Showing posts with label computers. Show all posts
Showing posts with label computers. Show all posts

Friday, December 19, 2014

It's almost like a new machine

So I made some updates to my desktop computer, finally:
  • Upgrade from Ubuntu 12.04 LTS to 14.04 LTS.  Yeah, I know, I'm not exactly a fast follower here, but I like my machines to work. Waiting a while to update to the next long term support release feels smart. I let others work out the kinks for a while before moving up.
  • Changed from 32 bit version to 64 bit version. I tried 64 bit a while back - probably in the 10.04 era - and had no end of trouble with software not being available in 64 bit, or not working properly. It appears those issues are now resolved.
  • Changed the boot disk from a standard hard disk to a solid state disk. Just a small one (128 MB) from Crucial but plenty big for the OS and swap space.
The difference in how the machine feels is amazing.

Boot time is substantially improved, though the POST on this motherboard still takes forever.

Apps load faster. Much faster. All that I/O wait while Chrome loaded for the first time is gone. Or rather, it's not gone, but I don't note it happening anymore.

Even simple things like working with email and playing YouTube videos are faster and smoother. I'm not sure why that is, but it seems to be.

This system has a new lease on life, which is a good thing. I hate buying new computers and this one should go another two years easy now. Maybe more than that.

Friday, September 6, 2013

Of Yahoo, And Opportunities Bungled

This is an odd post for me, in a way.  You may find it boring, and if so you may simply skip it, I won't mind.  But this has been bugging me for a while now, so...

I am a member of a bunch of Yahoo groups.  Years ago, I think, yahoo bought some small company that made the original groups product.  Or perhaps I am wrong and they created it themselves.  Groups is an interesting beast. It has a web based UI but mostly works via email.  You send a message to a particular email address and it is forwarded out (as email) to the group members.  It's a handy way of organizing people and distributing information.

There are competitors, of course, most notably Google's very similar functionality.  And you can use any number of bulletin board systems from various sources, which you can host such things on your own server or find services to host them for you.

But a number of the groups I am a member of have a significant proportion of members who still aren't all that computer savvy.  Trying to get them to go to a website every day (or multiple times a day) is tough.  You're competing for limited time and interest, and it's a losing battle.  But most of these folks already use email, so if you can get them signed up as a member of a group, they're in, without changing their daily routine.  In ten years or so that worry won't be a problem.  Most people will be much more computer friendly, and getting something setup to move the information around will be easier, so there will be fewer hurdles in any case.

But back to groups... when I started using them, Yahoo had a clear UI advantage over Google's implementation.  There were still places it sucked, but Google's UI was pretty much impenetrable, so Yahoo won the day, particularly for those lists that contain a larger percentage of people who are less comfortable with computers and the Internet.

But Google has continued to work on their product.  They have improved it over time, and it may be to the point where it is usable by laypeople now.  I'm not sure of that because I haven't tried to create a new Google group in some time, but I have used Google's groups a bit since they use them to provide some kinds of support and discussions about their products.

Yahoo, on the other hand, let its groups product stagnate.  Nothing changed or was improved for years.  It's been the same UI and feature set since I first started using it, and problems have crept in.  Sometimes messages are delayed for unknown reasons between Yahoo's servers, images as part of email messages aren't always handled well, and so on.  But overall it worked, and Yahoo milked it by spending as little as possible on it to keep it running.

Then, just a few days ago, something changed.  The first indication of a problem was a huge batch of email delays that no one could explain.  They got so bad that people in my most active group complained bitterly.  And then, for some of us, the word "neo" entered our consciousness.

"Neo" means a new UI for Yahoo groups, and some reorganization of the features.  But it also means a lot more, including, but probably not limited to:

  • Bugs.  And features that don't work or don't work reliably.  It's not clear if some of these issues are based on the browser, the OS, or just buggy code, but there are a number of serious problems.
  • Features that have gone missing.  Things you used to be able to find in the UI are now gone.
  • Incredibly bad UI design.  Want to search the contents of the messages in a particular group?  Don't click on the obvious "search" icon and enter your text because that only lets you search for message numbers, which no one will ever know or use.  Instead enter your text in the search box at the top of the page and press the button that says "Search Groups", clearly indicating that your search will span all of your groups, or - more likely - all of Yahoo Groups, which is clearly not what you want if you're searching for a message in one particular group.  Who designed that and how did they get the job?
  • Unhappy customers.  Tens of thousands of requests to abandon the neo update and go back to the way things were.  Really.
  • A complete lack of QA effort.  Neo is clearly not ready for prime time.  It's alpha quality software, or early beta at best.

So the nightmare that is "neo" is now a part of my life.  Users are switched, not whole groups, so some of the people in my groups are using the new UI with me, while others see no changes yet.  But they will.  Yahoo claims there is no going back.

Meanwhile Marissa Meyer seems to think the most important thing she can be involved in is the redesign of the Yahoo logo.  Something that no one cares about - but her, apparently - and that definitely deserves a lot less attention than the neo debacle in Yahoo Groups.

What can I do about all of this?  Looking at it reasonably, very little.  Moving from Yahoo Groups to some other platform might result in a newer and better feature set, with more ability to control and archive the contents, better search features, and so on.  But moving entails change, and that is always risky.  There would, no doubt, be a large loss of participation in all of the groups I am involved with if they were to move to some - any - new system.  So, unless neo proves unbearable and the bugs really don't get fixed, we're probably stuck with it.  And I'd bet those working at Yahoo know it.  They're probably counting on it.

The funniest thing about this is that I am ranting about it in a post on Blogger... a Google product.  Want to know how relevant Yahoo is these days?  Look no further than that.

Monday, July 1, 2013

Google Reader is Gone (and I don't miss it)

Today is the last day for Google Reader.  Or maybe yesterday was, depending on what they meant by July 1st being the end, and whether or not there is an off-by-one error in their code somewhere.  (Joke!)

But I don't miss Google Reader at all, and I was a fairly heavy user.  Why not?  Because I use BazQux Reader.

I started trying all of the alternatives back when Reader's demise was announced.  I tried bunches of them, and pretty much disliked them all.  But BazQux was different.  Actually, I think it's better than Reader, at least for my usage model.

I'm not paid for this plug, and I hope I am unbiased.

If you've been living under a rock and only found out that Reader dies today, now is the time to look for an alternative.   First, of course, export your Reader subscription list, if you still can.  Then give BazQux a try.  I hope you like it.

http://bazqux.com/

Tuesday, June 11, 2013

Richard Stallman Is Wrong About Cloud Computing, At Least In Some Ways

TL;DR: No matter what Richard Stallman may say, there is a place for cloud computing.

In an article in The Guardian, Richard Stallman calls using web based programs "worse than stupidity" and a trap to get people locked into proprietary systems.

Is he right?  In some ways, maybe, but as I see it, for the population in general, he's off base.

I'm probably not the right person to criticize.  I've only got about 20 years of programming behind me, mostly for companies no one has heard of.  I've worked for one ISP, one OS developer, and a bunch of other places.  I graduated with a CS degree long enough ago that OO was still a university concept, not actually in use in the field, and I never took to it for several reasons.  As it happens, I'm sick of all of that now, and would rather carve stone, but that doesn't matter.  I still do a lot of things on computers, using cloud computing of one sort or another, as well as some local computing power too.

Oh, and I know Stallman will never see this, which is just fine with me.  I'm a nobody in comparison, but I still think I have a valid point.

Stallman claims that cloud computing is all marketing hype.  But let's look at this a bit more deeply.

If you have a computer at home, the chances are it runs Windows.  Alternatively, if you don't run Windows, it is most likely you're an Apple Mac user, and thus run MacOS.  If you fall into those categories, Stallman has no use for you.  Those are both proprietary operating systems and lock you into the same evils that cloud computing does.  You're screwed, by definition.

In terms of popularity, I think after that come tablets and smartphones.  Those generally run Android - which is open source - or IOS (from Apple) or Windows.  Let's just assume that Stallman hates anything from Apple and Microsoft - probably a good bet - and think about Android for a minute.

I have an Android phone, and I love it, but it is running an old version of the OS.  It's not even two years old but - despite promises to the contrary - both the manufacturer and mobile carrier have failed to update it.

Yes, technically, I could root the phone, back it up, and install the latest version of Android myself. But that takes time, risks turning the phone into a brick, and requires me to do all ongoing maintenance from there on out as well.  While I might eventually attempt it, most of the people who own smart phones aren't going to bother.  Too much trouble.   So, many people running Android are locked into an old, unsupported OS by a combination of their carrier and phone maker.  Stallman probably writes them all off to, if I had to guess, though he might claim the the companies involved are doing evil in the process.

