Thursday, October 24, 2013

Linking TED-5000 to plotwatt.com

Since the demise of Google PowerMeter on September 16, 2011 I haven't done much with the data from my TED 5000 power meter .

I recently upgraded the TED firmware, and see there is support for several other 3rd party utilities, so I've started pushing data to plotwatt.   They offer commercial services, as well as free analysis for residential users.   Their secret sauce is "advanced machine learning algorithms" to figure out what appliances are drawing power, similar to the Load Profile feature in the TED-5000.  So far, mine is still learning, they warn you that it can take as much as 30 days to learn.

The plotwatt service supports not just The Energy Detective (TED-5000), but also supports WattVision, Blue Line Innovations PowerCost Monitor (with WiFi bridge), Current Cost,and eGauge. as well as an API for rolling your own data source.

I've tried activating and deactivating the 3rd party posting in TED, but it always seems to want to send just one sample every 5 minutes, which is well outside the maximum interval of 100 seconds recommended by plotwatt to get the benefits of their advanced machine learning algorithms...

Wednesday, October 23, 2013

Pushing TED 5000 data as snapshot graphs with Chart::Clicker

I wanted to make my TED 5000-C power monitoring accessible both for internal clients that didn't have the horsepower to run Footprints, and also publish the data externally for remote clients.

 I put together a simple Perl script which uses the 1-minute-resolution historical data from the TED-5000 to build a simple graph using Chart::Clicker, like this:

Sunday, October 17, 2010

TED-5000 by The Energy Detective

Installed my TED-5000 from The Energy Detective.


The little handheld wireless display is sort of flimsy, but is handy to figure out the load from a light or other appliance -- flip the switch, wait a few seconds, compare the reported KW/h consumption. TED was the first consumer-installable measurement tool that integrates with Google powermeter, a driving reason behind choosing it over the competitors.

The only real problem I have with the system is that it is incompatible with old-style X10 signals;  when you connect TED, it causes some X10 devices to go crazy, specifically, they turn on by themselves.   Pretty bad problem for something that is supposed to help *reduce* how much power you use.

Monday, January 12, 2009

NDA expired

I'm no longer under my former employer's Non-Disclosure.

Good things to come.

Thursday, March 13, 2008

Soekris troubles (2.5" SATA hard drive mounting kit)

The system arrived with the motherboard mounted in the small (light green) case, and the 2.5" SATA hard drive mounting kit in a separate plastic bag. The drive kit is the problem

I'm using a SanDisk 256MB CF for the OS, and once I got the hang of PXEboot (and gave up on the 4.3 snapshots), installing OpenBSD to flash was easy enough.

The trouble came when I went to mount an extra laptop SATA drive in the case. The mounting kit came without instructions, just an iron bracket, four screws, four brass standoffs:


The standoffs replace the screws that mount the motherboard to the case, but the four screws are too long -- I tried using them to hold the plate (bracket) to the standoffs, and the case top would no longer fit, the screw sticks up to far.

Tried tightening the screw the rest of the way down, and succeeded...

in breaking off the threaded part in the case!

The bottom of the brass standoff can be seen in the socket on the bottom of the case, so now there's nothing holding down that corner of the motherboard:



The screws are too long to use anywhere, they also don't work to hold the drive to the bracket, but at least I managed not to break one off in the drive too.

Wednesday, March 12, 2008

Soekris arrived!

My Soekris Net5501-70 arrived today.

Oddly, the default serial console is 19200, not 9600. Working on CF boot media now, at least until I pick up a cheap multi-gigabyte card from Fry's.


