Thursday, January 21, 2021

My rants on the sars-cov-2 pandemic

Disclaimer: The words below are "my" rants. I am not a Doctor, chemist or a  Biologist. I am an Engineer. So, there may be mistakes. Do your homework like I have done mine. I dont vouch for authenticity of the matter in the links provided.

     Plenty has been written about the birth and spread of Covid 19. Plenty more than any other pandemic the earth has ever seen. There are already books on the origins and the spread of the virus. They also speak of the spineless governments of the world. The pandemic has had its share of false news and conspiracy theories ranging from 

1. The virus was already existing 

2. It is the same as the normal cold virus 

3. Pharma companies along with the governments have blown it out of proportion

4. Pharma companies wanted to move the people away from usual way of administering medicines to RNA/DNA medicines 

5. Some other businessmen wanted to reduce the population of the world 

6. Pharma industry was not getting enough grants from the governments of the world to shift medicines to RNA/DNA based and ....... 

https://www.livescience.com/common-cold-coronaviruses-t-cells-covid-19-immunity.html 

    The above link tries to explain why the sars-cov-2 virus does not impact certain people. It also talks about our immune system and how it gets trained by one variant of a similar virus and can produce the necessary actions required to nullify the effects of the virus. So, what about a human who has not contacted any related virus. Well, as per the link, that particular person is at risk. If that is so, Americans normally had a vaccine every year for the influenza virus and yet they are one of the most affected countries in terms of percentage of death and infections. First thing is the influenza and the covid virus are of a different class. The antibodies developed for the influenza virus will not(may not) help in fighting the covid 19 variant. 

https://www.britannica.com/story/what-is-the-difference-between-influenza-and-covid-19u 

There, lets us stop the discussion regarding the similarities between them. What about the class of corona virus, were they already existing? Yes. As per the link below 

https://www.healthline.com/health/coronavirus-types

https://www.nationalgeographic.com/science/2021/01/covid-19-will-likely-be-with-us-forever-heres-how-well-live-with-it/

     There have been two well known and documented class of "corona" virus. When we talk about corona virus, we are talking about a class of virus, with a spiked protein cover around the viral payload. These two instances have been contained by isolation and quarantine. These were not spread by asymptomatic humans. If we already know about the corona virus and we contained the previous two, how did we end up in a global pandemic. 

    This can be attributed to the carelessness of the governments of the world. The governments governed by the corporations decided that the aviation industry cannot be stopped. They decided that, the best way to cover this up is to remain silent. May be in many other cases, it might have worked. However, it did not work out in this case. When all the nationalist/jingoist mindsets have been satisfied, the news was allowed into the open. 

    By now SARS-CoV-2, the virus which causes covid 19 was taken everywhere across the globe. The main attribute for this wide spread is that the asymptomatic people were the major spreaders. This aspect of this variant, is what makes it stand apart in the corona series. The damage by the viral load are very similar and attack the respiratory system, the most, with other aspects being discovered as we move ahead in time. If the virus spread was isolated at origin, like the previous two cases, we could have stopped the spread and this blog post wouldn't have existed. 

    Time is a *^%^h. This would be one more instance of a corona virus isolated in a particular geographic place and affect a few 100 people. It is very difficult to gauge the importance of an individual in this business minded planet. It is like this planet has been outsourced and business has to run at any cost, even if the last human is erased. It is like the next batch of humans are toiling somewhere else in a similar manner and all the business will shift to the next planet after the end of the last human on this planet. 

    The lockdowns, or worldwide isolation and quarantine appeared like an eye wash and half hearted, last resort plan. People were moving and the virus was already taken to all the countries across the globe. This isolation and quarantine works only if applied on a scale taken up on the previous known variants of the corona virus. Lockdowns are "face savers" for the politicians and the businessmen. There is no scientific/economical backing for a global lockdown except a political/business perspective. 

    Now, let us come to the treatment. I dont know why the medical companies gave up on treatment and focused only on a vaccine. I dont know the logic/economical aspect of this decision and we dont have a treatment as of date. But, vaccines have been cleared and have been administered to lakhs based on studies on thousands in a very short time. Majority of the vaccines are like proof of concept and highly advanced science of gene editing and precise chemistry of RNA. Reading about the RNA/DNA vaccines, is like reading a fantasy book. It reads like science fiction. If we can do this much for producing a vaccine, how difficult is to use the same technology to do something bad. Dont get me started by denying this. We are not far away, wherein, DNA/RNA jabs with blueprints of all the known viruses will be injected into the human body. It is like an attack dictionary on Missile warning systems. The approach for these vaccines is to generate antibodies for the spike protein. Now, this approach can fail once there is a change in this, in a drastic way. Yes the virus can mutate in many ways. What if, the spike mutates?

    The medical industry took this route by telling that the traditional way of making a vaccine by killing the virus and then injecting this into the human body is time consuming. This is totally %#^*^t. We already have vaccines made from this method and also cleared for use. The major advantage with this approach is we are giving a hint to our immune system about nearly all the properties of this virus. So, this would generate antibodies for many of the chemical combinations present in the virus. 

    The RNA/DNA methodology of making medicines is a great method for big pharma for getting a tight grip on the medicines. This will nearly kill the generics industry. Two recently cleared DNA/RNA vaccines make a statement that the DNA/RNA in the human cells are not touched. Can a normal human, know whether this is true? If DNA/RNA is the methodology of administering medicines, then, governments need to wakeup and ensure that enough competition is fostered and all the developments are available in public domain. It is not wrong, even if the governments start investing in state owned research facilities and upgrade them to the same capabilities as big pharma. In this way we can ensure that there is a lot of testing and availability of these advances are available to the common man. 

    The most interesting take from this pandemic is the polarization of people across the world. The main reason is that big pharma is not good at explaining the cause and the effect. It is like explaining light to the last animal in evolution which had not felt light around it. Our belief systems, our blind beliefs, our limited education, our limited brain usage, our limitation as a human being, has showcased beautifully. It is very interesting to listen to all the conclusions and the reason for these conclusions regarding the pandemic. No two individuals in the same home share the same idea about the pandemic. Many people are convinced that Europeans and Americans are dying of Covid 19 because their immune system is not as strong as their Asian counterpart. This class is forgetting that it originated in Asia and the highest number of deaths happened in Asia. This would have made Russel peters so angry that he would have to change the portion of his standup comedy where he talks about an instance of him landing at Mumbai Airport for the first time and welcomed with smell of shit. 

