Thursday, June 28, 2007

ISP Giants Form New Lobbying Group

WASHINGTON, D.C., U.S.A., (14 Jan 2002, 4:54 PM CST) A clutch of the nation's largest Internet service providers (ISPs) today announced that they had joined forces to form a new lobbying group that will address the growing number of high-tech policy matters that directly concern ISP operators.

America Online, Verizon Online, WorldCom Inc., Earthlink and a handful of other ISP giants have signed on as founding members of the United States Internet Service Provider Association (US ISPA).

"This is an awfully focused organization," said Stewart Baker, an attorney for the Washington law firm Steptoe & Johnson, who is serving as the group's general counsel. "These are ISPs - large ones - who are really pooling their resources to address issues that effect ISPs specifically."

Although many of the founding companies are active members of other high-tech associations and lobbying groups, the US ISPA will be the first such group to address the specific needs of the nation's largest ISPs, Baker said.

The top legislative priority for the group will be to define parameters for how ISPs work with law enforcement agencies, particularly in the wake of the Sept. 11 terrorist attacks, Baker said. Baker said that the ISPs want to make it clear to Congress "what they can do and what they can't do," in terms of assisting criminal investigations.

Other legislative issues on the group's plate will include the obligations of ISPs under international cybercrime rules and critical infrastructure protection as it relates to service providers.

Baker acknowledged that the founding members of the US ISPA include several companies that argue against one another in other areas of the high-tech policy debate, but he said that the companies also have plenty of common ground. "We'll be working on the things we have in common, and there are a lot of them," Baker said.

Verizon and WorldCom particularly have argued opposite sides in the debate over whether Bell companies (like Verizon) should be allowed to offer long-distance broadband Internet service without opening their local phone service markets to competition.

The US ISPA Web site is still under construction, but will eventually be online at http://www.usispa.org.

Internet Providers Form New Group To Address Security, Liability Issues
Dow Jones Newswires

WASHINGTON (January 14, 2002) Several Internet companies announced Monday the creation of a new group representing service providers and said it will focus on compliance and liability issues. The U.S. Internet Service Provider Association will replace the Commercial Internet eXchange, which is disbanding.

According to US ISPA, the change came about because "as the ISP community has matured so have its needs for an organization that could represent the growing legal and policy issues common to service providers."

Founding members of US ISPA's board include representatives from AOL Time Warner Inc.'s America Online, Cable & Wireless PLC, Earthlink Inc., eBay Inc., Teleglobe, Verizon Online and WorldCom Inc.

"We are very excited about the new focus and membership of US ISPA," said Clint Smith, president of the association and vice president and chief network counsel of WorldCom.

The group's vice president, Tom Dailey, said: "The US ISPA will serve as an effective voice for the ISP community on a wide variety of compliance and liability issues of common interest to ISPs."

He said some issues the group will examine include Internet security, online liability and compliance with the new antiterrorism law, the USA-Patriot Act and the Council of Europe Convention on Cybercrime.

The group said it will also provide a forum for critical infrastructure and cyber-security issues, and looks forward to working closely with the federal government on efforts launched since Sept. 11.

The group said it will also advance "a variety of other policy and legal issues of concern to ISPs, such as Internet privacy, content regulations and intellectual property."

The group's press release did not specifically mention open access, a hot issue in the past. Open access refers to a policy that forces a cable operator providing Internet service using affiliated ISP to sell unaffiliated ISPs access to the cable pipeline.

http://www.cix.org/articles.html





Wednesday, June 27, 2007

Wireless Internet Service Providers

Wireless Internet service providers offer their customers wireless Internet - that is, web access which requires no physical connections to a modem. All of the required technology for going online is cable-free. There are no land based cables to connect from the computer to the modem. A signal is placed in the computer, and the customer is provided with a wireless modem to pick up the signal. A cable-free connection should be fast and quick to install. Consumers may be considering getting cable-free web services. They can find plenty of companies offering these services both locally and online. Nearly every major web provider offers both a traditional cable web connection and a cable-free connection. Thus, it may be difficult to choose the best wireless Internet service provider. In order to make the decision, consumers will need to look at the price, customer service and the quality of the services of each company.

The great thing about no cables is the convenience. The best wireless Internet service will share all of the benefits people should take advantage of as cable-free customers. The most common benefit is the mobility. Those who travel a great deal can find it very convenient to have. As long as customers can find a cable-free hot spot, they can use the connection. This is convenient for students on the go and traveling business men. In many coffee shops or Internet cafes today, there are routers that allow customers to bring in laptops and surf the web while drinking lattes and cappuccinos. This makes it very much worth any extra cost. Plus, customers with several home computers will get one router that can accommodate all of them, making it easy for multiple computers to log online at once. In addition, using no cables is fast. The best wireless Internet service connects at rates up to 1Mbps or more. This allows for quicker webpage loading and downloading. Customers may find this necessary if job or school work requires a lot of web research as well as downloading of images.

