Showing posts with label tech. Show all posts
Showing posts with label tech. Show all posts

Friday, December 19, 2014

It's almost like a new machine

So I made some updates to my desktop computer, finally:
  • Upgrade from Ubuntu 12.04 LTS to 14.04 LTS.  Yeah, I know, I'm not exactly a fast follower here, but I like my machines to work. Waiting a while to update to the next long term support release feels smart. I let others work out the kinks for a while before moving up.
  • Changed from 32 bit version to 64 bit version. I tried 64 bit a while back - probably in the 10.04 era - and had no end of trouble with software not being available in 64 bit, or not working properly. It appears those issues are now resolved.
  • Changed the boot disk from a standard hard disk to a solid state disk. Just a small one (128 MB) from Crucial but plenty big for the OS and swap space.
The difference in how the machine feels is amazing.

Boot time is substantially improved, though the POST on this motherboard still takes forever.

Apps load faster. Much faster. All that I/O wait while Chrome loaded for the first time is gone. Or rather, it's not gone, but I don't note it happening anymore.

Even simple things like working with email and playing YouTube videos are faster and smoother. I'm not sure why that is, but it seems to be.

This system has a new lease on life, which is a good thing. I hate buying new computers and this one should go another two years easy now. Maybe more than that.

Monday, October 20, 2014

Cognitive Dissonance At The Gas Station

You've all probably seen the sign at the gas station telling you not to use your cell phone while filling your tank. Something like this one:


The first thing to know about that is that it's wrong. No one has ever found a connection between cell phones and explosions at gas stations. No one.  Here, check it out for yourself:

http://www.snopes.com/autos/hazards/gasvapor.asp
http://www.hoaxorfact.com/Technology/explosion-at-gas-station-mobile-usage.html

Yes, a spark can cause a fire from the gas vapors, but cell phones don't spark unless something is seriously wrong - perhaps like this:

http://www.phonearena.com/news/Apple-iPhone-4-allegedly-catches-on-fire-while-charging-overnight_id28312

That said, you wouldn't think the company that put up that stupid sign saying you should turn off your phone also put up this:


Yes, those signs are on the very same gas pump. I've grayed out much of it because it doesn't matter. Just in case you can't read it, it says "SMART PHONE CHECK-IN at a Valero Station to receive one (1) entry to sweepstakes." Really.

Turn off your phone!
Use your phone to check in and enter our sweepstakes!

Hey, Valero! Which is it? Will I die in a fiery explosion if I check-in? Can I (or my next of kin) hit you with a suit if that happens?

Sometimes I have no idea how we continue to survive.

This shouldn't bug me, I know. It's a small thing, but it is the small things that help explain why we haven't found intelligent life anywhere in the universe yet: because there isn't any. Not even here on earth.

Monday, March 3, 2014

Passwords Revisited

A while back I wrote a long post about passwords: how they work, how they are cracked, how to pick them, etc.  Here's a link to it.

But computer security is an arms race. The bad guys change tactics to react to what the good guys (that would be you) do. In this case, one of the ideas that was newish (at least to me, at the time) isn't so useful anymore. Much of that post is still relevant, but apparently hackers have started cracking passwords made of disparate words strung together.

Here's a post from Bruce Schneier - someone I trust in the security field - that discusses choosing good passwords. His preferred technique is one I discussed as well, so not all is lost.

https://www.schneier.com/blog/archives/2014/03/choosing_secure_1.html

I'm really glad to hear him say that changing passwords regularly is more trouble than it is worth. I wish more computer security places understood that.

So, read what Bruce has to say. It's good advice.

Wednesday, February 12, 2014

Well now... that's something nice I never knew...

I'm sure I am the only one who didn't know this until just now, but if you're a Chrome user, you can grab a tab and drag it off, away from the chrome window, and it will get put into a new chrome window by itself.  And, correspondingly, you can drag a tab into another chrome Window and it will get sucked in and become a tabbed page in that window.

There's a bit of trickiness to getting tabs to merge into other windows... I haven't yet figured out all the magic, but it definitely does work.

I can't tell you how many times I have opened a new window and then loaded up a page I had open elsewhere so I could compare things side by side.

I wish I'd known about this a long time ago!

Saturday, December 28, 2013

Linux Rant IV

These posts are starting to need better names. Maybe something like:

Linux Rant IV - Revenge of Gnome-Shell

So that went well. Not.

Debian 7.3.0 installed cleanly and booted. It looked great. But when I logged into Gnome, it was just as slow as anything Ubuntu did. Crawling. Awful. Unusable.

Diligent digging - aka, bringing up the system monitor and looking at what processes were eating CPU time - showed the culprit is named gnome-shell.

Some googling leads me to wonder if I didn't trip over a known problem in Gnome. Perhaps something in this thread about an llvmpipe being a problem is related. I have no clue.

http://forums.fedoraforum.org/showthread.php?t=285415

In any case, Debian 7.3.0 running Gnome is just as useless on my laptop as Ubuntu running Gnome. And that makes me worry about (eventually) installing anything running Gnome on my desktop machine.

I am starting to wonder if I will ever get something to run on these laptops without significant pain. And it turns out that my wife's laptop has an ATI graphics chip in it, not an nvidia, so all this work on my laptop might not lead to a solution for hers.

I am just thrilled with all of this. Thrilled I say.

