QNAP ransomware attack

Its the first time I have owned a NAS when a big ransomware attack is underway. Its clear QNAP haven’t done enough and learned about this a 5 days ago via bleeping computer.

I am very aware of ransomware attacks on standard computers and keep the firmware and software up to date when I see the updates. Its clear the notification of updates could be more viable, as its not that often I’m logged into the NAS. I have email and push on but I’d like to see more options on this front.

Bleeping computer has the full details of what you need to look out for and what you should do if you are being attacked.

A slightly better solution

xps13 camera cover
My Dell XPS 13 with the little microdot

A while ago I mentioned how the super tiny bevels on my new Dell XPS13 and Acer Chromebook make a camera cover look so silly. Some people mentioned to me about using duck tape, which I gather doesn’t leave as much stickyness after use.

chromebook camera cover
My chromebook with the microdot camera cover

But I also was pointed to little micro-dots which use the same glue as duck tape but are a lot more discreet than a slice of duck tape. The sheet I got has a number of them in different sizes.

lens covers

Its a lot better than what I had before but lets see how long they stick around with general use.

Presentation problems with Ubuntu, think I might have found the problem?

I have no idea why or what happen, but this is likely the 4 or 5th time my Ubuntu machine has become unstable while presenting live on zoom.

Tonight I gave a presentation for the Mozilla Festival about adaptive podcasting. I did some tests because I wanted to see if I could switch the audio from my headset mic to the Android phone running the app. Things were not working, so I decided to use the audio captures instead. Everything was fine, presentation in Google Chrome using google slides and Miro in Firefox for the workshop portion later. Zoom for video sharing.

Everything was smooth then I started Chrome in presentation mode but remember I need to turn on auto-generated subtitles. I switch to Zoom on my second screen try and turn it on but everything refreshes and freezes except my mouse cursor. The camera light is still on and sound is working (both mic and audio). I am forced to run the whole hour long workshop with no access to my slides, zoom or anything else. So I freestyle it.

I remembered a few times before something similar things happening while giving a presentation at Agile Manchester, UCD gathering, Immersive Arts Lab 8 and last week at the publicspaces conference. However the difference has been the laptop had paused for a short while (couple of minutes) before returning to normal state. This time I ended up rebooting the whole laptop.

Thinking about the circumstances of the other times, I suspected it might be Zoom but then its happened with Hopin too. It can’t be the laptop because I now I have a brand new laptop and although they are both Ubuntu the first three were Ubuntu 18.04.3 LTS. While I was running Ubuntu 20.4.2 LTS for the publicspaces conference and Mozilla festival. This leads me to the other common element which is Google chrome, which I use because its google slides (I tend to only sign into my google account with chrome).

Then I found problems with Chrome and fullscreen.

Even if its not quite right, I’ll be testing running Google slides from Firefox instead.

One upside of todays presentation is the amazing response I got from people on the call who really enjoyed the pure storytelling. Although I am glad for my co-host, having shared the slides and miro whiteboard right at the start.

Big thanks to everyone and the lovely words people have shared with me.

We got to do better than this… Webcam covers

Camera cover on the new XPS13
How attractive on a new laptop

I agree this is a privileged thing but I got a replacement for my aging Dell XPS 13 work laptop. Another Dell XPS 13 but the updated version with much better support for Ubuntu. Its a great machine!

Dell XPS13 with that camera cover
My Dell XPS13 with that SD card, I mean camera cover sticking out

One thing I did look forward to was the new position of the webcam from the hinge alongside the keyboard. To the top of the screen like most laptops. There is a problem however, as the bezels get smaller the camera covers are not keeping up.

This isn’t just my new Dell XPS but also the Chromebook I got last year.

Chromebook camera cover sticking out
Looks like there is a SD card sticking out of my Chromebook

I gather there is sticker packs which don’t leave that usual glue stuff, which I’ll give a try but I certainly feel like I’m putting a plaster (literately) on a much deeper rooted problem. Camera should never be possible to enable without the light coming on full stop.