Price is very important to every customer. Of all of the ways to connect online, the cheapest is typically dial-up. Now, even those who offer dial-up services are also wireless Internet service providers. This can help save some money if customers are hoping to keep the services within their budget. Price isn't everything, though. Consumers also need to consider the level of quality of their services and the quality of their customer assistance. Use a major search engine to look for the best wireless Internet service. Consumers will find that there are many choices out there. Visit the websites for some of major companies and get a price. Usually, they will post the prices of their services online. Some customers may have to call others and get a quote. Keep in mind that many cable and even telephone companies may offer cable-free services. Call local branches to get prices. They may be able to offer a special package for current customers.

No matter what company seems best, customers must be sure to select a reliable company. Consumers may decide to go with a lesser known company. This is fine as long as they are reputable. Although price matters, it is more important that they provide good customer assistance and a reliable cable-free connection. If customers have too many problems with the company, it's best to consider taking business else where. Don't sign on for lengthy terms to save money. Some wireless Internet service providers may offer discounts if customers agree to their cable-free services for a year or more, but try to sign up for no more than six months. This will allow enough time to test the waters. Thus, those who are unhappy, won't have to get mad, they can just get out without fees or penalties. "He that is slow to wrath is of great understanding: but he that is hasty of spirit exalteth folly." (Proverbs 14:29)


http://www.christianet.com/internetservices/bestwirelessinternetservice.htm

Dsl High Speed Internet Service

DSL high speed Internet service is just one of the many options for connecting to the World Wide Web, other services include cable, satellite, wireless and dial-up. DSL Internet service is among the fastest solutions available to consumers and is generally the most popular to date. With many people running home based businesses, telecommuting and using the Internet for various forms of entertainment, the faster the better is what most consumers prefer. Slow, dial-up connections are less and less popular unless they are the only choice in certain rural areas. Soon, however, DSL and other forms of high speed connections will push slower access to the back of the line in every corner of the country.

Cable and Digital Subscriber Loop connections are still on top of the pile in regards to speed, affordability and access. Most individuals and businesses want capabilities of all the advanced media options such as streaming audio and video, Voice Over Internet Protocol, video cams and other soon-to-arrive functions. DSL high speed Internet service will take a further leap with the upcoming advancement through VDSL. Very High Bit-Rate DSL will offer super charged bandwidth that will out-perform the typical DSL service that most consumers are content with. VDSL is not available as of yet in many areas, but before long this new access will make an impact as the hot, newcomer to web connection.

Making a choice among the various connection options depend on availability, functions required and price. For those who want wireless service for their laptops while traveling, the wireless connection capability is available in a limited capacity. Travelers are especially in need of this type of access, but must generally be within 1,000 feet of a local, wireless access point. This is great for those who are in hotels, airports, or around public arenas and need freedom with their laptops. DSL Internet service is available in many hotels and travel centers, but wireless connection provides the desired mobility and it found in many travel spots throughout the US.

Satellite services offer consumers any where in America access to the web if they are in proper range. Requirements are generally that the southern sky must be visible in the target range in order for a consumer to have access. While this may provide availability to some consumers who do not have access to DSL high speed Internet service, it is not as cheap. Satellite access is generally almost twice as much as the other most popular forms of access. Dial up access has been around for some time and is known for its slower transmission speed for data, especially for files and digital media outputs. However, for those who do not want to pay a higher price for DSL Internet service or cable but want a faster access through this method, there is dialup Internet access which is faster than the older, dialup system.

For faster surfing, this method may be sufficient for marginal computer users, but for transmitting large files, nothing has changed in slow transmissions. Cable access is getting very common for web connections since many areas, including rural regions, now have cable television services. Web connection is over the cable network and is offered only by a provider that has made a business deal with the respective cable company. While it is helpful to have high speed access over television cable outlets when there is no other, it does limit choices of providers to the one that has a monopoly with the cable company. This limits competitive pricing among providers and leaves consumers at the mercy of whatever is available.

While a DSL Internet service produces online access through phone connections, older phone connections that do not have copper wiring cannot accommodate this high speed choice. "Let your speech be always with grace, seasoned with salt, that ye may know how ye ought to answer every man." (Col. 4:6) Many rural areas of the country are still operating with older phone lines, so high speed web access is not available, although it is rapidly drawing near as many phone companies are reworking systems as well as installing new ones. The accommodation of high speed access is advantageous to all concerned and it will continue to push the limits into rural and out-of-the way places in the US.