POST: 012345689bcefghips1234ajklnopqr,,,tvwxy








comBIOS ver. 1.33 20070103 Copyright (C) 2000-2007 Soekris Engineering.

net5501

0512 Mbyte Memory CPU Geode LX 500 Mhz


Slot Vend Dev ClassRev Cmd Stat CL LT HT Base1 Base2 Int
-------------------------------------------------------------------
0:01:2 1022 2082 10100000 0006 0220 08 00 00 A0000000 00000000 10
0:06:0 1106 3053 02000096 0117 0210 08 40 00 0000E101 A0004000 11
0:07:0 1106 3053 02000096 0117 0210 08 40 00 0000E201 A0004100 05
0:08:0 1106 3053 02000096 0117 0210 08 40 00 0000E301 A0004200 09
0:09:0 1106 3053 02000096 0117 0210 08 40 00 0000E401 A0004300 12
0:20:0 1022 2090 06010003 0009 02A0 08 40 80 00006001 00006101
0:20:2 1022 209A 01018001 0005 02A0 08 00 00 00000000 00000000
0:21:0 1022 2094 0C031002 0006 0230 08 00 80 A0005000 00000000 15
0:21:1 1022 2095 0C032002 0006 0230 08 00 00 A0006000 00000000 15

1 Seconds to automatic boot. Press Ctrl-P for entering Monitor.

Intel UNDI, PXE-2.0 (build 082)
Copyright (C) 1997,1998,1999 Intel Corporation
VIA Rhine III Management Adapter v2.43 (2005/12/15)
PXE-E61: Media test failure, check cable

PXE-M0F: Exiting Intel PXE ROM.

No Boot device available, enter monitor.


comBIOS Monitor. Press ? for help.

>

Thursday, January 25, 2007

Re: Sunfire V100 reports "dc0: failed to force tx and rx to idle state"?

I'd mentioned dc0 problems quite a while back, and they're still an issue.

Just did a fresh install of 4.0 from the release CD on a Sunfire V100,and as soon as I did "ifconfig dc1 up", I got this message:
dc0: failed to force tx and rx to idle state

This time I hadn't even gotten around to setting up the network orforcing the speed and duplex, so it's not what I'd previously suspected...

I would still like to know what causes this, and whether it's something to worry about.

Tuesday, December 26, 2006

Why T-Mobile picture messages are resized

Found an explanation for why TMobile messes with your picture messages:



http://www.howardforums.com/showthread.php?t=1064299&highlight=prepaid



So the problem is that T-Mobile is doing this intentionally in their MMS gateway. There are a couple of hacks to get around this, but they are non-trivial.



There's a slight difference between MMS (multimedia phone messages) and emails, which is why sending a picture as an "email" gives different results.

Friday, May 5, 2006

Cell Tower Mapping

I ran across this about six months ago, forgot where.

http://www.cellreception.com/towers/

Also has an area to post notes on cell phone dead spots.I've also noticed that many carriers are improving their onlinecoverage maps, but these tend to show "signal strength" by broad areaswithout explicitly depicting the location of towers...

Thursday, June 9, 2005

Alarm Beacon for USB

I'm not aware of anything supported under OpenBSD,but this article could be a good start towards such a project:


http://www.linuxjournal.com/article/7353



(Yes, I know the article is about Linux. But the $59 USB beaconthey used in the article is platform-agnostic.)

Tuesday, June 7, 2005

More on the Apple PAC bug

Apple has this as case # 49365331.



Apple *still* doesn't realize the impact of this problem. I had to go througha group at work that has a megabuck support contract (hundreds of G5s),just to get a case number assigned.



The Proxy Automatic Configuration URL feature, as implemented in Safari, is broken. Instead of just making one HTTP request for the PAC file at the start of a session, Safari 2.0(412) makes a HTTP request to the PAC server once for each *object* requested -- for each HTTP request out to the Internet,a corresponding request is made to a local HTTP server, for the PAC file.I've seen individual workstations making PAC request at rates as highas 57 GETs/second, totalling over ten thousand hits in a day from a single Tiger workstation.



For comparison, the average MS-Windows client hits the PAC URL a mere 7 times per day. Normally a web browser will retrieve a fresh copy of PAC when first launched,and then cache this copy, refreshing the contents either based on the Expires header or using an internal refresh timeout (Under MSIE, the refresh time can be set using the IEAK).



When using a local PAC file (a file::/localhost/... URL), the network problems are avoided, but browser performance is poor, with sporadic broken images and general slowness in loading pages.