The tale of Amazon and the imported Qnap Nas

2 Qnap NAS boxes
Which one is the grey import?

I have almost no words for what’s happened recently with my Qnap NAS.

I decided a while ago that it was time to replace the server in my bedroom with a QNAP NAS. I had it with the heat during the summer and frankly it was long overdue. Plus a few people recommended them to me, plus pointed me at NAS compares. I bought the NAS from Amazon.co.uk as it was the cheapest by about 100 pounds, plus they had the 8gig version of the TS653D. Almost everywhere else had a 4gig only version. I knew I needed a bit of memory as I was going to replace my ubuntu server, which ran at 45-70c depending if it was transcoding for plex.

I bought the NAS from Amazon.co.uk https://www.amazon.co.uk/gp/product/B0896YVN5L. There was no mention this was coming from America as a grey import. After I bought it I noticed it came from Texas, USA with via UPS and it took about 10 days. I didn’t think too much about it once it arrived, got it set up and moved all my data over (this took weeks!). However when I tried applying for the 5 year extended warranty thats when things got interesting.

5 years of warrenty

Having applied to Qnap, answered their questions, I sent them the invoice which I got from Amazon. However Qnap replied with.

From the invoice, this is sold by Amazon Export Sales LLC, and the customer also pay the import fee, the customer should know the unit is not from local distributor.
The note says: “Only products that are sold and purchased from the same region are eligible for a warranty extension.”. 

Please confirm with Amazon.co.uk that the NAS unit came from UK (distributor) and not from US.

We went back and forth for a while but I got back on to Amazon. They insured me the NAS is a UK model. Qnap of course were not budging, the serial number wasn’t right and regardless if I bought it form Amazon.co.uk it was a grey import. I did think it was strange it was coming from America but I just thought it was where the stock was from. Plus Amazon kept confirming its a UK version.

Then finally I got into an exchange with Amazon customer services.

10:53 PM QNAP won’t provide a warranty for the NAS because its not a UK/EU NAS I bought it through the amazon.co.uk with pounds but say its a US version
10:54 PM Rizzwan | I can see it is Amazon global store order. Allow me a moment to connect you with them for further help.
10:55 PM Global order? I bought it through amazon.co.uk

Then Rizzwan was replaced by Tamsyn…

10:55 PM Tamsyn has joined and will be ready to chat in just a minute. Tamsyn | ​This is Ta​mmy from Amazon. ​ I’ll be assisting you.​
10:57 PM Here is the email I got from QNAP… (same as above)
11:00 PM Tamsyn |  Yes it is from a UK distributor
11:01 PM I need something from Amazon to prove this, as QNAP won’t extend the warranty otherwise I have given them the invoice already
11:03 PM Tamsyn | what is the for the return ?
11:05 PM I don’t understand?
11:05 PM Tamsyn | what is the reason for sending the item back ?
11:07 PM I can’t get a extended warranty for the QNAP NAS
11:08 PM Tamsyn | Reason I’m asking is because I can refund you
11:09 PM Its a sub £1000 device and want to make sure it doesn’t go wrong, so the extended warranty is important Can I exchange it instead? because all my data is on the device now
11:09 PM Tamsyn |  cannot exchange
11:10 PM Do you have anything else I can send to QNAP to prove its a UK/EU version? They want proof – “Please confirm with Amazon.co.uk that the NAS unit came from UK (distributor) and not from US.
11:12 PM Tamsyn | We can send them an email what is the email
11:13 PM Its done through their support forum- as the email is no reply – noreply@qnap.com. If you can send me something I can try and get a email to send to them I’m sending them this… “I am talking with Tamsyn | Customer Service Amazon.co.uk and they confirmed it is from a UK distributor – Tamsyn is asking for an email address to forward you details of the UK distributor”
11:17 PM Tamsyn | yes that is fine
11:17 PM Is there a email I should ask QNAP to contact you on?
11:18 PM Tamsyn |  yes
11:18 PM Thanks… you understand why I don’t want to send it back but I really want to get this sorted out because I want to keep it for at least 3 years 11:19 PM Tamsyn |  Yes I understand 🙂
11:19 PM Thanks QNAP are slow to reply, so is there a way of holding the return based on the outcome of this conversation with QNAP They usually take about 2 days to reply
11:20 PM Tamsyn | okay that is fine
11:24 PM Thanks, and I guess once I hear back from QNAP I join this chat again Just for reference I’m talking with Gerry ********* from QNAP… “From warranty information, it shows the NAS unit was sold from Amazon US and not Amazon.co.uk
Please confirm with Amazon.co.uk that the NAS unit came from UK (distributor) and not from US.

