Tuesday, October 18, 2016
Mobile 'Störsender' von Audi
Ich wohne unweit einer vielbefahrenen Straße.
Nun ist mir folgendes in meinen "benachbarten WLAN" aufgefallen:

Dabei handelt es sich anscheinend um WLAN Netze die in Audi KfZ on-board erzeugt werden.
Die konkrete Konfiguration führt leider dazu das umgebende Netze beeinträchtigt werden da sowohl die Wahl des Kanals (6) als auch die Wahl der Kanalbreite (40 Mhz) ungeschickt/ignorant ist.
Ich nehme an das Kanal 6 und 40Mhz die Werkseinstellungen sind.
Zur Bandbreite: 802.11-2012 fordert das Systeme beim Erkennen von überlappenden Netzen von 40 auf 20 Mhz zurückschalten. Eine normgerechte Implementation lässt sich nicht auf 40Mhz festlegen.
Im städtischen Umfeld findet man daher auch kaum 40Mhz breite 2.4Ghz Netze, von ein paar bekloppten Plasteroutern mal abgesehen.
Die Beobachtung das alle Audi MMI Wlans die an meinem Netz vorbeikommen 40Mhz breit sind lässt mich schliessen das Audi hier die entsprechenden Mechanismen nicht implementiert hat und somit diverse Standards,u.a. 802.11-2012 nicht entspricht. Dies kann übrigens auch die Zulassung der Geräte betreffen.
Das alles wäre mir fast egal, wäre das 2,4Ghz ISM Band nicht so schmal.
Mit 20Mhz existieren maximal 3 überlappungsfrei Kanäle (1,6,11 bzw 1,7,13). Überlappungsfrei ist da auch relativ da die Filter nicht immer die entsprechende Flankensteilheit besitzen. Wenn die Fahrzeuge 20Mhz breit auf Kanal 6 wären, so bliebe ungefähr 2/3 des Spektrums unbehelligt.
Sie sind aber 40Mhz breit und auf Kanal 6, was so ziemlich die schlechteste Lösung ist.
Es gibt 2 überlappungsfreie 40Mhz Bereiche (1+5 und 9+13).
40Mhz auf Kanal 6 heisst das kein überlappungsfreier Kanal exisitiert - auch keine 20Mhz Kanäle. :-(
Daimler kriegt das übrigens korrekt hin ;-)
Daher die Bitte an Audi:
Seit doch gute Nachbarn und verhaltet euch normgerecht (20 Mhz Kanalbreite).
Nun ist mir folgendes in meinen "benachbarten WLAN" aufgefallen:

Dabei handelt es sich anscheinend um WLAN Netze die in Audi KfZ on-board erzeugt werden.
Die konkrete Konfiguration führt leider dazu das umgebende Netze beeinträchtigt werden da sowohl die Wahl des Kanals (6) als auch die Wahl der Kanalbreite (40 Mhz) ungeschickt/ignorant ist.
Ich nehme an das Kanal 6 und 40Mhz die Werkseinstellungen sind.
Zur Bandbreite: 802.11-2012 fordert das Systeme beim Erkennen von überlappenden Netzen von 40 auf 20 Mhz zurückschalten. Eine normgerechte Implementation lässt sich nicht auf 40Mhz festlegen.
Im städtischen Umfeld findet man daher auch kaum 40Mhz breite 2.4Ghz Netze, von ein paar bekloppten Plasteroutern mal abgesehen.
Die Beobachtung das alle Audi MMI Wlans die an meinem Netz vorbeikommen 40Mhz breit sind lässt mich schliessen das Audi hier die entsprechenden Mechanismen nicht implementiert hat und somit diverse Standards,u.a. 802.11-2012 nicht entspricht. Dies kann übrigens auch die Zulassung der Geräte betreffen.
Das alles wäre mir fast egal, wäre das 2,4Ghz ISM Band nicht so schmal.
Mit 20Mhz existieren maximal 3 überlappungsfrei Kanäle (1,6,11 bzw 1,7,13). Überlappungsfrei ist da auch relativ da die Filter nicht immer die entsprechende Flankensteilheit besitzen. Wenn die Fahrzeuge 20Mhz breit auf Kanal 6 wären, so bliebe ungefähr 2/3 des Spektrums unbehelligt.
Sie sind aber 40Mhz breit und auf Kanal 6, was so ziemlich die schlechteste Lösung ist.
Es gibt 2 überlappungsfreie 40Mhz Bereiche (1+5 und 9+13).
40Mhz auf Kanal 6 heisst das kein überlappungsfreier Kanal exisitiert - auch keine 20Mhz Kanäle. :-(
Daimler kriegt das übrigens korrekt hin ;-)
Seit doch gute Nachbarn und verhaltet euch normgerecht (20 Mhz Kanalbreite).
Saturday, September 10, 2016
Making Of wiekaltistderkanal.de Sensor Version II
I am building a new sensor for wiekaltistderkanal.de.
In June 2016 I wrote: "Münster's local bathing lake for the masses is the local canal, "Dortmund-Ems Kanal". Excellent water quality & very popular. Looking for a project that fills a void - @todendah suggested: "I want to know whether it's too cold!". So that became our first [FreifunkLP] project deployed in the wild. Starting today we have deployed a solar powered temperature sensor at Stadthafen 2. We are really curious how long it will last. :-) The sensor is autonomous (solar) and very close to water so we are not yet convinced that it will last. The river police however speculated that it will get nicked first. :-)"
The coppers were right: It got stolen after 2 months. So I am building a new one.
I have been asked a few details about the sensor, so I am documenting the build here.
Some references: Dortmund Ems Kanal: Wikipedia (german, dutch)
The first version: https://www.thethingsnetwork.org/forum/t/time-for-a-swim/2567/4
To no surprise, water is the enemy. The sensor was (and will be) mounted about 30cm above water level at Dortmund-Ems Kanal. The water level there is very stable (the authorities monitor, publish (yay!) the water levels. So I thought that (besides rain) there would be the occasional splash.
Boy was I wrong! The canal is a waterway with (relative to it's size) rather large ships (110m x 10m) which cause significant swell. So significant that the sensor is fully submerged on a regular basis. V1 was not made for that. It had a few flaws:
Flaw #1: Antenna
For whatever reason I used an external rod antenna screwed onto a gold SMA connector. I knew the antenna was not weather proof but I thought that it would probably take much longer than the sensors lifetime for the thing to rot. That was correct. ;-) What I did not think is that water will run down the inside of the antenna and end up in the inside of the SMA connection and make it's way to the inside. Someone from warpzone asked (innocently) why I was using an external antenna with a plastic case. Duh! So at first revision I removed the antenna, plugged the hole and used an internal wire antenna instead.
Flaw #2: Ventilation opening
I think that any case need some sort of ventilation to avoid condensation. My first solution for this was an opening in the bottom containing a very small pipe that extended a few cm up into the case. I thought this would provide minimal ventilation and be immune to the occasional splash. Furthermore the pipe was small enough that it would keep out most insects. I never found out whether this anti-condensation approach worked since at each revision I found about 1cm of water in the case.
The pipe was later extended to got all the way to the top of the case.
Flaw #3: Power production/consumption
V1 used a 70x55mm 0,5W panel which provided plenty of power during sunny days. But even in summer this was insufficient at overcast days. On problem is that the panel is not ideally oriented. The panel is glued to the case to make the while setup as robust as possible. Nothing I want to change here. V1 used a Couloumb counter to measure battery charge/discharge. Rob65 in the TTN forum pointed out that it has a major design flaw as it drains energy through an ill dimensioned pull-up resistor. I payed for this flaw with 1mA. :-(
When using a 3,3V system you also need to close the two solder jumpers (SJ2, SJ3) on the underside.