Going to have to discuss options with the wife. It may be time to throw in the towel and get new laptops.  These were purchased in Feb of 2004. Yes, really. They are almost 10 years old. We could probably spend $400 each and get something much faster. Ben was telling me to do this the other day, and while I hate to admit it, he might have a point. Gotta think it through.

Such fun. Hopefully this is the last Linux Rant for a while. At least until George Lucas and/or Disney get their grubby hands on the rights to them. The sequels will probably be really painful.


Linux Rant III

The story so far:

Desperate to find a linux distribution that runs well on ancient Pentium M chips, our hero has done some awful things with Ubuntu, installing 10.04, then upgrading to 12.04, but at that point the display driver stopped working, and he got sick of it. We pick up with the action there...

With the help of my friend Ben, I was lead to the magic of Ctrl-Alt-F2, which brings up a text login screen (aka a tty) so I could login to the running Ubuntu system, even as the GUI was running and completely unusable.

Some poking around - again aided by Ben - revealed that the laptop has an nvidia graphics chip, and that it was running an open source driver. That driver - I know from past experience - is bad news and doesn't support at least some older nvidia chips, including mine. So I googled around and figured out how to install the proprietary driver from nvidia, which does know how to work with my machine. Installed it. Rebooted.

Change 1: now the system comes up with a little tiny graphics window as it boots, instead of using the full screen. Odd, but I don't care because... I can login and the graphics work again. Well, sort of...

As with the boot side of things, I wound up operating in a little, tiny screen - 1024x768 out of a much larger monitor capable of supporting much higher resolutions. Odd, but at least I can login and work within Linux now without going over to a tty.

Dig into system settings and found the proprietary driver tool, in which I learn that the nvidia driver, while apparently installed, hasn't been activated yet. OK. Activate it. And wait while it downloads and installs the driver again. Huh? But never mind that because once it completes it tells me that the driver is now activated. All I have to do is reboot, which I do, and...

Success. Amazing. The login screen is still really tiny for unknown reasons, but after logging in I get a full sized, max resolution screen. Ubuntu 12.04 is actually running on my laptop.

But that isn't all I wanted to do, sadly. I want to get rid of Unity, a user interface that I continue to dislike. Back to Google and there are some simple steps I find to install Gnome. It will be a choice at login time, apparently, which UI runs. So off to the software center to get and install Gnome. Done. Reboot.
Aside: has anyone else noted that I am rebooting an awful lot? It's like working on bloody Windows. But I digress...
The system comes back up and I select Gnome. Actually, Gnome 3, I think, as it isn't obvious. The choices are "Gnome", "Gnome Classic", and "Gnome Classic (no effects)". You tell me.

And the screen clears... and there is a looooong pause. Minutes. Then a menu bar appears at the top of the screen. Is it done loading? I don't know. I have never used Gnome 3, and don't know how it is used. Move the mouse to one of the icons in the upper right and click. Nothing happens. Try right click. Nothing happens. Hmmm. Odd. Maybe this menu looking thing on the left? Again, nothing. Maybe it's stuck?

Force a reboot.

Login again, but this time to "Gnome Classic". And wait a loooooong time again. When it finally appears at least it looks something like the UI that Ubuntu was using before Unity. Good. But it's also unresponsive.

Force a reboot. Try "Gnome Classic" again. This time be more patient. Mouse to menu, click, and wait. Oh... look! Eventually the menu appears. Well... that indicates there is a real performance problem. Start the system monitor and wait for it to come up.
Aside: yes, I am an idiot. Should have done ctrl-alt-F2 again and used top. Instead I waited forever for the system monitor to come up.
In the end I learned the CUP was 100% busy, and eventually learned that something called compiz was the culprit.

Over to the other computer. Google something like "compiz using too much cpu". Lots of complaints, various proposed solutions. Try a couple of them, including installing magic software to muck with compiz internals and speed it up. (From the tty, of course, where things run reasonably quickly.)

Reboot, again. Login to Unity this time. The usual UI, quick and fine. OK. Logout, login to one of the Gnome choices. Still slow. Worse than molasses in January. Not good.

Give up. This sucks. Apparently Ubuntu has decided that my hardware isn't worth supporting, that Gnome is an afterthought on 12.04, that Unity rules all, and that anyone who feels differently deserves nothing.

Back to the other computer, back to debian.org. Download the network installer CD ISO image for 7.3.0. Burn it to a CD.

Take the rest of the night off. This has been crazy, and I am far better off doing something fun than making my forehead bleed - more! - on this project.

Saturday morning. Try again. Insert Debian CD into laptop and boot. Select graphical install. Answer the questions. All but one is simple. (I have no clue what answer to give it for my domain name, so I left it blank. Life goes on.)

As I type this the system has already repartitioned and reformatted the disk, and has just finished downloading over 1300 package files to install them.

What happens next? I have no clue, but I do know that Debian booted on my ancient system just fine, so that seems good. Once the install finishes I will poke around and see where things are at. While that goes on, I think I will go have some lunch.

Friday, December 27, 2013

Linux Rant II

As per a comment I left in G+ to my previous post, I started the ugly update process to try and get my laptop running something usable.

First, I installed Ubuntu 10.04. It seemed to work. Rebooted fine, and let me log in. All seemed good.

Then I brought up the update tool and it told me there was a new LTS release - 12.04 - available to upgrade to. Perfect. So I told it to do that. And I waited.

An hour or two later I found it waiting for input to go ahead and replace certain libraries (I think) that it needed to do before it could actually process the update. Fine. I allowed that.