So far, no matter which of the choices I've listed, you're very likely to be in a category that Stallman dislikes.

What does that leave?

In the personal and mobile computing world, that leaves Linux and the latest version of Android, the latter getting updated all the time and leaving more and more people behind as that happens.

So, what makes the few percent that actually run those systems - the ones Stallman might like - tick?  They're all serious geeks, for starters.  They know their tech and aren't afraid to mess with it.  It's fun to do so, in fact.

Let me give a different perspective on this: I run Linux at home and it requires real effort.  Here's an example:

Recently, Ubuntu discontinued support for the version of Linux I was using.  Their newest version no longer supports older CPUS - like the one found in my laptop - so it cannot run out of the box on it for me. It does run on my desktop, but it has a new UI that I really don't like, which completely changes the way I have to interact with the computer.  (I strongly prefer focus-follows-mouse, not click-to-focus, for various reasons, but the Unity UI makes that choice unavailable by default.  And there are behaviors in this UI that make no sense on a desktop, but since they are trying to create on UI that will also work on pad computers and smartphones, we're stuck with it.  In short, I think it stinks.)

And then there was the time that I had to wait a year for Linux to support a new motherboard, and the time Ubuntu changed to the open source graphics card driver too soon, and it didn't support my system, and getting printing to work was a pain, and I had about three choices for scanners that the manufacturer actually says support Linux, and when I did the recently required OS upgrade, the scanner stopped working and I had to go find 2 totally different things that were required to make it work and execute commands at the command line, as the superuser, to make things right again.  Really.

None of that is going to be easy to explain to most users.  Stallman would have no problem with it, and compared to most I had little trouble, but I am not about to make Linux support a brand new motherboard.  I have a lot of other things to do with my life.

Stallman might argue that I can change to another Linux vendor, and I did look around when Ubuntu unilaterally decided that non-PAE CPUs were so old that no one would care if they weren't supported anymore.  But I am not all that happy with anything I have seen so far.  Over the years I have used a number of Linux versions, and I have suffered from all kinds of problems with both hardware and software compatibility.  Thus far, Linux Mint runs on the laptop - despite being Ubuntu and Debian based - but I am not convinced that I want to run it on my desktop yet.  Too many unknowns.  I have no idea how that issue will shake out.

Looking at this objectively, Canonical - the makers of Ubuntu - have done their very best to both lock me into their system and piss me off about their hardware support changes.  They act just like a proprietary OS vendor in some ways.  And given past experience, most of the other Linux vendors I have used do the same.

So on the OS front just about everyone is going to have a problem.  Either Stallman won't approve of your OS (walled garden or crap) or, in the unlikely event that we happen to select something he approves of, we're in for a perpetual maintenance nightmare.  And I repeat: am fairly well versed in the technology.  My parents are never going to run Linux.  Never.  Way too complicated.

But let's think a bit more about the nature of the beast here.  The OS is only the start of the issue, and Stallman's real complaint - at least in that article - is about cloud computing, which goes beyond the OS and into the application arena.

For example, apparently Stallman doesn't like gmail.  Because it - and other webmail systems like it, one assumes - will lock their users into one solution, and put them at the mercy of Google (or Yahoo, or Microsoft, or whoever).

Perhaps, but...

I ran my own instance of sendmail for several years, so I could totally handle my own email.  It's a configuration nightmare.  Not fun.  No way is grandma going to do it.  And you have to update the software all the time to patch for security issues, and there are always things breaking in weird ways.  It is my belief that mail server administration is only for those who enjoy pain.

Beyond, that, though, come other issues.  If I run my own mail server at home, I've got no simple way to do something like have email that gets delivered to that home computer also be available on my Android phone when I am not at home.  I could setup a POP or IMAP server, I suppose, but then I have to have some way to make it visible to the outside world, when my ISP NATs everything by default.  Possible, maybe, but way too much trouble.  And not something my mother is ever going to want to understand.

Oh... maybe Stallman wants everyone to have their own server in a data center somewhere, with a public IP address.  That would let them run all of this server software in a simpler way, I suppose, but does grandma really want to do that?  Or maybe we should all be using virtual machines for this?  But wait... that's cloud computing.  Can't do that.

What else does using a webmail system get me?  Over the years I've had disks fail and lost everything on them.  So running my own email system means a very intensive backup system is required.  Gee... with webmail, someone else is backing things up, storing multiple copies, and generally making sure the hardware isn't going out of date or failing.  I'd call that a win.  They are also monitoring capacity and adding more (and faster) CPUs when they are needed.  Another thing I can avoid.

So, let's summarize: with gmail - or any of the other major webmail systems - I can read my email anywhere, it's backed up, and I don't have to do hardware or software maintenance on anything on the server side.  That adds value in my eyes.  But according to Stallman, it's all just there as marketing hype and to lock me into a particular service.  I guess the choice is obvious to him.

How about other software?

My various Linux installs come with LibreOffice (formerly Open Office, before Oracle did the nasty to Sun), and it's a fine office suite as these things go.  But sharing documents with others - and having edits done in just one place, rather than having to sync up everyone's changes, which is something I actually do - isn't easy with LibreOffice, just as it isn't easy with MS Office.   But Google's office apps - available via Google Drive - do a nice job of that.  And I never have to update the software.  They make my life easier, not harder.  And there are other office suite vendors as well, so I have choices.  And Google lets me export my data in a number of open formats.  So I am not really locked in at all.  Huh.  Interesting.

I also use the image manipulation program Gimp regularly, and while it is very powerful, it isn't as easy to use for some photo work as I have found some cloud photo software to be.  And again, there are many choices here.  And since images can be downloaded in common formats... no lock in.  Fascinating.

What does all of this mean?

For me - and I suspect for most of us - cloud computing provides real value in the form of simplicity.  Of course it is possible to pick a bad provider and/or get locked into something you cannot get out of, but as my examples above indicate, that is happening on the open source side as well.  Just how many times should the average user have to reinstall Linux until he gets a version that works for him?  And how much research should he have to do to keep it running?  (And never mind figuring out how to configure the nightmare that is sendmail.)

For Stallman - and those like him - running everything themselves on their own local hardware may be fine.  And I don't mind a bit if he does that.  In fact I hope that over time it gets easier for all of us to run this stuff ourselves if we want to.  But most of us aren't going to be able to master all of the knowledge needed to make these things run well, or even work at all in some cases.  Cloud computing can help simplify things for the end user immensely if all they need is an OS and an up to date browser.  That's a lot less to maintain, backup, and keep virus free.

On the business side things get a bit less clear, I admit.  But what some forms of cloud computing offer is hard to beat.  If your business grows, do you really want to have to add racks of servers yourself to support it?  Maybe, but perhaps you'd rather use Amazon's cloud services to deal with at least some of that.  If it saves you time and/or money, it might be worthwhile.

Are you locked in if you go that route?  Yes.  But you're just as locked in with any solution.  If you do it yourself you're locked into the OS you pick, the hardware you chose, the data center you lease space from (or the building you lease or own to build your own data center), and so on.  And when you go down the application route, you're locked into whatever you buy or build.

Lock in, to some degree, is a matter of fact, and no major change is simple when you think about these things.  None.

But if cloud computing means you can get more capacity quickly, when you need it, rather than waiting two weeks for the servers you need to arrive and get configured, that could be a real win for at least some businesses.  To discard it as all marketing hype is to miss the point.

I respect Richard Stallman for his principled stance, but in reality, things are a lot more complicated than he lets on.  There is a place for cloud computing - of various kinds - for both end users and businesses.  Of course there are tradeoffs - and even risks - but if he thinks that doing everything locally avoids those issues, his head is firmly planted in the sand.



Monday, August 22, 2011

On Passwords

Multiple people have recently asked for information about how to create, use, and protect passwords.  We all have them, but - oddly - no one teaches us anything useful about them.  Some of us figure these things out, but most people never do.  And if you don't think about it, it is very easy to get into real trouble.

My goal is to help you avoid having your accounts hacked and your identity stolen.  There is a lot of information here, I know, but the topic is important.  Please read on.

First, the obligatory disclaimer:  I am not a security expert, and would never claim to be one, though I have spent enough time in high tech to be able to discuss this issue in some depth.  Hopefully I can make it clearer to you, but the subject is much deeper than even I know.  If you are interested there is a lot more to learn.  It's also important to note that even if you follow all of the best practices you can still have a password stolen or cracked. Sorry, but that's the truth.