For many users of high speed access, the choice may be between cable or a DSL high speed Internet service. Although for some, there is no choice and location will determine which can be purchased. In either case, the prices are generally the same with DSL Internet service edging out cable at times by a few dollars more for installation and monthly fees. If both services are available, there are many variables that can effect which will be the most useful for any consumer. DSL speeds will depend on the distance from the Internet Service Provider, while cable speeds will depend on saturation of users at any one time on the cable line. It may be helpful to question neighbors and businesses in the surrounding area as to the type of speed and service they receive.

http://www.christianet.com/internetservices/dslhighspeedinternetservice.htm

Tuesday, June 26, 2007

Labels battle to hold onto DMCA win

The recording industry on Friday fought to preserve a preliminary courtroom victory, arguing that Verizon Communications has no choice but to hand over the identity of an alleged Kazaa music pirate

Why hasn't anyone heard of Jazzanova? I know, I know, this is my second column about them in almost as many months. But I just purchased The Remixes 1997-2000, and my CD player has not been able to part with it for weeks now. Maybe a review of it will serve as a kind of exorcism, and make way for another album in my boom box.

In case you don't know, (and you probably don't, unless you're from either Munich, Berlin, or Williamsburg, Brooklyn, where the people seem to know everything about good music) Jazzanova are a DJ collective comprised of six men with entertaining names like Jurgen von Knoblauch and Roskoe Kretschmann. They began playing and remixing records together in 1995. They describe their music as a hybrid of jazz, bossanova, (hence the name) soul, disco, R&B, and a little bit of everything else. They radically reinvent other artists' tracks, giving them the unique Jazzanova sound.

If I have any complaint about this album, it's that the aforesaid sound can get a bit samey. As background music, it's peppered with standout moments where you lean in and listen, curious to hear exactly what's going on. If you're playing it on your Discman/Walkman/MP3 player, you might find yourself skipping some tracks.

The two-CD set starts off with 4 Hero's We Who Are Not As Others. Eerie synth chimes immediately give you the feeling that what you're about to listen to is going to kick ass. It does, but with a whisper, not a scream. Jazzanova turn the track into what sounds like a robot band playing fusion. It's calm, intricate, and undeniably electronic.

Marschmellows' Soulpower is pure pop-funk, complete with slap-bassline, hand-claps, and squelching synths. They even break it down and add whooshing Seventies sounds at the end. Jazzanova manage to replicate an entire decade's worth of music in one song, and still make it their own cool blend.

Truby Trio's Carajillo melds Afro-pop with drum-pad beats and a simple, jazzy house piano line. The singers' voices call and answer to each other. It's music you want to turn up full volume and clamp headphones over your ears, but it's also perfect as background.

High Priestess, by Karma, has a big-band-shuffle feel that swings even when it turns into a bongo-ridden ¾ voodoo beat. Lazy upright bass and blasts of brass punctuate this swampy mire till it sounds like there's a full-on tribal ritual going on somewhere in the bayou. Every so often the heat breaks, but it always comes back full force before long.

Azymuth's Amazon Adventure starts with a beat that sounds as if it came straight off a Casio pre-programmed selection. It's soon accented with more organic instruments; a high piano, another upright bass, live drumming. It's intelligent hold music.

Absolute Space, by Koop, is more of the same Casio-on-ecstasy spasmodic jazz drumming and chiming piano, this time with a fair Bjork impression over the top. Although the drumming occasionally breaks the monotony by leaning toward an exhilarating Brazilian beat, this isn't one of my favorites. The same formula's applied in Ian Pooley's What's Your Number, but now something other than nonchalance is in the mix, as a woman's voice declares emotionally that "things change". This is one of the only songs in a minor key on the two-disc set.

Visit Venus's Planet of Breaks takes the frenetic jazz pace down to a nice steady dub. The drums flow, every once in a while broken by a little eddy of beats and beeps. Toward the end, however, the drummer once again gets carried away with himself. He might try listening to some Metallica, change the mood a little.
In a strongly worded brief filed in federal district court in Washington, the Recording Industry Association of America (RIAA) assailed Verizon's request for a stay of a 21 January order as a brazen attempt by the telecommunications firm to "evade its responsibilities under the law".

The lawsuit, filed last August, pits the 1998 Digital Millennium Copyright Act (DMCA) against Internet users' right to remain anonymous online. With the vocal assistance of civil liberties groups, Verizon has argued that the DMCA's turbocharged subpoena process is not sufficiently privacy-protective, because it can be used to glean the identities of hundreds or thousands of suspected peer-to-peer pirates at a time.