In MacOS Panther and Tiger, the option to configure proxy settings is under System Preferences/Network/Proxies. This menu gives the user the option to set the "PAC File URL", but no option for how/whether this file is cached and refreshed. Also, Safari does not respect Expires header sent with the PAC file.For each object accessed, Safari makes a new TCP connection to the PAC server (specifying "Connection: close") and sends a HTTP/1.0 request.



Workarounds:

Installing 10.4.1 does not resolve this issue.

Switching to Firefox eliminates this problem. Firefox will only download the PAC file at session start, or when the user manually chooses to reload it.



(P.S. A description of this problem was sent one week ago to the official "product-security@apple.com" address. Further assistance in bringing this issue to the attention of the Safari development team is appreciated.)



(P.P.S. I must give credit to Isaac Claymore for independently identifying the problem about a week before I first noticed it.)

Monday, June 6, 2005

Problems using MacOSXProxyAutoconfig under Tiger

Tiger introduces a serious problem with proxy.pac, no fix is availablefrom Apple.


There is a serious flaw with using aproxy.pac URL for Safari 2.0 on Tiger (MacOS 10.4.1). Specifically, Safari loads the PAC file and parses it correctly forthe first HTTP request, and then repeats the process for each HTTP request it makes. So each new Tiger workstation vastly increases theload on the server hosting your PAC file.


So if a user visits http://www.cnn.com/ which contains 21 unique web objects,Safari will generate 21 additional requests for the PAC. This bug is easy to independently confirm by checking the access log on the server hosting the PAC file. I figured this out only after the PAC server crashed :)

Wednesday, April 27, 2005

dc0: failed to force tx and rx to idle state

Sunfire V100 running OpenBSD 3.7 Sparc64 freshly installed offvia the official CD, is reporting "dc0: failed to force tx and rx toidle state".

Is this just cosmetic, or an actual problem?

Looking at the source code for the dc drive, this seems to be related tosetting speed and duplex (I lock the interfaces to 100/full).

I have an identical machine running 3.6, does not show this message,only the machines upgraded to 3.7 give this warning.

Saturday, February 12, 2005

DNS monitor

Had a little incident today, so I ended up writing this.

Uses 'nslookup' because I actually wanted some of the nslookup side-effects;for example, it's difficult to get 'host' to "show it's work" and yetalso producethe same output in the same order each time (so the 'diff' will work correctly). Crude, yet effective.

Hopefully It'll just run quietly for years, never kicking off emails from cron,but at least now I won't be blindsided when somebody decides that simplybecause you can't ping something, it's okay to delete the host from DNS ;)





$ cat $HOME/bin/dns-validate.pl



#! /usr/bin/perl



#



# No authorship, no copyright, no support.



# KK2005



#



#



$nslookup="/usr/sbin/nslookup";







$dir=$ENV{'HOME'}."/public_html/dns/";







$oldfile=$dir."status.then";



$outfile=$dir."status.now";







@ns= ( "127.0.0.1","207.227.240.1",



);



#



#



#



die "Missing nslookup $nslookup $!" unless(-x $nslookup);







chdir($dir) die $!;



rename($outfile,$oldfile);







system("co -q -l $outfile");



open(OUT,">$outfile") die $!;







while() {



next if(m/^#/);



chomp;



print OUT "#" x 64, "\n";



print OUT "#\n# ",$_,"#\n\n";







foreach $server (sort(@ns)) {



print OUT "\n # Server $server\n";



print OUT `nslookup $_ $server`;



print OUT "\n";



}



print OUT "### End $_ $nameserver###\n";



}



print OUT "\n###\n# End nslookup\n#\n";











print OUT "\n# Contents of /etc/resolv.conf\n",`cat /etc/resolv.conf`,"\n";



print OUT "###EOF###\n";







close(OUT);



chmod(0644,$outfile);







system("ci", "-u", "-q", "-m$0", $outfile);



system("diff", "-w", "-c", "-T", $oldfile, $outfile);



exit($?);











__DATA__



#



#



# Enter your hostnames here, one per line.



# Comment lines must have a '#' as the very first character



#



# Example entries below, I recommend removing these.



#



127.0.0.1



example.com



###EOF###

Monday, October 25, 2004

Strange hardware errors? Consider a PROM Firmware upgrade

Every so often we run into a machine, physically identical to other boxes successfully converted, that fails in weird ways -- network and drive controllers not found, sporadic failure to recognize drives, etc.

