2015-12-31

2016

2016 should be interesting! A&A have a lot going on.

I personally have a lot going on - I won't bore you with details (that is what Facebook is for), but I am pleased to see my daughter planning to get married.

We have the new terabyte services launching - and whilst these are initially very specific services, FTTC, 80/20 capped, with the phone line part (no calls) as a new 12 month service (see here), we really hope that over the coming months some of the restrictions will go away, and more services can start to be measured in terabytes of usage and not gigabytes. I remember ISDN dialup and the dream of megabytes, let alone gigabytes or terabytes. I am actually really pleased we can start to measure usage in such terms, even if only on these specific new services. DON'T HASSLE THE SALES TEAM (they told me to make this big and bold) as we won't have a proper ordering system for about 2 weeks at the soonest. If you want this soon - best to get on the irc channel as we'll be asking for guinea pigs next month.

Our data SIMs are expected to allow 4G real soon. I have seen this working, but there is a lot going on at our suppliers with this and a lot of testing and tweaking, but we know it can work and expect it any day. The only down side is no improvement on pricing - so 4G lets you spend a lot very quickly. However, there are plenty of good business uses of proper fixed IPv4 with 1500 byte MTU and no filters on a mobile device. And for occasional use, like my iPad, it works out really quite sensibly priced! We'd love to do the same on voice SIMs, but that will take some more work.

2015 was actually quite good for finally sorting SIM card printing - it is silly, I know, but getting printers that work properly was not easy. We print cards with artwork of your choice and our logo, and so on. It should be irrelevant as you throw that away but it makes all the difference in the presentation, and we can do proper corporate branding on SIMs now, either as a mobile telephony service provider or as a corporate network. We even do an ID card printing service now which is starting to take off with schools and even ISPs using them for staff ID cards.

We had been making progress on SMS and other related stuff, but that is stalled slightly. We are trying to kick start that and have some improvements to services and prices for SMS soon. It is odd, we sort of expected SMS to go the way of fax machines, and the dodo, but the universal nature of mobile SMS and the closed nature of things like iMessage mean it is still a "thing"!

We have some massive work on the core network, and scarily some 40Gb/s optics involved in a fibre ring. This is happening real soon (January I expect), and we have extra transit and peering and links to carriers going in. This is kind of important to handle expansion of our network, especially with terabyte services. We have a new member of the ops team with a lot of experience, and things are plowing ahead on this. As ever there will also be a load of work on our systems, and we recently launched https://control.aa.net.uk/ as a new https link for our control pages (clueless) which meets some of the latest standards for https properly. Much more to do. We also want to improve the way we handle signed and encrypted email with customers this year. Privacy is important and we should be on the ball on this.

We even have new hardware this coming year, with the next generation of FireBrick expected this year with a true fibre interface and faster throughput and IPSec. We are working on the next generation of the larger scale kit as well, obviously.

Of course, fighting the IP Bill is important. I have done a lot in 2015, including talking to the home office, actually talking to the Joint Committee in parliament, talking to a peer in the Lords, and next month talking again in parliament on the matter. I have been on TV a couple of times on this too. I have a petition at over 10,000 signatures on encryption. It is hard to get over the importance of this, and there is a campaign that ORG are running to try and counter the government spin/PR campaign on this - do consider contributing (here) - we have!

Even little things, like the way we post out routers, are changing. We now have the new Royal Mail Shipping API and so should be able to get their tracked services so we can send a router that does not have to be signed for, and can even have a pre-arranged "safe place" to leave it, but is tracked to confirm delivery. We'll know more on that next week.

We are set to grow and improve in every area of our services for a very exciting 2016 ahead.

There are also moves afoot to improve the A&A web site - we'll see how that goes.

Happy New Year to all of our customers from myself and all of the staff. We may be a small family business, but we really appreciate your continued support.

