Wednesday, September 3, 2014

VMware Fusion 7 Pro. A must have upgrade.


VMware just released Fusion 7 Pro with some major changes and updates. The most obvious are support for Yosemite OSX 10.10, improve performance, GPU upgrades.

However, if you are Mac based developer who is involved with ESXi or vSphere, this is an absolute must-have upgrade. This version definitely gives weight to the "Pro" denomination. The remote server integration makes it well worth the $80 upgrade and $150 full price.

So what is new?

I'm not going to rehashed some press release or product page. You can read that directly on VMware's own product page here:http://www.vmware.com/products/fusion-pro/ . Improved performance. Check! Improved Retina support. Check!

The "what's big" is the vSphere, ESXi support. This is only in the Pro version and it definitely makes it a big differentiator between the regular Fusion 7.

For those Mac developers who tirelessly worked for years with ESXi, your normal modus operandi was to install a Windows VM and run vSphere Client in a Windows' Guest. Now,  a majority of those functions are built right into Fusion Pro.

In the screenshot below, I can see my local VMs and in the preview pane and I can now see the inventory of my remote Virtual Machines. I even get general stats on usage of the remote server.


Yep. Now you can start, stop, modify remote Virtual Machines, and even deploy OVFs right inside Fusion Pro.

Impressive indeed!

You simply, connect and you have some basic control. This is simply a killer feature.





Another benefit to this is you can now run Virtual Machines remotely. I have 6 and 8-core AMD ESXi white box servers running in my basement. They have  16 and 32GB of RAM with 3 terabyte of data storage. I don't need to even run my development VMs on my Macbook. Rather, I can control and run them remotely. Sure, you can VNC or RDP in but that method is often laggy and unpleasant. Nor can you enable features of the guest via traditional remote desktop connectivity.

Here, you can run and enable device features remotely. For example, I run a proxy server and have a stand-by failover VM on another server. Both are running with the same IP. When one fails, I simply enable the networking on the standby unit to take over. The guest will utilize whatever CPU and GPU processing power your remote host hypervisor has.




So if you have VMs on a ESXi, vSphere or Windows Workstation, you can now run your VM on beefier, remote boxes. The whole start-up and control process feels and acts if you are running locally. I am very impressed. You won't get unity or shared folders on remote VMs. Thus, you'd still need to run those VMs locally for those guests that need those features. However, for most console OSes (Linux apps servers), you can simply run them remotely.

Furthermore, you can now provision on-the-fly fairly quickly.


Fusion 7 Pro has the ability to export OVFs built in the interface.  You now no longer have to run command line tools like ovftool to export your Virtual Machine  into a ESXi/vSphere format. You can even drag-n-drop local Virtual Machines you built on your Mac and it will upload and deploy on your ESXi server in a seamless Mac-like fashion. Again, killer upgrade.

Pictured below is an example. I dragged a local LAMP stack from my Macbook onto my remote ESXi server box and voila. Instant provisioning.


You can also export and download as well.


I must say, these Pro features are impressive. It doesn't have all the features of the Windows ESXi client but it covers most of the stuff I need on a day to day basis. The OVF export takes the hassle of tweaking VMDK and thin provisioning.

Now, let me comment on some of the other features of Fusion 7.

You can select what GPU you want to use if your Mac has a hybrid graphics card set-up. Before, I had to use some hacks to disable the NVDIA card but now, you can set it in the VM guest.


This will save battery power considerably for Macbooks with dual GPUs.  Console based OS and older operating systems will no longer start the GPU if you don't want them to. My macbook no longer whizzes the fan when I want to fire up an old copy of Windows XP or CentOS.


They've also improved Retina support. For non HiDPI operating systems, the rendering doesn't look so bad anymore. Pictured above is Windows XP and it now looks fairly good without the nasty dithering blockiness found in earlier versions.

User interface wise, it is an clean, streamlined new look that will fit right in with Yosemite.



Overall, I am very impressed. I am definitely giving this upgrade a big thumbs up.

Logitech introduces the K480 multi device bluetooth keyboard



Today, Logitech announces the new K480 keyboard. It is a bluetooth keyboard that allows you to pair up to 3 devices. This sounds exactly like the K810/K811 I reviewed a while back.


I guess the basic difference is this is $50 instead of $99. It also has a jog dial versus Fn keys. However, I still like the K810/811s due to the fact they glow at night with the illuminated keyboards. This doesn't appear to have illuminated keys. Oh, I forgot, this new K480 does have a slide in cradle to dock your phone and tablet. That is pretty cool except the green color doesn't suit me and I can do without the white version.