    We have politicians feeling for the dead, at the least. No corporation has stopped working or repented for any death of their workers. The politicians feel for the dead but are not ready to consider universal healthcare as an option. What is the use of feeling for the dead, when you did not feel for the living? This is the same in all businesses. The plentiful Human resource at its disposal make the business not at all concerned about the people dead with a known reason. People die every minute for a plenty of reasons, but when they die for a reason which the whole world knows may happen is what makes the death more sick. In fact majority of the work available in the world is broken to such an extent that you just have to plugin a new human to do that job. This is what is making the corporations not to take any serious thought towards the pandemic. 

    The medical profession is also at its most liberal best. Any complication can be labelled a "covid 19" case. Stop, dont draw your daggers, this statement was for medical practitioners who have done it or on planning to do it. How am I making this statement so confidently. Well, nobody is allowed to see or touch the patient. He is packed completely and burnt without any second opinion. So, what I am telling is it is very much possible, has been done and can be done. 

    There is one more issue regarding non believers. They are so pissed off by the care taken by the people who believe that there is a virus. Like the non believers who throw the caution to the wind, there is a population who believe that yes, we have a pandemic at hand. Of course there is another population which is exactly in between. They wear their mask below the chin. Never was their hands. These people will wear the mask when they hear some bad news regarding people whom they knew. It will be momentary, maybe for a few days. These people are not bothered about the complete believers or complete non-believers. The problem is with the non-believers. They will make fun of the middlemen and the complete believers alike. The believers will not make fun of the non-believers but are worried that this group will get them affected. They believers are angry on the other two groups. 

    The reason for the hue and cry created by the spread of sars-cov-2 is that, the human body might not detect it as a virus and fight it with enough fervor similar to a virus database it maintains. As time passed we got to know that a major portion of humanity had this virus in their immune database. However, one more issue which caused such widespread attention and lockdown is the fact that asymptomatic people were spreading it. And the virus once in the air, lived a very long time. All this information led to the situation we are today. 

    The good news is that, contrary to initial belief, the human body did fight the virus and many people did develop immunity. Now, the vaccines are here to help people with lesser immunity by adding the info of this virus into their database. This is the reason, I am of the opinion that recipients of the vaccine should be checked for antibodies and the situation of the immune system for this virus before vaccinating them. If they have already developed sufficient amount of immunity, it is of no use to vaccinate them. And we dont know what would be the result of such an action. But, nowhere this is being tested. In fact, every person to be vaccinated should be checked thoroughly for his medical history and compare it with the side effects of the vaccine. Based on satisfactory study and heuristics, the person should be suggested for vaccination. 

 

    Proteins are made of amino acids. And the "some" amino acids on the spike of sars-cov-2 virus are similar to the ones found on the placenta. In fact "some" of these amino acids can be found in other proteins in the human body. A vaccine based on this protein might induce antibodies against the protein with "some" similar amino acids. There is no proof for this. Hence there is no proof to stat that a similarly designed vaccine will induce antibodies attacking the placenta and in turn render woman infertile. There is no proof for this. 

    The human genome is made of DNA. The mRNA vaccine is not supposed to enter the nucleous of the cell. The DNA based vaccines which put the DNA of the spike protein into the cell are not supposed to interfere with the Human DNA. The chances of the vaccine altering the DNA is nearly nil. We dont know what will be the result of that small chance and we dont have any proof if it might happen at all. 

     Whatever be the truth, The wearing of re-usable masks have man advantages. During your commute you are going to filter out at least some of the dust. It will protect your face from the cold breeze. And of course, you are going to be protected from other viruses floating in the air. The other aspect we are practicing is what is difficult to maintain and that is physical distancing. But it is also has many advantages. This will avoid crowded meetings and only the required personnel will be called. This will require plenty of advance planning and to the point discussions. And please kindly use re-usable masks. The planet is already strained to the max with the plastic piling up. 

Sunday, January 17, 2021

Media player daemon: Playing music with mpd and mpc

My love for the Media player daemon is clear if you have gone through my other blog posts. I like its concept. It is simple, straightforward and does what it is supposed to do. Play music. The combination of mpd and mpc is awesome. It is akin to watching a good buddy movie. They are just so perfect together. If you are a person who would like to "see" the song list and control the music by visual controls, you are also covered. There are a plethora of clients for the mpd. In terms of simplicity an curtness, there is nothing closer to mpc. 

 This post is about the barest minimum required to start playing music without the screen filling up with the file names. Installing mpd on arch is as simple as a, b, c.... really. 

pacman -S mpc mpd 

copy /etc/mpd.conf to .config/mpd/mpd.conf Overwrite the file with the information below 

--------------------------------

# Recommended location for database 

db_file "~/.config/mpd/database" 

# Logs to systemd journal 

log_file "syslog" 

# The music directory is by default the XDG directory, uncomment to amend and choose a different directory 

# I like to symlink all my sources of music to the default Music folder. Ultimately, tell the directory where # your media is stored. 

music_directory "~/Music/music" 

# Uncomment to refresh the database whenever files in the music_directory are changed 

#auto_update "yes" 

#These are my choices for the requisite files. Al these files are required. So, if you would like to change the locations, do so. But ensure that these directories are user accessible with write permissions. 

playlist_directory "~/.config/mpd/playlists" 

pid_file "~/.config/mpd/pid" 

state_file "~/.config/mpd/state" 

sticker_file "~/.config/mpd/sticker.sql" 

#This is if you are using pulse audio. If you are using also, change accordingly audio_output { 

type "pulse" 

name "pulse audio" 

----------------------------

Save the file. reboot 

Now, the first step ensure that mpd is running.

mpd 

On success, the above command will not spit out anything. Now, the daemon is running and waiting to server you music. Let us now, build a database of songs available in our directory we specified in mpd.conf. 

Now we have to populate our database. Before doing this step, I suggest you to check whether your music has good metadata related to track names, albums, etc. If not, it is always good to invest some time in editing the id3 tags of your music. This will help us in getting "that" song to play. 