Matthew Oppenheim, a senior vice president at the RIAA, said in a conference call Friday that Verizon was exaggerating the privacy risks of complying with requests made under the DMCA. Verizon and its allies, including a former Clinton administration privacy official, have suggested that copyright holders should file a "John Doe" lawsuit to unmask suspected peer-to-peer infringers instead of wielding DMCA subpoenas.

"In private conversations with the RIAA, Verizon has made it very clear that this is not a privacy issue," Oppenheim said. "They said they would be happy to turn over the names of some of their customers, as long as they don't have to turn over the names of a lot of their customers."

At issue in the RIAA's request is section 512 of the DMCA, which permits a copyright owner to send a subpoena ordering a "service provider" to turn over information about a subscriber. The service provider must promptly comply with that order, and no judge's approval is required first. In August, the RIAA asked a federal court for an order under the DMCA compelling Verizon Communications to reveal the name of a Kazaa subscriber accused of illegally trading hundreds of songs.

Oppenheim said that Congress had created a careful balance between privacy and copyright when drafting the DMCA, and Verizon's argument that the DMCA applies only to material hosted on its own servers is specious. "They're not engaged in private conduct," Oppenheim said about peer-to-peer users. "They're on public networks making available hundreds of music recordings to millions of other users. They're not doing anything in private. They don't have the right to anonymously commit a crime."

Sarah Deutsch, a Verizon vice president and associate general counsel, said: "This is just the RIAA's desperate attempt to divert public attention from the fact that they want unlimited access to private communications. They're trying to divert attention from some of the bad publicity that this case has garnered."

Deutsch said the RIAA had spurned a compromise proposal. "We offered that while the case was pending, we would forward cease-and-desist letters to our subscribers, at our own cost, without revealing our customers' identities," Deutsch said. "But RIAA refused."

Verizon has appealed last month's order to comply with the DMCA subpoena, but the US Court of Appeals for the District of Columbia will not hear the case until US district judge John Bates decides, possibly in the next few weeks, to grant a stay or not.

In last month's 37-page decision, Bates ruled that Congress used "language that is clear" when crafting the DMCA. "Under Verizon's reading of the act, a significant amount of potential copyright infringement would be shielded from the subpoena authority of the DMCA," Bates wrote. "That would, in effect, give Internet copyright infringers shelter from the long arm of the DMCA subpoena power, and allow infringement to flourish."

In another court filing Friday, the RIAA moved to strike a declaration last Thursday from Peter Swire, an Ohio State University law professor and former Clinton administration official, as irrelevant. "Mr. Swire's declaration boils down to nothing more than a twelve-paragraph legal brief, largely derived from speculation -- most, if not all, of which directly contradicts this court's prior ruling," stated the RIAA in its legal filing. "While his 'sworn' statements may have a place in law review articles and policy debates, they have no place in a court of law."

If the RIAA prevails in this legal skirmish, it seems intent on pursuing DMCA subpoenas against other Internet providers. In a third court filing Friday, the trade group filed a statement from Jonathan Whitehead, an antipiracy vice president at the RIAA. Whitehead's statement said he sent Internet service provider EarthLink a DMCA subpoena on Wednesday for the identification of a single peer-to-peer user.
I have both a gripe and a rave about this record, and they're one and the same. As I began to review this album, sometimes I would let a track play, begin to write about it, and turn to my CD player to find another track had started playing without my being aware the song had changed. This is disconcerting if you're trying to listen to the album as a collection of songs, which is how it's presented. I think it would sound fantastic as a continuous mix, without the usual two or three seconds of silent space separating songs. Chill-out music, which is what this is, sounds better without interruptions. I'd like to experience a Jazzanova live set to see if I'm right about this album sounding better as one huge song. Because if I view it that way, it's stellar.

http://news.zdnet.co.uk/itmanagement/0,1000000308,2130153,00.htm

Thus bends law to avoid responsibility for child porn

British telco Thus is arguing that it cannot legally check for paedophile content, despite making a pledge in February to actively remove unlawful content from its newsgroups.

The owner of ISP Demon Internet is using the Indecency with Children Act that criminalises the possession or distribution of child pornography, to justify its claim that it is illegal for an Internet Service Provider (ISP) to download indecent images from its servers for the purpose of checking for illegal content.

"I'm limited by simple legislation that prevents me from looking at child pornography -- how do you decide that something is paedophilic when it's illegal for me to look at it?" said Keith Monserrat, director of legal and regulation at Thus.

There is however a working code of practice within the Internet industry that allows police, the Internet Watch foundation and content providers to check for illegal content on the Web. Hermod Stener, lawyer at city firm Charles Russell, confirmed there is nothing within UK legislation to prevent an ISP from checking articles that it is hosting.

