Category Archives: Arca Noae

Panorama Video Driver Package version 1.10 released

Arca Noae is pleased to announce the immediate availability of our Panorama Video Driver Package for OS/2 and eComStation version 1.10.

This is a maintenance release containing minor installer and screen object enhancements. This update is not critical but will bring Panorama in your system up-to-date with the recently released version of ArcaOS. If you have ArcaOS version 5.0.2 then you already have this update.

More information about the Panorama Package may be found in the Panorama wiki.

If you have ArcaOS, this driver package is available for download from the Arca Noae website as part of the Support & Maintenance subscription for your ArcaOS product. Please log into your account and see your ArcaOS order details page to access your software.

If you have an Arca Noae OS/2 & eCS Drivers and Software Subscription, this driver package is available for download from the Arca Noae website as part of your Arca Noae OS/2 & eCS Drivers and Software Subscription. Please log into your account in order to access your software.

If you are still running OS/2 and/or eComStation systems and haven’t yet purchased a software subscription, this is a great reason to do so now. It may also be a good time to consider moving up to ArcaOS.

ArcaOS 5.0.2 Bootable USB Stick Image 2018-02-12 Package Released

AOSBoot USB stickArca Noae is pleased to announce the immediate availability of our new ArcaOS Bootable USB Stick Image 2018-02-12 Package.

This package follows onto the included USB stick creation utility shipped with ArcaOS 5.0.2, allowing you to create a bootable USB ArcaOS 5.0.2 installation stick without a running OS/2 system. The package includes native binaries to restore the stick image from Windows, Mac, and Linux, as well as OS/2. Once the image is restored, eject, re-insert, and simply copy your personalized ISO (separately downloaded) to the stick per the included directions, which are also detailed in the ArcaOS support wiki. The stick may then be inserted into any USB 2.0-controlled port in the target system, which is then booted into the ArcaOS installer.

If you are still running OS/2 and/or eComStation systems and haven’t yet moved up to ArcaOS, this is a great time to do so. It’s never been easier to install any OS/2-based operating system.

ArcaOS

ArcaOS 5.0.2 now available

Arca Noae is pleased to announce the immediate availability of ArcaOS 5.0.2, the second maintenance release of ArcaOS 5.0 (Blue Lion).

ArcaOS 5.0.2 is the result of many hours of collaborative work to update and refine ArcaOS 5.0. Post-install fixes are included, and these will be made available for separate download as part of the ArcaOS 5.0 Support & Maintenance subscription shortly. In the meantime, a full download of the refreshed media image is required to obtain these fixes and updates.

ArcaOS 5.0.2 includes well over 60 updates and fixes since 5.0.1, and introduces for the first time ever available, the ability to boot an OS/2-based operating system from USB stick media and perform an installation. This new facility – AltBoot – should enable ArcaOS to be installed on many systems where traditional DVD-based booting has not been possible.

A bootable ArcaOS 5.0.2 USB stick may be created from any major operating system at hand (Windows, Linux, MacOS, and of course, OS/2, eComStation, and ArcaOS). The USB stick image package will be made available as a separate download.

If everything is working in your current installation, it may be prudent to wait for the subscription content to become available, as Arca Noae has not classified any of the 5.0.2 updates as critical.

If you have experienced difficulty installing ArcaOS 5.0.1, the fixes and updates included in 5.0.2 may address your issue(s).

For a complete list of updates in this release, see the ArcaOS wiki.

To download your fresh ISO, simply visit your customer portal page, select the Orders & Subscriptions link on the navigation panel to the left, then click on the order for your ArcaOS license. Once there, click the download link to request a fresh ISO, and wait for your notification email.

Arca Noae Package Manager version 1.0.2 has been released

Arca Noae is pleased to announce the immediate availability of an updated Arca Noae Package Manager for ArcaOS, OS/2, and eComStation. (1.0.2)

This is a minor release, but with lots of new functionality, including:

  • Prioritization of installed/updated packages, and prompted rebooting (should eliminate various problems when updating all packages).
  • Export & import of package lists, designed to make it easier to keep different systems in sync or when a complete refresh is required.
  • Fixed problems filtering out spurious checksum messages.
  • Improved error message formatting overall.
  • Program now gracefully handles bad or offline repositories.
  • Secure repositories can now be disabled/enabled in Repository Manager.
  • Cancelling credential entry for a secure repository now automatically
    disables it.
  • Some changes to menu names and arrangement.
  • Improved and expanded help guide.
  • Various bug fixes and other minor improvements.

Arca Noae Package Manager is available in English with Spanish, French, Italian, German, Dutch, and Swedish language packs. Some have added help file translations in this version.

This open source utility is available to everyone, free of charge, regardless whether you have an Arca Noae software subscription or an ArcaOS license.

Please review the wiki for important first-time installation and upgrade notes and other tips.

Updated Uniaud Driver Package Released

Arca Noae is pleased to announce the immediate availability of an updated Uniaud Audio Driver Package for ArcaOS, OS/2, and eComStation. (Uniaud-20180117)

This is a minor maintenance release that contains some fixes for Realtek mixer devices.

This release of Uniaud32 also implements MSI support. MSI only works with the ACPI PSD version 3.23.04 or higher. It is not required to use the ACPI PSD with Uniaud. If you don’t use ACPI then Uniaud will just use normal interrupts. If you are using the ACPI PSD, it must be version 3.23.04 or higher or your system may trap. If you are using an earlier version of ACPI, upgrade ACPI first before installing this version of Uniaud.

