Monday, 19 March 2018

Jenkins community account password audit

Their system looks similar to how publishing of plugins works in the Jenkins project:

  • Accounts are protected by passwords chosen by users.

  • Individual contributors have permission to release the components they maintain.

  • The components they release are used by millions of developers around the world to deliver their software.

In other words, weak passwords are a problem for us just as much as for NPM, and what happened to them could happen to us.

To address this problem, the Jenkins security and infra teams have recently collaborated on a password audit. The audit covered all accounts with permissions to upload plugins and components, and on accounts with other levels of privileged infrastructure access. We ran brute force tools on salted password hashes of those accounts looking for "weak" passwords — passwords present in a set of publicly available password lists we chose for this audit.

We checked the password of every qualifying account for every unsafe password rather than trying to match them to any previous password leaks' email/password pairs. Users with weak account passwords were notified via email a few weeks ago and were asked to change their password to something stronger.

We performed the same checks over the previous weekend, but this time we only checked the passwords of accounts whose passwords were deemed weak during our first check. We then invalidated the password of any account whose password was still not considered "strong" (i.e. their password was unchanged or had been changed to another weak password). Users of those accounts will need to request a password reset before signing in again.

We plan to implement further safeguards, including improving the account management app at https://account.jenkins.io to reject weak passwords. If you’re interested in helping the security team make Jenkins more secure, let us know on the jenkinsci-dev mailing list, or request to join the security team.

What Is cfprefsd, and Why Is It Running on my Mac?

You’re browsing Activity Monitor when you notice something named cfprefsd. What is this, and should you be worried about it?

Enabling Mission-Critical Data to Feed Clinical Decisions in Healthcare

We’re excited to announce that we’ll be hosting an upcoming webinar with Clearsense LLC on March 29th! Clearsense is a smart data organization based in Jacksonville, Florida that is re-imagining and simplifying data analytics to help healthcare organizations realize measurable value from their data. They have developed a secure, cloud-based healthcare data ecosystem that rapidly consumes […]

The post Enabling Mission-Critical Data to Feed Clinical Decisions in Healthcare appeared first on Hortonworks.

4 Ways to Look Better On Conference Calls and Streaming Video

Whether you have to video conference call for work or you’re film YouTube videos for fun (and profit?) we increasingly find ourselves in…

Click Here to Continue Reading

How to Get Started with Android’s Home Screens

The Android home screen is powerful and customizable—if you take the time to set it up. While not an extensive guide on all things home screen, this beginner’s guide to the Android launcher should help get you started.

Hortonworks Operational Services: Embark on Your Big Data Journey with Confidence

Aaron Wiebe contributed to this blog. Data-driven insights have been hailed as a differentiator, one that may render companies obsolete if they are unable to take advantage of this trend. With this realization, business and IT leaders are keen to get started quickly in order to exploit the capabilities of big data as a competitive […]

The post Hortonworks Operational Services: Embark on Your Big Data Journey with Confidence appeared first on Hortonworks.

How to Download Your Photos from Facebook

Facebook isn’t the best place for keeping your photos, but its convenience makes it a decent space for sharing them. If you want to download a photo you’ve uploaded (or even one your friend has uploaded), here’s how.

What’s the Difference Between Cloud File Syncing and Cloud Backup?

Not all cloud file storage services are the same. There’s a big difference between file syncing tools like Dropbox and online backup services like Backblaze when it comes to backing up your important files.

Sunday, 18 March 2018

Geek Trivia: What Off-The-Shelf Addition Did NASA Scientists Add To The Voyager Probes At The Last Minute?

Think you know the answer? Click through to see if you're right!

Smart meters to rationalise electricity consumption in India

You will soon be able to operate your home appliances remotely. You'll also be able to check which appliance is consuming more electricity.

How to View (and Monitor) Your Credit Report For Free

If you keep a regular eye on your credit report, you’ll notice when identity thieves open accounts in your name and when errors are listed that might cause you problems in the future. Here’s how to do it for free.

Saturday, 17 March 2018

How to Get Started Listening to Podcasts

You keep hearing about podcasts—from friends, online, even on TV. But what are podcasts, and how do you get started listening to them?

Geek Trivia: The 1956 Centurion, A Buick Concept Car, Had Which Of These Modern Features In It?

Think you know the answer? Click through to see if you're right!

How to Make Siri Understand You Better

Siri isn’t all that great to begin with, but here are some ways to at least improve the Siri experience and get her to understand you better when shouting voice commands.

Friday, 16 March 2018

Geek Trivia: Historically, Valuable Library Books Were Protected With?

Think you know the answer? Click through to see if you're right!