Sometimes the problem turns out to be an actual hardware problem,
other times the root cause is the firmware version, either OBP
(OpenBoot PROM) or (less commonly) POST. The Sparc64 project page
hints at such issues, but does not go into details.

Sun provides a "Standalone PROM Update Utility" on CDROM, as well as
documentation on upgrading firmware:
http://sunsolve.sun.com/data/802/802-3233/pdf/802-3233-25.pdf

It is technically possible to update the PROM from a netboot server.
If you don't already have a netboot server, an alternative (suggested by Mike Scher) for systems without a CDROM drive is to keep a bootable SCA drive, containing a 32-bit Solaris and the latest prom update utility in the root partition.

Friday, December 27, 2002

OpenBSD Sparc64 on Sunfire V120

OpenBSD works amazingly well on "our" new SunFire V100 hardware.

With my pre-existing netboot buildout, doing a network installation on the SunFire was quick and easy -- faster than the Solaris network installation, if not quite as self-completing as my "fire and forget" firewall build boot :)

There are a number of security enhancements inherent in OpenBSD by which we can justify this admittedly unusual choice of operating system for DNS and other specialized applications where security is more important than "normalization"

Kevin


(P.S. FreeBSD 5.0 for Sparc64 supports most of the same modern Solaris systems as OpenBSD (Oddly, no Ultra-2 SCSI support, but FreeBSD does work on E220/E250) and offers SMP support for systems that have multiple CPUs)

Thursday, December 26, 2002

Sudo advocacy

Some additional comments on the subject of "sudo" (http://www.courtesan.com/sudo/).

Sudo (Super User Do) is a popular solution for Unix access control, permitting regular users to run certain commands as root or as a role account, without the risks of shared passwords, and without the need for users to memorize yet another password. On many of my personal Unix systems, "sudo" is the only file with "setuid root" permission!

Has there been any consideration of the option to use the advanced (http://www.courtesan.com/sudo/intro.html) features of the "sudo" package? For example, maintaining a single global "sudoers" file on a (secure) central management host, "pushing" copies of this single standard configuration file to all managed Unix servers?

Use of a single global, centrally-managed "sudoers" file offers numerous advantages:
  • Simplifies changes that affect many servers, including adding and removing access to commands and user access (allowing for near instantaneous hire/fire access updates).
  • Grouping of users, of hosts, and of commands allows discrete access control from a single global file.
  • This type of centrally-controlled "sudo" deployment on Solaris is used at many large corporations, including Lockheed Martin.
  • Without the need for users (or even most administrators) to know the root password, this password can be stored more securely, and "root" can be a restricted "role" account under Solaris 8 RBAC.
  • One single file to audit for access control of root and role account commands for all hosts.
  • Automatic generation and reporting of command audit trails, locally and/or to a central log host.

I am aware of a few drawbacks, including the reasons Data Security uses this approach for other configuration files, but not for "sudoers":
Compromise of any host which uses the global "sudoers" file exposes sensitive information about the purpose, users, and access controls on other hosts using the same "sudoers" configuration.
Compromise of the central management host may make it easier to compromise the client hosts.
Effective security requires recompiling "sudo" to use SecurID authentication instead of passwords.

Automatic updating of the "sudoers" file on large numbers of remote hosts can be accomplished in a number of ways. Through the use of "ssh" and "rsync", changes to the global configuration can be distributed, via either "push" or "pull" scripting, quickly and efficiently.

Tuesday, November 5, 2002

Unpublished Solaris RPC exploit against 'rpcbind' in the wild?