Once you are sure of your metadata. Go ahead and build the database. 

mpc update 

The above command will take some time. Give it a few minutes. To know whether all the songs have been added to the database run the command below. If you see that the last song is the same when you run the command below, multiple times, then you know that the database is completely built. 

mpc listall 

Of course, your database is going to be huge. And depending on your mood, you would like to pick and choose. Let us now create a playlist based on certain criteria. You are now in that retro dance mood and would like to listen to the evergreen Jackson. There are multiple ways to search for Jackson songs in your database based on how your id3 tags are created. If you would like to add all albums with the name Jackson in your album name then you would do 

mpc searchadd album jackson 

I know, Now you want to see what is the playlist which is create by the above command, For this you would 

mpc playlist 

Now, you remembered that there are certain files with Jackson in their names but are not part of an album with jackson in them. Then to add all the songs with title containing jackson 

mpc searchadd title jackson 

Now, check your playlist again 

mpc playlist 

The nerd in you is glowing. You now have all the titles you want to play in your playlist. Hit it. 

mpc play 

Of course, you have got used to seeking music with other command line players by hitting the arrow keys. However, the command for seeking in mpc is(Again, you can map keys and what not.....) 

mpc seek +00:04:00 

The above command is for seeking the song by 04 minutes. I think the logic is clear. This works both for individual files or if you have a file with multiple songs. If you have individual songs in files then 

mpc seek +80% 

would be better. 

 In the middle of your listening pleasure, you would like to know the details of the song being played now

 mpc status  

will give you information regarding the present song and plenty other data related to the present playlist.

For seeking back change the + sign to -. An alias for all the above would be best. 

The post is not complete without gratitude to all the devs and users who make all this possible. The GNU/Linux land and the BSD universe have not stopped surprising me.

 

 PS: Just, one more thing.

 mpc searchplay title jackson

 which will create the playlist and start playing.

Sunday, January 3, 2021

GPG: Encryption and digital signature for the masses Part II

Disclaimer: This is a very serious topic. The observations made here are for a starter. Kindly refer to the man pages and other text books which specialize in guiding for advanced and high stake uses. I am not responsible for any unwanted results by following the notes below. Understand the seriousness of the job on hand and read enough.

 So what is stopping you from creating a key with 

name: Joe biden
email: president@america.gov

Nothing. But you are not going to go a long way with this. The thing is, gpg is not your answer to everything. It is just a tool to sign documents and encrypt the documents. The authenticity of the person sending you the document is still to be checked by going out in the open or from other trusted sources on the public network.

Trust and untrust a key

We have already learnt how to trust your friends public key and record that trust in your keyring. Let us now assume that you want to share the public key of your friend with another of your friends. Now, you extract public key of your friend from your public keyring and save it in an armored format file. Now, if you open the file created for viewing, you can observe that the file also contains your public key also!! How did it land there. It landed there when you "trusted" your friends key. You can forward this file to your another friend who wants the public key of your first friend. The presence of your public key in the file is like you are confirming that the person whose key it belongs is someone you know. This is all good. This is how a "web of trust" is built up. However, this is a two edged sword. When you share the file in question to your second friend. You are also hinting to your second friend that you are "communicating" with that person. This is something that privacy purists will oppose. So, choose wisely. If possible remove your public key from the file your created to share with your second friend.

Let us assume we signed a public key signed@dd.com

Now, we have arrived at some information doubting the key above. So, we have to remove the "trust" we endowed on the above key. Let us remove our signature on the above key

gpg --edit-key signed@dd.com

on the gpg prompt

revsig

go though the queries and revoke the signature.

end the prompt by typing

save

at the prompt

Now, your signature is not on the public key signed@dd.com
If the original public key signed by you is on any key servers, now is the time to push the updated key without your signature on it.

PGP/GPG/OpenPGP


When we talk about asymmetric encryption we come across three abbreviations PGP, OpenPGP and GnuPG(GPG)

PGP is a commercial offering. OpenPGP is an open standard which anybody can implement in code. One such OpenPGP implementation in actual code is GnuPG(GPG). GPG is "free as in freedom" software and is the one to be used by the general public. GPG is licensed under copyleft GNU GPL. So any commercial usage in a tinned product should ensure that the GPL is complied with. For the general public, it is as easy as using GNU/Linux operating systems.

Safeguarding your keys


The key pairs have different exposure levels. The public key has to be made as much "public" as possible and the private key should be kept as private as possible. The "privateness" for your revocation certificate is the same as the private key. Ensure the safe upkeep of these two keys. Guard it upto your life and just below it.

Print your private key and your revocation certificate on good quality paper, store it on storage device, store it on a cdrom and lock it up in a bank safe locker. That is the amount of care you should take care of these two aspects of GPG. If you want to take it with you, ensure that they are encrypted on your storage device and better if the entire device is having file system which is completely encrypted. So, you get two levels of encryption.

Information in your keys


The next thing is the creation of your key pairs. Should you use your "real" name as in "your" name? Should you use your "real" email id? Should the keys expire? If so, what is the optimum expiry age? Should we enter any comment?
These questions have subjective answers. As per the answers for the questions on the public network, the most answers ask users to provide their "real" information. 

This helps in getting you into the "web of trust" which is like the phone book of GPG users. I would suggest, again, a suggestion only, that you should use your real information to bring credibility to your public key. So, yes use your "real" name, "real" email id and also a comment which would make you stand out if your name is more generic. As for the expiry of keys, it is recommended by many experts that you should be expiring your keys at "regular" intervals. Doing so have many advantages. Easy revocation since after the expiry it is of no use to anybody. Keeps your public key ahead of technical obsolescence. 

Dont forget that you can add an image to the created key. This can be your real photograph or any image left for you imagination. Just be careful about whatever decision you take.

More on keys

The last 08 digits of the fingerprint is also called the keyid.
The email id and the name information will be the userid or the UID.

When you want to specify a specific key on the gpg command line, you can use the UID or the keyid.

If you use

gpg --list-keys friend@friendship.com    or
gpg --list-keys A2E43218 ( If using the keyid of the key )

it does not print the fingerprint.

To print the fingerprint of a key

gpg --fingerprint friend@friendship.com


A public key could have been signed previously by other gpg users. On import of a new public key, you can check out all the signatures on the public key by

gpg --list-sigs friend@friendship.com

Keyservers

If you are using keyservers then

1. If you signed a friend's public key after downloading from the keyserver, then you can update the friend's public key with a copy of which you signed.

gpg --send-keys friend.friendship.com --keyserver subkeys.pgp.net(Enter the address of your key server here)

2. To receive a key from the keyserver

gpg --recv-keys friend.friendship.com(Here as usual, you can use the keyid)

3. Keep your keyring updated with any updates to the keys which you have downloaded from the keyserver. There would be changes to the public keys you downloaded a long ago from the keyserver, in terms of UIDs, email ids, the number of signatures on a particular public key

gpg --refresh-keys --keyserver subkeys.pgp.net

Privacy & Anonymity

Though, gpg keeps the information you want to share as private, it does not make you anonymous. But it can "help" you if you are serious on anonymity and you belong to the press. When you send encrypted information through regular public network channels like email, it is still possible to know who has sent the encrypted information, without knowing what is in the encrypted information. 