Royal Mail Shipping API - finally working

Since Royal Mail are pulling the plug on Smart Stamp, tomorrow, we have been rushing to get an alternative postage system in place. The obvious choice was the Royal Mail Shipping API, which they document on their web site.

This allows us to print postage, which is purchased "on account" rather than pre-paid on card like Smart Stamp.

The API uses XML and SOAP, and seems to be documented in the technical specification on the web site. There is an on-boarding platform to allow testing, and a check list of tests done before you can go live.

Frustratingly, in spite of a couple of months notice it took until 3pm the day before Christmas Eve before we got any credentials to test. All of my testing failed with "Authorisation Failure". Looking at the the documentation and the information they sent over this is clearly a common problem. There is a lot in the technical specification and they have code samples for generating the authentication strings in the XML in php, python, exe, and others.

However, today (yes, very last minute) we finally have this working on their live platform, so here is a list of the issues which I hope they can fix, and others can learn from.

Client certificate

Even though the https uses a self signed certificate their end, they want you to use a specific client certificate they issue. This means we'll have to faff with renewing it every year or so.

Why the certificate is not the only authentication is beyond me, or why, when using https, they do not simply use plain text http authentication or plain text SOAP authentication, is also a mystery.

Authentication

The authentication uses SOAP WSSE Password Digest authentication. This is well document, and involves sending a Created date/time, a Nonce random value to avoid replay attacks, and a Password which is a password digest. The digest is defined for WSSE as SHA1(Created+Nonce+Password) and both nonce and the digest are sent in Base64 in the XML.

What Royal Mail expect is: (a) Nonce is 16 byte binary value (b) "Password" as used in the WSSE hash is actually Base64(SHA1(PlainTextPassword)). This means you send Base64(SHA1(Created+None+Base64(SHA1(PlainTextPassword))))

Their documentation does not exactly make this clear at all, and contradicts itself,. Their example code does not do this, it uses just SHA-1(PlainTextPassword) as the password in the WSSE algorithm, so generates credentials that do not work. Their help desk would not actually make an XML file that works to the actual on-boarding system. They confirmed the examples I made using their own code fragments were "right" when there were not, and only used some SOAPUI test platform rather than using the actual on-boarding system. This wasted a LOT of my time.

I note that at least one example used a timestamp that was local time with a Z suffix (meaning UTC), so I half expect this to all go horribly wrong at the end of March.

ApplicationId

The application ID looks to be sort of your account number, a 10 digit code. But for some reason both the on-boarding and live systems cannot actually work with the right application ID, and helpfully just say authorisation failed. They have provided a different one to use for now. This just compounds the confusion over the authentication hash as trying either way of doing the hash still fails when using the right application ID.

Also, they quoted the application ID wrongly in the first place in their email, just to add to the fun.

Schema Errors

The XML you send is checked against the schema, and a single character out of place just says Schema Validation Failed. No clue where it got to. This is a nightmare to debug.

This is made worse by the specification actually quoting at least one object name incorrectly, so if you follow the spec you will get a schema validation error. For example, object unitofMeasure is actually unitOfMeasure.

XML namespace

Anyone that uses an XML library or understands XML namespaces will know how they work - each object and even attribute can have an associated namespace, which is itself usually a long URI.

These are then typically abbreviated to an arbitrary prefix. So soap:Envelope is saying that the Envelope object is in the soap namespace, but there is an xmlns:soap attribute somewhere at or above that object saying what the namespace actually is.

The tags you use are normally totally arbitrary, however, when I tried using different tags to those they used it failed validation! I don't know if this is only the on boarding system, but it means they are not doing XML right. Thankfully, using the tags they expect is not that hard, but it a requirement they should make clear.

It gets worse though, and this may only be on-boarding again, but the location of the namespace matters! Not for the schema validation, no, that would be too easy, but for authentication. My XML library places the namespace declaration as close to the outer most usage of that namespace. But doing that means you get the ever unhelpful Authorisation Failed error. This again compounds the confusion of the hash used. Thankfully my XML library has a mode that puts all namespace declarations on the top level, and that was good enough for the on boarding system (albeit not quite matching their examples).