For the solar panel, I removed the wires from the panel, drilled two holes in the case and glued the whole panel to the case and finally re-soldered the wires. I also filled the holes from the inside with silicone which helps to prevent the wires to come loose when moved around. After the silicon has somewhat cured I used more of the stuff to seal edges on the front. The protective film the panel is removed as last step.
I am really sure that this is watertight. However since the panel I've used has "open" (unsealed) edges I think it's possible that moisture may creep in from the front. Time will tell.
In the end I had something like this:

Required battery capacity assumption:
V1 consumed about 1,1mA
V2 should have much lower power consumption, approx 1mA lower.
If we assume it's 1mA (its going to be lower) we'd need 24mAh per day.
In wintertime (below -20℃ is a very rare event) - the capacity will roughly half, so 48mAh per day.
LiPos do somewhat between 200 and 500 cycles. This is a problem. This should (be able to last) longer than a year. This page suggest that limiting depth discharge increases lifetime a lot.
x10 = 500mAh.
The end of the world is near, for sure, but until then there will be some light during the day.
What I don't know how much energy the panel will produce on a cloudy winter day. Data from V1 suggested that on rainy (summer) days there may not be any charge at all.
Anyway, for good measure I'll go with ~2000mAh.
I also want to do an experiment with supercaps, perhaps with the next build
The process of adding the solar panel is described above.
Furthermore, I drilled a hole in the top to mount the antenna.
There are two holes in the bottom, one for the sensor wires and one for a "breathing plug". This is basically a small piece of goretex membrane and is IP68 proof. (Product, search for "vent plug membrane" to find more)


By the way, if someone has a suggestion how to integrate a waterproof USB connector - to be able to do maintenance without breaking the seal - that would be welcome information
As you can see I went for chains instead of cable ties this time :-)
I changed the OTA protocol a bit to give higher resolution values for temperatures and to cope with the additional sensors. Furthermore the Autonomo has a voltage divider hooked to Vbat and an AD input that allows for simple measurements of the battery voltage which I also included.
The Node-RED sketch was reworked accordingly.

The current software can be found here: https://github.com/kgbvax/kanaltemp
In June 2016 I wrote: "Münster's local bathing lake for the masses is the local canal, "Dortmund-Ems Kanal". Excellent water quality & very popular. Looking for a project that fills a void - @todendah suggested: "I want to know whether it's too cold!". So that became our first [FreifunkLP] project deployed in the wild. Starting today we have deployed a solar powered temperature sensor at Stadthafen 2. We are really curious how long it will last. :-) The sensor is autonomous (solar) and very close to water so we are not yet convinced that it will last. The river police however speculated that it will get nicked first. :-)"
The coppers were right: It got stolen after 2 months. So I am building a new one.
I have been asked a few details about the sensor, so I am documenting the build here.
Some references: Dortmund Ems Kanal: Wikipedia (german, dutch)
The first version: https://www.thethingsnetwork.org/forum/t/time-for-a-swim/2567/4
Lessons learned from Version 1
To no surprise, water is the enemy. The sensor was (and will be) mounted about 30cm above water level at Dortmund-Ems Kanal. The water level there is very stable (the authorities monitor, publish (yay!) the water levels. So I thought that (besides rain) there would be the occasional splash.
Boy was I wrong! The canal is a waterway with (relative to it's size) rather large ships (110m x 10m) which cause significant swell. So significant that the sensor is fully submerged on a regular basis. V1 was not made for that. It had a few flaws:
Flaw #1: Antenna
For whatever reason I used an external rod antenna screwed onto a gold SMA connector. I knew the antenna was not weather proof but I thought that it would probably take much longer than the sensors lifetime for the thing to rot. That was correct. ;-) What I did not think is that water will run down the inside of the antenna and end up in the inside of the SMA connection and make it's way to the inside. Someone from warpzone asked (innocently) why I was using an external antenna with a plastic case. Duh! So at first revision I removed the antenna, plugged the hole and used an internal wire antenna instead.
Flaw #2: Ventilation opening
I think that any case need some sort of ventilation to avoid condensation. My first solution for this was an opening in the bottom containing a very small pipe that extended a few cm up into the case. I thought this would provide minimal ventilation and be immune to the occasional splash. Furthermore the pipe was small enough that it would keep out most insects. I never found out whether this anti-condensation approach worked since at each revision I found about 1cm of water in the case.
The pipe was later extended to got all the way to the top of the case.
Flaw #3: Power production/consumption
V1 used a 70x55mm 0,5W panel which provided plenty of power during sunny days. But even in summer this was insufficient at overcast days. On problem is that the panel is not ideally oriented. The panel is glued to the case to make the while setup as robust as possible. Nothing I want to change here. V1 used a Couloumb counter to measure battery charge/discharge. Rob65 in the TTN forum pointed out that it has a major design flaw as it drains energy through an ill dimensioned pull-up resistor. I payed for this flaw with 1mA. :-(
Features for version II
I had plans for a new version even before the original sensor got nicked.
Goals:
- Long term autonomy (ideally through winter)
- Improved water resistance
- Two temperature sensors to measure temperatures at two depths
- Improved idiot resistance
- Against damage
- Against theft
Parts
- Case: Aluminium HPDC case (Reichelt RND 455-00042). This is not waterproof by design but I believe some silicone will do the job. Maintenance is difficult though.
- Antenna: Delock LTE Antenna 88749. Since it's a metal case, I need an external antenna again. Perhaps there are smaller ones out there but that's the one I got. This is rugged and made for outdoor (so they say). I did not worry too much about RF performance as this will close to a gateway (it should be at the level of a stubby).
- Energy:
- 1W solar panel 80x100 (seeed studio). This fits nicely on the case and should provide more power than V1 to carry us through the long dark winter. ;-) Although I currently believe that 0,5W would do as well.
- Battery: I went with a 2000mAh single cell lipo. See the discussion on "Battery" below.
- Sensors
- 3x DS18b20
- LTC4150 Coulomb counter (Sparkfun, meh)
- MCU: SODAQ Autonomo. This is an expensive part. I considered using a Feather instead but then I went with the same part as V1 as I have code & experience to do power management on that part (which I may need to re-discover for other platforms). I also used the groove shield (which is absolutely not required) but makes it a bit modular and I had it lying around anyway. You could use other parts of course, for example a RN2483 with a Teensy LC (you need to add LiPo charging then) or an Adafruit Feather LoRa.
- LoRaWAN: RN2483 on bee socket.
Power
As the goal is to create something that is 100% solar powered & autonomous for a long time and I have little experience with such a thing I decided in V1 (and V2) that I want to measure charge/discharge to better understand what's going on. This is done with a coulomb counter (instead of a fuel gauge).
Wiring:
If you do not remove that R7, you will see 1mA loss through ill-dimensioned 3k3 pull-up.
I used a microscope to unsolder this but and magnifying glass should do.
I used a microscope to unsolder this but and magnifying glass should do.
When using a 3,3V system you also need to close the two solder jumpers (SJ2, SJ3) on the underside.
For the solar panel, I removed the wires from the panel, drilled two holes in the case and glued the whole panel to the case and finally re-soldered the wires. I also filled the holes from the inside with silicone which helps to prevent the wires to come loose when moved around. After the silicon has somewhat cured I used more of the stuff to seal edges on the front. The protective film the panel is removed as last step.
I am really sure that this is watertight. However since the panel I've used has "open" (unsealed) edges I think it's possible that moisture may creep in from the front. Time will tell.
In the end I had something like this:
Battery
V1 used a 1600mAh lipo which was plenty.Required battery capacity assumption:
V1 consumed about 1,1mA
V2 should have much lower power consumption, approx 1mA lower.