The public key is advertised publicly. It is trivial to find out the owner of a public key. If you dont want to share the public key with others, then how do you send personalized and encrypted information? One possible way is to encrypt your public key with the public key of the specific recipient. Send that encrypted key to the recipient, who in turn can get your public key by decrypting with his private key. The Tor network can be used for sending gpg encrypted information including the gpg encrypted public key.


Wednesday, December 30, 2020

GPG: Encryption and digital signature for the masses

Disclaimer: This is a very serious topic. The observations made here are for a starter. Kindly refer to the man pages and other text books which specialize in guiding for advanced and high stake uses. I am not responsible for any unwanted results by following the notes below. Understand the seriousness of the job on hand and read enough. 

     The notes below are culled from the public network from various sources. Thanks to the free software foundation for the fantastic gpg tool and all the original authors of the pgp standard. GPG is really "encryption" for the masses. Kindly refer to directions from master users for creation and usage of GPG. The recommended way of creating a key pair is on a computer with

1. The operating system to be installed with images downloaded and checked for the integrity of the OS image on another computer connected to the internet.
2. Install the downloaded operating system on new vanilla hardware and the computer should not be connected to the internet even while installing the OS.
3. After installing the OS generate the keypair ensuring that the computer is in now way connected to the public network.

Even if you dont want to create the keys in the way mentioned above. It is required to know the above information.

--------------------------------

    Private key cryptography and symmetric cryptography are the same phrases. They are just a complicated way of telling that the cipher and key used for encrypting a message is the same that has to be used to decrypt the message. That is, the cipher and the key is first shipped to the recipient. Then the actual encrypted message is sent.

Public key cryptography/asymmetric cryptography:

    A mathematical process generates a pair of keys. A message encrypted by one key of this pair, can be decrypted by the other key of this pair. One key is called the public key(can be shared with the whole world) and the other is called the private key or the secret key(Not to be shared with "anybody").

How asymmetric cryptography works:

 
    Let us assume the data of individuals in the whole world is maintained in a database with their respective public key. So we pickup the name and the corresponding public key on this database(provided we know this is the person whom we want to communicate). Now

1. we create a message which is to be sent to "only" this individual.
2. we encrypt this message with the public key available in the database.
3. send the message to the individual through the public network, by means like email ....
4. The recipient will then decrypt this message with his private key
5. No individual in the world will be able to decrypt this since the message can be decrypted with its pair which was generated by the mathematical process which produced the public/private key pair

-------------------------------

Creating and managing gpg keypairs

Let us now get down to "actually" creating the key pairs. We will be using GPG(GNU Privacy Guard). Kindly refer to the man pages for further information and the public network for deeper insights. GPG is a common on all the *nix operating systems and is available for the proprietary operating systems also.


The first step is to generate a key pair. Run the following command

gpg --full-generate-key

On running the above command in a terminal you will be asked the following queries. Answer accordingly.

a. Choose the type of key: We will choose the default RSA
b. choose the bits for your key: Let us choose the longest option(We are in modern times)
c. Expiry date: I would go for an yearly update
d. Real name: Here you have an option of putting your real name(You can ofcourse not tell your real name. But, to use it in place like github etc, it is better to have your real name)
e. Email address: The same logic as above is applicable here also
f. There is a comment field: You may fill it up or recommended by many people to leave it empty

After the above step gpg asks to enter your passphrase. 

This is a very "important" step. The passphrase is intentionally called a "phrase" it is not called a password. This has to be as long as possible. It is better if it has a mixture of alphanumeric characters interspersed with special characters like @%(%$) etc. It has to be sufficiently long. This is what protects your private key. Please use a long phrase, which you can remember very easily and quickly. In fact you should be flamboyant when your are typing out your phrase. At the same time that phrase should be alien to anybody else on the planet.

Once you enter the passphrase, gpg starts the mathematical part required to generate the key pairs. Help out with sufficient entropy(randomness) by opening lot of firefox tabs, plenty of word processors and go ahead and do whatever work you want to do with your computer. This improves the entropy required to ensure the randomness of the digits generated for your key.

Once you generate the keys, the keys are stored in what is called a "keyring" Just know that the keys are safe in a box and locked by your passphrase

To print out the public key which was generated

gpg --list-key

To get the public key in a format which is accepted worldwide

gpg --export --armor dfdf@fdfd.com > dfdf_pubkey.asc

To display your public key
 

cat dfdf_pubkey.asc

Once this is generated, you can share it with the world. If your friend wants to add your public key to his keyring, then he would

gpg --import dfdf_pubkey.asc

There, now he has your public key in his keyring.


To list the private keys

gpg --list-secret-keys   

Now it is required to generate a revocation certificate. Why are we in such a hurry in creating one. Well, we should have the revocation certificate handy, if the keys have been compromised and you think that the keys can be used by others to gain access or sign documents with your keys and send it to inappropriate places. With revocation certificate you can revoke the key pairs and also tell the whole world about it so that the whole world knows that there is no relationship with your previous sets of keys. The latest version of gpg creates a revocation certificate during the key pair creation process itself, fantastic.

gpg --gen-revoke fdfd@dfdf.com > fdfd_revoke.asc

Now you will be asked for the reason. Choose the appropriate reason.

The file you created is called the ASCII armor file.

So, we have created the revocation certificate. This certificate will be used to revoke our key pairs.

gpg --import revoke.asc

Now if you run

gpg --list-key

You will get your public key information with "revoked" added

Now you can really delete your key pairs

gpg --delete-secret-keys fdfd@dfdf.com


gpg --delete-keys fdfd@dfdf.com

Now if your list your keys

gpg --list-key

The output will be empty

Let us now remove the revocation certificate also

rm fdfd_revoke.asc

-------------------------------
 

Encryption


Let us now encrypt and share some secret documents with friends on the public network

To start with you should have

1. Got the public key of your friend.
2. Import the public key into your keyring.
3. Did your homework to ensure that the public key does indeed belong to your friend.

We have done the homework and are sure thatthe public key shared by your friend is genuine. Let us now go ahead and trust the public key by signing your friends public key with your private key

gpg --sign-key friend@friendship.com

Now, to encrypt the document and ensure that the only recipient who can decrypt the document is your friend,

gpg --encrypt -r friend@friendship.com secret_document.txt

The command will output secret_document.txt.gpg which is a binary file

If you prefer the ascii armor format

gpg --encrypt --armor -r friend@friendship.com secret_document.txt

which would output secret_document.txt.asc again a binary file.