I'll probably pick one of these up as I always have a need for bluetooth keyboards.



Proper way to run TOR and TAILS in a Virtual Machine

Note: This post is for informational purposes only. I use Tails/Tors for network analysis and intrusion detection of my network for academic purposes.

Tails is a TOR based amnesic based operating system.  It is basically a Live-CD/USB operating system that gets you on to the TOR based Onion network for complete privacy. The normal usage is to run it off a CD or USB. Virtual Machines are not recommended but people do it anyways. I won't get into the debate or discuss the merit of running it via live boot USB versus running it in a VM. The basic argument against the VM's premise is if the host hypervisor is compromised, you are not truly anonymous. Furthermore, keyloggers, remote desktop can cause problems. Lastly, most VM's bridge or NAT networking can potentially leak info.

If you are going to run it in a VM, I have some suggestions. Hence, the topic of this blog post.

First of all, you want to have much isolation as possible. Most Hypervisors allow you to dedicate specific hardware to the guest operating system. Never share anything. This includes soundcards, bluetooth, and most importantly ethernet/wi-fi devices.

For the sake of this post, I am using Mac OSX and VMWare Fusion. However, the concepts and principles apply to Windows, Linux or VirtualBox.

When you create your guest, try not to store it on your drive.If you do store it on your drive, encrypt it. And encrypt it again. My main hard drive has file fault but I go even further and store my image in an Encrypted container. In this case a DMG.




I can then go toss my DMG image into an encrypted USB stick.
Then go another step further and use VMware's built-in encryption to protect the VM file.


(be sure to enable it to ON!)

Since the whole guest will be relatively small, I strongly suggest throwing it on a USB stick. You don't want anything on your host.

Now to the VM itself. Clean it up.

I then remove everything I do not need. Remove the Sound Card. Disable the bluetooth sharing.
Everything except USB.  If you need sound, I have a solution for that later.


Most importantly, remove the hard drive as you don't need it. You will be booting from the ISO file. Your VM files should be less than 2MB.


Now, lets beging the isolation process.
Disable the Network Adapter.
Yes. Disable the network adapter.

In fact, you can disable all networking on your host computer. When you bridge or NAT, you cannot truly mask your host's computer with advance sniffing. Your host computer doesn't even need to be physically connected to the network.

Now, if you disable networking, how do you get on the Internet or have any networking?
This is the important piece of info. Get yourself some cheap NIC devices.  USB ethernet dongles, wi-fi sticks. Treat them like disposable SIM cards you have on disposable phones. The MAC ethernet addresses of those devices will be unique and will not trace back to your computer. 



No bridging. Not NAT traversal. Complete isolation from the host. If you no longer have a need for the NIC, simply throw it away and get a new one. That last tip is for the paranoid.

Under your USB settings, you will want the guest operating system to "own" the particular device.
In this case, my portable USB dongle. Since Tails uses Debian, I've notice most USB network and wireless dongles work out of the box including the ASIX 88179 USB 3.0 gigabit dongle.


Once you boot into TAILS, you'll see the USB network adapters as if they were native to the TAILS operating system.

 I would also do a simple ifconfig to verify you are indeed using the hardware.



Another cool thing you can do is dedicate a separate USB mouse/keyboard to the Virtual Machine. This should eliminate one of the key concerns of running Tails inside a VM - potential keylogging from the Host. As for sound, since you disabled sharing from the host, you can use a USB sound DAC if you really want sound inside Tails. Again, you need to give dedicated USB ownership to the guest.

Here I use a Motorola LapDock. I dedicate a separate full screen display to my VM and use the built in keyboard/trackpad. The key entries are unknown to  my host Macbook Pro. Also pictured is an Apple 10/100 USB dongle that also works very well with Tails.


Now back to my disclaimer on the top of this post. This is for informational purposes. I've been evaluating Tails/Tor to see if anyone on our network can go un-detected. We've provisioned Kali intrusion boxes; sniffed network with Wireshark/Ethereal and we are still testing. I have to say, I am very impressed and scared at the same time.





Sunday, August 24, 2014

David & Goliath. Bargain Bin Budget Laptops Acer 11.6 in and Toshiba 17.3 in Windows 8.1


My kid is entering the first grade so I decided to upgrade his computer. His first computer was an Acer C710 Chromebook. It served him well for Preschool and Kindergarten. I think Chromebooks satisfies most needs but the one thing I hated about the C710 Chromebook was the battery life. Thus, I sought out his replacement. I heard great things about the 710 replacement, the C720 but the allure of cheap Windows laptops tempted me. Low and behold, a few of the brick-n-mortart stores are selling ultra cheap Windows 8.1 celeron budget laptops. First, I got him a 17.3" Toshiba laptop. Yes, 17.3" 1600x900 6lb behemoth. It was $250 so why not. Then, Best Buy flashed an 11.6 Acer for $130 so I couldn't resist. I decided to let hime choose what he wanted to keep.