Please consider this entire piece my opinion only, and note that your mileage may vary.

Begin At The Beginning:

The first problem with passwords is their very name: "password".  Many people think a "password" has to be a word because that's what it says.  Nope.  And, in fact, a single word - any single word - is just about the least secure thing you can use for a password. To explain why, and eventually get to how to create and protect good passwords, I will cover the following things:
  • How Passwords Work - A short overview of how a simple password system actually works.
  • How Passwords Are Compromised - How the bad guys get them without much work, without even having to guess or decrypt them, and how to protect yourself from at least some of those issues.
  • How Passwords Are Cracked - How a password is actually figured out "the hard way".
  • How To Create Good Passwords - What makes one strong and another weak.  How to create good ones reliably.
  • How To Manage Too Many Passwords - How do you remember 50 different passwords?
  • Other Thoughts on Passwords - Some other things to note in the world of passwords and security.
  • In Summary - A very quick recap.
Here we go...

How Passwords Work:

On any well designed system, passwords are stored in a text file or database table that contains your login name and an encrypted version of your password, among other things.  Here's a made up example table with those two fields separated by a colon.

bob:7y+kj8hs
jeff:IY67kH_1
jeffa:9jHg=ih1
mary:khy8ue4_
susan:iop74rf3

Part of a password system involves some complicated program code to encrypt passwords.  An encryption routine takes a string as input and returns a different string as output, with the intent that the output string cannot easily be associated with the input string.  In the example, we can see that jeff's encrypted password is "IY67kH_1".

I won't bother with the math behind encryption, mostly because it is way beyond me.  Suffice it to say that it is very, very complicated, and there are many ways it can be done.  The goals, though, are easy to understand:
  • No one should be able to look at an encrypted string and find out what the original string was.  Even with a super computer capable of doing math very quickly and knowing the code used for the encryption, the problem - going backwards from the encrypted string to the original password - should take hundreds of years.  Incidentally, this is why you can't just get someone to look up and tell you your password on a well designed system.  It's encrypted in such a way that no one can practically reverse it.
  • The encrypted output needs to be in some standard format.  The simple example above has the output string limited to 8 characters, and allows both alphanumeric and a few special characters.
With that background, here's how a very simple password system works.  First, the system looks in its table for the user name.  If it doesn't find it, it emits an error of some kind (usually saying it's an "invalid user") and lets the user try again.  If it finds the user, it takes the password that was entered, encrypts it, and compares the result with the encrypted password that user has in the table.  If they match, the user is logged in.  If they don't match, an error is emitted saying something like "bad user name or password", and the user gets to try again.

As an example, we'll use my made up login - "jeff" - and the corresponding made up (and very poor) password "obvious".

If I enter "julie" and "bad_password", I get "invalid user" because there is no user named "julie" in the password table.  Note that the system didn't even both doing anything with the password I entered because there was no matching user.

If I enter "jeff" and "bad_password", I get an "invalid user or password" error message.  The system isn't sure if I entered the wrong user name or the wrong password.  (It is true that I entered a valid user name, but I might have entered the wrong one.  Perhaps I meant to enter "jeffa" and didn't type the final 'a' in the user name.)

if I enter "jeff" and "obvious" the user name matches a valid name, and the password, once encrypted to "IY67kH_1" matches the entry in the table, so I am allowed into the system.

Note that you cannot enter the encrypted string as your password.  If I enter "IY67kH_1" as my password when I log in, that string will be encrypted to something else, and the result won't match, so my login attempt will fail.

That's it, a very simplified version of how a password system works.  There are many wrinkles, or course: how to create a new user and their password, how to change a password, and various ways to make passwords more secure, among others, but the core of the system is there.  Your password gets encrypted into a string that can be safely stored in the system, and that string is compared with the encrypted version of the password you enter when you want to log in.  Most importantly, no one can read or see your actual password.

How Passwords Are Compromised:

The first and biggest risk most of us suffer from is making our unencrypted passwords readily available to the bad guys.  Hopefully a lot of this is just review, but the following are some of the common errors people make when dealing with passwords
  • We give our passwords to the wrong people.
  • We let others see us enter our passwords.
  • We write our passwords down.
  • Even worse, we send our passwords to others in email.
  • We use insecure computers where malware has been installed.
  • We respond to phishing attacks.
  • We enter our passwords into insecure systems or use insecure protocols to send our passwords to systems.
  • We use the same password for many systems.
These are all common sense things, but they turn out to be ways that passwords are regularly stolen by people who aren't above doing bad things with them.  Note that none of these cases talk about what your password actually is.  Though there are important issues related to password selection, the first thing you have to do is develop good "password hygiene".

The most important, and yet simplest rule of password management is never, ever, tell your password to someone you don't trust, 100%.  Period.  Can you count on that person to keep it a secret, and not let it out?  Even accidentally?  Probably not.  Even for a friend or a spouse the chances of letting it slip are high, particularly given the above list of issues. The best way to protect yourself is to keep all your passwords private all the time.

This isn't always obvious, though.  An example: someone calls from your phone company, claiming they are doing some system maintenance on your account and asking for the password you use to get into their online system.  Do not give it to them.  They should not need it.  Ever.  If for some reason you are inclined to believe them, hang up, call the company yourself, and ask someone in customer service about it.  If you make the call - to the company's 800 number - and the new person you talk to says the request is legitimate - and they do need the password - it is safer.  It's still stupid, but safer.  After all, you are about to tell your password to another human, who could easily write it down and do bad things with it later.  Any well designed system should never require a user to divulge a password to a human, particularly via some non-secure route, like over the phone.

Note that you cannot just ask the original caller for a phone number to verify things.  They could give you a number for a collaborator who will tell you exactly what they want you to hear.  Get the phone number for yourself - from the company web site, perhaps - and call that.  Only when you initiate the call to a known good phone number and are told that the request is legitimate should you consider complying.  And even then you should ask to speak to a manager and tell them that their systems are poorly designed and they should not be requiring their customers to give their passwords to strangers over the phone.

Assuming you are keeping your passwords to yourself, the next step is to avoid having others see you enter them.

When you go to the ATM you look over your shoulder before entering your PIN, right?  That's the idea, but you have to think about it all the time.  When you enter a password into your smart phone - even just to unlock it - while standing in the terminal at an airport, how many people just saw you enter that number?  And if your phone is stolen 10 minutes later, they have access to everything on it, right?  If you're in the library using a computer and someone watches you login, that account is compromised.  Your boss watches over your shoulder as you login at work... compromised.  And so on.

Those who are paranoid about these things might seem crazy.  That ATM on the street in town is risky because someone standing at a window 3 floors up across the street with a pair of binoculars and a good digital camera can read the account number off your ATM card as you put it into the machine, and see your PIN as you enter it.  Yes, really.

You have to be certain that when you enter your password - for any system - no one sees you do so.  While that sounds simple, most people don't think about it much, and the results are all around us.

Next: do you write your passwords down?  You might have dozens of them, for various sites at work and on the Internet.  Can you remember them all?  Of course not, so you write them down.  And where is that paper with the passwords save?  Under your keyboard?  In the pencil drawer of your desk at work?  Taped to your monitor?  Any passwords that are written down are, by definition, already compromised.  If you have to write them down, at least put them someplace no one can see through your windows or passing by your office door, and where they won't ever be looked for, even by a determined thief with time to kill.  But, in truth, a written password is a compromised password, and you should never write them down if you can avoid it.  There will be more on how to manage large numbers of passwords later on.

By extension, sometimes people or systems put passwords in email.  The problems with that are much, much worse than just telling the recipient the password, or writing it down.  Unless you do something special - which most people never figure out - email isn't encrypted, and it can be routed through many different computers between you and the recipient.  It can be copied, left on disks along the way, and read by various people with access to those computers along the route.  Any password in an email should be assumed to be compromised.  If you encounter an online system that sends your password out in email, first change it immediately, then send the site a note complaining about it.  Better yet, cancel your account with the site and tell them why you did so.

An exception to passwords in email is if you are resetting a forgotten password.  The site may send you a new password in email in this case.  When they do, login IMMEDIATELY and change that password to something new that was never in an email.  There are limited options in a password recovery setting, and emailing out a new password - often one that will expire quickly or that can only be used once - is acceptable, but you must follow through and change it quickly to reduce the risk that someone will get into your account with that new password before you do.