You can now send this document through any channel available on the public network and are assured that your friend with whose public key the file was encrypted can only decrypt it with his private key. From now on, if you, the author have deleted the original secret_document.txt also cannot decrypt the resultant file secret_document.txt.gpg.

To avoid this you can add yourself also as a recipient

gpg --encrypt -r friend@friendship.com -r fdfd@dfdf.com

Now, you the author with email id fdfd@dfdf.com can also decrypt the file as and when required and can safely now delete the original file

-------------------------------


Digital signature


We have all the way been talking about encrypting a document. We want to ensure that the document reaches and is ready only by the individual(s) to which it was intended. This is fine. Let us forget encryption for a moment and think of a public document. Anyone reading a public document should be ensured that this particular document is an un-altered copy authored by a particular person. The document should be able to speak about the author. That is, the document should be signed by the original author. This ensures the reader that the document is an un-altered document and is as was imagined by the author. We are talking a synonymous situation of physically signing a document. We are talking about an electronically signed document.

gpg allows us to do this. When we are signing a file we are not encrypting the file, we are just creating a binary file with contents of the signed file as well as information about our signature. The signing and verifying methodology described below makes use of the fact that the signed file has the contents of the signed file as well as the signature in one single file.

 When gpg signs a document there are two things which are ensured

1. Integrity: When the recipient checks for the signature authenticity and it matches, it also means that the signed document received is not altered in any manner

2. Authentication: Again, when the recipient checks for the signature authenticity and it matches, it also means that the document is indeed from the person who really sent the message by signing with his private key

gpg --sign document.txt

This will create document.txt.gpg, a binary file which includes the content of document.txt and the signature.

Before creating the .gpg file, you will be asked to enter the passphrase, Now, you have affixed your signature on the document. This process makes use of your private key. So, as per the pgp convention, if you encrypt with one part of the key pair, the other key pair is used to decrypt the document. Now, since you have added your signature to the document with your private key, the confirmation of ownership can be done with your public key. Since your public key is supposed to be public, anybody, with access to your public key will be able to ensure that document is created by you. However, the world can view the document by using gpg --decrypt as discussed below and view it but not ensure that the document was really signed by you and you are the creator of the document 

Now, on receipt of the file, the recipient to start with, will first check for the authenticity of the signature. This is done by

gpg --verify document.txt.gpg

The output will show the signature and will term the signature as good, if you have the public key of the sender in your keyring. So we now have attested that the file infact, is created by the creator we were expecting.

Now to proceed to view the contents of the document, let us decrypt it, ie, let us bring it back to viewable state.

gpg --decrypt document.txt.gpg >> document.txt

The above step will still re-create the original file though the authors public key is not present in the keyring. gpg will just tell that the signature cannot be verified.

I think you are used to seeing signed documents with an armor ascii format. To achieve this

gpg --sign --armor document.txt

This will generate document.txt.asc, a binary file which includes the signature in armor ascii format with the contents of the file

To verify the file and as well as decrypt

gpg --verify document.txt.asc >> document.txt

Once you trust the public key and are sure that the public key indeed belongs to the individual you know, that trust can be extended into your keyring by signing the author's public key with your private key. This can be checked in various ways. If we know the author and his online activities, we could go to the place he is most active and check for his email credentials with his pgp fingerprint on that website. Or we could go to the many pgp key servers over the public network and search for the fingerprint or the email id in the fingerprint. It should match with the copy of the public key we have. Once you are content that this is the person associated with the key, then and only then change his public key in your keyring to trusted. This will remove some warnings when you check the signature of the files from the author which talks about "...Not certified with a trusted signature...". To do that

gpg --sign-key author@creator.com

After this when you verify the signed files received from the author by

gpg --verify document.txt.gpg


you will not find any warnings

Down the line, by some means you start doubting the public key and the associated individual it is time to revoke the "trusted key" status in your keyring. Now the thing is once you create add a key in the keyring, any further edits are possible only from within the gpg command. Here we are interested in removing the trust from the public key. So you would start the gpg editor like

gpg --edit-key author@creator.com


Now you will get the gpg> prompt
Enter "help" to get all the options. Here we are interested in revoking the trust we put in the above public key
type revsig at the gpg prompt
You will be prompted for the reason, answer accordingly. Exit and save when prompted. Now, you have successfully removed/revoked the "trusted" badge from author@creator.com
 

----------------------------------

Digital signature for special case involving pure text files

 
If you are dealing only with text files. It will better if the text and the sign appear in the same file as a regular document. It is like you have a text document and you affix your signature to the end of the document. gpg provides this facility through

gpg --clearsign document.txt

will create a document.txt.asc

Now the recipient can open the file with

cat document.txt.asc

which will have the content of the document as well as the signature at the end of the document. Now, to verify the signature, the recipient would

gpg --verify document.txt.asc


Now, to get back the original document only, without the signature then the recipient would

gpg --decrypt document.txt.asc > document.txt

--------------------------------

Digital signatures for huge binary files

 
All this time we have been using gpg such that the contents of the signed file and the signature are available in the output file of the gpg command. This might not be conducive as the file sizes grow. It is better off to have the signature separate from the signed file. With this, the file and the signature are two different files. Just remember that to check the signature with the associated file both have to be in the same directory and the file names cannot be changed.

To create a signature separate from the signed document

gpg --detach-sign --armor document.txt


This will output a file document.txt.asc. (You still have your original document.txt unchanged). This file contains only the signature but is associated with the original file document.txt. This is the methodology used to share binary files and packages on the public network. You will have the package/software you would like to download and adjacent to that you will have

1. The signature (normally it will be labelled the pgp file)
2. The public key of the author

You download the above two along with the software package

1. Put all the three files in a single directory
2. Import the public key of the author
3. Sign the public key of the author with your private key after doing your homework about the authenticity of the public key
4. check the signature
5. On no warnings proceed with the installation of the package

Wednesday, December 23, 2020

Arch GNU/Linux and OpenBSD on mac mini 2018, 2019, 2020(Intel processors)

     The laptop is not an ideal computer when you are sitting at the same desk and especially when you are at home. At home, the best computer would be a desktop. For the past 5 - 10 years I have been using laptop at home, but desktops at work. I observed that I have been killing the battery. I have my laptop always connected to the power supply and that is not good. Draining your battery just because you should drain it, though you are near to a power supply is not something which I can digest. For nearly an year used the raspberry pi 4 as a desktop and tried the frugal method of using a computer. I have been mighty happy with the direction the raspberry pi is headed. I loved what the rpi foundation is doing. It is the apple philosophy of making the hardware and software together but with freedom software ethics in place. Yes, there are still blobs being used, but the foundation is putting enough efforts to tend towards an open ecosystem of software and hardware. 