Thus, today's post are about two compelling, cheap, low-end Windows PCs in our household.

Thursday, August 21, 2014

Amazon FireTV


I got myself an Amazon TV last week when they were available for $60. $84 plus 20% off coupon. I figure why not. I ended up getting the game controller as well. I don't have much to write about it but I gotta say it is cool.

I have NetFlix, Plex, Amazon Prime video, and some light games. The Amazon FireTV appstore is very lacking. There is probably only three good games on it - RipTide, Asphalt 8, and Amazon Studio's in-house Sev Zero. The other games are pretty much boring. The App library is very limited so you can't install something like ES Explorer or MX video player without going the sideloading route. You can root it and get the Google Play store on it. However, I don't have the time for those shenanigans. I would not buy this in the hopes of having a convenient Android TV gaming console. It isn't quit yet there.

I had a Logitech Google TV that we used primarily as PLEX and NetFlix Client. It was handy because of the keyboard and the keyboard itself is a universal TV remote.
With the FireTV, we don't have that so we have to make do with TV remote, FireTV remote, and external keyboard.

I have a USB wireless K400 keyboard so it makes it very usable to search for PLEX and Netflix titles. It is also good to have Amazon Video right there without the need for Airplay or Chromecasting. Plex is a $4 app. I already have it on my Amazon App Store and Google Play but I guess there is a separate one for the Fire TV. Again, I don't have the time or inclination to side load Plex from another source just to save $4.

The voice control is real simple that even my 6 year old kid can use. Speaking of kids, you'll definitely want to enable Parental controls. Otherwise, anyone can just buy apps and media. Parental control forces a numeric PIN for purchases.

Overall, I like it. Most retailers are now selling it for $84. I don't know if that is a permanent price drop but it is a good value. Is it better than the Apple TV. In some ways yes, it has more options and gaming. However, AppleTV has iTunes ecosystem and AirPlay. With the Apple TV, I don''t need to make a cohesive effort to upload my content to Amazon's cloud. Everything works in the background on Apple's ecosystem. Then again, I don't think I'll be sharing family photos on Amazon's photo cloud system nor would I upload all my music to Amazon's music. I'm glad I have both.




Wednesday, August 20, 2014

Upgrading the G-Drive G-Connect hard drive


A few weeks ago, I wrote about the G-Tech G-Connect iOS NAS drive. It is a 500GB 2.5" NAS that allows you to stream videos to iOS as well as act as a micro AFP file share / TimeMachine server. It has onboard ethernet as well as Wi-Fi built in. They routinely go on sale for $39.99 at Frys and I actually like them very, very much.  I am able to store files off my PLEX server that my kids can't view. AKA "Daddy files."

The issue with them is they only store 500GB.This device is discontinued and I wouldn't pay more than the $40 street price for these. However, they are pretty easy to crack open and you can easily replace the built in drive with a larger capacity drive.

I did just that with a 1TB Western Digital 2.5" blue drive.



The drive I replaced it with appears to be thicker. Possibly 9.5 mm height and the built in one may be 7.5 mm tall. With some work, I was able to manage the swap. I was concerned that Hitachi (who now owns G-Tech) may have added some special firmware that locks their devices to their own drives but that was not the case. I just attached the drive and formatted it as normal. Once booted, I was able to see it in the network.


Voila. 1TB available. These make good TimeMachine remote backups. $40 for the G-Connect and $60 for a 1TB 2.5" drive.




Tuesday, August 19, 2014

Crazy Cheap Acer 11" Netbook / Laptop on Sale

I just ordered an 11.6" laptop for $129. Yep, $129. That is crazy.
Sure, it isn't a speed demon but $129. This would make a low power NAS, linux ultralight.

I saw my newsfeed flash a sale for an 11.6" notebook at $179. I went online to Best Buy and refreshed the page and it dropped to $129.99. This was around midnight on 2014-08-19. It sold out quick. It is an Acer Aspire 11.6" E3-111. The RAM is upgrade-able so I'll throw in an 8GB stick I have lying around.



It has a N2830 Celeron which isn't particularly fast but it has the same specs as the ASUS C200 Chromebook. It is completely fanless, so this should be very interesting.



I will update with a review once I get it.

Edit: This was legit. If it was a price mistake, Best Buy did honor the price and I picked it up.