Assuming you're careful about all of those risks, then you must consider the computers you are using.

Computer viruses, key loggers, and other malware are a significant threat, and probably account for the bulk of compromised passwords.  These risks are more severe for any computer running Windows simply because there are so many of them in the world.  Some argue that Windows itself has more security holes for various reasons, and so is inherently unsafe.  My opinion is that was demonstrably true years ago, but it may be changing for the better lately.  Still, if you want access to a lot of passwords you go where they are, right?  That's Windows.  Macs are starting to get attacked as well, though, so don't rest on your laurels if you're a Mac user.  And other operating systems will eventually have the same problem if they don't already, so use caution.

As a rule, don't do anything critical on a public computer, or one whose status you don't know.  Library computers are handy, but do you know they are up to date, virus scanned, and free of malware?  Probably not, so don't do your banking there. Always exit and restart the web browser completely before using it on a public computer, and check to see that the operating system and anti-virus software are up to date as well.  If you can't tell it is up to date, I wouldn't enter any passwords - or do anything personally identifiable - while using that computer.

On your own computers you should always keep the operating system up to date and install patches as they come out, since they fix vulnerabilities that can make your machine open to viruses, key loggers, and other malware.

A key logger is a program that runs in the background and stores all of your key strokes, sending them off to someone else when something interesting happens.  If it sees a request from your web browser to a bank, stores the next 500 key strokes you enter along with the URL it saw, and sends it all to the bad guys, your bank account could be empty in the morning.

To avoid this, always run a good anti-virus program.  These can help reduce the risk that you are compromised, though they cannot completely eliminate it.  New viruses - ones not yet recognized by anti-virus software - are always popping up, so while they are a good defense, they are not perfect.  Still, they are a requirement.

Keeping your software up to date is critical.  Anyone still running IE6 or Windows XP is in serious jeopardy of having their identity stolen.  Old versions of any browser or operating system have similar issues, though.  If you are running Windows, consider running any browser other than Internet Explorer.  For a long time IE was the most used browser out there, and therefore the biggest target.  Security problems were often found in IE as a result of that market dominant role.  There are security problems in FireFox, Chrome and Opera as well, but they are different, generally less commonly encountered, and less likely to be taken advantage of.  Install one of those other browsers, keep it up to date, and use it for anything critical - like online banking - at least.  In my opinion, IE has improved, but not enough that I would trust it yet.

Another layer of protection comes from practicing "safe software".  That's an old term for being careful about how you handle data and move it between computers.  If you get an attachment in an email, don't open or run it, even if it comes from someone you know.  The sender might have an infected computer that sent you that email without his knowledge, and it could easily contain a virus.  If it is important that you view or run it, save it to disk, scan it with your up to date anti-virus software, and only proceed if it is clean.  (Some anti-virus software scans email attachments as they arrive, which is great, but caution is always best.)  If you are given a disk or thumb drive, scan all files on it for viruses too, before running or opening any one of them, for the same reason.  In fact, if you move a thumb drive or disk from a computer you don't trust to one you do, scan it for viruses before running or opening anything.  There are viruses that travel via thumb drives, for example, and can hide on the drive without affecting the files on it.

This may seem like overkill, but the number of infected computers is huge, and the number of security holes in any operating system or program is high.  You have to be as careful as possible to avoid infecting your computer with something that will give your passwords - and your identity - to someone else.  As a bonus it helps avoid viruses that do damage to your computer and files, so it is good practice in any case.

And while we're talking about these things, be extra careful about email.  Never "click through" an email to get to a website and login, even if you think it looks OK.  This is particularly critical for banking related sites.  The specific attack is called "phishing", and it is deceptively simple.

The bad guy sends you (and 10 million other people) an email that looks like it comes from your bank.  The return address is your bank, all the usual graphics are there, and so on.  You click on a link in the email and wind up at a web page that looks just like your bank's login page, so you enter your name and password.  What happens next doesn't matter, though, because you've just given your login details to the bad guys.  The email was a fake, and the web site didn't really belong to your bank.  You can bet they will be getting into your account quickly, though, and taking all the money they can get from you.  Or they might wait six months and hack you then, when you've totally forgotten about this incident.

To avoid this, do not click on links in an email, or at least don't login from pages your get to by clicking on links in email.  Bring up a browser window and enter the URL for your bank manually, then login and do whatever the email said you need to.  If you have any concerns about the validity of the email call the company in question on the phone - using a known number you got from someplace other than the email you're not sure of - and ask about it.

Sadly, there are other ways passwords are compromised, and some are harder for the average user to notice.

Some programs don't encrypt passwords when they go over the Internet.  Such systems are nearly as bad as putting your password in an email.  And if you use such a system on a wifi network you're totally hosed.  Reading packets on a wired network is pretty simple, and snooping other users on an open wifi network isn't hard either.  In short, know where your passwords are going, and be sure you are using HTTPS or other secure protocols to send them over the network.  Your browser will show you a lock icon if it is sure the site you are connecting to is using HTTPS.  If it isn't secure, be careful about entering your login and password.

Sadly, some sites use HTTP - an insecure protocol - for the login page, but use HTTPS to send the user name and password.  Thus, the page you appear to enter the login data into isn't shown to be secure by your browser, but the connection made to send the data to the server actually is secure.  I generally find these sites have a second login page that is fully delivered in HTTPS, and thus easier to recognize as secure.  Look for a link labelled "login" or something similar on the non-secure main page and see what you find when you click on that.  Complain to sites that don't obviously use HTTPS for their login page, so they will fix things to be more obviously secure.

Finally, in the realm of things that weaken your security, don't use the same password for multiple accounts.  If you do, and it gets compromised, you have a major problem.  If the login and password you used for your yahoo email account can get the bad guys into your bank, or the account you have to manage your airline rewards program, well, you brought the trouble upon yourself.  Using different passwords is critical.  Yes, it is a problem to manage and remember all those passwords, but it is a critical step to keep your data - and identity - secure.

Security of any type begins by keeping your important login information safe.  How paranoid you want to be is up to you, but the risks described here have gotten people in trouble - in real life - for years.  How many spam emails have you gotten from someone you know?  The password for some email account they have was compromised - probably in a way described above - and was used to send that spam.  It happens all the time, and sending spam is probably the least bad of the things that might happen as a result.

Even if you're careful about who you share your passwords with, the computers you work on, and so on, an account can still get stolen.  At this point we're talking about passwords themselves and how they get cracked, which is a whole different kettle of fish.

How Passwords Get Cracked:

A cracked password is one that someone figures out in some technical way, possibly by reversing the encryption, or (more likely) by guessing likely passwords until they find one that works.

In general it isn't the NSA (or some similar foreign government agency with a zillion dollars and lots of time) who wants into your account.  Instead it's some kid in the Ukraine who wants to empty your bank account, or some "friend" who wants to ruin your day.  These people have no budget to speak of, and won't bother to wait 250 years for a computer program to reverse your password.  So they go after the simple stuff and hope to get lucky.  It turns out there are lots of simple things they can do to get into your accounts, and your choices can make things easier or harder for them.

Some of these methods won't look easy to you, but they are actually pretty simple.  In many cases you can get programs to do these things for free - or very little money - in the darker corners of the Internet, and the good guys use very similar tools to check the security if networks, computers, and passwords all the time.  Also note that some are used in combination, but for simplicity I describe them individually.

The first approach is to try obvious passwords.  Many studies report that lots of people use really simple passwords, which means the hacker can try a few dozen passwords and often find a way in.  Some examples of bad passwords include: "abcdef", "password", "qwerty", "12345678", and so on.  It turns out that any simple thing for you to type or remember is just as simple for someone else to guess.  In any given system a large percentage of accounts are vulnerable to this sort of attack.  If 20% of gmail users have really obvious passwords, the only real problem is figuring out which of those gmail accounts the bad guys want to break into, right?

Another thing they can try is a dictionary attack.  It is easy to get a list of words - a dictionary - and try them all.  The bad guys try logging in with your user name and each word in the dictionary as the password until it works.  The chances of success are high because so many people use real words as their passwords.   Near the top of this article I said that any single, real word is a weak password.  Now you know why.   It can take a while to break in if they are logging in from a remote computer, but they don't do it by hand.  Instead they use a computer program to do it.  This kind of attack is disturbingly simple and effective.