Rather annoyingly they mix some objects using V1 of their API with some using V2. They also have subordinate objects that are in the default XML namespace (so untagged), which means you cannot simply make the whole message have an xmlns at the top level and avoid using tags. It is just messy.

Service Matrix

They have a service matrix - the services they offer are a combination of a service type, service offering, service format and enhancements, and then separate options for signature. It is actually really messy, e.g. for recorded delivery you use a service enhancement (a number) on a normal service list 1st class post, and do not set the "signature" field! Basically, we had to make a table of what things to set for each service we wanted to use. But we don't have a clear list of options from Royal Mail, i.e. other than just the title of each so not clear initially that CRL is Royal Mail 24 and Royal Mail 48 which are account (cheaper) versions of STL 1st and 2nd class! We hope to find out more next week, and something about the tracked but not signed for options which we want to use for routers.


I hope this is useful to anyone else doing this... P.S. I have C code for this - ask me on irc.

2015-12-30

Honoured, thank you.

My petition has exceeded 10,000 signatures and so should get a response from government.

Thank you all - let us see if it is a sane response.

To sign, see https://petition.parliament.uk/petitions/106369


2015-12-27

#IPBill implications

So, it is Christmas, and my son is having some fun knocking up an on-line game. Occasionally he needs my help but to be honest he is not doing badly with some javascript, mysql back-end, and a few of my tools I knocked up many years ago, and he is learning something about designing the software and making it work.

We knocked up an on-line poker game some years ago whilst on holiday, it can indeed be fun.

One of the first, and essential, features of the game was a simple in-game chat. This is a feature of most games.

There are a couple of other features which are likely to be part of this game or any game in future - one is running the game on a cheap VM (Virtual Machine) from some VM provider which are typically not in the UK. The other is the availability of free https certificates from someone like https://letsencrypt.org. Indeed some VM providers are working with Let's Encrypt to make it simple.

But hang on! The second you make a game like this, with an on-line chat like this, you have just created a secure communications platform with encryption that ends outside the UK.

James is not making permanent logs of the in-game chat. He has no intercept capability or any resources to make one. He has not published any contact details (he does not have to - not taking money, not a company, not trading) so nowhere to send a RIPA request.

The on-line secure chat is simply a side effect of a simple free on-line game a kid has knocked up (OK not so much a kid any more, but this could be done by a kid).

Where does the Draft Investigatory Powers Bill fit in with this?

Who tracks the creation of such things - he is not advertising it - it is for him and some mates to play a game, but it could be used by terrorists. It could be created by terrorists in the first place.

Who ensures that such platforms have intercept capabilities, and data retention of communications data? Who pays for it all?

It is just one more example of how the IP Bill is just broken, and not fit for purpose, even though it seeks to reach way beyond normal privacy and human rights.

2015-12-24

Live on TV via Skype!

I am not a Skype fan. We have used "proper VoIP" for a long time, but it works.

But I am also not a fan of spending 90 minutes or so on train and taxi in to London to Millbank studios, being on-air for 4 minutes, and then spending as long getting home. So when Russia Today (RT, Sky channel 512) wanted me on TV and said maybe Skype, I tried it.


It works OK. But it is not that good quality and the sound even broke up.

So I am wondering if I should set up a studio. I have been on RT twice, Sky News several times, BBC a few times, so it may be worth tinkering. I should be able to set up a decent camera and some lights and a decent mic. The idea is that I could provide a web page with streaming live audio/video in HD and use a telephone call in earpiece as talkback.

I wonder if TV studios can handle that - I would think so if they can manage Skype.

I may have to put one of those big "ON-AIR" red lights outside the man-cave though :-)

Royal Mail Shipping API

Update: See latest blog post on this.

Having worked out what the WSSE PasswordDigest uses, I am struggling to get past "Authorization Failure.", and sadly it sounds like they have all buggered off home.