Came back a couple of hours after that to find 2 dialog boxes on the screen. The one in the back was fine, and just told me that the machine needed to be rebooted, which I expected would be the case. The one in front, though, was completely illegible. There were things that were obviously supposed to be characters in it, but they were rectangular boxes instead. A row of them that was obviously supposed to be some sort of status or error message, but it was completely unreadable. There was, however, an obvious button with just 2 such boxes in it, which probably meant "OK", so I clicked on that and the dialog disappeared. Odd, but whatever.

Then I clicked on the reboot dialog. And it rebooted. Success, right?

Well, no. Not quite. First it tried to shut down and hung during the process. Fine. Power off, then power back up.

It booted, and got me to the login screen. That's good. Entered my password and...

Gibberish. A screen full of junk that look mostly like random memory instead of whatever it is supposed to display. No ability to read anything, execute any commands, nothing.

Power off, power on. Try again. Same result.

Theory: Ubuntu has switched to some half baked open source driver for the graphics chip maker in my laptop, and that driver doesn't know how to fully support the ancient chip in my ancient machine. If I want to make this work I may have to figure out how to install the proper proprietary driver on the silly thing, but that may well require getting it to bloody work in the first place. Maybe I can boot into some safe mode and poke around. I don't even remember which graphics card is used in that laptop. Gah!

But it was late, so I gave up and went to bed. I may fiddle with this again this afternoon. It'll be about as much fun as getting a root canal, I'm sure, but I'll see what I can do.

Such fun. I might even post a video of my Ubuntu boot experience, but that would mean figuring out YouTube, and that would probably be just as fraught with errors and issues.

Ben says I should check out Debian. Maybe I will do that. And maybe Arch. All I want is something that bloody works.

Thursday, December 26, 2013

Linux Rant

So... I am suffering some Linux frustrations. Yeah... I know... what about Linux isn't frustrating, right?

But I am going to get this off my chest. If you don't care, the internet is full of alternatives. Go find one now. If you're a geek and think you can help, read on.

1) Ubuntu's Unity UI sucks.  No, really. It stinks.

I use Ubuntu 12.04 LTS because I want a Long Term Support version. I don't want to upgrade my OS twice a year... I do not need that level of sys-admin pain. And I know Ubuntu 12.04 is over 18 months old, so maybe there are improvements to the Unity UI that I haven't seen. But, frankly, what I have now sucks.

I run a dual headed system with monitors of different sizes. You have no idea how often things get wonky when I simply move a window from one monitor to the other. Sometimes it disappears off to some other workspace and I have to go hunting for it. Sometimes the mouse winds up many inches from the window I am moving, making additional manipulation and positioning "interesting. And sometimes the window winds up with the title bar and menus completely invisible. None of these things are crippling, but they are all irritating. Very irritating.

And then there's Dash, a mystery thing that pops up whenever I accidentally hit the "Windows" key to let me search (I guess) for things on my system. It's not exactly intuitive, and - apparently - in later versions of Unity it winds up sending ostensibly private search terms to places like Amazon.com. Yay! (That was sarcasm... in case it wasn't obvious. I do not want my desktop search terms sent to Amazon, and I have no clue why anyone at Canonical thinks that is a good idea.) I have yet to figure out why Dash is a good thing. So far it's just an irritant.

Another problem with Unity is the loss of focus-follows-mouse and the corresponding ability to leave a window that has the focus in the background. I love focus-follows-mouse. Just move the mouse over a different window and it gets whatever you type. Easy. And that window doesn't have to come to the front and obscure everything else. Nice and simple. But Unity doesn't give me that, so it sucks. By definition.

I guess Ubuntu wanted to create Unity so they could unify the world: desktop computers, laptops, tablets, and smartphones could all run the same user interface. Screw that! I don't want my smartphone to have the same UI as my desktop computer. Know why? Because I don't do the same things on those devices. Any idiot can see that is the case. Sure, sometimes I do similar things, but I don't make phone calls on my desktop (I don't even Skype) and I don't watch YouTube on my phone. (Who wants to pay for the bandwidth for that? Are they nuts, or just happy to shovel buckets of money to a smarmy telco?) To me, the idea of a unified, cross device UI was dead before it was ever implemented.

I limp along with Unity because, frankly, I am afraid to change it. I have seen some things about how I could get Gnome to run instead, and maybe I will try it, but only when I have a backup system running that I can use in case my main system dies in the process. I have an ancient laptop that I should be able to live - or test - on, but therein lies another story...

2) Ubuntu is phasing out support for older CPUs.  I cannot install Ubuntu 12.04 on my Dell Inspiron 8600. It's got a Pentium M chip in it that lacks something called the "PAE flag", and later Ubuntu distributions have stopped booting on those older chips.

Let's stop and ponder that for a moment: the OS that claims to run well on older hardware (as compared with Windows) is going away from supporting, um, older hardware. No, honestly. Wait... what?

This laptop is perfectly good for 99.99% of what I need to do on a computer, but Ubuntu's last 3 or 4 releases won't install on it.  Oddly, I think you can upgrade an older version of Ubuntu to a newer one and it will still boot, but you cannot get their base distribution to install from scratch. I am not making this up.

What sort of idiot at Canonical makes these decisions? Honestly? How do you get an OS to take off and get people to use it if they cannot try it on an older machine first?