     Now, the thing with the rpi ecosystem is that you have to be abreast of the developments. If you use the bleeding edge software, you should be ready for the occasional glitches. Now, this is a problem, if you want to just start the computer and do an immediate task. Yes, if you run the debian stable, ie, the official rpi os, you are better off. But, the software is outdated for somebody who has been spoilt for using arch Gnu/Linux or Debian testing. Yes there are plenty other options for Operating systems. But, they all have something lacking. I have tried one and all. I have tried the ubuntu dev version, which I used for a long time. But, it was borked many a times during a upgrade. So, it is back to reading the forums and clearing up stuff. Plenty of experiments were carried out. I live a couple of months on the command line "only". It was very interesting and I liked the challenges that were presented. After an year, something happened and the pi 4 started acting strange. It was time to move on. The first rpi 4 had a damaged sd card slot before the usb booting came out. So, as for now, the rpi efforts are shelved.

    As is the norm for a lull after the storm, I decided to take it a little easy this time and decided to have a cheap desktop solution for my daily use at home and keep the laptop for mobile purposes. Started searching the used computer market for a sleek desktop. Plenty of Intel nuc's came along. Every single model has a lacuna on some issues. Marketing and the modelling of these systems is a total failure by Intel. The number of variants is mind boggling and utterly confusing. Searched for mini pcs from other brands like HP and Dell. Nothing interesting came up. This is the time, Apple came out with its M1 processor. I was surprised that Apple released a Mac Mini with its inhouse processor. Started knowing about the Mac mini and at the same time started looking up the used pc market. There was no way, I would be buying any device from Apple on which I cannot install GNU/Linux. I have a mac book pro 2015 which runs Arch Gnu/Linux and OpenBSD like a dream. In summary, I like apple hardware and hate their software and the lockups they try to force people to stay on macos. Until, I can install Gnu/Linux or BSDs, I dont have any gripe with apple. I love the way they make their hardware. If customization is allowed, the choices are easily laid out and of course can be very very very costly.

    Since Gnu/Linux on a mac mini M1 is still a very looooong shot, I started looking at the older versions. I liked the form factor of the mac mini. There was one more surprise, the extensibility of the mac minis. This was a complete shocker. Four thunderbolt 3 ports, two usb 3 ports, Gigabit ethernet ports, 3.5mm jack. It is like the voltage of the shocks went on increasing. Settled to buy a mac mini 2018. Waited and searched for a month and I got my hand on a "very" affordable mac mini. The build quality is excellent. The option of upgrading ram upto 64GB of DDR4 was un-believable. Postponed the upgrade for a later date. Already had a 32" LG 4k monitor, a mechanical keyboard and a M501 logitech mouse. Had an external ssd which I was using to boot up the raspberry pi. Everything just fell in place. The onboard storage is only 128GB. But I am OK with it.

    Searched the public network for installing Gnu/Linux on a mac mini. The literature is very limited. But, could put together a collection of information necessary. Infact, the installation of Gnu/Linux or a BSD on a mac mini is much simpler than that of installing windows through Bootcamp, which was a breeze when I bought the macbook pro 2015. Installation of Gnu/Linux or BSD is mighty straight forward and can be summed up as

1. Disable the secure boot and file system protection(csrutil disable) on the mac mini


2. Partition the external ssd hard drive(Dont forget to create a FAT32 partition with type set to EFI as the first partition on the external SSD, a 512MB partition will do) for Gnu/Linux and OpenBSD(I prefer OpenBSD to Freebsd just for the fact that the graphics stack is "owned" by the core devs of the project and all other security related "firsts". Again a "sensible" default) 


3. If you want to install OpenBSD do not forget to create a partition of type OpenBSD before starting the installation on any other GNU/Linux box. This will provide you and option during installation to chose that particular partition. This just makes the job easy for installing OpenBSD in multiple boot machines.


4. Download and install the refind boot manager from macos(You can install this in the macos recovery which you have entered to disable the file system protection). I just love this application. My gratitude to all the devs and users of this excellent tool.


5. Install Arch Gnu/Linux. I chose to install arco Gnu/Linux for a change and I loved the installer. Be wary of choosing other software options provided during the setup process. It struggled to download and install these. It is better to install these extra options doled out to you after the base arco install. The installation was flawless. Again dont forget to choose the EFI partition created in step two and set the boot flag. This option will be thrown to you when you select the EFI partition to be mounted as /boot/efi


6. Install OpenBSD. I love the installer. I have expressed my awe at the defaults the installer puts up. Installation process was flawless. It trumped the arco install process. Kudos to the OpenBSD team. Here again, OpenBSD expects an EFI partition on the first partition of the external SSD, which we have already met.
7. Wifi and sound through the 3.5mm jack does not work. This is the same for Arco Gnu/Linux and OpenBSD.


8. Resolved Wifi by using an USB adapter and resolved the sound issued by taking the output from my monitor.


9. At some occasions, refind is unable to boot up macos. The work around as of now is to shutdown the mini and restart. At the chime press the alt key. This will bring up the apple boot loader. If you are lucky you will see the options for choosing the apple drive and the EFI partition on the external ssd. If you are unlucky, you will definitely get to boot the macos partition. To boot the FLOSS operating systems, just reboot and you will be presented with the refind menu.


10. Dont forget to enable the file system protection again by entering the recovery menu(csrutil enable).


11. Arch Gnu/Linux and OpenBSD run flawlessly and the availability of 4 thunderbolt 3 ports is freaking amazing.


12. The form factor is just perfect for putting it in a compartment in my table without clogging the surface of the table for space. Resulting in one of the neatest desks I have maintained.


PS: All of a sudden, my arch gnu/linux installation was not detecting the Ethernet connection. Ran 

lspci

After searching the public network for the Ethernet hardware detected, tried

# modprobe tg3

reboot, and Ethernet started working.