If we assume it's 1mA (its going to be lower) we'd need 24mAh per day.
In wintertime (below -20℃ is a very rare event) - the capacity will roughly half, so 48mAh per day.
LiPos do somewhat between 200 and 500 cycles. This is a problem. This should (be able to last) longer than a year. This page suggest that limiting depth discharge increases lifetime a lot.
x10 = 500mAh.
The end of the world is near, for sure, but until then there will be some light during the day.
What I don't know how much energy the panel will produce on a cloudy winter day. Data from V1 suggested that on rainy (summer) days there may not be any charge at all.
Anyway, for good measure I'll go with ~2000mAh.
I also want to do an experiment with supercaps, perhaps with the next build
Temperature Sensors
These are DS18B20 Dallas One-Wire sensors. You can get them in a watertight enclosure with (long) wiring. I am using two to get two reading at different depths. The 2nd sensor will be 1m below the first one. Although one-wire sensors can be daisy chained (forming a bus) I am too lazy for the and use two DIOs. This will be using powered (3-wire) mode.
Sensor 1
Black (GND) - to- GND
Red (Pwr) - to - 3V3
Yellow (data) - to - DIO2
Sensor 2
Like sensor 1 but data goes to DIO3
Between data lines and 3V3 I use a 5,6k pull-up. Wiring for this is "flying" ;-) Heat-shrink tubes hold this together...
I also used hot-glue filled heat-shrink tubes to tie the two cables together at some points and coloured heat shrink tubes spaced at 10cm around the anticipated water-line. These depth markers will help with installation later on.
Since I had spare material I rigged a third sensor to record the battery temperature / inside temperature of the case.
Since I had spare material I rigged a third sensor to record the battery temperature / inside temperature of the case.
MCU
The Autonomo comes ready to go. I've disabled on-board charge indicator LED (SJ4 - http://support.sodaq.com/sodaq-one/autonomо/features-autonomo/) since nobody will see it ;-)Case
The case is aluminium so "the elements" should not be a a problem. It will develop a (gray) oxide film which is waterproof thus preventing further corrosion. (There are scenarios where this does not work, by the way). It's not watertight by design but since there is a single cover I plan to use by beloved silicone to make it watertight.The process of adding the solar panel is described above.
Furthermore, I drilled a hole in the top to mount the antenna.
There are two holes in the bottom, one for the sensor wires and one for a "breathing plug". This is basically a small piece of goretex membrane and is IP68 proof. (Product, search for "vent plug membrane" to find more)
By the way, if someone has a suggestion how to integrate a waterproof USB connector - to be able to do maintenance without breaking the seal - that would be welcome information
As you can see I went for chains instead of cable ties this time :-)
warpzone.ms tribute feature
None :-(
Software
The Node-RED sketch was reworked accordingly.

The current software can be found here: https://github.com/kgbvax/kanaltemp
TODO
* Sealing the case
* Mounting
* Adapt the feeds for ELK, opensensemap and dweet.
Friday, October 16, 2015
Perfekte Vollüberwachung von Kfz Bewegungen durch VDS+eCall
Was mich im Kontext VDS wundert ist das "der Deutsche Autofahrer" und der ADAC noch nicht auf die Barrikaden gegangen sind:
eCall: Jedes Kfz in Deutschland wird mit einer SIM ausgerüstet (ab 2018)
+ VDS: vollständige Erfassung von Standortdaten von Mobilfunkteilnehmern (also auch eCall Module in Kfz)
= perfekte Vollüberwachung aller Fahrzeugbewegungen in Deutschland.
Auch ohne das man ein eingeschaltetes Telefon mitführt.
Ach so: Ich operiere unter der Prämisse das die Einschränkungen in der Datennutzung VDS nicht halten. Ist schon praktisch soetwas, bei Fahrerflucht. Gut das geht "gerade noch nicht", da kommen wir aber schon noch hin.
Bzgl. eCall: Das wäre dann zu retten, wenn das eCall Modul sich nur im Notfall im Netz einbucht. Die eCall Norm fordert "[...] im Normalbetrieb [..] nicht verfolgbar sind". Da wäre die Kuh dann vom Eis.
Ich habe mal Hersteller meines Kfz (aus bayrischer Herstellung) gerade mal gefragt der eine entsprechende SIM eingebaut hat wie die das sehen. Bin gespannt.
eCall: Jedes Kfz in Deutschland wird mit einer SIM ausgerüstet (ab 2018)
+ VDS: vollständige Erfassung von Standortdaten von Mobilfunkteilnehmern (also auch eCall Module in Kfz)
= perfekte Vollüberwachung aller Fahrzeugbewegungen in Deutschland.
Auch ohne das man ein eingeschaltetes Telefon mitführt.
Ach so: Ich operiere unter der Prämisse das die Einschränkungen in der Datennutzung VDS nicht halten. Ist schon praktisch soetwas, bei Fahrerflucht. Gut das geht "gerade noch nicht", da kommen wir aber schon noch hin.
Bzgl. eCall: Das wäre dann zu retten, wenn das eCall Modul sich nur im Notfall im Netz einbucht. Die eCall Norm fordert "[...] im Normalbetrieb [..] nicht verfolgbar sind". Da wäre die Kuh dann vom Eis.
Ich habe mal Hersteller meines Kfz (aus bayrischer Herstellung) gerade mal gefragt der eine entsprechende SIM eingebaut hat wie die das sehen. Bin gespannt.
Friday, September 4, 2015
Reiseinformationen: Fluchhafen München
"Der Flughafen München liegt in der schwer erreichbaren Nähe von München."
(Dieter Hildebrand)
Warnung Die S-Bahn München besitzt eine sehr hohe Dichte an Kontrolettis. Münchener Kontrolettis haben einen U-Bahn Phobie, denn dort trifft man sie nie. Fazit: 2x S-Bahn gefahren, 2x 40 EURonen gelatzt. 2 Jahre U-Bahn gefahren, keine Cent abgedrückt. Klingt nach Break Even?
(Dieter Hildebrand)
Abbildung 1: Illustration eins dämlichen Slogans
Der Weg von/zu Fluchhafen München
- Hin: Mit dem Flieger (je nach Wetter)
- Goto 3
- Fort: Mit dem Flieger (je nach Wetter)
Mehr muss man nicht wissen
Transport
Abbildung 2: Pixelfolter
Alternativ (wenn's denn wirklich sein soll) dann kann man auch mit der S-Bahn fahren.
Die eumelt auf verschlungenen Pfaden zweimal um München herum, tritt kurz in österreichisches Territorium ein und kommt dann nach einer kleinen Ewigkeit am Hauptbahnhof zum stehen - sofern sie unterwegs keinen Platten hat. Von diesen Routen hat man sogar zwei zur Auswahl, je nachdem ob man eher linksdrehend oder rechtsdrehen kutschiert werden möchte. Man kann auch einen frühzeitig einen ersten Höhepunkt in die Odysee einflechten, indem man in "Feldmoching" (Name ist da Programm) in die U-Bahn umsteigt. Ich weiss nicht wofür das gut sein soll, aber wenn's schön macht.
Die eumelt auf verschlungenen Pfaden zweimal um München herum, tritt kurz in österreichisches Territorium ein und kommt dann nach einer kleinen Ewigkeit am Hauptbahnhof zum stehen - sofern sie unterwegs keinen Platten hat. Von diesen Routen hat man sogar zwei zur Auswahl, je nachdem ob man eher linksdrehend oder rechtsdrehen kutschiert werden möchte. Man kann auch einen frühzeitig einen ersten Höhepunkt in die Odysee einflechten, indem man in "Feldmoching" (Name ist da Programm) in die U-Bahn umsteigt. Ich weiss nicht wofür das gut sein soll, aber wenn's schön macht.