3) As an alternative I am looking at Linux Mint. In fact, I have version 13 of Mint installed on that laptop, and it boots, despite being Ubuntu based. But it's not that simple. (It's never that simple.) What UI should I chose with Linux Mint? I installed one running something called "xfce", but I could also have chosen "Cinnamon" or "Mate". None of those is Gnome. None is KDE either. And all their user experiences are a bit different. Gah! Xfce is OK, I guess, but I liked Gnome and it isn't Gnome. Maybe I should have tried Mate, but at the time I was poking at this there wasn't good information about what Mate was, nor why I would want it. The same is true of Cinnamon now. Why on earth would I want that? No clue.

I just need something that works. How hard can it be?

Well, as if to answer that question, today I pulled out the laptop and updated Mint. I am trying to figure out what to install on my wife's similarly ancient laptop, and we know it cannot be Ubuntu 12.04, so I figured I would update Mint and refresh my memory about it. And it does (happily) turn out that Mint 13 is an LTS version, supported for another 2 or 3 years, which is good. But when I ran the update tool I got errors about it being unable to resolve certain domain names... domains that it needs to get certain package lists. Huh?

OK, maybe, some machine is down. And maybe no one has fixed it because it is the day after Christmas. And maybe I can try again in a day or two and it will work. Maybe. But I don't know. Lots of stuff did update, but not everything, and I don't have a clue how badly off things are. If there is a problem with Mint 13 that is more than a sick server, though, I certainly don't want to install it on my wife's laptop.

And don't get me started on printing and scanning. My wife tried to print to our color laser printer the other day and it came out monochrome. I had to get a copy of the file from her and print it from my machine to get it to print in color. Her laptop thinks our Xerox color laser printer isn't color.

I suppose we could buy new laptop computers and install a more recent version of Linux on them, but which one? And do I really want to do that if I then have to upgrade the OS when it goes out of support in less than a year? Or should I install Ubuntu 12.04 and risk getting Gnome to work on it? And just how good will that experience be? I was hoping to test that on my ancient laptop, but I cannot get there easily.

Maybe if I install Ubuntu 10.x which will run on the laptop, then upgrade to Ubuntu 12.04, and then install the Gnome system... simple! (Sarcasm again. But maybe my only real choice.)

I hear some of you... Why not just go with Windows? Or a Mac?

Suffice it to say I have my reasons.

I wouldn't trust a Windows machine with anything where security matters, and I gave Steve Jobs money a few times and he only let me down. Windows machines are great if you want to suffer with virus attacks every 15 seconds. And Macs are fine if you're doing exactly what the geeks at Apple thought you would be doing, but if you ever try to do anything else, you're screwed. (And yes, I have examples. You don't want to know.)

So for the moment I guess it's Linux. Unless I want to install Plan 9... now there's an idea!

Thursday, December 12, 2013

Trying to deal with Twitter... differently...

So... some time back in this very blog I indicated that I didn't get twitter, and that I didn't use it.  That changed as I found myself trying to update people in my neighborhood about local fire related items and events. I found a place for twitter.

I used it purely to send data out about fires and the like. Email isn't always a good vehicle for real time information distribution. It can suffer delays, and people don't always get email quickly. But twitter lets people get things via their phone, and (with luck, anyway) the number of delayed transmissions for the SMS messages twitter sends out will be lower than the email delays I've seen.

So, fine. I started using twitter for that.

Then it turns out I have some friends that use twitter. Of course. So - much like Facebook - if you want to see what is going on, you need to follow them on their platform of choice. Fine. And of course they follow some interesting people, and there are a bunch of emergency information sources on twitter as well, so I wound up following about 40 people.

Next I discovered that my web host makes use of twitter too, and they respond to questions there. Interesting. But if I send questions to them using my existing twitter account, those tweets will show up in the feeds of people following me for emergency information, which is not something I wanted to do.

And someone I wanted to contact in real life doesn't give out an email address, but she's on twitter. Not a huge deal, but again I don't want to cause cruft to show up in the twitter streams of those who follow me for emergency purposes only. Gah.

So guess what... the one who said he doesn't tweet now has two twitter accounts, and is struggling to find a good Linux client that supports that situation. So far, I have tried three:

  • Gwibber is OK, at best, but it doesn't make use of the colors you assign to each account. That means arriving tweets are intermixed and you need to know which ones come from where if you care. Also, when I send a tweet, I can find no way to choose which account the new tweet will come from. That's bad. But so far it's the best I've found.
  • Birdie claims to support multiple accounts, but I couldn't figure out how to make it actually do that. One account was OK, but if I tried to add another one it seemed to just add the first one a second time. Odd and pointless.
  • Hotot wouldn't work at all. I could not get it to let me login. No clue why.

I may look into Poly, but it's in pre-alpha status still, and I don't know how stable it is. But it may be better than Gwibber, so I will ponder.

This is craziness, I know. But here I am, trying to be part of the modern age. Again.

If you're silly enough to want to follow me on twitter, I am:

  • @jrpstonecarver - my emergency info account, mostly for Santa Cruz Mountain residents who want to know about fires and other events in our area
  • @jeffpstonecarver - my new account, for everything else

If I was following you before, I still am, but possibly on the new account if you're not one of those I track for emergency information.

What on earth am I doing?

Tuesday, October 22, 2013

Facebook is not a good, directed, communications mechanism

Time for another rant. Sorry. Sort of.

I have several friends who seem to live on Facebook. The fact that they do so doesn't bother me. That's fine. Go ahead and post your musings, your pictures of food, your status updates, etc. Whatever you like by way of generalities and banalities is just fine on FB. I really don't mind.

But please do NOT assume that whatever you post to FB gets to everyone who knows or cares. It doesn't work that way. Really.