Saturday, November 7, 2020

15K Kms on my Royal Enfield classic Chrome 500

     It has been a long time since I wrote about my motorcycle drive, The Royal Enfield Classic 500. The last thing I wrote was about the feeling after riding 500Kms. The thing is it took very little time to reach that mile stone. However, the present mile stone of 15K Kms has taken a very, very long time considering the amount of distances and places bikers cover in their journey. But, the drive still feels fresh and every day the drive is new. The adrenaline rush is still the same. The grunt on the bike is still the same. 

     The lockdown gave me the opportunity to drive the bike like I would have dreamt of driving in the Himalayas. Working for a company which cannot afford a lockdown, gave me the opportunity of taking the beast to the sea, and boy, did I take him to the sea, I took him to the ocean. It was like I wasted 20 odd years by waiting on the bike. Waiting on the reason that the bike is so bulky, so heavy. What a journey it has been. I never felt so comfortable on any bike I have driven to date. Even on bikes which are supposed to be comfortable, I have been the opposite. There is a joy when I drive the bike which cannot be expressed, explained. 

     In my (very) younger days, I always thought that going "fast" is what is biking about. Oh, boy, was I wrong. Cruising at a constant speed is what is biking about. It is more about the journey than the destination. Yes, I can hear you, the bottom line is all it matters. But, whenever anybody wants to reason out the causes for the bottom line, then you always try to remember the journey, However, alas, you dont remember much, because all your efforts were on the destination. 

     Newton's laws of motions have been now constrained to the things visible to the naked eye and comprehensible to the naked eye. And when that man told that "Eveybody moves(likes to move) in a straight line and in uniform motion", he knew what he was talking about. There is a certain joy in cruising, There is a certain joy in constant velocity. There is a certain joy in not creating an opposing force, there is a joy in blending. The joy of driving.... 

     The bike is as good as it was bought. It has the same sheen in its chrome finish. In fact the company has now brought the same chrome finish for its 350cc lines of bikes, which was exclusive to the 500cc for all these years. A fresh wash and the bike starts gleaming. It is like it is grinning with its mouth wide open, ear to ear. It is like an invitation to start a new journey. It is like there is no end. It is like you can make the same journey, provided you decide that what matters is the journey and not the destination. It is like.....

Friday, October 30, 2020

Going "console only "on GNU/Linux

Got frustrated with the time taken for the browser to load up and then dependency trap for installing other gui applications. Add to that the nuisance of gtk and qt quirks on a 4K monitor. The feeling is share by many. But as we shall see living in this place is not easy. The major difficult piece of the puzzle is the browser. All your banking, shopping options are ruled out in the terminal. 

 

What I did here was to disable even the start of the X server. I disabled sytemd unit which is supposed to reach the graphical login target. Disabled the graphical login manager, lightdm in my case. Disabled all the cloud stuff which ubuntu GNU/Linux starts with lot of difficulty. In fact, because of this the first boot of ubuntu after install is a hit or a miss. After boot do not try to login immediately. There are plenty of things ubuntu is doing in that phase. If you try to login, it will fail. Wait for 10 minutes, approx, it might be higher so that it spews many lines of information over the login prompt, then it will allow you to login and change the default password. 

 

Disabled ssh service, because the rpi 4 is connected to a 4K monitor. Even during login, ubuntu tries to plenty of things. It will try to check for updates and provide a notification once in the motd. It will also provide information from the ubuntu motd server which canonical wants you to see. It will also spew out certain information from your computer like memory usage, load on the cpu etc. All this will take plenty of time considering the rpi 4. Find the respective scripts and disable them to speed up the time required to reach the login prompt. So, we have reached the login prompt. The fonts are so tiny, you have to squint to type any commands. First thing is to first reconfigure the fonts. Get the biggest font available while running the re configuring tool. Yes, the size can be changed, but the fonts are horrible. They are not for your daily tasks. All the fonts which you had installed in your X is now out of reach. 

 

The console well, is a console. It will display fonts which are baked into the linux kernel. If anybody knows how to change the fonts on the default console, kindly advice or drop a link. But, as of now, we have a readable console and the font size is alright. The fonts are not. We have been pampered for the variety of fonts on X. It is a requirement that we should do something about it. Step in, fbterm. As the name suggests it is a terminal emulator designed to work with a framebuffer. The biggest advantage, supports all the fonts supported on X. There goes my first gripe about the console. So, we install fbterm and start and run it at the console. The console is taken over by fbterm and again we have micro-sized fonts, but nice looking fonts taken from the X environment you had installed earlier. Let us go ahead and fix the fonts by restarting fbterm with fbterm -s 24. This was for my monitor. Try experimenting with different sizes to get the optimum size. 

 

The config file for fbterm is in .fbtermrc. Well, I already see your smiling face and I have received your gratitude and in turn it is time to congratulate you for completing the first time required for living in the console. Whatever further tools we are planning to used depends on this success. The fonts are beautiful and they are your favorite ones. They look good and it is as though you are back on your terminal emulator on X, but without all its bells and whistles(another name for bloat). You now can clearly distinguish between l and 1, 0 and O, I and L. I would like to thank all the creators of fonts which can clearly distinguish the characters of the English language. It is an artists job and the creator of any font is an artist. 

 

You opened the fbterm man page and want to edit the configuration file by reading the manual, you are out of luck. You are on the console. There are no windowing systems. What d you do, you press C-A-F2 and switch to the next virtual console and login again. Then you can switch between the virtual consoles. Your are now flabbergasted. You have started hating yourself for moving away from X. But, fritter not, there are further goodies which come with fbterm. You can create multiple windows and switch to them using shortcuts as mentioned in the fbterm man page. This will give you a method of moving between multiple windows and then moving between them. 

 

 Let us go to the next step. Now, you would like to group certain windows and recognize them for a specific task group. You have a web page related, you have a manual page related and couple of windows concerned to the programming task related to the web page and the man page. You are out of luck. You cant see all the windows at once together on one single screen. Frustration. Enter terminal multiplexer. The first name which comes to he mind is tmux, if you are a year 2000 person and screen, if you are before that. These are excellent tools and are blind faith groups unto themselves. So, if you like a tool, silently use them. Do not compare them and publish your comparisons. This is because, if you have reached a position where you compare both these tools, that means you already "prefer" one among them. This will start a war. We already have the longest running war between Vi and GNU Emacs. These are the kitchen sinks of terminal multiplexers. 

