 21, 2007

Display Slot information on pSeries

I used to login to HMC and see the slot informations. Just found that there is an easier way:

To list all the PCI hot plug slots, enter:

lsslot -c pci

The system displays a message similar to the following:

Slot name Description Device(s) Connected
U0.4-P1-I1 PCI 64 bit, 33MHz, 3.3 volt slot empty
U0.4-P1-I2 PCI 64 bit, 33MHz, 3.3 volt slot scsi0
U0.4-P1-I3 PCI 64 bit, 33MHz, 3.3 volt slot unknown
U0.4-P1-I5 PCI 64 bit, 33MHz, 3.3 volt slot empty

Also can use -a and -o for available and occupied resources

Also, can use "lsslot -c slot" to display virtual-slot as well

Ref: http://www.ncsa.uiuc.edu/UserInfo/Resources/Hardware/IBMp690/IBM/usr/share/man/info/en_US/a_doc_lib/cmds/aixcmds3/lsslot.htm

Friday, September 14, 2007

HMC with command line

HMC webconsole is a good tool for doing LPAR administration, but it would be better if I can manage some jobs in command level:

Get the system name
lssyscfg -r sys -F name

Get the LPAR names, id and state
lssyscfg -m -r lpar -F name,lpar_id,state

Details of a LPAR
lssyscfg -m -r prof --filter "lpar_ids=2"

List resources
lshwres -r mem -m --level sys

List LPAR resources location
lshwres -m -r io --rsubtype slot -F description,unit_phys_loc,bus_id,phys_loc,lpar_id (--filter "lpar_ids=x")

Ref: http://www-941.ibm.com/collaboration/wiki/display/LinuxP/HMC+command+line

Sunday, September 09, 2007

Cisco VPN client

vpnc is Cisco VPN client for Linux. I always use it to connect to my company at home. However, I found that I couldn't connect on one day. After checking, it was because I have updated the Ubuntu vpnc package. The new config file need to add a "NAT Traversal Mode cisco-udp":

...
IPSec gateway
IPSec ID
IPSec secret
Xauth username
Xauth password

NAT Traversal Mode cisco-udp
...

After added the list line, everything is okay again :>