"No statute would prevent an ISP from downloading Web pages that it is hosting in order to check them," said Stener. "It's more a question of them wanting to avoid responsibility for their content -- giving a simple answer."

Demon Internet requires all registered users to sign up to an "Acceptable Use Policy" that warns against customers using the service for illegal purposes. The terms and conditions state: "We will investigate suspected or alleged breaches of this AUP... Demon Internet, at its discretion, may run manual or automatic systems to determine compliance with this AUP. Customers are deemed to have granted permission for this limited intrusion onto their networks or machines."

"Their terms and conditions state that they are able to access everything on their Web pages," said Stener. "When entering a newsgroup, the service provider is contractually bound to reserve the right to throw people out if they are doing something unlawful."

The Internet Watch Foundation (IWF) -- the regulatory body responsible for protecting children online -- currently checks for indecent images on the Web by sight, which involves downloading child pornography in order to assess whether or not articles are illegal. "The very strictest application of the law is a conundrum that there's no way out of," said David Kerr, chairman of IWF.

Monserrat prevents any of his staff from personally checking newsgroup articles reported by customers to contain child pornography. "How do I know that I will not be considered an accomplice to a crime," he asked. Stener pointed out that there is little logic in this argument. "They are an accomplice to a crime if they are hosting illegal content," he explained.

An EU directive, called the Horizontal Selling Directive, due to be finalised shortly, will make it obligatory for ISPs to remove unlawful content from their servers on positive knowledge.

"This implies an obligation to go into newsgroups and download articles in order to check their content," Stener argued. Kerr said that half of the Web sites reported to the IWF to contain indecent images are actually not illegal. "It is acceptable for ISPs to check these complaints themselves, as the public at large are easily shocked by content, and don't know what's acceptable," he said.

"It's a matter of ISPs keeping their own house in order," agreed police inspector Terry Jones at Greater Manchester police Obscene Publications Unit.

Thus embarked upon a moral crusade in February to actively remove known paedophile content from its newsgroups. One week into its ambitious crackdown on child pornography, reports were already branding the decision "unworkable". Thus continues to deny knowledge of claims that they are still hosting two offending newsgroups the IWF alerted it to a year ago.

http://news.zdnet.co.uk/itmanagement/0,1000000308,2085357,00.htm

Monday, June 25, 2007

My own private ISP

Setting up your own Internet service provider can sometimes be the only way to get satisfactory Internet access options. In case you should want to give it a try, here's a case study: my own experience.

Over the past year or two, thousands of computer users have been flocking to open source operating systems such as Linux, FreeBSD, and OpenBSD. A mere five years ago, however, the thought of a "free" operating system in the corporate environment was virtually unheard of. While designing the network topology for one of my first clients, it took months to convince them to allow Linux workstations into their Sun environment.

Now that open source is finally getting the recognition that it deserves, many corporations are starting to integrate "free" products into their networks. Other companies, mostly home businesses and geek startups, rely solely on open source software to create their magic. Sosik-Hamor Networks is 100% open source with the exception of a Cisco router and a few Macintosh workstations.

Bandwidth requirements
About six months ago my wife Kelly and I decided we had outgrown our current Internet connection and it was time to rethink our plans for the future. I was currently a UNIX systems administrator for Lucent Microelectronics but was looking for more of a challenge. I was also doing some freelance consultation and Web design and we started to question the reliability and security of using our 500 Kbps cablemodem to connect to our colocated Linux Web server.

Kelly and I started discussing different bandwidth options in our price range. ISDN was outrageously expensive, ADSL wasn't available yet, and the new breed of cable modems being released by our ISP were going to be DHCP-only, which was not an option for our home network. Then, as if to fully realize every geek's dream, Kelly said, "We're already paying an arm and a leg for the colocated server ... how much is a T1?" So, Sosik-Hamor Networks was born.

Installing the T1
After shopping around for bandwidth with local ISPs and some of the larger telcos, we started running into problems. Since we're located in the middle of nowhere and our local telco is a monopoly, we had extremely limited options. Our local telco was either unable or unwilling to bring in a co-op line from an external provider, so we were forced to go with them for our T1. With this experience, we found out that physical location is one of the most important things to consider when putting together a business that will require high-speed access. Make sure that your local telco can handle a high-speed line from any ISP of your choice.

Because the sales representative couldn't comprehend why a home business would need a T1, I was greeted with much suspicion. It took over four months just to get a price quote and another month before the fiber was run from the telco to our street. On top of that, every step of the installation was met with hostility from the ISP due to the fact that I took a very direct approach after being blown off for five months: "Give meservice or I'll sue you for not allowing me to choose an alternate provider." Although blunt and hostile, a contract was in my hands within two hours and fiber was dropped into the basement a week later.