 

If you are a person believing in the *nix philosophy of "One tool that does one thing and does it best", then you have an alternate option. Many a times I had tried to pull myself together and learn tmux, but since I was using the i3 wm, I thought that it is not worth the effort. I could open as many windows and all would be started side by side preparing a huge canvas for exchanging information. I am in love with i3 wm for its simplicity and doing what it is supposed to do and doesnt do anything more. A huge shoutout to all the devs and users of this fantastic wm. Now, once again my terminal multiplexer flames were re-kindled by Mr. Bronie Robertson on his youtube channel. I like his videos. They are short and to the point with excellent examples and use case scenarios. 

 

Plentiful thanks to him for introducing me to abduco. Such a strange name. If there are explanations for the name kindly enlighten me. A session management tool with such a strange and difficult to pronounce name. However, what caught my attention was the ease with which Bronie did the session management. No obscure keystrokes to remember. Just session management and nothing else. In fact, I understood session management in that under 10 minutes video, than I had tried for a good 10 years. So, Thank you Bronie. Yes, there might be plenty other things required for complex setups, but for a desktop use and a home network user, that is exactly what the doctor would prescribe. 

 

 So, three main things which a session manager has to do. Create a session. Detach a session. Re-connect to a session. abduco does all the three with elan. All technicalities, I would redirect you to Mr. Bronie. So to create a session, let us understand what is a session. A session is a group of tasks related to one another. It is a method of grouping applications and open files related to a task on hand. Let us say the session you have created contains a compile task which will take another hour. Now, you are free to let us say, listen to some music, read a novel, well, things like that. What we now do is, detach the task on hand. And now, the compiling and all other windows are moved to the background and keep running. We will now create another session and do the relaxing stuff related to music and reading. You now want to continue listening to music and then you would like to check your online accounts like your email, your toots etc. You detach the multimedia session and start a new session with these applications. Its been an hour and you would like check on your compile session, You detach the online session and re-connect to compiling session and so on. That is session management for dummies. 

 

But in a session, if you have to have multiple windows grouped together, it is all good in an X environment. If you remember we are at a console running fbterm. We were very happy with good fonts but a bit sad about moving between windows as every window occupied the complete screen making it very difficult to share information between windows. Enter dvtm. The expansion will be dynamic virtual terminal manager. The name tells everything. It is there to manage windows. It will create, position, delete windows. It is an equivalent to i3 wm and more close to dwm wm but for terminals. When we create a new window in dvtm, we are starting a new terminal waiting for our input. dvtm does exactly what i3 does. It just arranges windows side by side in many different ways. But all your window contents are there for you to see and transfer between windows in the same screen. For our case it is a window manager for the console. 

 

I hated the console because if you wanted to refer to a man page and return back to the editor, you had to suspend the editor read up and remember the man page and then suspend the man page and bring back the editor to the foreground and dump whatever you remembered from the man page. This is no way ideal. For the optimal setup, we combine a session manager with a terminal manager and you have Window management for the console. How do we do it? Well just run both the commands in unison as so.

 

abduco -c session_name dvtm -m ^x 

 

What we are doing is asking our session manager abduco to create(-c) a new session and name that session "session-name" and the application it has to run is dvtm. The next option is for the MOD key. The default key for the MOD key is ^g. Yes, you are a bit confused here. For i3 users, the MOD key used to be a single key like the super key or the ALT key. But, these keys are not recognized by the console. So keep the default or change it to the value which I use, since x is close to the control key than the g key. Once you run this command, a session is created and control is handed over to dvtm. Now here you can start using the keybindings as suggested in the man page of dvtm. MOD-c will create a window in the tiled mode. Another MOD-c press will create another terminal window and so on. MOD-j and MOD-k will move between the windows and all windows are available in one single screen. 

 

I cannot express my joy, when I saw my console splitting into multiple windows. For everything else there is MasterCard. You did plenty of work by moving between windows and your program is now copiling. Time to relax. Detach the session by pressing MOD-\. You now land back at your console. Now run another command as so abduco -c relax dvtm -m ^x You get a fresh canvas. Create multiple windows again for playing your music with lyrics, reading a book by the next window. 

 

Enough of recreation, back to work. But, you want the music continue to play and want the book you were reading to be at the same place. Detach this session again by pressing MOD-\. Run without any arguments, abduco, will list all the live sessions. Run this command with the session name abduco -a session_name Now you are connected back to your compiling and editing session with all the windows as you left them when you detached from this session. The compiling is not complete, detach again and then re-connect to your relax session and continue reading your book. 

 

You are smiling. Your low spec PC is so responsive. But, But, We are living in a modern world and it is very difficult to survive without a pdf viewer, an image viewer, a video player, an ebook reader, a music player, a text reader(should we talk about it), web browser, a spread sheet, a document writer, a presentation tool and what not........ 

 

Let us try and resolve these applications one by one.

1. Let us start with a pdf viewer. This was rather easy. I was happy that the less command is more than capable of displaying text based pdfs. It will display pdfs with images, but the images are ignored.

2. An image viewer. For this the framebuffer image viewer, fbi is upto the task and is enough for viewing images and also includes the capability to perform a slideshow of the images supplied to the command.

3. For a Text reader/editor we are spoilt for choice and I would rather not talk about the options here. Whatever I talk about would be less.

4. If we come to the web browser, we do have choices, but none capable of handling 2 - 4GB of modern websites. We have applications for displaying true html. Blogs written with text only are a joy to read. I would recommend w3m. It also has support for images(I have not tried out this feature). If you access gopher holes or the modern avatar, the gemini space, then you are in luck and there are plenty of options. With the gopher and gemini protocol, you are at home in the console. Want to access your banking site, forget it.

5. If you are on the fediverse, there are clients for the mastodon network. There are clients for reddit.

6. For reading ebooks like epubs and mobis, I would recommend epy.

7. For searching the web we have the duckduckgo client ddgr and surfraw. Both are powerful and meet all the web searching requirements. 

8. Playing music has always been easy on the console with plenty of applications. My personal favorite is the mpd and mpc combination with ncmcpp added into the mix. 

9. For playing video, mpv is my default goto. The framebuffer device plays most of the videos thrown at it. 

This has already been a very long post. If you made it this far, then you are definitely a console junkie. If I could give you a hint of the entrance to the rabbit hole, then I would be most happy. Dont forget to buy yourself a mechanical keyboard. Thanks to all the devs and users who wrote all those wonderful applications and of course GNU/Linux. The journey with the tux and the beastie and the puffer since the year 2000 has been nothing but joy. I would like to end the post with the tagline of distrowatch. "Put the fun back into computing. Use GNU/Linux, Freebsd, Openbsd, Netbsd, Plan9, templeos, Haiku, Minix, GNU ..."