Then out of nowhere Tamsyn was replaced by Collen…

11:30 PM C Collen has joined and will be ready to chat in just a minute. Collen | Customer Service Hello, Ian Please note this was a global store order Sold and shipped by amazon US Order Placed: Tuesday, 3 November 2020 (GMT) C
11:33 PM Hold on Tamsyn said it was sold from a UK reseller a moment ago
11:34 PM Collen | Customer Service Please look at email from Tuesday, 3 November 2020 01:51 (GMT) C
11:39 PM Collen | Customer Service Global Store Amazon Marketplace order with Amazon Export Sales LLC C
11:45 PM Collen | Customer Service Do you wish to return the item for a refund? C
11:45 PM I would like to do an exchange as I am using the NAS, Ok I see it says Amazon Export Sales LLC This was not clear on the site when I bought it.
11:48 PM Collen | Customer Service We can only refund a USA item only on return We cant replace it C
11:48 PM Right I see, can I get a UK version then return the old one?
11:49 PM Collen | Customer Service Yes C
11:51 PM This was not clear at all when I bought it on the site
11:51 PM Collen | Customer Service However you will need to re order C

So in short Amazon mislead me by never making clear this was a grey import QNAP NAS. Yes when I got the invoice, I could see it was coming from Texas but it was too late by then. Simple as this, customer service lied to me and to QNAP.

Cheeky!

In the end Amazon/Collen did send me the return details and I had 7 days to return the QNAP NAS back to Texas. Annoyingly I had to print the return slips and I don’t own a printer, luckily colleague Jimmy helped out by printing them out for me. In the mean while I got in touch with QNAP, they pointed me in the direction of Scan.com and I was able to buy and get almost the exact same model sent to the next day. I say almost exact because I opted for the 32gig version as I was considering add more memory anyway and this would save me a lot of hassle.

Telling enough, Scan.com when I called them to confirm the speed of delivery, told me a few other customers have had the same problem with Grey imports sent from America and bought from Amazon.co.uk.

With the clock ticking, I was worried it was going to take forever to move everything across but I found it was super quick when I found this guide to move from one device to another. Pretty much start the NAS, update the firmware and slot the disks in the same slots. The migration took about 2hours in total, which is amazing. I was wondering about taking time off work to get this sorted but there was no need.

QNAP nas's
Which one is UK and which one is American?

Just enough time to take some pictures of them side by side then box up the grey import/amazon one, add all the labels then take it to the UPS drop off which just happened to be in China town. Can’t tell you why I didn’t get a taxi or take the tram half the way there, but it was certainly a work out for my lockdown arms.

4 weeks later I received my full refund from Amazon.co.uk and I’m sitting pretty with my QNAP NAS with 5 year warranty.

Why is Slack storing passwords in plain text on Android devices?

https://mas.to/@cubicgarden/105712244073779967

I posted about Slack’s bug on mastodon. I knew this was going to be a pain the ass changing all those passwords, even with them all sitting in my password manager and most using 2fa.

However some of the users of Mastodon asked the question, why does the Slack app store the passwords on the device at all?

I thought about this and they are right. The app connects to a remote server and should request the user login. Once logged in, it should provide some kind of secure key/cookie/hash on the device not the actual password. On top of this, it certainly shouldn’t be in the form of plaintext.

Mistake, bug or not, this should not happen.

Port trunking/Link aggregation on a TPlink AC2300 router

My new NAS comes with dual 2.5gigabit LAN ports (providing a total of 5 gigabit of bandwidth). Its not much use to me because its plugged into a 1gigabit router, attached to 1gigabit internet and a 1 gigabit internal network.