The example they sent me matched what I worked out, it includes a Nonce, and a Created date time, and using the password supplied, I was able to create the same Password digest.

To do this I had to use a Password in the algorithm that was not the actual password.

Password_Digest = Base64 ( SHA-1 ( nonce + created + password ) )

I had to use a base64(sha1(password)) in its place. That worked to match the example. But it is not letting me log in. I used this because the specification says "For Shipping API V2 the password used in the below formula is the base 64 encoding of the SHA-1 hash of the plain text password." even though it goes on to say "Password_Digest = Base64(SHA-1(Nonce + Created + SHA-1(Password)))"

However, I have found the spec has errors, little things like it defines an object unitofMeasure which if used causes the whole fail to report "schema validation failure". The example had unitOfMeasure which works. So I cannot actually trust the spec. Not a good start.

However, they helpfully provide a zip of various versions of the authentication done in different languages. This is useful, but also shows that something that should be simple is in fact clearly very complicated.

In perl they provide :-

my $conct = $nonce . $creationdate . (sha1($password));
my $passworddigest = encode_base64(sha1($conct));

Which seems to use simply the raw SHA-1 of the password in the algorithm, not a base64 of it.

In PHP they provide :-

$nonce_date_pwd = pack("A*",$nonce) . pack("A*",$CREATIONDATE) . pack("H*",sha1($password));
 $PASSWORDDIGEST = base64_encode(pack('H*', sha1($nonce_date_pwd)));

Now, my PHP is not good, but reading up, the H* means hex encoded. So that looks like it uses a hex coding of the SHA-1 of the password in the algorithm, not a base64 coded version.

In python :-

hashedpassword = sha.new(password).digest()
digest = sha.new(nonce + CREATIONDATE + hashedpassword).digest()
PASSWORDDIGEST = base64.b64encode(digest)

Which looks like using the raw SHA-1 in the algorithm, not a base64 coded.

So I am thinking the spec, and the example they gave me, is wrong. I even tried using their python code to generate Created, Nonce, and Password fields.

Sadly, it is not working to get past "Authorization Failure.", and it looks like the have buggered off home.

This is NOT THE WAY to specify an API. You need clear documentation that is actually correct, and you need helpful error messages on your on-ramp system. Not impressed at all.

Update: Nope, they are there until 6pm - yay, well done Royal Mail - trying to find the problem for me now.

Update: We are back to the base64(SHA-1(plaintextpassword)) now, and using a different applicationId, and working. Yes, that disagrees with all of their code samples! So hoping to get on live system soon.

2015-12-23

We must all be better than average

We have seen UK politicians afflicted with this stupidity too, but today it seems that Clinton stated, categorically "I wouldn't keep any school open that wasn't doing a better than average job".

http://www.weeklystandard.com/clinton-i-wouldnt-keep-any-school-open-that-wasnt-doing-a-better-than-average-job/article/2000327#.VnoXnsQZTmq.facebook

Now, I should not have to explain this, but just in case I do...

"average" is the "middle". There are lots of technical ways one can work out "average" and I won't go in to any detail, but basically, in generally terms, if you have a set of something, like "schools", always, half will be "below average" and half will be "above average".

And what is worse, if you closed the half of all schools that were "below average", then the average would change, and would now mean that half the of the schools you have left are "above average" and half would be "below average".

You keep doing this until the best school in the country is the only one left open, and it is "only average".

I say this with some dismay - why are people so thick?, but I have to remember that OFCOM defined in the code of practice that 10% of all broadband lines are "faulty" as they are in the "bottom 10th percentile", and again, if removed or fixed, then the average and 10th percentile moves up. It is the same stupidity right here in the UK in official OFCOM code of practice.

Wallot inspector

What is fun with a nice UV ink jet printer is on what you can print... One thing is a bank card. This is now my Monzo card, oops. Yeh, I can...