There are tricks to make a dictionary style attack work faster.  If the bad guy can get the list of user names and encrypted passwords, for example, then he can look for weak passwords much more quickly.  An insider can get that data for him, a security bug might expose the data, or a poorly secured computer system might make the password table available to an earlier attack.  Once they have the table, they simply encrypt an entire dictionary once and compare the results with all the encrypted passwords in the table.  Any matches they find become hacked accounts because they know both the login name and the original password. I am simplifying a lot, but this does happen.

If someone wants to get into your account specifically, and not just any account on a system, they can try things related to you in particular.  If they know your birthday or anniversary, the names of your spouse, children, and pets, the kind of car you drive, and things like that, those turn out to be likely passwords.  Trying a bunch of them may get them into your account because so many people use things related to themselves as passwords.  Also, many of those things are regularly used as answers to security questions, which are asked when you forget your password and want to reset it.  More on that later, but if the bad guy can get the system he's hacking to reset your password to something new, he's gotten in (or kept you out), so keeping personally identifying information private is always a good idea.

If someone is really serious they might try calling you and claiming to be from the company whose site they are interested in, and ask you for your password directly, as part of some security check.  If you fall for it, you might give them the password yourself.  Or they might claim to be doing a survey and ask for the number of people who live with you, their genders and first names.  Now they have additional passwords to try.  They might call your friends and associates at work and ask questions about you, again leading to possible passwords.  They could also call your system administrator at work, pretend to be you, and ask that the password be reset, at which time they can get into your computer because they are told (or even pick) the new password.  This is called a social attack, and while it isn't common to do this to get into someone's Facebook account, it is often used to get into more important systems.  Corporate or government espionage can happen this way, as can people trying to get data from the police or other organizations with information that isn't publicly available.  Celebrities suffer these sorts of attacks as well.

To avoid most of these issues, the best defense is a good, strong, password, one that you've told no one else, that isn't associated with you in any way, and which is hard for a computer to figure out.  Any particular system may impose limits on your password choices, but the basic ways in which you can create strong passwords are pretty simple.

How To Create Good Passwords:

The best passwords are hard for computer programs to guess or figure out, but easy for humans to remember.  That leads to some obvious choices in password selection.  The longer the string, the harder it will be for a computer to reverse the encryption process, for example, so longer passwords are better.  Non-words are always better than using a single word, but multiple words is good, particularly if they are unrelated.  Using special characters, numbers, and mixing case makes the password that much harder to guess - or reverse - too.

The system you are working with may impose limits, though, many of which are particularly stupid.  Maximum length limits are a problem; older systems often limit passwords to 8 characters, for example.  Some systems won't allow spaces or non-alphanumeric characters in passwords, or perhaps just a few special characters are possible.  These sorts of systems are making your life less secure, so consider just how much you need to use them at all and avoid them if you can.  Where you have to use them, though, you have to work within their rules.

If the system has no length or character limits of any significance, you can create long passwords by using multiple real words strung together:  "zebra goldfish piano golf".  While that is just four real words, all in lower case, that phrase of 25 characters is not in any dictionary, so it isn't subject to a dictionary attack, and it isn't associated with me in any way, so it cannot be guessed from my personal information.  In addition, even though it uses only lower case letters, it's long enough that reversing the encryption on it will be very hard.  This technique - stringing together a few normal words that you can easily remember - is a powerful one, and it is recommended if the system you are using supports it.  Note that you should not use words related to the system in question, either; "password for yahoo mail" is a poor choice for your yahoo mail account.   Also note that the spaces are optional: "PeanutSystemFlagCthulhu" is a perfectly good password.

If the system you're using requires shorter passwords, the best technique I have encountered is to use the first letters of a phrase, often with some substitutions or case changes.  For example, if I remember the phrase: "This is my password.  It should be longer."  I can use the first letters to create my password: "TimpIsbl".  If I want to I can substitute something like a number 1 for an i, and perhaps a $ for an s, creating: "T1mpI$bl".  These kinds of passwords work well on systems with limitations on length and/or characters allowed.  They are not easily guessed, provided the phrase is well chosen and unrelated to you in any way, and can contain as much character diversity as whatever system you're using allows.  Pick a phrase that you will remember easily, make a couple of substitutions in it, and you're done.

Whatever you do, don't use a single, real word as a password, and don't use anything easily associated with yourself, your family, your history, or the system or company the password is related to.

Here are some other things to avoid while creating passwords:

Managing multiple passwords is a challenge, so some people use passwords that are related in some way to help remember things.  This can work, but can also introduce risks, so be careful.  If all of my multi-word passwords are of the same form:

        password 4 email
        password 4 bank
        password 4 shopping

they are much less secure.  If one gets compromised, the bad guys might start guessing at the other passwords I use with some success.  Thus, patterns in your passwords should be avoided.

Some systems require you to change your password regularly.  In my opinion this is a really poor choice on the part of the system administrators, but it does happen.  Many people using these systems can't remember their passwords since they change so often, so they do one of a few things to help remember them.  Often they write them down somewhere, resulting in a list of passwords that they just add to as they change, and making their password available to anyone finding the list.  Alternately they may use change some part of the password each time but leave the rest the same.  This can result in much less secure passwords, commonly involving dates:

        MayPassword
        JunePassword
        JulyPassword

and so on for a system requiring monthly changes.  These sorts of passwords are less secure than a good password that is unrelated in any way to the user (even if that password changes much less often) and they regularly get written down too.

Telling your system administrators that password rotation is a bad idea will probably get you nowhere, though, so be a good citizen and pick a new, good, password each time, preferably using one of the methods given above, and read on to learn a bit more about how to manage large numbers of passwords.

How To Manage Too Many Passwords:

I don't know about you, but I am lucky to be able to remember the number of my own cell phone, so a huge list of passwords is a real problem.  And in this day and age that huge list is all too real. Keeping them straight is a significant challenge, one that I am not certain we have resolved just yet.

Still, there are at least a couple of approaches for this sort of thing.

The first is to avoid passwords entirely whenever possible.  If an online shopping site gives you the choice, don't create an account with them.  Yes, it means you'll have to enter your data every time you come back, but you also won't have to remember another password.  An added benefit is that they may not keep any permanently stored data about you, which means there is less chance of having your data compromised if their servers get hacked.

The alternative is to create a throw-away login every time you use a site, and never come back to it.  You can use a random string as your password and not remember it at all.  If they need an email address, remember that many email systems let you add a dash and additional characters to your email address, so you can give them something unique, and later filter out all email from that site if they start sending you spam.  For example, if your email address is foobar@gmail.com, you can tell a website that your email address is foobar-xyz@gmail.com.  Then, after your business with the site is finished, you can add a filter in gmail to get rid of anything sent to foobar-xyz@gmail.com.

If you really want to sever the connection between you and the site, though, create a whole new email address with any of the free email systems, use it for one or a few transactions or sites, and then delete it.

And while you're thinking about this, you don't have to give most sites on the Internet real data about you.  They want your birthday?  Tell them you were born on January 1, 1902 and are thus well over 100 years old.  How will they know it isn't true?  Remember that any personal data you let out is something that can be used against you, to hack any less than perfect passwords, or as part of a concerted identity theft effort.  If there isn't a good reason for the site to have that data, don't give them anything real.

But even using those tactics we still have too many logins and passwords to remember.  The list is long: banks, shopping sites we use a lot, places we pay bills to, information sources, and so on, not to mention the inevitable systems at work.  In these cases you cannot create a new account each time, and thus an alternative is needed, and that alternative is called password management software.

Password management software gives you a way to store all your passwords in a safe, encrypted format.  You get at them using a master password, and then once that system is running you can copy your user names and passwords and paste them into the login pages of websites you use.  When you exit your password management system it locks up your list of passwords in an encrypted format that, in theory, only you can get at.

The security of all password management software requires that your computers are up to date and virus free.  Anything that can run at will on your computer and/or log your keystrokes means you have no security, so always, ALWAYS, patch your computers and keep your virus scanner up to date.

There are at least 2 kinds of password management software:
  • It may be installed on your computer
  • It may be a service you use over the Internet
Software installed on your computer means that no one other than those with access to your machine has any chance of getting your passwords, so it is potentially safer.  On the other hand, you can't get to your passwords from multiple computers, so if you use more than one it may be less useful.  Do an Internet search for "password manager" to find programs available that do this sort of job.  Compare them for features and read reviews before making a choice.