The final price tag for fiber installation and ISP setup for the 950 foot fiber run was $2,500 total and $970/month for a full 1.544MBps T1. Telco circuit charges and ISP bandwidth fees are all covered under the monthly charge, which is an incredible deal compared to the $8,000 installation and $3,400/month quote I was getting from some other ISPs in the area.

Network planning
During the wait for the T1, Kelly and I came up with a detailed network topology map and decided exactly what hardware and software would be required to put together an inexpensive and upgradable network that could be modified with minimal service interruptions.

* Cisco networking equipment will be used exclusively.
* The DMZ outside the firewall must be switched and SNMP-aware.
* The LAN inside the firewall will eventually be switched and SNMP-aware.
* All software must be 100% open source.
* OpenBSD will be used exclusively outside the firewall.
* Linux will be used exclusively inside the firewall.
* Macintoshes will be used exclusively for project development.
* The internal file server must be AppleTalk or AppleShare capable.
* A secure auditing workstation will sit between the DMZ switch and the DMZ ethernet port on the router.

After taking stock of our current hardware, we then compiled a list of what we owned and what we needed. All of the purchased hardware was chosen because outstanding deals had been found.

* Available hardware: SPARCstation 2, 64MB RAM, 1.2GB HDD
* SPARCstation 1+, 32MB RAM, 540MB HDD
* AMD K6/233, 96MB RAM, 4.6GB and 5.2GB HDD
* AMD K6/266, 128MB RAM, 7.2GB HDD
* IBM Aptiva P166MMX, 64MB RAM, 3.5GB and 25GB HDD
* Team Internet 486dx2/66, 64MB RAM, 1.2GB HDD
* Apple iMac G3/266, 160MB RAM, 6.2GB HDD
* Apple PowerMacintosh G3/400, 144MB RAM, 9.2GB HDD
* Miscellaneous m68k Macintoshes
* MaxTech 24-port Unmanaged Hub
* 2 Addtron 8-port Unmanaged Hubs

* Hardware to purchase: Cisco 2611 router
* WIC-1DSU-T1 integrated DSU/CSU
* Kalpana EPS-2015 RS managed switch
* 19" wallmount telco rack
* 8' steel equipment rack

Next, we started distributing the machines. The AMD systems and SPARCstations would become OpenBSD servers in the DMZ and the IBM and Apple systems would become Linux and Mac OS 8.6 production boxes on the internal LAN. Linux was chosen for the IBM Aptiva because we not only needed a file server but also a workstation-style installation with the X-Window System to run X applications such as xload from the servers in the DMZ. The final Team Internet machine became an OpenBSD security and auditing workstation to keep track of traffic and the little gremlins that tend to creep into networks.

Getting online
When shopping around for Cisco hardware, I ran across a friend on #cisco on EFNet Internet Relay Chat. He gave me the pros and cons of each Cisco router and put together a great deal on a new Cisco 2611 with integrated WIC-1DSU-T1 DSU/CSU for $2,500. I later ordered a 32MB RAM upgrade from Crucial Technology for $70 to bring the router up to 40MB.

Now that we had a router, we needed to pick up a switch for the DMZ. Switching was absolutely required because sniffing would be an issue with any colocated servers. Since we only needed a switch to protect against sniffing and wouldn't need cutting-edge network management features for a while, we tracked down some surplus Kalpana switches and an EPS-2015 RS for $125.

After months of fighting with our ISP, the fiber was finally dropped into the basement and the fiber patch panel and MUX were installed on top of the router and switch on our 19 inch wallmount rack. A few hours later, we were up and running with a minimal configuration and pinging the ISP. The installation tech left us on our own and we started router configuration for the DMZ, firewall, and NAT. Another half hour and our Macs behind the firewall could see the outside world.

Setting up core services
Since the SPARCstations are extremely slow at the command line but work great for months on end at menial tasks, they became the dedicated "core" servers that would take care of tasks such as DNS, outbound Web proxy, and outbound e-mail. We also decided that these two servers would be completely hardened with virtually no services whatsoever. Water would be configured as a bastion nameserver while earth would only handle DNS and outbound Web proxy and e-mail.

* Required software: Red Hat Linux 6.0
* OpenBSD 2.5
* Apache 1.3.4
* MySQL 3.22.22
* PHP3 3.0.12
* Qmail 1.0.3
* Squid 2.1.PATCH2
* Netatalk 1.4b2

earth.shn.nu

The SPARCstation 2 became "earth," the primary server that takes care of all core operations at Sosik-Hamor Networks. This system was the first to be installed because it had an external CD-ROM drive that could be used for FTP installs for other machines. OpenBSD 2.5 boot floppies were downloaded from ftp.openbsd.org and we started an FTP install on earth.