There are a growing number of (unofficial, but reliable) reports
from various sources of new, unpublished exploits targeting RPC
services on Solaris, including Solaris 2.6, 8, and Solaris 9,
both Intel and Sparc.


This is unconnected with the recent publically announced SGI/IRIX
vulnerabilities, also related to 'rpcbind' (aka 'portmapper').


The most reliable reports are of penetration and defacement against
Internet servers running Solaris 8, with all current official
Sun patches applied. There is also the possibility of the upcoming
release of "blended-threat" worms, for example, a worm with a payload
containing both an (unrelated) MS-RPC exploit for Win32/Intel and a
Solaris/Sparc exploit against rpcbind.


Any Solaris system running 'rpcbind', regardless of what services,
if any, are registered with RPC, should be considered vulnerable.


There is no official patch from Sun, this vulnerability has not been
confirmed by Sun Microsystems nor by CERT. Prior vulnerabilities of
this nature have been exploited in the wild for several months before
being officially addressed by the Sun Security Coordination Team.


On many systems, it may be possible to disable the RPC service
if no NFS or other applications/protocols which rely on RPC are in use.
If it is not possible to entirely disable the RPC service, you may wish
to consider implementing one of several mechanisms to protect the RPC
services from remote access.


We are not able to provide details or recommendations for protecting
RPC at this time. There are third-party 'rpcbind' implementations
which support TCPwrappers, however we have not done any recent testing
with this class of software.


Any system exposed on the Internet with 'rpcbind' running and
TCP port 111 accessible should be considered to be compromised.

Thursday, September 19, 2002

The state of Email encryption: GnuPG, PGP and PGP.Com

Recently, there have been some question about the status of email encryption, both within the Company, and for communication with external users. Currently, the Company has no policy or standards regarding encryption and encrypted email. We do support production processes using encrypted files. Specifically, PGP is used to exchange sensitive information with outside vendors for XXX and certain financial applications.

There are many other useful business tasks facilitated by Public-key cryptography. More information on this technology is available on our intranet server.


IT Audit and the Network and Data Security groups have been using PGP-Freeware with positive results. As explained below, use of PGP-Freeware for business communications is no longer permissible, under PGP.Com's interpretation of the license for that product.


PGP and GnuPG public key queries and key-registration using Internet keyservers will work for HTTP keyservers (after configuration of the client proxy settings, however, registration and queries will not work using LDAP protocol to servers on the Internet. Our team no longer operates an Intranet keyserver, due to a drive failure on our development machine


There are plug-ins for PGP and GnuPG for Outlook and Outlook Express, along with many other email clients. Microsoft has no plans to directly support PGP in Outlook, Exchange or Active Directory, instead, Microsoft provides integrated support for S/MIME, using the X.509 certificate format. Here is a (somewhat dated) comparison between the various protocols:

http://www.imc.org/smime-pgpmime.html


In general, S/MIME is easier to deploy in a Microsoft-centric (Exchange and AD) environment, for purely internal communications, yet PGP/MIME (and now OpenPGP) is the de-facto standard on the Internet.


The commercial PGP division was recently sold by Network Associates. There is a new "PGP.Com" site, with information on products and pricing:
http://www.pgp.com/faq.php

Will You Continue to Support Freeware Products?
Yes. PGP will continue the tradition of freeware products for non-commercial use. The next release of PGP freeware will be in November 2002 for PGP 8.0 for Windows and MacOS X. Customers using freeware products for commercial use - using PGP freeware to communicate with licensed business users - must immediately cease usage and purchase a commercial PGP license. Products can be purchased at https://store.pgp.com/.

Company employees using the "PGP Freeware" unlicensed application must immediately cease usage.

Promotional pricing for the commercial PGP product is available through October 31st. The promotional price for "Corporate Desktop" is $70, "PGP Mail" is $45. Prices are per-seat for any quantity, these prices will increase significantly on November 1st, 2002.
http://www.pgp.com/promo.php


An alternative to purchasing commercial PGP is to deploy GnuPG, the GNU-licensed freeware implementation:

  • http://www.gnupg.org/
  • http://www3.gdata.de/gpg/