Auch unterhaltsam ist die Trennung des Zuges der West-Route (S1) in Neufahrn. Der (undefinierbare) Teil fährt weiter nach Freising, der andere Teil zum Flughafen. Führt regelmässig zu Schweissausbrüchen bei den nicht ortsansässigen Fahrgästen. Wie kann man nur auf die verwegene Idee kommen ohne ortskundigen Führer den lokalen Nahverkehr zu Nutzen? Dies beklagt auch die Bergwacht regelmässig in ihrem Jahresbericht aber das ist eine andere Geschichte.
Warnung Die S-Bahn München besitzt eine sehr hohe Dichte an Kontrolettis. Münchener Kontrolettis haben einen U-Bahn Phobie, denn dort trifft man sie nie. Fazit: 2x S-Bahn gefahren, 2x 40 EURonen gelatzt. 2 Jahre U-Bahn gefahren, keine Cent abgedrückt. Klingt nach Break Even?
Weiterhin kann man sich für den fünfachen Preis in einem rostigen Benz-TAXI von einem Fahrer der manchmal nichtmal einen Stadtplan sein eigen nennt auf den zahlereichen ringförmigen Parkplätzen (die von listigen Bayern zweck preussenveralberung als Autobahnen beschildert wurde) einliefern lassen. Dies dauert eher länger und ist wie gesagt teuerer als die Bahn. Dafür gibt es immer mal wieder lustige Begebenheiten wie "Best of Boney-M auf 11", Unfälle, Staus, Achselschweiss, Irrfahrten, unfreiwillige Lebensgeschichten und abgefallene Komponenten.
Fliegen?
Als Zugabe ist der Fluchhafen München mit traumwandlerischer Sicherheit in einer Gegend abgeworfen worden, in der es entweder nebelig ist oder gewittert.
Wenn man so denn mal wieder auf den Airbus wartet bieten sich im sogenannten "Terminal" folgende Aktivtäten zum Zeitvertreib an:
Wenn man so denn mal wieder auf den Airbus wartet bieten sich im sogenannten "Terminal" folgende Aktivtäten zum Zeitvertreib an:
- Man bewegt sich ins Airbräu im Zentralgebäude und ertränkt dort seinen Kummer
- Man geht in Il Mondo dort gibt es ordentliches Essen (nicht wirklich günstig & keine 'Kleinigkeiten') und einen guten Blick auf die Flieger die sich die Fahrgestelle in den Rumpf stehen (da es ja vermutlich mal wieder nebelig ist oder die Blitz zucken)
- Man findet ein herrenloses Gate, bemächtigt sich dort der Sprechanlage und erzählt dem anwesenden Volk erstmal wo der Hammer hängt.
Zusammenfassung
- Wohne in München oder
- fahre Zug oder
- bleib zuhause.
p.s.
- Das Terminal 1 hinter der Security ist übrigens von den Nichtrauch-Nazis überrannt
worden. Terminal 2 hat noch Camel Fluchtburgen. - Die hübschen Bilder kommen allesamt aus den Kampfblättern der Mobil in München e.V. http://www.mobil.org
Zugabe
Abbildung 4: Vollständiger Wirklichkeitsverlust
(Verfasst im Jahre 2008 AD)
Sunday, August 23, 2015
Tuesday, June 30, 2015
Freifunk: Abstand vom Internet gewinnen - Projekt Metaschnorchel
(Kontext: Ich grübel über Sandkastenspiele im VDS Kontext nach)
Wenn man sich "das" mit VDS & TKG gibt, dann möchte man als Freifunk Verein (oder Gruppe) möglichst wenig mit TKG zu tun haben wie es scheint.
Wenn man sich "das" mit VDS & TKG gibt, dann möchte man als Freifunk Verein (oder Gruppe) möglichst wenig mit TKG zu tun haben wie es scheint.
Dazu ist es IMHO hilfreich, wenn die Communities nicht Betreiber des Meshnetzes sind oder sich so aufführen. Betreiber ist derjenige der rechtliche und tatsächlichen Kontrolle ausübt (mehr in einem speziell Fall hier: http://www.kanzlei.biz/nc/urteile/16-03-2012-bgh-v-zr-98-11.html ).
Damit man nicht als Betreiber der Mesh-Netzes gesehen wird kann es sinnvoll sein bestimmte Merkmale anzustreben:
- Freifunk Communities sind nicht Eigentümer der Mesh-Knoten. - Bei Privatpersonen / Unternehmen ist das ja eh kein Problem. Die Knoten gehören den Menschen da draußen. Dies sollte aber insbesondere bei Verwendung von Spendengeldern berücksichtigt werden. D.h. Eigentum übertragen (und nicht nur hinstellen). Es gibt auch andere Gründe warum man Hardware nicht besitzen will. Haftung, Gewährleistung, Erwartungshaltungen, Wartung etc.
- Freifunk Communities haben in der Regel keinen Zugang zu Mesh-Knoten. - Meint z.b. SSH Keys. Sollten man doch bitte vermeiden. Ist wie ich es verstehe heute auch schon gegeben.
- Das Mesh-Netz ist ohne Gateway funktionsfähig - Wenn Infrastruktur der Freifunk Vereine/Gruppen nicht essentiell für die Nutzung zum Datenaustausch ist, dann kann ich mir vorstellen das man gut argumentieren kann das man nicht der Betreiber ist, sondern eben nur einen Dienst anbietet: Gateway ins Internet.
- Das ist heute bei Gluon Communities nicht so ganz plausibel, es sei denn man baut Layer 2 Dienste auf. Also eher nicht. Die Mindestfunktion die das Netz autonom beherrschen sollte ist vermutlich:
- IP Addressvergabe - vielleicht ist der Distributed DHCP von @tcatm ein erster Schritt in die Richtung? Toll wäre es ein (lokales) Mesh ohne Uplink schaffen könnte IP Adressen zu vergeben. Gibt es andere Ansätze oder wurde das schonmal gelöst?
- Irgendeine Form von Dienste Discovery. Wie man das technisch macht habe ich keine Idee aber in einem lokalen Mesh könnte ich mir Multicast DNS durchaus vorstellen. Würde ad-hoc funktionieren und es gibt eben auch Client Dienste.
- Es gibt lokale Dienste - Dürfte die Plausibilität erhöhen.
Was wir dann hätten wäre ein Netz welches
- ohne zentrale Infrastruktur der Communites funktioniert
- demonstrierbar Kommunikation ermöglicht
- dessen Hardware den Knotenbetreibern gehört / in Gemeinbesitz ist und die Knotenbetreiber die alleinige Kontrolle über die Knoten haben.
- ohne zentrale Infrastruktur der Communites funktioniert
- demonstrierbar Kommunikation ermöglicht
- dessen Hardware den Knotenbetreibern gehört / in Gemeinbesitz ist und die Knotenbetreiber die alleinige Kontrolle über die Knoten haben.
UND
einige Freifunk Communities bieten auf dieser Basis einen Dienst "Internet Gateway" an.
einige Freifunk Communities bieten auf dieser Basis einen Dienst "Internet Gateway" an.
Könnte VDS resistent sein. Oder Selbsttäuschung?
Und auch unabhängig von VDS klingt das alles sehr wünschenswert.
Meinungen?