Manufacturing Industry Use Cases, Challenges, and Strategies for Dealing with Huge Data Volumes

Last month, we held the most recent Manufacturing and Transportation Customer Community call. These calls occur a couple times per quarter and act as an opportunity for leaders in both the manufacturing and transportation industries to have a roundtable discussion regarding use cases, business challenges, and best practices. Industry communities are collaborative, industry-focused communities that […]

The post Manufacturing Industry Use Cases, Challenges, and Strategies for Dealing with Huge Data Volumes appeared first on Hortonworks.

Amazon’s Is Rolling Out “Brief Mode” For Some Echo Users to Make Alexa Less Talkative

Amazon’s Alexa is a useful voice assistant, but sometimes it can talk a little too much.

Click Here to Continue Reading

What is cloudd, and Why Is It Running on my Mac?

You might have noticed something named cloudd running on your Mac while using Activity Monitor. Should you be worried? What is this? This process is part of macOS, and is related to iCloud.

What Is Fuchsia, Google’s New Operating System?

Fuchsia a totally new operating system, currently in the very early stages of development at Google. How does it differ from Android and Chrome, and might it replace either one? Let’s break it down.

IBM and Hortonworks Partnership Highlighted at IBM THINK 2018!

Hortonworks and IBM’s partnership has brought multiple joint solutions for Global Data Management to the market. From HDP on Power Systems and Spectrum Scale Storage which provides customers fast access to data and a cost-effective platform for running their big data workloads; to building joint solutions for data scientists and business leaders with HDP and […]

The post IBM and Hortonworks Partnership Highlighted at IBM THINK 2018! appeared first on Hortonworks.

How to Set Up and Use “Routines” in Google Assistant

Google recently announced that Assistant would be getting “Routines” that let people execute multiple actions with a single phrase. Routines are now live, and here’s how to use them.

Best Humidifiers for Your Dry Home or Office

Dry weather isn’t just rough on your skin, it’s rough on your general health and even on your home.

Click Here to Continue Reading

How to Make Facebook Less Annoying

Facebook has become a must-use service for a lot of people. Unfortunately, Facebook has some annoying quirks, not the least of which is how it handles your news feed. Here’s how to make it better.

How to Get Refunds for Apps and Games

Some app and game stores offer refunds for digital purchases, and some don’t. For example, you can get refunds for Android and iPhone apps, or PC games you purchase from Steam or elsewhere.

How to Use a Dark Theme in Windows 10

Windows offers a setting named Dark Mode that applies a dark theme to apps you get from the Windows Store. It doesn’t affect desktop apps, or tools like File Explorer, but we’ve got some other solutions for those. Here’s how to get your whole desktop (or as much as possible) looking dark.

IT Decision-Makers Must Focus on the Importance of Big Data Staffing

The importance of big data staffing will only increase as technologies such as artificial intelligence and machine learning grow rapidly.

The post IT Decision-Makers Must Focus on the Importance of Big Data Staffing appeared first on Hortonworks.

Selected Sessions to Watch for at Spark + AI Summit 2018

Early last month, we announced our agenda for Spark + AI Summit 2018, with over 180 selected talks with 11 tracks and training courses. For this summit, we have added four new tracks to expand its scope to include Deep Learning Frameworks, AI, Productionizing Machine Learning, Hardware in the Cloud, and Python and Advanced Analytics.

For want of worthy experience—whether picking a restaurant to dine, electing a book to read, or choosing a talk to attend at a conference—often a nudge guides, a nod affirms, and a review confirms. Rebecca Knight suggests in Harvard Business Review “How to Get Most Out of a Conference” by listening to what experts have to say, being strategic with your time, and choosing the right sessions.

As the program chair of the summit, and to help you choose some sessions, a few talks from each of these new tracks caught my attention: All seem prominent in their promise, possibility, and practicality, and I wish to share them with you:

AI Use Cases and New Opportunities:

Deep Learning Techniques:

Productionizing Machine Learning:

Python and Advanced Analytics:

Hardware in the Cloud:

Stay tuned for keynote announcements and favorite picks from other tracks by notable technical speakers from the community and big data practioners.

If you have not registered, use code “JulesChoice” for a 15% discount during registration. I hope to see you all there.

--

Try Databricks for free. Get started today.

The post Selected Sessions to Watch for at Spark + AI Summit 2018 appeared first on Databricks.

Security hardening: Jenkins LTS 2.107.1 switches XStream / Remoting blacklists to whitelists (JEP-200)

This is a post about a major change in Jenkins, which is available starting from Jenkins 2.102 and Jenkins LTS 2.107.1. This is a change with a serious risk of regressions in plugins. If you are a Jenkins administrator, please read this blogpost and upgrade guidelines BEFORE upgrading.

I would like to provide some heads-up about the JEP-200 change, which is included into the new Jenkins LTS 2.107.x baseline.