However I noticed a feature on my router called link aggregation. In theory I can plug both LAN ports into the router and get 2gigabits of bandwidth to the NAS. Ok its only mainly useful for multiple connections to the NAS because everything else is sitting on a 1gigabit networking. But you can imagine uploading a lot of data from the NAS and also editing video on my LAN connected laptop.

Link aggreation on TPlink

When looking at the TPlink help page,  it looks pretty straight-forward. However when looking at my router there is no options. No link aggregation options. I checked I have the latest updated firmware and I was thinking of sending it back… till I spoke to a friend and he convinced me to set up port trunking from the NAS side just in case the router has it enabled by default now.

Port trunking

As you can imagine, it worked… I mainly write this as I couldn’t find an answer when I searched for details previously.

Next upgrade for the switches will be from 1gigabits to 2.5gigabits.

Schedule messages on Android

This slideshow requires JavaScript.

Happy to see Google messages getting schedule messages at long last. Its been a long time in coming after Gmail’s schedule send last year.I have been using the beta and enjoying sending messages at 1am for a quite some time now.

Be great if Signal also added scheduling, although I did buy tasker to solve the scheduling of text and signal but haven’t sat down and played with it yet.

I knew the day was coming for my Pixel2

https://mas.to/@cubicgarden/105356319833794257

Google Pixel’s come with 3 years of supported updates, I knew this but it was a shock when I saw the note saying

Regular updates have ended for this device

Although its still night and day from some of the devices I have owned in the past. For example my work Nokia 8 is still stuck with Android 9 (Pie).

Using Yuno hosting for all my fediverse needs?

My raspberrypi4 yunoserver

It was in a discussion with Derek Caelin who created the video Decentralised social networks vs the trolls. Who mentioned Yuno host while I mentioned how much trouble I was having getting Funkwhale working to replace mixcloud.

I had bought a raspberry pi 4 at the start of April to replace my raspberry pi 2 and maybe add something to the kitchen audio setup. But hadn’t really done much with it. So the other day while watching a film I built the case, downloaded the yunohost image on to a 128gig microSD card and got it all running.

Got to say Yuno host is pretty nice and easy to setup. The hardest part was getting the DNS all setup with one of my own domains. Now its kinda setup, I have been looking through the app catalogue and spotted many of the apps/services I wanted to run in docker such as Funkwhale, Calibre-web, Pixelfed, Zerotier, Wallabag, Mastodon, Matrix, etc, etc…

Currently having a bit of fiddle trying to setup the DNS records to allow multiple applications hosted on one system.

I’m impressed so far… Although I am thinking it could be so much better on a more powerful machine. I could use one of my older laptops instead, however I gather the performance will actually be better on the pi. To be fair with a gigabit ethernet network adaptive, I don’t need to worry about storage so much. Although I’m looking at maybe switching my Ubuntu server to Yuno if I can get everything I currently run working.

Expect to hear more as I start installing more services.

Signal or Threema or how about both?

I have been a fan and person encouraging the use of signal over the likes of whatsapp. Its been good to me but like every piece of software there are things I would change about them. For example the whole pin code thing is not only concerning but also a real challenge for casual users.

The pin code thing and phone number thing is not that much of a concern for most but I’ve been keeping an eye on others coming into the space. Threema is one such messaging app which seems to have all the privacy and security needed backed with its strong European base in Switzerland.

I wrote it off in my mind because it didn’t have a open code base for security  experts to view openly. However that recently changed with them opensourcing the code base.

Because of this change I’m relooking at the Threema, although I don’t think I’ll be dumping Signal as a result but rather using both?

The Asus C434 Chromebook

Asus Chromebook Flip C434 review image 1

I recently bought myself a new Chromebook. I considered getting a Dell XPS13 (which is my work machine) or Lenovo X1 carbon but decided I wanted to replace my old Asus Chromebook which I was giving to my parents to replace their very old Samsung Chromebook.

Its been good to have my own laptop as a backup when my work laptop goes wrong for what ever reason (i’m currently running it off a external SSD). I have enjoyed the Android integration in the past but when I learned about the Linux integration and I was sold.