Total installation took around 45 minutes from start to finish, including downloading the approximately 250MB full distribution over the T1. Since the FTP installation method decompresses and installs files on the fly, like Linux, no scratch disk is required. Once finished, an obscure and long root passwd was chosen and the machine was rebooted into single user mode. All services except FTP and Daytime were disabled in inetd.conf and all daemons except named were disabled in rc.conf. Even portmap was disabled because the server would never be used in an open file server environment. The machine was rebooted and brought up on the Net.

With the machine up and running, the first software to be installed was SSH. To get up and running quickly, the pre-built SSH binary package was downloaded from ftp.openbsd.org and installed using pkg_add. The system was now accessible from the outside world, so I started up a few SSH sessions from my Macintosh.

The full i386 and SPARC OpenBSD 2.5 distributions were downloaded from ftp.openbsd.org and put in /home/ftp/pub/openbsd so we could immediately start installing on the other three servers. Anonymous FTP was configured and temporarily enabled for this task, but would be disabled once the other installations were finished. Although anonymous FTP is not a direct security hole, it is one more port to tempt a potential attacker.

Qmail was downloaded from www.qmail.org and installed from source because there hasn't been a direct qmail port for OpenBSD yet. Compiling qmail took a while because of the slow processor, but installation and configuration was painless. TCP wrappers were configured so qmail could only relay e-mail from the DMZ and firewall networks, and then set up as a secondary MX to queue e-mail for any other domains on the network should a primary mail server go down.

Squid was then installed for the outbound Web proxy to help hide the identity of machines in use behind the firewall. Configured with a 100MB disk cache and maximum privacy features enabled, Squid caches often accessed Web pages and hides the USER_AGENT and USER_REFERER strings so make it more difficult for Web servers to track movement from page to page. As with qmail, Squid only allows connections from within Sosik-Hamor Networks.

Forward and reverse nameserver zone files were then created from the default templates Sosik-Hamor Networks' primary domains. Zone transfers were disabled except for other nameservers in the DMZ, which makes it difficult for an attacker to download the forward and reverse maps of the network.

With earth up and running, other machines were brought online over the course of the next two or three days.

water.shn.nu

Because water, the SPARCstation 1+, would be a bastion nameserver, only minimal packages would be required. Compilers and other niceties were not installed because any patches and upgrades that were needed could be mirrored from earth. The only other package installed was SSH to allow for secure remote logins.

The installation process for water was virtually the same as earth except, instead of wasting bandwidth over the T1, OpenBSD was installed via FTP from earth. After installation was finished and the machine was brought up in single user mode, everything was commented out of inetd.conf and disabled in rc.conf except for named and sshd.

Although water was configured as a secondary nameserver to pull zone transfers from earth, we decided to list it first in the zone files and with InterNIC/NuNIC. That way most DNS requests would come into water first and keep earth free for other duties. Even though DNS isn't a very CPU or network intensive task, a nameserver that handles 100 or 200 domains needs to be carefully configured.

Setting up Web services
Most large Web hosting companies run multiprocessor PII and PIII machines to handle their high workload. Since we were just starting out and our old colocated P90 Linux server with 64MB RAM handled 50,000 hits a day without breaking a sweat, we figured that, until we got busy, our two existing AMD K6 systems would be perfect for our personal and client Web servers. Both K6 systems were basically the same, but we opted to use the K6/233 for fire and the more powerful K6/266 for wind.

fire.shn.nu

Fire was built first because we needed a machine to act as our testbed and production server for our corporate and project Web sites. All new configurations and software are tested on fire before going live on wind, and most interactive development packages from the ports tree are installed because fire is also used as the primary staff shell server.

All OpenBSD packages were installed via FTP from earth and all non-essential services were disabled in single user mode before bringing the system up on the Net. Because this was going to be a staff production system, quite a few services were left enabled and installed.

As with all of our systems, SSH was the first software to get installed to allow for secure remote access. Qmail was then installed and configured for virtual domain support with no relaying. With this configuration, qmail only allows inbound email or outbound email originating from localhost. Also, e-mail for each domain is handled by its own individual account and users have full configuration over aliases and forwarding without root intervention.

MySQL was then installed from the ports tree for all Web sites that need database interaction. A simple make; make install in the ports tree took care of everything and the MySQL server was up and running. The only additional change made to the default configuration was to create a mysql user, change the ownership of /var/db/mysql from root to mysql and make safe_mysqld launch as the user mysql user from rc.local.