First off, there are people like me that don't use FB. The Zuckerberg clan long ago lost my respect for how they handle personal information, set defaults for new features, and the way they run the site. (Hint: breaking things is bad, not creative or useful.) As a result, I don't use my FB account anymore. I still have one - for now - but I never go read my wall (or feed, or stream, or whatever FB is calling it these days). If you want to reach people like me, you'll have to pick another communications medium: email, voice, text, whatever. But please do not assume that just writing a status update on FB constitutes an effective way of telling me something specific. I won't get it. And while I know FB has something like 1.5 billion users, it doesn't have everyone signed up yet.

But let's assume I was still using FB. Would it work for directed communication with me? Actually, no. There are at least three reasons that FB's design makes it a poor choice for communicating directed information, even between actual users of the site itself.
  1. Importance ordering of your wall. By default, FB has (or had, last time I was there) algorithms that automatically tried to sort the most important items from your stream and put them at the top. Things it deems less important are farther down, making them easy to miss. Yes, you can change the sort to time order, rather than based on their arbitrary (and usually incorrect, in my experience) importance order, but that change isn't sticky, so you have to do it every time you visit the site. It is, therefore, easy to forget to switch it back on each viewing, and when you see something you've read before, you might conclude - incorrectly - that you're caught up, and thus miss something that one of your FB friends expects you to see.

  2. You're probably unable to keep up with your stream. If you have friends that use FB a lot, you get a lot of things on your wall. And if you're not vigilant about turning off posts from games and the like, you're flooded with various other posts as well, things that don't convey particularly useful information. Add a few other people who post a lot - particularly humor and pictures - and it becomes impossible to keep up with the stream. When that happens you will miss posts from people, and if someone is trying to tell you something specific, you'll be out of luck.

  3. Finally, FB doesn't send your posts to every friend's wall. There was a big flap about this a while ago, and it may not apply to people with low numbers of friends, but they announced that not every status update gets to all of your friends and followers. In fact, if you want to get more eyeballs on something, they have a mechanism through which you can pay money to give your post a wider distribution. Unless they have changed (or broken) things, that continues to this day, so announcing an event on FB may or may not get to everyone you're expecting to attend.
Effectively, FB is an unreliable communications tool. It is designed that way, and it works as designed.

So, please, if you want to communicate specifically with a group of people, pick some other communications mechanism to make it happen. There are many choices these days - email, phone, and text at least - and anything that works is better than one that doesn't.

In part this is a "get off my lawn" rant, I know, but that isn't all of it. If you're really trying to communicate specific data to specific people, FB is not the right tool for the job. And as I say, I really don't mind anyone using it... just not for that particular purpose.

Thank you for your cooperation in this matter.

Tuesday, March 5, 2013

Programming Rant... Sorry.

For those of you who are not technical, or who don't care about programming, feel free to skip this post.  I just have to get this out of my system.

I'm currently slogging through a book on JavaScript.  I have a project I want to work on that needs to run in a browser and perhaps be turned into a stand alone smart phone application, so JavaScript seems to be the way to go given what I read.  I could be wrong, but it's where I am starting.

The book in question is an O'Reilly JavaScript tome, and as an introduction to the language it isn't too bad, at least if you have some programming background.  But the language itself is leading me to continue my belief that OO programming is a disaster.

I get the basic idea behind objects and methods.  I am certain that some percentage of programming problems benefit from a system in which objects are available, but I suspect the number of such problems is pretty small overall.  Pick your percentage... I really don't care.  What matters to me is the complexity increase and efficiency decrease that come with OO.  Most programmers have no clue just how their code actually works at the lowest levels anymore, and most schools certainly aren't teaching it.  OO techniques just magnify those problems in enormous ways.

By way of example, here's a bit of code from the book I am reading, reformatted a bit to look OK in this post. It's only an example, and the author does mention that it will be slower than other approaches, but, well... just take a peek:

function Range(from, to) {
    // Don't store the endpoints as
    // properties of this object.

    // Instead define accessor functions
    // that return the endpoint values.
    // These values are stored in the
    // closure.
    this.from = function() { return from; }
    this.to = function() { return to; }

}

// The methods on the prototype can't

// see the endpoints directly: they have
// to invoke the accessor methods just
// like everyone else.
Range.prototype = {
    constructor: Range,
    includes: function(x) {
        return this.from() <= x &&
               x <= this.to();
    },
    foreach: function(f) {
        for(var x=Math.ceil(this.from()),
            max=this.to(); x<= max;
            x++) {
            f(x);
        }
    },
    toString: function() {
        return "(" + this.from() +
               "..." + this.to() + ")"; }
};


and with that code defined, he shows how it can be used:

// An "immutable" range
var r = new Range(1,5);
// Mutate by replacing the method
r.from = function() { return 0; };


The first thing - for the uninitiated - is that this code is implementing an object called a range, which is nominally just two integers. The range (1...5) means the numbers 1, 2, 3, 4, and 5 are in the range, and all other integers are not. Simple enough. And obviously ranges have two endpoints, right? So where, exactly, are those endpoints stored in that code?

The author has an earlier version of this code that uses two variables to store the start and end of the range, but in this version they are not obviously present.  I read this code several times, trying to figure it out, before the very last line in the example - the one starting "r.from =" finally tipped me off.

I'm an experienced programmer, and a reasonably good one.  Not the best, but above average in my professional experience.  I've worked with some really brilliant people over the years, and know where at least a few of my limitations are.  Given what I know, this sample code can only be described as ugly and unmaintainable.