An online password manager does the same job as one you install on your local computer, but it is a service provided by a company, and it requires an Internet connection to use.  That may seem like a drawback, but remember that if you need passwords you're probably online already, so it generally doesn't matter.  Online services of this type let you access your passwords from more than one computer - you just need to remember your master password to get in - but your data is stored on their servers, not your local machine.  I suggest looking for services where all encryption is done on your local computer before any data is sent to the servers.  That makes the data more secure, but it usually means that the service provider cannot recover your data if you forget your master password.  A search for "online password manager" will find these services.  Again, compare carefully before making a choice.

Both locally installed and online password managers let you save user names, passwords, URLs, and often other data associated with each login you're storing.  They have user interfaces that let you copy a password without displaying it, making it impossible for someone looking over your shoulder to see what your passwords are.  Many have tools to generate new, strong, random passwords for you, so that you can create unique passwords for each site you use.  Some have the ability to automatically log you in to sites as well.  Once you store the URL and the needed login data, you can get the tool to bring up a new browser window automatically logged in to the site of your choice, usually with just one mouse click.

Password management tools are important if you have to manage many different accounts, but they all suffer from the same weakness: the master password.  If that password gets compromised, all the passwords you have stored in the service or software are at risk.  For that reason it is critical that you treat that master password with care, and that it is as strong as you can possibly make it.  Never, under any circumstances, share it with anyone, and don't write it down.

I'm not going to recommend a password manager program.  Doing so is beyond the scope of this document, and individual requirements vary substantially, but there are quite a few choices available.

Other Thoughts On Passwords:

Many online systems make use of so called "security questions" as part of a password reset system.  Basically they let you select one or more questions and tell them what answer to expect when they know who you are, and then later - if you forget your password - they ask you one or more of those questions and will do the reset if you provide the expected answer(s).  The problem with these systems is that they are inherently weak as most users deal with them.  Maybe you're given a choice of the following questions:
  • What is your mother's maiden name?
  • What was the name of your first pet?
  • Where were you born?
  • The last 4 digits of your social security number
And you give them answers like:
  • Marx
  • Groucho
  • Tuskaloosa
  • 1234
The problem, of course, is that none of that data is secure in the modern world, and yet each one of those answers is, effectively, a password, and should be treated like one.  Of course that data is easy to remember, but by this point in your life how many people know where you were born, or the answers to any of those other questions?  If you're like most of us the answer is a lot of people know these sorts of things, and many of the rest of those answers can be searched for on the Internet for little or no money.

For some reason it seems like almost every company I deal with uses the last 4 digits of my SSN to confirm my identity, and with genealogical web sites abounding, mother's maiden names are common knowledge.  In fact, the answers to most of the usual security questions are a very simple social attack away from being compromised, if they aren't already commonly known or easily searchable.

What to do?  Treat those questions just like they ask for a password, not as a request for specific data.  The computer will never know that your mother's maiden name isn't really "Cg6y_t@$fg", but the bad guys won't know that was what you answered that question with either.  Of course, now you have yet another password to remember, and this one is going to get even less use than the regular password you use to get into the site, but if you're using a password management system which lets you take notes, you can log the security questions and your chosen - nonsense - answers there, for lookup when you need them for some reason.

This may seem like a lot of effort, but it is easy to disrupt people's lives - and sometimes steal their money or identity - using password recovery systems.  Don't treat them lightly.

Another place where we get lazy - and risk compromise - is by letting our web browsers store passwords for us.  This is very convenient, of course, and at times it is just fine.  If your browser remembers your password for the local newspaper, perhaps, and it gets compromised, someone can read articles and maybe post comments as if they were you.  Not necessarily a big deal.  Things get worse, though, if your browser remembers your amazon.com password.  Now a thief can login and order things using the credit card numbers you have saved there, possibly costing you real money and time.  And if your banking passwords are stored in your browser, well, you might just as well leave your keys in the car and the engine running all the time.

Browser based password storage is fine for sites with essentially no risk as a result of a stolen computer.  But if there is anything important on a web site, don't ever let any browser store the password for you.  You have to remember it yourself, or use your password management system to keep track of it.  Anything else is asking for trouble.

And, of course, never use browser stored passwords on a shared or public computer.

ATM PINs are among the worst possible passwords in existence.  If they're limited to 4 digits there are only 10,000 possible PINs, which is way too tiny a set.  Sadly, though, ATM networks often don't deal with longer PINs.  I encountered this once, years ago, while travelling overseas.  My ATM card worked just fine in the US with my longer PIN, but was useless in ATMs where I was.  I only figured this out once I was over there, of course, and I had to go into banks to get cash.  Hopefully the banks will get a handle on this, but always be extremely careful with your ATM card.  Once lost it is a high speed route to an empty bank account.

In Summary:
  • Create good, strong passwords using the initial letters of a phrase or several unrelated words strung together.  In either case additional security comes with some character substitutions into upper case, numbers and special characters.  Be sure your selected phrase or words aren't related to you or the system in question too.
  • Never share your passwords with anyone, deliberately or otherwise.
  • Never use the same password for multiple sites.
  • Consider using password management software if you have too many passwords to remember.
Welcome to the modern world.  Ain't it fun?

Update 9/26/11: my friend David Clunie posted a blog post about this video, that discusses some of what I talk about above.  Thanks David!

Tuesday, March 30, 2010

Embrace the Cloud

I've got multiple friends who hate the entire idea of cloud computing.  They despise storing their data on the servers maintained by someone else, particularly Google.

I am rapidly coming to the opposite conclusion, and that's despite having a less than optimal ISP and a connection that rarely gets any faster than about 850kbps.

As I have used the cloud I keep finding things it makes better or simpler.  The first - and most obvious - is backup.  If my cloud providers are backing up the data for me, I don't need to worry about disk failures.  And as I am one who has suffered traumatic data loss in the past - at work, in an environment where there was no automated backup of desktop systems - I really appreciate letting someone else worry about the safety of my data.

There are a couple of obvious counters to that argument.  The first is that my cloud provider might disappear - probably by going bankrupt - taking my data with it, or their backup processes might be less than optimal.  For that reason I tend to use major companies as my providers.  Yes, bad things could happen, but it isn't likely, and the chances of my laptop being dropped or suffering a disk failure are much higher.  And for anything critical I can always download a copy, right?

Another obvious objection is that the cloud provider might decide my data is evil in some way, as when a blogging site shuts down a particular blog for containing spam, even if it really doesn't.  Recovery in that case is problematic, but it is possible if your provider has a system in place to review those decisions.  My own documents and content are pretty tame, and definitely not spammy or copyrighted by anyone else, so the odds on hitting this issue are slim at worst.

Data security is another objection I hear.  "I don't want X to have my data."  And I get that to some degree.  Some people hate the idea of their cloud provider scanning their data to better target ads, or whatever.   At some point, though, it is important to step back and assess the nature of your data usage.  An absolute minimum is really private.  Financial information needs to be kept safe, of course.  Health records might need that kind of protection, but as the nation limps towards electronic storage for that data it might make sense to put what I have online somewhere that my doctor can see it and add to it, right?  I suppose the occasional letter or some such should be private too, but in all honesty, who is going to read such things?  Who would even want to?

If I had something to hide I can imagine feeling very differently about this, but the vast majority of us are law abiding people who value convenience over that level of security, at least as far as trivial data goes.  Yes, I'd love to see something legal that prevents ISPs and cloud service providers from examining your data without your express consent, but until then it's a simple matter of keeping the few things I really care about out of the cloud.  The rest can go there, in theory.  It's convenient.


And make no mistake about it, convenience is what matters.  I like being able to edit documents online and know that they will be there when I change computers, without any complex data migration issues.  I like being able to share some of those documents with others too.

Picking the right cloud supplier, though, also requires examining their systems and polices to see what it takes to get your data out if you need to.  Here, so far, Google is a star.  All the services I use with Google (except Blogger, amusingly) make it easy to get my data out in useful formats.  Google docs, in particular, lets me export to my local disk in several ways that can easily be imported into other applications.

I'm sure there will be replies to this post from those who disagree, and I'll be accused of being simple minded about these things.  But for me, at least for now, the cloud is looking better and better.  Bring on Chrome-OS, too.  Something small and fast would be great.  Even better than Linux.

Thursday, January 28, 2010

Thoughts on the iPad

I'm not a Mac fanboy.  I bought two Macs in the dim and distant past and both had serious problems.  More recently I find that Apple's prices are too high and their products - while they work very well if you're doing exactly what Apple anticipated - are problematic if you're trying to do something Apple's engineers didn't plan for.