A database is useless without a bridge to get data to and from the Web server, so PHP3 was installed. This required recompiling Apache from scratch in /usr/src/usr.sbin/httpd, so the Configuration file was modified to add in all the extra modules that we needed, ./Configure was run and then the PHP3 module was installed into the Apache source tree. Other various modules were added as well and then Apache was recompiled and dropped into /usr/sbin. Once compiled, suexec was also compiled and dropped into the Apache sbin directory to allow for secure execution of CGI binaries.

Once all of the servers were set up, niceties such as Emacs and Pine were installed from the ports tree. Deciding which applications get installed is simply a matter of user preference, so take a look through /usr/ports and do a make install for anything that looks interesting. Pre-built binaries are also available from ftp.openbsd.org. Smaller applications are just fine to run from precompiled binary packages, but larger applications that need tuning (Apache, MySQL, etc.) should be compiled from the ports tree on the system they will be running on.

wind.shn.nu

Wind is an exact mirror of fire and acts as the clients server. The only difference between wind and fire is that miscellaneous applications may get installed at each client's request (IRC scripts, etc.).

akasha.shn.nu

Akasha is the watchful eye that makes sure all is well out in the DMZ. It sits on a hub between the DMZ switch and the DMZ ethernet port on the router and constantly runs a sniffer and network analyzer to look out for "interesting" traffic. The main purpose for this is to keep track of per-MAC address accounting and to look for denial of service attacks or other nasty packets that may come across the fiber. Depending on the requirements at the moment, akasha may be the Team Internet 486dx2/66 running OpenBSD or a Macintosh IIcx running Mac OS 7.5.5.

Setting up the internal network
Now that the DMZ was set up and ready to go, the systems on the LAN inside the firewall needed to be reloaded and configured.

socks.shn.nu
Socks was chosen to be the internal file server and Red Hat Linux 6.0 was installed. Of the two disks, the 3.5GB was used as the boot disk with /home for home directories and the 25GB data disk was mounted as one huge 23.5GB partition under /home/warehouse01. As the need arises, more 25GB (or larger) disks will be installed as /home/warehouse02, etc.

Because of the large drives, the entire Red Hat distribution was installed and unused services were disabled for security. Making the jump from Red Hat Linux 5.0 to 6.0 was quite a large step, and I wanted to see everything 6.0 had to offer. So, not only was socks configured as a file server, but also as a user workstation to play with the new window managers that have become available. Even though virtually all Web site development is done using Adobe GoLive under Mac OS, the Linux workstation is used for most systems administration tasks.

To serve our internal Macintosh G3 workstations, socks also runs Netatalk, the UNIX implementation of the AppleTalk protocol. File transfer speeds over the internal 10BaseT LAN are surprisingly fast, but we will be moving to switched 100BaseT eventually to help speed things up. 10BaseT seems fast until you routinely start opening up 20MB Photoshop files for editing. All other services on socks are set up almost exactly like fire with Apache, MySQL, PHP3, etc.

To tie everything together, a Belkin OmniView 6-port KVM switch was used to control akasha, fire, wind and socks from the same keyboard, mouse, and monitor. All machines sit on an 8 foot vented steel rack, and an air conditioner keeps the machine temperature at 72 degrees. The entire NOC can be controlled from the keyboard and monitor hooked up to the OmniView.

DIY: Do It Yourself!
Overall, setting up an Internet resource provider isn't that expensive. A mixture of OpenBSD and Linux can make older workstations into perfect servers and keep initial startup costs extremely low. Using existing hardware and 100% open source software, we kept our startup costs under $8,000 and -- even using brand new systems -- easily stayed under $15,000. Also, by dropping fiber into a home business, your home office becomes a business expense with the added benefit of Mb speeds at home!ø

http://itmanagement.earthweb.com/erp/article.php/11072_615281_1

Hollywood gossip blogger downed by ISP

INTERNET GOSSIP Blogger Perez Hilton has had his infamous website shut by his ISP.

Hilton, who's real name is Mario Lavandeira, is well known throughout the industry for his gossipy bogging. He appeared at this year’s Much Music Video Awards last weekend in Toronto.

But Hilton has been accused of nicking copyrighted photos in four separate lawsuits initiated by eight different photo agencies.

Sheesh he should have doctored pictures of the Everywhere Girl. Everyone else does.

According to Variety the site’s webhost Crucial Paradigm stated that if they received another notice of copyright violation against PerezHilton.com it would take the site down.

It looks like they did this yesterday. The site is back up now.

http://www.theinquirer.net/default.aspx?article=40506