The use of a closure is enough to drive some programmers to drink.  (I know plenty who never understood recursion.  Closures are much, much worse.)  Code of this kind is intrinsically difficult to read, difficult to follow, difficult to edit, and so on.  And for those brilliant programmers out there who think this is easy to read and maintain, I cannot stress strongly enough how wrong you are.  You're only thinking of it from your point of view, not the poor sod who is going to add something new to this code 2 years after you've changed jobs.

Once, years ago, I saw code like this in some C code my employer was maintaining:

int f( char *a, char* b)
{
    char *temp;

    /* ... lots of code that doesn't refer */
    /* to the variable "temp" in any way ... */

    strcpy( a, temp );

    /* ... code that doesn't matter ... */
}

I was doing some porting work and found that cruft.  Digging into the change history of the file in question showed me that a support engineer had "fixed" a bug by inserting the temp variable and making use of it in that way.  The fact that he hadn't allocated space to copy into and was instead writing over who-knows-what on the stack didn't even occur to him.  He'd tested his code and it worked just fine, so what did it matter?  And yes, I tracked him down and talked to him personally.  He simply didn't get it.

Really.

The world is full of cases - and people - like that.  As a result, the best code for the real world is, sadly, the most readable and maintainable code possible, not the fastest, not the most clever, not the shortest.  Fancy programming techniques - like the vast majority of OO - simply make things slower, harder to understand, and vastly increase the "go wrong" space in which programs can fail.

What I am learning about JavaScript - and about OO in general - is that my gut feel was right.  These languages are disasters.  Inexperienced programmers are creating things that should never see the light of day using idiomatic programming techniques they should never even try to use.

Sure, if you're writing some one-off bit of code that will never be reused, or will only be maintained by you, fine, write it however you want.  I don't care.  But if you're working on something that will outlast your time with it, or (more likely) your time with the employer who owns it, you have an obligation to write it in such a way that the next guy that looks at it can quickly and easily figure out what you were doing, why you were doing it, and make changes as needed without breaking the universe.

OO was supposed to help that, and within limits it may.  But if JavaScript is any example (or C++, for that matter), the languages themselves have an amazing ability to make the code harder to read and maintain.

If we were all brilliant programmers, that wouldn't matter, but we're not, and it does.

Monday, April 2, 2012

Privacy Matters

The recent hubbub about the iPhone app Girls Around Me has me thinking a bit more than usual about privacy, and about what it means in the real world.

There's been some fear mongering about it, and some statements that it represents the future. In the latter camp I even saw an article by someone from Forbes in which she claimed that perhaps the people with open profiles on Facebook and open access to their FourSquare data chose to set things up that way.

Really?

Here in the USA, where people cannot name their elected officials with any regularity, where evolution is not a fact, and where we care a lot more about American Idol than we do about the real questions facing us, do you really want to suggest that the average person has a clue what their privacy settings really are in Facebook, FourSquare, Twitter, and who knows how many other systems?

I wouldn't make that claim.

I'm a software engineer, and I can assure you that the privacy settings on Facebook are hard to find, default to the wrong values, and are very often difficult to understand in any depth.  I assume FourSquare is similar, though I have to admit that the very idea of checking in and announcing my presence away from my home seems crazy.  It's an invitation to a robbery, at the very least, so I have never signed up.

But let's run with that theory.  Perhaps some of the women who showed up on Girls Around Me really did want to announce their presence in that way, and perhaps most of the people using that app weren't rapists, muggers, and so on.  That's fine, and it might be true, but stop and think about your friends list for a bit.

I suspect most Facebook users have friended individuals they barely know, or don't know at all.  Are the people checking into places being certain to navigate Facebook's fiendishly complex privacy settings so that only friends they actually know and trust are seeing their location?  I seriously doubt it.

Geolocation data has a whole slew of downsides when applied on a personal level.  There is, I will admit, some upside to this data when properly controlled, but what we are seeing with Girls Around Me - and any number of current or future apps that do similar things - is the use of that data in ways that many aren't comfortable with.  (And don't even get some of my more reactionary friends talking about the dangers of geolocation data in the hands of the government.  No, really... don't go there.)  More interesting, to me anyway, is that most of us have no idea the data we give to Facebook and other services can be used like that.  If we could control our data more easily, this would be a non issue.

And in my opinion, it is the fact that control of our own data is so hard that is really the problem.  To pick on Facebook - because they are an easy target, though they are far from the only offender - your profile should default to being visible to friends only.  You should have to make individual bits of profile data public one at a time, and geolocation data should never be shared publicly.

If I ran the zoo, when you friended someone in Facebook (or any other service) you would have to assign a level of trust to each person, and if you didn't pick something different the default would be "no trust".  People you don't trust get very little in the way of data from you, including almost nothing personally identifiable. With just a few levels of trust, you could get all the way to your spouse and/or anyone else you would give a blank, signed check to.  And levels of trust would be used when posting your status or checking in, defaulting to only the most trusted group every time, but letting you broaden the recipients as needed (by allowing less trusted people to see the post).

In a nutshell, these systems should default closed - to avoid unexpected sharing - but allow broader sharing when the user specifically chooses to do so.

In general, people don't think about privacy and consequences when they post.  The vast majority of the time they don't even bother worrying about who should see a post, which is why we have so many stories about bosses and employees sharing inappropriately on Facebook and elsewhere.  Given that, claiming that many people want to be as exposed as Girls Around Me makes them doesn't seem right.  I'd bet most of the people who were that exposed would react negatively to finding out just what they were subjecting themselves to.