All that aside, I find the iPad interesting, at least as a concept.  I am unlikely to buy that specific product from Apple.  The cost is actually OK, as far as I can tell, but...
  • I hate ATT as a network provider.  (And no, Verizon isn't any better.  Currently I'm on T-Mobile, which has much better customer service than either.  Their network, I know, isn't nearly as good, but then again I don't travel all that much, so it's OK for me.)
  • It has no multitasking.
  • Battery life may not be long enough to be a good e-book reader.
What the iPad does, though, is whet my appetite for something similar.  The vast majority of what I do on a computer could be done on such a device, though I'm not entirely sure about the keyboard without trying it.  Still, a fanless, lightweight, general purpose computer of that form factor could be very handy.

Imagine something of the general size and shape to the iPad running Chrome OS or a similar Linux variant.  (Such a device needs a lightweight OS, not Windows or MacOS, but something specifically designed for this environment.)  It should have a good integration with the Internet - essentially providing a cloud computing environment - but I also want both local data storage and locally run applications.

Being fanless is important to me. My existing laptop is just fine until I am sitting in a quiet room trying to think and the fan clicks on because FireFox is using too much CPU.  That's deafening and silly.

I also want a customer replaceable battery.  I know that will add to cost, weight, and thickness, but it's simply a requirement.

I just read a rumor that Google and HTC may be working on a tablet style computer.  That's what actually made me write this.  That's a device I'd love to see, and if they did a good enough job I'd buy it.

This is all just idle speculation on my part, but the age of the tablet computer may be coming.  I look forward to seeing what it looks like.

Wednesday, December 9, 2009

Initial Experience with Google's Chrome Browser for Linux

Yesterday I installed the first generally available beta release of the Chrome browser for Linux. Initially it seemed OK, and a friend asked for a review, so here it is. Sadly, however, I am back to using FireFox. Chrome isn't ready to displace FireFox yet. At least not for me. Maybe someday.

The issues I encountered include:

  • There is no "Open All in Tabs" option in the bookmark menus. This may just be something I do, but every morning I use:
          Bookmarks | morning links | open all in tabs
    to bring up at least a dozen web sites that I read while I wake up and get ready to face the day.  I find it handy to have that ability, but that feature is not present on Chrome.  For me, while this isn't a deal breaker, it does make it less likely I'll stay with the browser.

  • Java didn't work for me at installation.  Javascript is fine, I think, but Java is dead. Chrome attempted to pull all of the configuration information from my FireFox installation, but apparently there is something about the Java config on my Linux machine (running Ubuntu 8.04 LTS and FireFox 3.0.15) that it didn't understand or like.  I posted this problem to the Google Chrome Help forum and so far the only response has been several other people saying they have the same issue.  Maybe there is a fix for this, but if so I don't yet know it.  For now, this is a serious issue.

  • This isn't a big deal, but there isn't as much control over fonts with Chrome as there is with FireFox.  That's a blessing and a curse, of course.  It's easy to screw up someone's CSS based website by telling FireFox that sites cannot override your font choices and/or selecting font sizes different from those the site expects, but I live with it and make use of it regularly.  I could live with what Chrome offers, but it's an irritant.

  • I cannot yet tell if Chrome is actually faster or more stable than FireFox.  My network connection isn't stellar, so delays are often the result of that rather than anything going on in the browser.  Plus, one of the major speed ups is supposed to be the way it runs local scripts, but Java isn't working, so...

  • I cannot get Chrome to display PDF files in the browser.  This is a significant problem, and once again FireFox handles it just fine.  If a link points to a PDF file FireFox opens it up in Acrobat (which I installed myself a long time ago, and whose configuration Chrome should have imported).  When this happens I get the Acrobat tool bar inside the browser window and can look at the document.  Sadly, however, Chrome just downloads the PDF file and then stares at me.  I was able to right click and save a copy of the PDF, but that's not as useful as viewing the document in the browser in many cases.  For me, Chrome for Linux strikes out there.  That said it's still a beta, and there might be something odd about my Linux install that keeps it from working out of the box.  Still, this is a problem I cannot work around.

  • At least one site doesn't work with Chrome that I know of, and my testing is pretty limited in that regard so far.  Now, I admit the site - a registration site for a non-profit I am affiliated with - is not setup to deal with FireFox all that well either, but it generates PDF files in some cases, and that breaks down as mentioned above.  Beyond that, however, after encountering the PDF load failure I was unable to get Chrome to download the PDF for external viewing.  It might have been user error, but it bugged me.  I had to switch back to FireFox to check on something because of it.

  • Finally, they've done some odd things with a menu and the way new tabs are opened up.  I think they've missed the UI boat as a result.  First, the menu issue: in FireFox if I put the cursor over a link and right click the top two menu choices are "Open in a New Window" followed by "Open in a New Tab" in that order.  Chrome reverses those menu options, so I was perpetually opening new windows with it when I meant to open new tabs.  That's an irritation that I could get over, though.  Yes, it's different, but yes, the most common option should be first.  And I suspect most of us actually open more things in tabs than windows these days.  With time I am sure it would become natural.

    It's what happens when I actually manage to get a new tab to open, though, that bugs me.  Say you're in FireFox and have 3 pages open, in tab1, tab2, and tab3.  You're currently viewing tab2 and you open two more pages (in tab4 & tab5) via the right click, "open in new tab" menu option.  When you're done you wind up with tabs arranged like this:

    tab1  tab2*  tab3  tab4  tab5

    (Tab2 is starred because it is the current tab.)  And that arrangement makes logical sense.  New tabs open on the rightmost end of the list, and they open in the order I make it happen.  If you do the exact same thing in Chrome for Linux, though, you get this arrangement:

    tab1  tab2*  tab5  tab4  tab3

    In Chrome new tabs open immediately to the right of the tab containing the current page, and they shift all other tabs to the right in the process.  That's just wrong, at least for me.  My brain is (more or less) wired to think of things linearly.  if I open tabs I expect them to appear in the order I open them, not the reverse of that order, and I expect to find them on the end of the list for easy access.

    I'm afraid Google just got this one wrong.  The FireFox behavior here is actually the right one.  As with some of these other issues, though, it is something I could probably live with given time.
That's the list of issues so far, and it's enough to have moved me back to FireFox for the forseeable future.  I'll look at later betas of Chrome and see if it improves, but for now I have to say there are a couple of serious issues and a number of nits that bug me.  It's not worth changing.

Google gets a lot of things right in my view, but not with Chrome for Linux.  At least not yet.

Friday, July 31, 2009

No, I don't "Tweet"

Here's another in a series of posts that will almost certainly offend some of my readers. I apologize up front, but I stand by my premise...

Yes, I am something of a Luddite, but that doesn't mean I'm completely nuts. Lately I am starting to think certain uses of technology are simply a bad idea. Consider:
  • Twitter
  • Facebook
  • Power Point in the school
All of these suffer from a single major issue: they encourage tiny thinking.

Yes, I know that Twitter has become a major news source, and yes that's a good thing. It may even be a democratizing influence, but all kinds of technologies with a few good uses suffer from huge drawbacks. I'm not going to make a list by way of example. If you can't come up with a few genies that did both harm and good when let out of the bottle you're not trying.

Put plainly, Twitter actively discourages complex thought. Far too many Americans can't string even a few words together. If the current generation grows up communicating in ultra compressed text snippets I really don't want to think about where we'll be. I am certain I won't like it though.

Facebook looked interesting to me after I started using it, and there are a lot of people I simply don't see that often. Our hectic lifestyles mean I'd never know what they are up to without Facebook or something like it. Lately, though, I've encountered something I don't like: people are mirroring their incomprehensible twitter feeds into their Facebook status updates.

Maybe I'd understand them if I did nothing but follow Twitter and/or their lives in depth, but I have a wife, a job, dogs to take care of, and things to to in the real world. Trying to understand these cryptic messages typed in on phone keyboards from the middle of nowhere isn't going down well with me. In truth I could probably ignore those - possibly by disabling the feeds from the guilty - but there's a related trend, and it's just as disturbing: short, pointless, repeated Facebook status messages.

How often do I need to know that someone is tired, or is going to bed? The minutia of daily life is just that: minutia. Tell me about the important things - or even the semi important things. Did you get a new job? A new house? Get engaged or divorced? Celebrating something important or had an epiphany of some sort? Great! Share away. Tell me about your kids, the things that made you whoop for joy or scream in despair. I'm fine with all that, and I will whoop or cry with you. I'll even do my best to support you when you're down. Just please don't use the vast resources of the Internet to tell me you're home from work.