I opted for the i5 version with 128gig of storage and 8 gig of memory. Why? Well I decided it needed to be slightly more powerful and act a bit more like a full laptop if it was going to run Linux apps. I see this Chromebook as a laptop I can use for most things including audio/image editing. Originally I got a good deal on a refurbished version which was great except Bluetooth was broken and it had to go back. I then bought this laptop brand new and it was shopped and delivered in all of 18 hours!

So far I have only installed htop, inkscape, Joplin, audacity, barrier, cheese and firefox in the linux terminal (love that its ian@penguin in the terminal and I have firefox installed!) then decided to install Flatpak on ChromeOS, I considered installing Snap but it sounds problematic currently.

Just checking out a bunch of ChromeOS blogs and I found this reddit faq useful to fix my linux install when it broke after I installed it and shutdown my chromebook too early.

Generally I’m very happy with this Asus Chromebook and its a good size, weight and I still love the tablet mode.

I finally bought the Oura smart ring

Oura  vs Motiv smart rings

I decided its about time I upgraded my smart ring. I originally bought the Motiv ring because it supported Android, had a better price tag and was interested in the 2 factor authentication.

It was good but then I hit a problem about 6 months down the line and although Motiv did the right thing of refunding me completely and letting me keep the ring. It certainly felt like it was on its way to unsupported space with the new owners.

Oura vs Motiv smart rings

So with the new Oura being a bit cheaper and finally some proper Android support, I decided its time.

First impressions are very good, the app is better than Motiv’s and the ring feels a lot more robust. It has 3 different contact points while the Motiv has one. I took the risk of skipping the ring sizing as I knew my size from the Motiv ring. Luckily they were very close but the Oura is a bit bigger giving me more options of fingers to use.

The app now finally syncs with Google fit (one of the biggest complaints for Android owners). I also noticed there is the ability to download the raw data in Json format. I do find the app a little messy but its got all what is needed and if not you can login on the web and see/manage your data.

Oura's charger

If I was going to say one bad thing about it, it would be simply the charger is quite big compared to the Motiv one, which I was able to carry around on my keychain. But its not like I’m going away for a long while, and I noticed the airplane mode which is great.

Currently everyone is using Oura and its the right decision if you need the best tracker on the market. Just glad I didn’t get it when it was mainly iOS as it would have been extremely annoying.

Looking forward to seeing its sleep tracking as the Motiv was pretty awful. Thankfully I use Sleep as Android.

Checking for Spy Cameras everywhere…

I recently been tracking a lot of Spycams in hotels and airbnb’s. Yes its currently mainly happening in the east a lot more it seems, but like most technological trends its on the way westward.

It very much reminds me of my experience in the Airbnb in Barcelona. Yes its was a listening device and they did declare it once we were in the flat but its not good enough. Airbnb is the wild west for this.

The spycameras are getting super small and higher quality all the time. For the last year I have been checking my hotel rooms (pre-covid19 when I could travel) with my camera phone and light. I’m not using an app but rather the camera light as my camera sees IR no problem. Theres some quite good tips in this travel site.

By the way, don’t search for “spycameras” on the web, as you will get some questionable results!

Epic games serves up some 1984 on the app stores

 

Epic battle unfolds

Its been a Epic (Pun intended) battle going back and forth for Epic games and the app stores (Apple & Google).

For mobile developers the 30% cut has been a talking point for a long while but the fact you can’t use other payment systems really put the foxes in the hen house. I won’t get into details as there are others which do a much better job. I love this timeline

But I found the Fortnite 1984 trailer absolutely spot on. Pointing directly at Apple and their classic 1984 advert.  Although to be fair like most big companies, Epic isn’t clean in this area but the monopoly & closed doors of the app stores is a big deal. Its very clear Epic games planned the lawsuit, the 1984 and the trigger event in a perfectly planned check move (chess).

Shall we get the popcorn ready for this clash of the titans?

Regardless of what happens, I’m sure mobile developers will massively benefit from Epic pulling the trigger. Of course many other big names have also jumped in behind Epic.