If the author of the Forbes piece wants to make herself available publicly, that's fine, and the various platforms are welcome to support that.  But it should always be a conscious choice with every post to make that kind of information available, never the default.  That's were the current systems get the design wrong.

Monday, August 22, 2011

On Passwords

Multiple people have recently asked for information about how to create, use, and protect passwords.  We all have them, but - oddly - no one teaches us anything useful about them.  Some of us figure these things out, but most people never do.  And if you don't think about it, it is very easy to get into real trouble.

My goal is to help you avoid having your accounts hacked and your identity stolen.  There is a lot of information here, I know, but the topic is important.  Please read on.

First, the obligatory disclaimer:  I am not a security expert, and would never claim to be one, though I have spent enough time in high tech to be able to discuss this issue in some depth.  Hopefully I can make it clearer to you, but the subject is much deeper than even I know.  If you are interested there is a lot more to learn.  It's also important to note that even if you follow all of the best practices you can still have a password stolen or cracked. Sorry, but that's the truth.

Please consider this entire piece my opinion only, and note that your mileage may vary.

Begin At The Beginning:

The first problem with passwords is their very name: "password".  Many people think a "password" has to be a word because that's what it says.  Nope.  And, in fact, a single word - any single word - is just about the least secure thing you can use for a password. To explain why, and eventually get to how to create and protect good passwords, I will cover the following things:
  • How Passwords Work - A short overview of how a simple password system actually works.
  • How Passwords Are Compromised - How the bad guys get them without much work, without even having to guess or decrypt them, and how to protect yourself from at least some of those issues.
  • How Passwords Are Cracked - How a password is actually figured out "the hard way".
  • How To Create Good Passwords - What makes one strong and another weak.  How to create good ones reliably.
  • How To Manage Too Many Passwords - How do you remember 50 different passwords?
  • Other Thoughts on Passwords - Some other things to note in the world of passwords and security.
  • In Summary - A very quick recap.
Here we go...

How Passwords Work:

On any well designed system, passwords are stored in a text file or database table that contains your login name and an encrypted version of your password, among other things.  Here's a made up example table with those two fields separated by a colon.

bob:7y+kj8hs
jeff:IY67kH_1
jeffa:9jHg=ih1
mary:khy8ue4_
susan:iop74rf3

Part of a password system involves some complicated program code to encrypt passwords.  An encryption routine takes a string as input and returns a different string as output, with the intent that the output string cannot easily be associated with the input string.  In the example, we can see that jeff's encrypted password is "IY67kH_1".

I won't bother with the math behind encryption, mostly because it is way beyond me.  Suffice it to say that it is very, very complicated, and there are many ways it can be done.  The goals, though, are easy to understand:
  • No one should be able to look at an encrypted string and find out what the original string was.  Even with a super computer capable of doing math very quickly and knowing the code used for the encryption, the problem - going backwards from the encrypted string to the original password - should take hundreds of years.  Incidentally, this is why you can't just get someone to look up and tell you your password on a well designed system.  It's encrypted in such a way that no one can practically reverse it.
  • The encrypted output needs to be in some standard format.  The simple example above has the output string limited to 8 characters, and allows both alphanumeric and a few special characters.
With that background, here's how a very simple password system works.  First, the system looks in its table for the user name.  If it doesn't find it, it emits an error of some kind (usually saying it's an "invalid user") and lets the user try again.  If it finds the user, it takes the password that was entered, encrypts it, and compares the result with the encrypted password that user has in the table.  If they match, the user is logged in.  If they don't match, an error is emitted saying something like "bad user name or password", and the user gets to try again.

As an example, we'll use my made up login - "jeff" - and the corresponding made up (and very poor) password "obvious".

If I enter "julie" and "bad_password", I get "invalid user" because there is no user named "julie" in the password table.  Note that the system didn't even both doing anything with the password I entered because there was no matching user.

If I enter "jeff" and "bad_password", I get an "invalid user or password" error message.  The system isn't sure if I entered the wrong user name or the wrong password.  (It is true that I entered a valid user name, but I might have entered the wrong one.  Perhaps I meant to enter "jeffa" and didn't type the final 'a' in the user name.)

if I enter "jeff" and "obvious" the user name matches a valid name, and the password, once encrypted to "IY67kH_1" matches the entry in the table, so I am allowed into the system.

Note that you cannot enter the encrypted string as your password.  If I enter "IY67kH_1" as my password when I log in, that string will be encrypted to something else, and the result won't match, so my login attempt will fail.

That's it, a very simplified version of how a password system works.  There are many wrinkles, or course: how to create a new user and their password, how to change a password, and various ways to make passwords more secure, among others, but the core of the system is there.  Your password gets encrypted into a string that can be safely stored in the system, and that string is compared with the encrypted version of the password you enter when you want to log in.  Most importantly, no one can read or see your actual password.

How Passwords Are Compromised:

The first and biggest risk most of us suffer from is making our unencrypted passwords readily available to the bad guys.  Hopefully a lot of this is just review, but the following are some of the common errors people make when dealing with passwords
  • We give our passwords to the wrong people.
  • We let others see us enter our passwords.
  • We write our passwords down.
  • Even worse, we send our passwords to others in email.
  • We use insecure computers where malware has been installed.
  • We respond to phishing attacks.
  • We enter our passwords into insecure systems or use insecure protocols to send our passwords to systems.
  • We use the same password for many systems.
These are all common sense things, but they turn out to be ways that passwords are regularly stolen by people who aren't above doing bad things with them.  Note that none of these cases talk about what your password actually is.  Though there are important issues related to password selection, the first thing you have to do is develop good "password hygiene".