Sunday, June 21, 2015
VDS vs Messenger: Deep Packet Clusterfuck
Im Kontext Freifunk beschäftige ich mich gerade mit möglichen VDS Auswirkungen auf Community Netze. Dabei kam ich auch an Messaging Diensten und Internet Telefonie vorbei:
(TKG Änderung: §113b) "im Fall von Internet-Telefondiensten auch die Internetprotokoll-Adressen des anrufenden und des angerufenen Anschlusses und zugewiesene Benutzerkennungen" sowie "bei der Übermittlung einer Kurz-, Multimedia- oder ähnlichen Nachricht; hierbei treten an die Stelle der Angaben nach Satz 1 Nummer 2 die Zeitpunkte der Versendung und des Empfangs der Nachricht;"
Wenn man an eine "Kurznachricht ähnliche Nachricht" denkt und kurz überlegt was heutzutage benutzt wird, dann kommt man sofort aus Messengerdienste, also WhatsApp, Skype, BBM, Threema etc. Ist das eine Kurznachricht ähnliche Nachricht? Ja. Wird das vom Entwurf erfasst? Mir persönlich unklar, auch weil ich über Abrenzung TKG/TMG stolpere. ECO meint Messaging Dienste werden nicht erfasst.
2015 SMS Kommunikationsmetadaten zu speichern und Messenger zu ignorieren klingt irgendwie sinnlos.
Hallo Schwerstkriminelle, Pro Tip: WhatsApp nutzen. Das WhatsApp mal "Privacy" versprechen würde hätte mir 2013 auch keiner geglaubt.
Also warten wir mal bis jemand aus dem Busch springt und auch Speicherung von "Messenger" Dienste fordert. 3...2...
Wie würde das den aussehen? Man muss in den Datenstrom reinschauen. Deep Packet Inspection nennt sich das. Ziemlich teure Technik. Aber würde das überhaupt helfen?
Halbwegs moderne Kurznachrichtendienste verschlüsseln ihre Kommunikation. Selbst Facebook/WhatsApp hat das mittlerweile begriffen. Zumindest die Verbindung zwischen Messenger und Server, die übliche Technik dazu heisst TLS (früher mal SSL genannt). "Bessere" machen dann noch Ende-Zu-Ende Verschlüsselung darauf. Nehmen wir mal threeema.ch als Beispiel, die machen das so.
Das Problem dabei ist das moderne Kryptographie doch recht gut funktioniert. Eine gute TLS Implementation "macht man nicht mal eben so auf". Und Unternehmen haben begriffen das "schwer abhörbar" heute ein Verkaufsargument ist. TLS ist auch noch nicht das Maximum, da geht noch was. Und Kryptographie ist billig.
Da hilft auch Deep Packet Inspection nicht. Was nun? Der Provider kann speichern das vermutlich eine Nachricht versendet wurde. Nicht wohin. Und nicht mit welcher "Nutzerkennung". Das dürfte aber bei einer Strafverfolgung nur sehr unbefriedigende Erkenntnisse liefern.
Die nächste Stufe wäre dann die Verschlüsselung so zu gestalten, das ein Provider doch reinschauen kann. Sprich sie per Gesetz kaputtzumachen.
David Cameron hat sowas schonmal pauschal in die Welt gesetzt.
"But the question is are we going to allow a means of communications which it simply isn’t possible to read. My answer to that question is: no, we must not" (Source)
Was dann kommt hatten wir schon, siehe Crypto Wars.
Für die jüngeren Leser: Dies bedeutet das man den Zugriff auf starke Verschlüsselung reguliert.
D.h. zum Beispiel bestimmte Apps zu verbieten. Bestimmten Programm-Code zu verbieten. Gedruckten Programm-Code verbieten. Ein Buch zu verbieten.
Und kein Szenario das ich für wahrscheinlich halte.
Für Internet-Telefonie gilt ähnliches.
Also können wir bitte von dem VDS Knochen ablassen und die Sicherheitsbedürfnissemit einem anderen Placebo befriedigen?
(TKG Änderung: §113b) "im Fall von Internet-Telefondiensten auch die Internetprotokoll-Adressen des anrufenden und des angerufenen Anschlusses und zugewiesene Benutzerkennungen" sowie "bei der Übermittlung einer Kurz-, Multimedia- oder ähnlichen Nachricht; hierbei treten an die Stelle der Angaben nach Satz 1 Nummer 2 die Zeitpunkte der Versendung und des Empfangs der Nachricht;"
Wenn man an eine "Kurznachricht ähnliche Nachricht" denkt und kurz überlegt was heutzutage benutzt wird, dann kommt man sofort aus Messengerdienste, also WhatsApp, Skype, BBM, Threema etc. Ist das eine Kurznachricht ähnliche Nachricht? Ja. Wird das vom Entwurf erfasst? Mir persönlich unklar, auch weil ich über Abrenzung TKG/TMG stolpere. ECO meint Messaging Dienste werden nicht erfasst.
2015 SMS Kommunikationsmetadaten zu speichern und Messenger zu ignorieren klingt irgendwie sinnlos.
Hallo Schwerstkriminelle, Pro Tip: WhatsApp nutzen. Das WhatsApp mal "Privacy" versprechen würde hätte mir 2013 auch keiner geglaubt.
Also warten wir mal bis jemand aus dem Busch springt und auch Speicherung von "Messenger" Dienste fordert. 3...2...
Wie würde das den aussehen? Man muss in den Datenstrom reinschauen. Deep Packet Inspection nennt sich das. Ziemlich teure Technik. Aber würde das überhaupt helfen?
Halbwegs moderne Kurznachrichtendienste verschlüsseln ihre Kommunikation. Selbst Facebook/WhatsApp hat das mittlerweile begriffen. Zumindest die Verbindung zwischen Messenger und Server, die übliche Technik dazu heisst TLS (früher mal SSL genannt). "Bessere" machen dann noch Ende-Zu-Ende Verschlüsselung darauf. Nehmen wir mal threeema.ch als Beispiel, die machen das so.
Das Problem dabei ist das moderne Kryptographie doch recht gut funktioniert. Eine gute TLS Implementation "macht man nicht mal eben so auf". Und Unternehmen haben begriffen das "schwer abhörbar" heute ein Verkaufsargument ist. TLS ist auch noch nicht das Maximum, da geht noch was. Und Kryptographie ist billig.
Da hilft auch Deep Packet Inspection nicht. Was nun? Der Provider kann speichern das vermutlich eine Nachricht versendet wurde. Nicht wohin. Und nicht mit welcher "Nutzerkennung". Das dürfte aber bei einer Strafverfolgung nur sehr unbefriedigende Erkenntnisse liefern.
Die nächste Stufe wäre dann die Verschlüsselung so zu gestalten, das ein Provider doch reinschauen kann. Sprich sie per Gesetz kaputtzumachen.
David Cameron hat sowas schonmal pauschal in die Welt gesetzt.
"But the question is are we going to allow a means of communications which it simply isn’t possible to read. My answer to that question is: no, we must not" (Source)
Was dann kommt hatten wir schon, siehe Crypto Wars.
Für die jüngeren Leser: Dies bedeutet das man den Zugriff auf starke Verschlüsselung reguliert.
D.h. zum Beispiel bestimmte Apps zu verbieten. Bestimmten Programm-Code zu verbieten. Gedruckten Programm-Code verbieten. Ein Buch zu verbieten.
Und kein Szenario das ich für wahrscheinlich halte.
Für Internet-Telefonie gilt ähnliches.
tl;dr
- VDS erfasst nur SMS & Friends.
- Heutzutage genutzte Messenger werden nicht erfasst.
- Es ist nicht möglich diese sinnvoll zu erfassen. Ein Rüstungswettlauf gegen Messenger Krypto kann selbst für "State Level Actors" schwierig sein.
- Crypto Wars anyone?