Background

For many years Jenkins used to specifically blacklist certain classes and packages according to known or suspected exploits. This approach has been proven unsustainable due to the risk of deserialization attacks via unknown classes from 3rd-party components, after the SECURITY-429/CVE-2017-1000353 fix in 2.46.2 it was decided to replace blacklists by more restrictive whitelists. In October 2017 Jesse Glick proposed a Jenkins Enhancement Proposal, which finally got accepted as JEP-200.

The change implies a risk of regressions in plugins serializing non-whitelisted Java-internal and 3rd-party classes, and that’s why it is so important to follow the upgrade guidelines for this release.

Current state

JEP-200 was first integrated in Jenkins 2.102 (released in January 2018), and it has got a lot of testing since that. See this blogpost for the original announcement.

Over the last two months we received more than 75 issues from users of Jenkins weekly releases. All these issues have been triaged, and we have released most of the fixes. More than 50 plugins were fixed in total, and many more plugins were updated in order to enable compatibility testing. A significant part of the discovered regressions were caused by real defects which were causing performance and stability issues in plugins. Thanks a lot to all the Jenkins contributors and plugin maintainers who helped deliver timely changes for this effort!

Over last 6 weeks Jenkins weekly releases had positive community ratings, the overall JEP-200 adoption reached ~12% of all Jenkins installations on March 01. All major plugins have been also tested directly or verified in the wild on weekly releases. So we are confident that the change is ready to be released in LTS.

On the other hand, we continue to receive JEP-200 regression reports. They are mostly caused by niche plugins which are not widely used in weekly releases, and unfortunately not all fixes have been released yet (see the Wiki page for up-to-date info). We anticipate more regressions to be reported after the LTS release and broader adoption.

In order to simplify the upgrade to the new LTS baseline, I have prepared some helpful materials together with Liam Newman and Jesse Glick. Below you can find the embedded slide deck and video, or scroll down to see the key information in the text form.

Video:

For Jenkins administrators

Upgrading to a core with JEP-200 requires a special update procedure, which is described below.

Upgrading Jenkins

  1. JEP-200 is not the only major change in 2.107.1, please read the full upgrade guide carefully

  2. If you have a way of testing the upgrade before applying it to production, do it

  3. Back up your instance so you have any easy way of rolling back

  4. Update all affected plugins. See this Wiki page for the list of affected plugins, fix statuses and workarounds

  5. Apply workarounds for non-released patches if needed (see below)

  6. Update to the new version of the Jenkins core

Using backups and staging servers is good advice before any upgrade but especially this one, given the relatively high risk of regression. Due to the nature of the changes, some plugins may refuse to load after the upgrade and cause your Jenkins service to fail to start.

After the upgrade

To the extent that advance testing of the impact of this change on popular plugins has been completed, most users (and even plugin developers) should not notice any difference. Still, it is highly advised to monitor your system after the upgrade, especially the following:

  • Jenkins System log (especially during the startup)

  • Job/Build logs

If you do encounter a log message referencing the https://jenkins.io/redirect/class-filter/ URL, most likely it is a JEP-200 regression. Example:

some.pkg.and.ClassName in file:/var/lib/jenkins/plugins/some-plugin-name/WEB-INF/lib/some-library-1.2.jar might be dangerous, so rejecting; see https://jenkins.io/redirect/class-filter/

If you see this kind of message, we highly recommend reporting it so that it can be investigated and probably fixed quickly.

Reporting JEP-200 issues

Please report any issues you encounter matching the above pattern in the Jenkins issue tracker, under the appropriate plugin component. Before reporting please check whether this issue has already been reported.

  1. Add the JEP-200 label

  2. Include the stacktrace you see in the log

  3. If possible, include complete steps to reproduce the problem from scratch

You can find examples of previously reported issues using this query.

Jenkins developers will evaluate issues and strive to offer a fix in the form of a core and/or plugin update. Right after the feature release there will be a special team triaging the reports with high priority See JEP-200 Maintenance plan for more info.

For more details and current status, see Plugins affected by fix for JEP-200.

Applying workarounds

Assuming you see no particular reason to think that the class in question has dangerous deserialization semantics, which is rare, it is possible to work around the problem in your own installation as a temporary expedient. Note the class name(s) mentioned in the JEP-200 log messages, and run Jenkins with the hudson.remoting.ClassFilter startup option, e.g.:

java -Dhudson.remoting.ClassFilter=some.pkg.and.ClassName,some.pkg.and.OtherClassName -jar jenkins.war ...

This workaround process may require several iterations, because classes whitelisted in the workaround may also include fields with types requiring whitelisting.

For plugin developers

If you are a plugin developer, please see the original JEP-200 announcement. That blog post provides guidelines for testing and fixing plugin compatibility after the JEP-200 changes. The presentation above also provides some information about what needs to be tested.

How to Select Hard Drives for Your Home NAS

If you’re thinking about jumping into the NAS game and are shopping around for high-capacity hard drives, not just any hard drive will do. Here’s what you need to know.