Years ago I heard a story on the radio about a pathological diarist. He documented every little thing in his life: what he had for lunch, at what time, where he sat while he was eating it, what he was going to next (after updating his diary), and so on. As I recall he was in his 40s or 50s and his diary was many, many books, all full of hand written, pointless drivel about nothing. I pitied the guy, and I suspect that vast diary will be thrown in the trash when he dies. No one is going to care, and all that effort is wasted.

I feel somewhat similar about people I know telling me (and all their other Facebook friends) they had green beans with dinner. Part of what causes these kinds of status updates - besides most of us (myself included!) having nothing important, relevant, or useful to say the vast majority of the time - is that the silly status box is so small. Facebook doesn't limit you to a tiny comment like Twitter, but the interface encourages it, and recent design changes at Facebook indicate they're moving farther in that direction. Yet again a powerful tool is helping make all of us - or at least its users - less capable of complex thought.

I must admit I've posted pointless status updates myself many times, but I am trying to stop it now. Actively working at it. Feel free to tell me this blog post qualifies as the same kind of inane babble, but at least I am trying to address a complex topic - something I care about - and am doing so in whole paragraphs, with real thought behind them. (Or the closest analog to real thought I can achieve.)

The last item on my list - Power Point use in schools - is just as bad, and just as dangerous to the future. An entire generation is growing up thinking that the best possible communication path is animated bullet points that slide into place on a screen with sound effects. "The Panama Canal is in South America. Click! Ships go through it. Click! The US helped build it. Click! And that's my presentation. Can I get my 'A' now? No? But I wrote the right number of bullet points and I had pictures and everything!"

How many avid readers do you know? How many of them are kids?

What about writing? Does anyone you know write more than a hundred characters with regularity? Probably not.

Nothing encourages thoughtful, intelligent communication anymore, and the technologies listed here are radically changing the way we communicate whether we like it or not. I am not optimistic about the direction of that change.

Sunday, March 1, 2009

Something Complicated Actually Worked!

I've been so busy lately I haven't been posting much. I apologize to each of my three readers for leaving them in suspense too often.

Today I get to report on a bit of good technology news. As you may know, my recent luck with tech - particularly computers - has not been stellar, but just this once I have something to share that seems to be OK.

My ISP - a no name outfit that does wireless connections here the in the Santa Cruz Mountains where Verizon and cable companies dare not provide reasonable service - has been giving me fits lately. The connection has been poor at best, and sometimes didn't work at all. They've been out for a couple of visits (one of which they've billed me for, which I will be complaining about to them soon) but in the end had to admit that they were simply unable to get me a reasonable signal. Not good.

In desperation I've searched for alternatives, and finally settled on something that seems to work. It's not lightning fast, but it works. It's an EVDO connection provided by Sprint in my case, though others can get something similar from Verizon.

I ordered an EVDO modem from Verizon and a Kyocera KR2 EVDO router. The modem arrived on Friday and I began playing with it. There, I appeared to hit a wall. Initializing it required a Windows machine which I lack. Thankfully I managed borrow one from a friend and did the initialization there. Once done, I could simply plug the EVDO modem into my Ubuntu 8.10 system and connect to the network from the network connection tool. It just worked. Amazing.

Even more amazing was the fact that the router arrived before I visited the friend who loaned me the Windows machine. Once I had initialized the modem and tested it in my Ubuntu 8.10 laptop, I removed the KR2 from the box, plugged the USB modem into it, connected the router to the laptop, and plugged in the router's power supply. Once everyone's POST had completed and the EVDO modem had said "hello" again to Sprint, I was back online, this time through the router, which also acts as a WiFi hotspot.

In other words, except for the silly requirement that my EVDO modem be initialized under Windows (or a Mac), it all just worked. Perfectly. First time.

That never happens.

So now I get to do some speed testing with it and see how it actually performs. So far we know it is an acceptable alternative, but we've done no optimization about placing the modem, etc. I may also need to add an external antenna to increase the bandwidth, but I'll learn that with time.

Right now what I have is something we can use when my regular ISP's connection isn't working properly. And if we can live with the data rate and the 5GB/month cap, I may be able to say good-bye to my old ISP permanently. Give me a couple of months to figure all of that out. I promise to report on it here eventually.

Sunday, February 8, 2009

I hate computers...

Yes, it's true, I despise computers, despite having programmed them for nearly 20 years and continuing to earn a living from the silly things.

I have a nice big rant building up inside me about how Linux is only the lesser evil among a selection of evils ranging all over the map in power and degree of vileness (is that even a word?), but for now, let's just say I hate computers in general. Every beeping one of them.

Why, you ask?

I've been trying to setup a new computer for 2 days now. Not much luck.

Oh, it runs, sort of. But I can't get the device driver for my graphics card to work, and the sound drivers completely fail too. But my OS is from April of 2008, so clearly it's just too old. The proprietary video driver is only supported by the latest version, and it appears that version may have better support for the open source driver too.

So far today the only thing that has gone right on the computer is this: I managed to replace the busted keyboard in my laptop with one that works. The stupid little trackpoint thing was causing the mouse cursor to move whenever I typed on the keyboard, and since I use focus-follows-mouse, that was a bit of a problem. Plus, once it started moving it was sometimes 30 seconds or so before it stopped being wedged in a corner of the display. Very irritating.

So at least that's working again, which is an improvement. It's actually possible to use it as a laptop again.

So, while I continue waiting for Surfnet's lousy network (don't get started... don't get started...) to download an ISO image of the latest Linux version - in the desperate hope it will deal with the video and sound options in my new computer a bit better, even though it will have bugs too, some of which I am already familiar with from other installations - I am going to go do something much less painful: tax preparation.

That should give you some idea of just how screwed up my weekend has been thanks to these infernal "labor saving" devices.

Sunday, January 25, 2009

The Printer Works

Small miracle: the Xerox Phaser 6130n that I bought works with Linux.

My version of Ubuntu (8.04) didn't want to support it initially. It didn't have a driver available and recommended a driver for a different Xerox model. That did not work. It spat out a few pages with gibberish on them instead of a test page.

I grubbed around on the CD that came with the printer and found a directory named "Linux". What? A major manufacturer supplying something for Linux right out of the box? Great! But what was in there was a .rpm file for a driver. Ubuntu doesn't use .rpm files for packages, it uses .deb files.

There is a way to convert between .rp and .deb package formats, and I started down that path, but simultaneously I went to the Xerox web site to see what they had out there. I hoped they'd have a pre-built .deb file I could download, since Ubuntu is pretty popular.

What I found, though, was a bit different. They had PPD files available, and PPD files allow the CUPS system to work with a printer just like a driver does. (Or so I gather, since my choices were to install a driver or a PPD file.)

So I downloaded the archive full of PPD files, extracted the one for the 6130, and installed it.

Like magic, the printer worked. It prints in color, prints images, etc. This is great news.

Every ink jet printer I've ever owned has ended its life with print heads full of dried up ink that will not be removed and prevents clear printing. The most recent one, while it was suffering from a clogged print head too, actually died a horrible mechanical death when something went "POP!" inside it one day. It never printed again.

I hope this new Xerox 6130 works out well. I've been without a printer for months now, trying to figure out what laser printer would work with Linux.

So far, so good!

Sunday, October 19, 2008

Computers and Fast Stupidity

I believe it was Scott Adams - creator of Dilbert - that once claimed we are all - every last one of us - stupid. A few minutes ago I refreshed my memory on that point. I am stupid. The loveliness of it in this case is that I used a computer to accomplish my stupidity, and therefore did it very quickly.

I am in the middle of a major set of updates to my website, and a big part of that website is my sculpture gallery. I wrote a program to create that gallery some years ago. Over the past month I'd made a slew of changes to that program, tested them, and was just about done. This morning I thought of one more change I wanted to make, so I started in on it.

That change required me to create a bunch of new files from a template. I created the first file and copied it over into all the other directories where I needed it. It was that copy that did me in. I automated the command and didn't test my automation carefully enough before running it. My 20K script for creating the gallery got written over with a copy of the new, one line, text file.

And before anyone tells me to go out and use some utility to get it back, I live on Linux, not Windows, and the file was overwritten, not simply deleted. The data blocks have been reused.
It's gone for good.

I have a copy of the script from before all my recent changes, at least. That gives me a starting point and saves a lot of time, but I still get to make the changes all over again. That's not even all that hard, really, as I know this stuff pretty well. But it does use time I could have spent on other things.

Oh well. Live and learn - and test carefully before running stupid, four line scripts that copy or delete files!

I'm off to start work on putting things right again.