Also können wir bitte von dem VDS Knochen ablassen und die Sicherheitsbedürfnisse
VDS vs Münster
Auf eine VDS Implementation freuen sich in Münster folgende Telekommunikationsgiganten, die die VDS bestimmt problemlos bewältigen werden:
- Messe und Congress Centrum Halle Münsterland GmbH
- AScode, Klausenburgweg
- nicos Aktiengesellschaft, Mendelstraße
- Offenes Usenet-Team e.V., Wesler Strasse
- Ratiodata IT-Lösungen & Services GmbH, Gustav-Stresemann-Weg
- RNT Regionale Nachrichten Technik GmbH, Grevener Strasse
- The Phone House Services GmbH, Münsterstrasse
- Völkel Mikroelektronik Gesellschaft mit beschränkter Haftung, Otto-Hahn-Strasse
- Webdiscount GmbH & Co. KG, Hafenweg
- Zwei Löwen mediawerk GmbH, Hafenweg
- 23Media GmbH, Grafschaft
- Alarmruf - Wachzentrale Sievers GmbH & Co. KG, An den Loddenbüschen
- endoo GmbH & Co. KG, Am Dornbusch
- Globe Development GmbH, Königsberger Strasse
- ICSmedia GmbH, Soester Straße
Tuesday, September 23, 2014
Zeitgeist Datenschutz for English Speakers
Kindergarten, Fahrvergüngen, Doppelgänger, Zeitgeist.
These are some of the terms that made it from the German language into English. I'd like to tell you about another one which is ever-present in today's German, more relevant than ever and has no direct translation into English.
Datenschutz. The dictionary says it's "data privacy" but from my understanding this does not really cut it. Like Angst which is not straight fear but is more specific, Datenschutz is the subject of "data privacy" but it also includes an underlying idea:
Datenschutz (noun).
Literally it means "data protection".
Initially it was also defined (by law in 1970) as such. The protection of data from manipulation, loss or theft. Over time that has changed (I won't go into detail about this process) but now it's something rather different.
Not the data is protected but the individuals which are represented by that data. Which brings us close to "data privacy".
Wikipedia (DE) defines Datenschutz as:
The protection from abusive information processing, protection of the right to informational self-determination. Protection of personality rights in the context of information processing or protection of privacy. Datenschutz stands for the idea that every human can decide for themselves to whom he/she makes what personal information available.
Although it is not stated in Germany's constitution, the constitutional court elevated a derived "right to informational self determination" to a fundamental right.
Datenschutz - as federal law - asserted 1986 that any processing of personal information is illegal unless permitted by law. The same law also calls for Datensparsamkeit (another good one) which literally means "data frugality" which goes hand in hand with Datenvermeidung (data avoidance).
Of course there are lot of exceptions and loopholes (hooray for bonus cards!) but the important bit seems to be that we had a public discussion over several years in Germany on Datenschutz in the context of a general census (which finally happened in 1987) and since this time the idea that "my data is my property" is prevalent.
Based on this discussion there is a deep distrust on anybody who is collecting data: Once data has been obtained, people (who have for example a large commercial incentive) will find creative and unexpected ways to use or combine it in interesting and abusive ways. This is difficult to fix once it happened and more difficult to prevent by regulation - unless you do not obtain the data in the first place.
Datenschutz is opinionated. It has this underlying assumption: We own and control our data. And unless you seek permission it's not ok to use it as you please.
But maybe I got "data privacy" wrong, if this is the case please enlighten me.
@ingomar
These are some of the terms that made it from the German language into English. I'd like to tell you about another one which is ever-present in today's German, more relevant than ever and has no direct translation into English.
Datenschutz. The dictionary says it's "data privacy" but from my understanding this does not really cut it. Like Angst which is not straight fear but is more specific, Datenschutz is the subject of "data privacy" but it also includes an underlying idea:
Datenschutz (noun).
Literally it means "data protection".
Initially it was also defined (by law in 1970) as such. The protection of data from manipulation, loss or theft. Over time that has changed (I won't go into detail about this process) but now it's something rather different.
Not the data is protected but the individuals which are represented by that data. Which brings us close to "data privacy".
Wikipedia (DE) defines Datenschutz as:
The protection from abusive information processing, protection of the right to informational self-determination. Protection of personality rights in the context of information processing or protection of privacy. Datenschutz stands for the idea that every human can decide for themselves to whom he/she makes what personal information available.
Although it is not stated in Germany's constitution, the constitutional court elevated a derived "right to informational self determination" to a fundamental right.
Datenschutz - as federal law - asserted 1986 that any processing of personal information is illegal unless permitted by law. The same law also calls for Datensparsamkeit (another good one) which literally means "data frugality" which goes hand in hand with Datenvermeidung (data avoidance).
Of course there are lot of exceptions and loopholes (hooray for bonus cards!) but the important bit seems to be that we had a public discussion over several years in Germany on Datenschutz in the context of a general census (which finally happened in 1987) and since this time the idea that "my data is my property" is prevalent.
Based on this discussion there is a deep distrust on anybody who is collecting data: Once data has been obtained, people (who have for example a large commercial incentive) will find creative and unexpected ways to use or combine it in interesting and abusive ways. This is difficult to fix once it happened and more difficult to prevent by regulation - unless you do not obtain the data in the first place.
Datenschutz is opinionated. It has this underlying assumption: We own and control our data. And unless you seek permission it's not ok to use it as you please.
But maybe I got "data privacy" wrong, if this is the case please enlighten me.
@ingomar
Thursday, June 5, 2014
Flatrate Saufen a la Telekom
Willkommen zum Flatrate Fest, powered by Telekom
Hier gibt es zu nervötenem Gejingle Bier vom Faß soviel du willst für nur einmalig 15€ (*1)
Das Fest beginnt um 18 Uhr.
(*1)
Faire Nutzungsklausel: Nach 60 Minuten (um sieben) wird die Bierzufuhr gedrosselt. Statt 0,5l pro Glas gibt es dann noch 4ml Gläser. Du kannst natürlich weiterhin beliebig oft zur Theke gehen und dir ein neues Bier holen.
Monday, December 24, 2012
DIY Fusion Drive in a 2012 27" iMac
I've just converted my brand-spanking new 27" iMac to a DIY Fusion Drive.
It works, but is not for the faint of heart:
Opening up the 27" iMac involves some major surgery. I used a 0.6mm plectrum to squeeze away the glue after a little warm up with a regular hair-dryer and two suction cups. The latter are not required.
Be warned that after you removed the adhesive tape (which is what it is) you won't be able to close the iMac properly unless you replace it. I had the display involuntarily come off once and was lucky to catch it. I recommend to wait until the iFixits of the world provide a replacement. Unfortunately I can not identify the sticky tape type. Despite what I read elsewhere, the internal disk may not be 2.5". My iMac (1G disk) came with a 3.5" Seagate Barracuda. You thus may require a 2.5" -> 3.5" adapter. Initially I replaced the internal HDD with an SSD and planned to install OS X from an USB stick. However I could not get the iMac to boot from an external USB disk or SD card which I have prepared using my MacBook. I think there may be something special about the iMac that defies booting from "non iMac" media. I know this sounds strange.
Network Recovery also failed with an error -2003F so I got utterly stuck. Here is how I resolved this:
I mounted the original internal disk back in the iMac and attached the SSD using the Seagate Thunderbolt adapter and the HDD using an USB3 adapter.
I then booted into recovery mode and first installed OSX on the SSD only so that I have proper recovery partition. I then mounted the SSD in the iMac and validated that it would in fact boot. Next, I put the original internal disk back, booted recovery mode once more and created the Fusion Drive on the SSD/external HD as per Jollyjinx' description and installed OS X. Works :-). Last step was to mount the SSD in the iMac. My current setup looks like this: Internal 256G Samsung SSD (840 Pro)
External 4TB Seagate Backup Plus interfaced through Thunderbolt.