More information about the Uniaud Package may be found in the Uniaud wiki.

If you have ArcaOS, this driver package is available for download from the Arca Noae website as part of the Support & Maintenance subscription for your ArcaOS product. Please log into your account and see your ArcaOS order details page to access your software.

If you have an Arca Noae OS/2 & eCS Drivers and Software Subscription, this driver package is available for download from the Arca Noae website as part of your Arca Noae OS/2 & eCS Drivers and Software Subscription. Please log into your account in order to access your software.

If you are still running OS/2 and/or eComStation systems and haven’t yet purchased a software subscription, this is a great reason to do so now. It may also be a good time to consider moving up to ArcaOS.

Policy statement concerning Spectre and Meltdown exploits

Spectre and Meltdown are terms used to describe two potential exploits in a class of security attacks commonly termed “timing attacks” because they access data which may be sensitive in nature (passwords and other information) from areas of memory which may only be available at specific times (either moved elsewhere or removed entirely at other times). They belong to the more general class termed “side-channel attacks,” because they exploit the hardware itself, rather than breaking encryption or utilizing a software flaw. For more technical information regarding these exploits, please refer to the links section, below.

Arca Noae engineers are monitoring the situation, and while there is still much contradictory information crossing the internet at this time, we believe we have been able to assess at least some of the risk and provide some guidance to users of the OS/2 platform (OS/2 Warp, eComStation, and ArcaOS). As further reliable information becomes available, this post will be updated to reflect any change in Arca Noae’s position and any actions we may plan to take.

General information

In order to gain access to any information in privileged memory using one of these exploits, a user-level application must be launched on the specific machine to be compromised. This means that presently, an OS/2 executable must be used as the attack vector. As of this writing, we are not aware of any such code which executes on the OS/2 platform.

Browser-based attacks (running JavaScript) appear to require greater precision in a high-resolution timer than is currently available on OS/2, making such exploits more difficult than on other platforms, if not altogether impossible. It should also be noted that any such JavaScript-based attack would have to also be specifically designed to handle access to memory regions as managed by OS/2 (in other words, a malicious JavaScript program must be written for OS/2 and specifically to run in the OS/2 browser version in which it is running; a JavaScript program written for Windows or Linux will not work on OS/2). Realistically, the chance of this level of coding detail is extremely small.

Risks – virtual installations vs bare metal

By far, virtualized environments (running OS/2 as a guest under some other more vulnerable platform) are at the greatest risk, because the host system may rightly have access to the guest’s memory and virtualized processor. A host running a vulnerable operating system with an exploitable CPU which remains unpatched is the greatest concern. Arca Noae believes bare metal installations of OS/2-based operating systems are at much less risk.

Arca Noae’s current strategy

To date, we have not identified a need for a kernel patch to mitigate the risk of any hypothetical Spectre or Meltdown attack against OS/2-based systems. We continue to monitor the available information and will adjust our strategy as conditions require.

Arca Noae’s current recommendations

For virtualized and bare metal installations, Arca Noae recommends only running software obtained from trusted sources. Per stand practice, reasonable security precautions should be taken when accessing the internet, particularly when visiting unfamiliar or untrusted sites, and browser cache should be cleared regularly. The use of a NAT firewall is also encouraged (either a separate one, as built into a broadband router or at a minimum, a software firewall running on the local OS/2 system, such as InJoy Firewall).

Because a malicious application designed to utilize one of these exploits would have to be downloaded or copied to the target OS/2 system and then executed locally, normal malware protections remain the best first line of defense.

For virtualized installations, Arca Noae recommends applying to the host system whatever patches are made available and recommended by the developer of the host operating system.

Updates

2019-02-14: Security researchers apparently conclude in this whitepaper that Spectre cannot be entirely mitigated at the software level.

2019-10-07: Intel engineers have proposed (official/latest Intel PDF, here) a new memory type, speculative-access protected memory (SAPM), to mitigate a common factor in side-channel attacks which access cache/memory.

Links

Official information

Spectre CVEs:

CVE-2017-5753

CVE-2017-5715

Meltdown CVE:

CVE-2017-5754

Mozilla Security Blog

CERT: CPU hardware vulnerable to side-channel attacks

Intel: Facts about side-channel analysis and Intel products

AMD: An update on AMD processor security

AHCI Driver Package version 2.04 released

Arca Noae is pleased to announce the immediate availability of our AHCI Disk Driver Package version 2.04 for ArcaOS, OS/2, and eComStation.

This is a maintenance release that contains minor fixes and updates.

  • Fixed the IOCtl pass-thru interface. Tools such as smartctl use this.
  • Removed the old smartctl program from the distribution.

More information about the AHCI Disk Package may be found in the AHCI wiki.

If you have ArcaOS, this driver package is available for download from the Arca Noae website as part of the Support & Maintenance subscription for your ArcaOS product. Please log into your account and see your ArcaOS order details page to access your software.

If you have an Arca Noae OS/2 & eCS Drivers and Software Subscription, this driver package is available for download from the Arca Noae website as part of your Arca Noae OS/2 & eCS Drivers and Software Subscription. Please log into your account in order to access your software.

If you are still running OS/2 and/or eComStation systems and haven’t yet purchased a software subscription, this is a great reason to do so now. It may also be a good time to consider moving up to ArcaOS.