Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Tuesday, 30 January 2018

Blessed English Translations

The Beatitudes are so called because each one starts with a Greek word, Makarios, which was rendered Beati in Latin and, most commonly, Blessed in English. That being the case you might expect that the underlying word used by Matthew would have something to do with blessings, or with being blessed. Nope. Makarios, the word Matthew uses, is unrelated to the Greek words for either.

A lot of commentaries on the Beatitudes tie themselves in knots attempting to explain why people who are clearly have not been blessed are described by Jesus as being so. They are missing the point. Others treat Jesus' words as if they are a list of things we have to do or be in order to be blessed by God: legalistic nonsense! You'd think there were enough rules and regulations in the Old Testament for anyone (613 is, I believe, the traditional count) without adding more (and Jesus is explicit, later in the sermon, that the Law stands as it is: no adding or taking away from it).

A few English translations render makarios as 'happy' instead of 'blessed'. That too is another word entirely. So what does makarios mean?

Originally makarios simply meant 'free from daily cares or worries' - which has an obvious link with later on in the Sermon on the Mount where Jesus says:
"Therefore I tell you, do not worry about your life, what you will eat or drink; or about your body, what you will wear. Is not life more than food, and the body more than clothes? ... But seek first his kingdom and his righteousness, and all these things will be given to you as well. Therefore do not worry about tomorrow, for tomorrow will worry about itself. Each day has enough trouble of its own."
But words in all languages are living things, with multiple meanings and implications, and makarios found itself being used in a conventional formula:-
  • "Makarios is the family man with his children" - because they were both his security for old age and the security of his line for future generations.
  • "Makarios is the rich man with his wealth" - because that protects against hard times when they come.
  • "Makarios are the pious on their inward well-being" - because that allows them to face future vicissitudes with equanimity.
  • "Makarios are the religious on their experience of God" - who will presumably ensure their future.
The link to the original meaning is reasonably clear for these, but then the meaning developed a bit further to become something more like 'congratulations' - for a new child, for a profitable business deal, for progress on piety or religion, and so on.

The other link in the chain to the Beatitudes comes with the adaptation of that formula to the Greek Old Testament (the Septuagint) where it is used (especially in the Psalms) about the peace and security which comes from doing things God's way:
  • Makarios is the nation whose God is the Lord; the people whom he has chosen for his own inheritance (Psalm 33:12).
  • Makarios is the man whose hope is in the name of the Lord (Psalm 40:4).
  • Makarios is the man who thinks on the poor and needy: the Lord shall deliver him in an evil day (Psalm 41:1).
  • O Lord of hosts, Makarios is the man that trusts in you (Psalm 84:12).
  • Makarios are they who observe justice, who do righteousness at all times (Psalm 106:3).
  • Makarios are all they that fear the Lord; who walk in his ways. You shall eat the labours of your hands: makarios are you, and it shall be well with you. Your wife shall be as a fruitful vine on the sides of your house: your children as young olive-plants round about your table. (Psalm 128:1-3).
That final one is a bit longer but gives a nice parallel to the earlier Greek example of the family man and his children.

So the meaning of makarios is somewhere in the range from 'free from care and worry', through 'secure for the future' and 'secure in God' to 'congratulations' (on securing your future).

There is at least one English translation which uses 'congratulations' for the Beatitudes; personally I feel uncomfortable congratulating people on their devastating loss or crushing oppression, however secure their future in God might be.

There is clearly no simple single English word which reflects exactly the resonances of makarios in Matthew's original - never mind Jesus' probable underlying Hebrew word ‘eshrĂȘ. So, pre-empting some future posts discussing other parts of the Beatitudes, I am currently inclined to go with 'secure in God', along the lines of:-
  • Secure in God are the spiritually poor, because they are already part of God's kingdom.
  • Secure in God are those who have suffered devastating loss, because they will be comforted. 
  • Secure in God are the crushed and oppressed, especially the landless poor, because they will inherit the land.
and so on.

In the end the Beatitudes are about bringing hope to the apparently hopeless and a future in God to those who feel they have no future.

A final thought: it's the Feast of St Brigit in a couple of days; if you click on the picture above, or on this link, it will take you to a poem called Brigit's Feast, which seems appropriate in a discussion on the Sermon on the Mount.

Thursday, 26 October 2017

What About KRACK?

A man in panic
It seems some marketing wonks at Norton have noticed the publicity around KRACK, a recently discovered vulnerability in the main wi-fi standard, and have decided to spread some FUD (fear, uncertainty and doubt) in the hope of generating a few extra sales for their VPN package.