After some usage I have to say it really delivers. Most of what I do feels blazingly fast. With a 4T disk. Just awesome. :-)
tl;dr
When you want to convert your 2012 27" iMac to a DIY fusion drive
Be prepared to see the iMac Display in a loosely attached state unless you replace the adhesive tape. Make sure that the display does not fall off.
Install the FD from the internal drive before replacing the internal drive
If you have done a similar conversion, I would be intrested to hear about it.
@ingomar
Be warned that after you removed the adhesive tape (which is what it is) you won't be able to close the iMac properly unless you replace it. I had the display involuntarily come off once and was lucky to catch it. I recommend to wait until the iFixits of the world provide a replacement. Unfortunately I can not identify the sticky tape type. Despite what I read elsewhere, the internal disk may not be 2.5". My iMac (1G disk) came with a 3.5" Seagate Barracuda. You thus may require a 2.5" -> 3.5" adapter. Initially I replaced the internal HDD with an SSD and planned to install OS X from an USB stick. However I could not get the iMac to boot from an external USB disk or SD card which I have prepared using my MacBook. I think there may be something special about the iMac that defies booting from "non iMac" media. I know this sounds strange.
Network Recovery also failed with an error -2003F so I got utterly stuck. Here is how I resolved this:
I mounted the original internal disk back in the iMac and attached the SSD using the Seagate Thunderbolt adapter and the HDD using an USB3 adapter.
I then booted into recovery mode and first installed OSX on the SSD only so that I have proper recovery partition. I then mounted the SSD in the iMac and validated that it would in fact boot. Next, I put the original internal disk back, booted recovery mode once more and created the Fusion Drive on the SSD/external HD as per Jollyjinx' description and installed OS X. Works :-). Last step was to mount the SSD in the iMac. My current setup looks like this:
Wednesday, November 7, 2012
Seagate Backup Plus 4GB: USB3 vs Thunderbolt
If you are considering to get a thunderbolt version of the Backup Plus disk or to retrofit the thunderbolt desktop adapter (STAE127) here are some measurements I took:
Via USB 3:
Via Thunderbolt, Seagate STAE127 desktop thunderbolt adapter:
Disk is a Seagate Backup Plus 4GB.
Host is a 2012 MBPr with 10.8.2
Friday, October 5, 2012
Warum heissen Griechische Restaurants wie sie heissen?
Ich habe mal in Köln gewohnt, so 10 Jahre. Neustadt-Nord.
10 Jahre lang bin ich regelmäßig an einem griechischem Restaurant vorbeigekommen das fast immer zu hatte. "Athos" heiss das.
Das lag zwischen dem "Dionisus" und dem "Diogenes". Echt.
Komisch das mit den Namen. Die Süddeutsche Zeitung spekuliert recht verwegen darauf das dies etwas mit der Herkunft des Gründers zu tun hat. Das ist natürlich völliger Unfug. Wie wir wissen kommen alle Griechen aus Griechenland, dann müssten ja alle Restaurants "beim Griechen" heissen. Tatsächlich sind das aber nur weniger als 5%.
An einem lauen Sommerabend konnte ich das Mysterium der Bezeichnung der Griechischen Restaurants durch Deduktion (φαντασία) lösen:
Es gab in der Zeit der Gründung vieler dieser Restaurants beim Gewerbeamt eine Liste aus der sich der Jungunternehmer einen Namen auszuwählen hatte. Dies war durch eine Verwaltungsvorschrift im Kontext des Anwerbeabkommen vom 30. März 1960 geregelt. Dort hiess es:
Und dann kommt die Liste.
Krass. Aber so war das damals. Unter den Talaren....
Die entsprechende Verwaltungsvorschrift wurde erst 1982 im Rahmen von EU (bzw EWG) Harmonisierungen verworfen. Das Ergebnis sehen wir heute. Aber wie heissen sie denn nun? Ich habe aus "OpenStreetMap" mal sämtliche als "griechische Restaurants" extrahiert, die Namen normalisiert und aus den rund 2000 kartographierten Restaurants folgende Verteilung erhalten: Aber es gibt Hoffnung in der Namenswüste.
Auch wenn sich solche Restaurants über Jahrzehnte halten und ihren Namen nichts verändern gibt es doch Neugründungen die sich erfrischend abgrenzen. In Berlin, Prenzlauer Berg habe ich "Frau Galinou kocht" gefunden.
Da werde ich mal hingehen.
Es gab in der Zeit der Gründung vieler dieser Restaurants beim Gewerbeamt eine Liste aus der sich der Jungunternehmer einen Namen auszuwählen hatte. Dies war durch eine Verwaltungsvorschrift im Kontext des Anwerbeabkommen vom 30. März 1960 geregelt. Dort hiess es:
"Um eine Verwechselung von Speiselokalen vorzubeugen und insbesondere die Bürger der BRD vor unvermittelten Olivenölgenuss (der sich auf den ungeübten Magen der Werktätigen überraschend auswirken kann) zu schützen haben Lokale, die hauptsächlich Speisen der grichischen Küche feilbieten, eine entsprechend eindeutige Bezeichnung zu führen. Dies kann durch die Verwendung der im folgenden genannten Eigennamen oder durch das Voranstellen des regionalen Gattungsbegriffs "Taverna" geschehen."
Und dann kommt die Liste.
Krass. Aber so war das damals. Unter den Talaren....
Die entsprechende Verwaltungsvorschrift wurde erst 1982 im Rahmen von EU (bzw EWG) Harmonisierungen verworfen. Das Ergebnis sehen wir heute. Aber wie heissen sie denn nun? Ich habe aus "OpenStreetMap" mal sämtliche als "griechische Restaurants" extrahiert, die Namen normalisiert und aus den rund 2000 kartographierten Restaurants folgende Verteilung erhalten: Aber es gibt Hoffnung in der Namenswüste.
Auch wenn sich solche Restaurants über Jahrzehnte halten und ihren Namen nichts verändern gibt es doch Neugründungen die sich erfrischend abgrenzen. In Berlin, Prenzlauer Berg habe ich "Frau Galinou kocht" gefunden.
Da werde ich mal hingehen.
Friday, July 22, 2011
HOWTO create an encrypted TimeMachine Backup on an Apple software RAID using Lion FileVault2
My MacPro is filled with disks which implies that a single disk of the type "the biggest you can buy" is insufficient for my TimeMachine needs. So far I have been using an OSX software RAID for TimeMachine which worked rather well.
As I want to use 10.7 / Lion full disk encryption, the whole encryption is moot if the same data is stored as clear-text in TimeMachine.
Even before Lion it was possible to use encrypted sparse disk images (as TimeCapsule uses them) to encrypt TimeMachine but frankly I don't assume that a 4Gb disk image is adequate.
Lion allows you to specify that you want your backups to be encrypted, but in my case this was refused with a simple "not supported on raid".
Using diskutil I managed to get it work anyway.
WARNING This worked for me. Once. I think.
This procedure may trash your data or set your cat on fire. Proceed at your own risk.
This procedure will delete all data on the raid volume. I didn't care too much as this was TimeMachine history only.
In Terminal, dump the current disk layout for reference:
"diskutil list". In my case this looks like this:
Note that the RAID volumes in my case were disk1s2 and disk2s2.
What I did was to delete the RAID in DiskUtility and to re-create it. You may not have to do this. Note that even if you do not re-create the RAID, you will still loose all data on the RAID-set.
Step 1: Create a RAID set:
Replace disk1s2, disk2s2 with the list of the partitions you want to use for this RAID-set.
If you don't want a "stripe" RAID0 you can use other types:
All the usual Apple RAID options can be used, including stacked RAIDs like RAID 10, RAID 0+1 etc. "man diskutil" or DiskUtility is your friend.
Now you should have a new RAID-set. Let's check:
Good. disk4 is the name of the Raid-set
We now have to create a CoreStorage Logical Volume Group.
CoreStorage is the new volume manager in Lion which is the foundation for FileVault2).
(Replace "disk4" with the name of your AppleRaid)
We now should have a CoreStore Logical Volume Group.
"diskutil cs list" will print it out:
There your have it, an encrypted RAID-set.
Point TimeMachine to the new location and that's it.
I haven't yet looked into details of FileVault2 (details are also very hard to come by at this time) so the whole exercise may be plain idiotic. For example I haven't tried whether I can restore from this volume (as the backup of 1,4Tb is still ongoing). I will update the post once I have tried this. You may want to wait for this ;-)
As I want to use 10.7 / Lion full disk encryption, the whole encryption is moot if the same data is stored as clear-text in TimeMachine.
Even before Lion it was possible to use encrypted sparse disk images (as TimeCapsule uses them) to encrypt TimeMachine but frankly I don't assume that a 4Gb disk image is adequate.
Lion allows you to specify that you want your backups to be encrypted, but in my case this was refused with a simple "not supported on raid".
Using diskutil I managed to get it work anyway.
WARNING This worked for me. Once. I think.
This procedure may trash your data or set your cat on fire. Proceed at your own risk.
This procedure will delete all data on the raid volume. I didn't care too much as this was TimeMachine history only.
In Terminal, dump the current disk layout for reference:
"diskutil list". In my case this looks like this:
/dev/disk0 #: TYPE NAME SIZE IDENTIFIER 0: GUID_partition_scheme *256.1 GB disk0 1: EFI 209.7 MB disk0s1 2: Apple_HFS SSD 255.2 GB disk0s2 3: Apple_Boot 650.0 MB disk0s5 /dev/disk1 #: TYPE NAME SIZE IDENTIFIER 0: GUID_partition_scheme *2.0 TB disk1 1: EFI 209.7 MB disk1s1 2: Apple_RAID 2.0 TB disk1s2 3: Apple_Boot Boot OS X 134.2 MB disk1s3 /dev/disk2 #: TYPE NAME SIZE IDENTIFIER 0: GUID_partition_scheme *2.0 TB disk2 1: EFI 209.7 MB disk2s1 2: Apple_RAID 2.0 TB disk2s2 3: Apple_Boot Boot OS X 134.2 MB disk2s3 ....
Note that the RAID volumes in my case were disk1s2 and disk2s2.
What I did was to delete the RAID in DiskUtility and to re-create it. You may not have to do this. Note that even if you do not re-create the RAID, you will still loose all data on the RAID-set.
Step 1: Create a RAID set:
diskutil ar create stripe myNewRaidSet JHFS+ disk1s2 disk2s2
Replace disk1s2, disk2s2 with the list of the partitions you want to use for this RAID-set.
If you don't want a "stripe" RAID0 you can use other types:
o "stripe" - Striped Volume (RAID 0) o "mirror" - Mirrored Volume (RAID 1) o "concat" - Concatenated Volume (Spanning)
All the usual Apple RAID options can be used, including stacked RAIDs like RAID 10, RAID 0+1 etc. "man diskutil" or DiskUtility is your friend.
Now you should have a new RAID-set. Let's check:
diskutil list ... /dev/disk4 #: TYPE NAME SIZE IDENTIFIER 0: Apple_HFS myNewRaidSet *4.0 TB disk4
Good. disk4 is the name of the Raid-set
We now have to create a CoreStorage Logical Volume Group.
CoreStorage is the new volume manager in Lion which is the foundation for FileVault2).
diskutil cs create myNewLvg disk4
(Replace "disk4" with the name of your AppleRaid)
We now should have a CoreStore Logical Volume Group.
"diskutil cs list" will print it out:
iomp:~ io$ diskutil cs list CoreStorage logical volume groups (1 found) | +-- Logical Volume Group 0CBCF265-CCC0-4564-90D2-30F5F3080FAB ========================================================= Name: myNewLvg Sequence: 1 Free Space: 3999958884352 B (4.0 TB) | +-< Physical Volume 3C01045D-9391-4707-B0D8-5DC1551BF459 ---------------------------------------------------- Index: 0 Disk: disk4 Status: Online Size: 4000109887488 B (4.0 TB)Excellent. We still don't have a volume that we can use, this is created in the next step:
diskutil cs createVolume 0CBCF265-CCC0-4564-90D2-30F5F3080FAB jhfs+ MyEncryptedRaid 100% -stdinpassphraseThe parameters in details:
- The lengthy hex string must be the UUID of the logical volume group you've created in the previous step. See above "myNewLvg"
- JHFS+ tells disktuil that we want a journaled HFS+ volume (which should be fine)
- 100% means - "use 100% of the logical volume group for this volume". You can create multiple smaller volumes if you fancy those.
- -stdinpassphrase will cause diskutil to ask for an encryption pass phrase.
CoreStorage logical volume groups (1 found) | +-- Logical Volume Group 0CBCF265-CCC0-4564-90D2-30F5F3080FAB ========================================================= Name: myNewLvg Sequence: 2 Free Space: 0 B (0 B) | +-< Physical Volume 3C01045D-9391-4707-B0D8-5DC1551BF459 | ---------------------------------------------------- | Index: 0 | Disk: disk4 | Status: Online | Size: 4000109887488 B (4.0 TB) | +-> Logical Volume Family B290CE10-87A6-4D75-AE3A-EF3ECF401635 ---------------------------------------------------------- Sequence: 2 Encryption Status: Unlocked Encryption Type: AES-XTS Encryption Context: Present Conversion Status: NoConversion Has Encrypted Extents: Yes Conversion Direction: -none- | +-> Logical Volume 948377BF-5F9B-47A1-A6D5-E98472F32072 --------------------------------------------------- Disk: disk5 Status: Online Sequence: 2 Size (Total): 3999958884352 B (4.0 TB) Size (Converted): -none- Revertible: No LV Name: tm4cc Volume Name: tm4cc Content Hint: Apple_HFS
There your have it, an encrypted RAID-set.
Point TimeMachine to the new location and that's it.
I haven't yet looked into details of FileVault2 (details are also very hard to come by at this time) so the whole exercise may be plain idiotic. For example I haven't tried whether I can restore from this volume (as the backup of 1,4Tb is still ongoing). I will update the post once I have tried this. You may want to wait for this ;-)
Wednesday, April 6, 2011
Dieser grüne Hype..
ist mir ja ein Rätsel.
Die CDU hat 7 AKWs abgestellt.
Die Grünen 0.
Wer ist denn hier nun grün? ;-)
Die CDU hat 7 AKWs abgestellt.
Die Grünen 0.
Wer ist denn hier nun grün? ;-)
Monday, June 14, 2010
Vuvuzela Filter im Eigenbau
Klingt ganz brauchbar und sollte auch mit jeder anderen Audio Software umsetzbar sein:
http://www.surfpoeten.de/tube/vuvuzela_filter
http://www.surfpoeten.de/tube/vuvuzela_filter
Friday, November 13, 2009
Monday, November 9, 2009
Beginnen wir mit etwas Seriösen
Soeben haben wir aus dem Spiegel erfahren, dass irgendwer in irgendwelchen Schichten von irgendwas Reste von Tieren gefunden hat, die viel wichtiger sind, als andere Reste von Tieren die jemals irgendjemand irgendwo irgendwann in irgendwelchen Schichten von irgendwas gefunden hat.
Subscribe to:
Posts (Atom)