I've been contacted by customers who have received scary emails from Norton telling them:
"All Wi-Fi connection points and devices could be vulnerable—your local coffee shop, home, or workplace connection.
KRACK can allow attackers access to important information like credit card numbers, passwords, and emails transmitted over Wi-Fi networks. This vulnerability can also allow attackers to potentially infect your devices with malware or ransomware."
Then comes the sales pitch:
"HIGHLY RECOMMENDED - Consider using a secure Virtual Private Network (VPN) such as Norton WiFi Privacy*, to help protect your data against this new threat."
Personally the last people I would trust to protect my wi-fi would be those who deliberately spread misleading information for gain, but that's a matter of personal (dis)taste.

So what is KRACK? Most wi-fi networks these days are encrypted to protect against eavesdropping, with the commonest form of encryption being something known as WPA2 (Wi-fi Protected Access 2). KRACK (Key Reinstallation Attacks) is a newly discovered way of breaking into WPA2-protected wi-fi networks. It targets the devices on the network, rather than the wi-fi as such, so changing your password doesn't help.

So far, so scary ... why am I suggesting Norton's email was more marketing FUD than engineering reality?

The way Microsoft and Apple implemented WPA2 on their PCs and laptops happens to be resistant to this particular attack, and both have released patches to fix remaining issues, so up-to-date Windows, iOS, macOS, tvOS and watchOS devices should be fine.

If you are sending credit card numbers and the like over the internet, I very much hope you are checking that the website you are sending them to uses https - every major vendor that I am aware of does. Https encrypts your details before they ever get near the wi-fi, so anyone breaking into the wi-fi would only get gobbledegook. Similarly with most passwords; and the vast majority of email providers support something similar (https, SSL or TLS) for email messages.

There are genuine concerns about smartphones. About half of smartphones being used were thought to be vulnerable when the problem was discovered (ironically, the newer ones with an Android version greater than 6.0). Apple phones should already be fixed, and Google's own phones should be updated with a fixed version of Android fairly quickly, but other manufacturers can be slow distributing updates. The comments above about https and other end-to-end encryption methods still apply though.

There are also concerns about the 'Internet of Things' - smart kettles, baby monitors used over the internet, and the like. To be honest, these have such a bad reputation for insecurity that I'm not sure KRACK makes much odds - although hopefully it will increase pressure on manufacturers to get a grip and take security seriously.

There are things that you should do as a result of this scare (under most circumstances buying a VPN service is NOT one of them):-
  • Make sure your Windows/macOS/iOs is up-to-date with its scheduled updates;
  • If you have an Android smart phone and its Android version is 6 or greater (or you cannot see what the version is), contact your phone supplier to ask if it is patched against KRACK;
  • If your printer software asks to patch your printer firmware (check the request comes from the printer software itself, not an email or a website pop-up) then let it.
  • If your broadband router came from your broadband supplier (not all do), contact them to see if they have updated the router software against KRACK.
  • If you are filling in personal information on a website, make sure the website address starts with https (sometimes this is indicated by a padlock) - if it doesn't, you can often add the 's' yourself and it will take you to a secure version of the page.
  • It is a good idea to protect all PCs and laptops with a reputable antivirus (Norton Antivirus is one example), for all sorts of important reasons. I suggest you seriously consider also protecting your Android smartphone with its own antivirus.
KRACK is mostly a major problem for high-level technical infrastructure and in corporate environments. For home users it is largely common sense and not letting the marketeers panic you. 

Monday, 13 June 2011

"We Hope That Little Girls Feast On The Bones Of Many Giving Souls"

Is that a great quote, or is it just a great quote?

It comes from hackers collective Lulzsec, after they emailed the UK National Health Service to let them know that various NHS admin passwords were known to them. As they put it, according to The Register:

We're a somewhat known band of pirate-ninjas that go by LulzSec.
Some time ago, we were traversing the Internets for signs of enemy fleets.
While you aren't considered an enemy - your work is of course brilliant - we did stumble upon several of your admin passwords, which are as follows....
We mean you no harm and only want to help you fix your tech issues. Also, we hope that little girls feast on the bones of many giving souls. All the best.
Lulz Security
Lulz are one of the groups busily embarrassing Sony by exposing the poor security of their websites (or, to put it another way, by hacking into Sony websites and taking copies of confidential data).

Now it seems they are revealing a more caring side: encouraging people to become bone marrow donors, presumably inspired by the story of Alice Pyne.