The most important, and yet simplest rule of password management is never, ever, tell your password to someone you don't trust, 100%.  Period.  Can you count on that person to keep it a secret, and not let it out?  Even accidentally?  Probably not.  Even for a friend or a spouse the chances of letting it slip are high, particularly given the above list of issues. The best way to protect yourself is to keep all your passwords private all the time.

This isn't always obvious, though.  An example: someone calls from your phone company, claiming they are doing some system maintenance on your account and asking for the password you use to get into their online system.  Do not give it to them.  They should not need it.  Ever.  If for some reason you are inclined to believe them, hang up, call the company yourself, and ask someone in customer service about it.  If you make the call - to the company's 800 number - and the new person you talk to says the request is legitimate - and they do need the password - it is safer.  It's still stupid, but safer.  After all, you are about to tell your password to another human, who could easily write it down and do bad things with it later.  Any well designed system should never require a user to divulge a password to a human, particularly via some non-secure route, like over the phone.

Note that you cannot just ask the original caller for a phone number to verify things.  They could give you a number for a collaborator who will tell you exactly what they want you to hear.  Get the phone number for yourself - from the company web site, perhaps - and call that.  Only when you initiate the call to a known good phone number and are told that the request is legitimate should you consider complying.  And even then you should ask to speak to a manager and tell them that their systems are poorly designed and they should not be requiring their customers to give their passwords to strangers over the phone.

Assuming you are keeping your passwords to yourself, the next step is to avoid having others see you enter them.

When you go to the ATM you look over your shoulder before entering your PIN, right?  That's the idea, but you have to think about it all the time.  When you enter a password into your smart phone - even just to unlock it - while standing in the terminal at an airport, how many people just saw you enter that number?  And if your phone is stolen 10 minutes later, they have access to everything on it, right?  If you're in the library using a computer and someone watches you login, that account is compromised.  Your boss watches over your shoulder as you login at work... compromised.  And so on.

Those who are paranoid about these things might seem crazy.  That ATM on the street in town is risky because someone standing at a window 3 floors up across the street with a pair of binoculars and a good digital camera can read the account number off your ATM card as you put it into the machine, and see your PIN as you enter it.  Yes, really.

You have to be certain that when you enter your password - for any system - no one sees you do so.  While that sounds simple, most people don't think about it much, and the results are all around us.

Next: do you write your passwords down?  You might have dozens of them, for various sites at work and on the Internet.  Can you remember them all?  Of course not, so you write them down.  And where is that paper with the passwords save?  Under your keyboard?  In the pencil drawer of your desk at work?  Taped to your monitor?  Any passwords that are written down are, by definition, already compromised.  If you have to write them down, at least put them someplace no one can see through your windows or passing by your office door, and where they won't ever be looked for, even by a determined thief with time to kill.  But, in truth, a written password is a compromised password, and you should never write them down if you can avoid it.  There will be more on how to manage large numbers of passwords later on.

By extension, sometimes people or systems put passwords in email.  The problems with that are much, much worse than just telling the recipient the password, or writing it down.  Unless you do something special - which most people never figure out - email isn't encrypted, and it can be routed through many different computers between you and the recipient.  It can be copied, left on disks along the way, and read by various people with access to those computers along the route.  Any password in an email should be assumed to be compromised.  If you encounter an online system that sends your password out in email, first change it immediately, then send the site a note complaining about it.  Better yet, cancel your account with the site and tell them why you did so.

An exception to passwords in email is if you are resetting a forgotten password.  The site may send you a new password in email in this case.  When they do, login IMMEDIATELY and change that password to something new that was never in an email.  There are limited options in a password recovery setting, and emailing out a new password - often one that will expire quickly or that can only be used once - is acceptable, but you must follow through and change it quickly to reduce the risk that someone will get into your account with that new password before you do.

Assuming you're careful about all of those risks, then you must consider the computers you are using.

Computer viruses, key loggers, and other malware are a significant threat, and probably account for the bulk of compromised passwords.  These risks are more severe for any computer running Windows simply because there are so many of them in the world.  Some argue that Windows itself has more security holes for various reasons, and so is inherently unsafe.  My opinion is that was demonstrably true years ago, but it may be changing for the better lately.  Still, if you want access to a lot of passwords you go where they are, right?  That's Windows.  Macs are starting to get attacked as well, though, so don't rest on your laurels if you're a Mac user.  And other operating systems will eventually have the same problem if they don't already, so use caution.

As a rule, don't do anything critical on a public computer, or one whose status you don't know.  Library computers are handy, but do you know they are up to date, virus scanned, and free of malware?  Probably not, so don't do your banking there. Always exit and restart the web browser completely before using it on a public computer, and check to see that the operating system and anti-virus software are up to date as well.  If you can't tell it is up to date, I wouldn't enter any passwords - or do anything personally identifiable - while using that computer.

On your own computers you should always keep the operating system up to date and install patches as they come out, since they fix vulnerabilities that can make your machine open to viruses, key loggers, and other malware.

A key logger is a program that runs in the background and stores all of your key strokes, sending them off to someone else when something interesting happens.  If it sees a request from your web browser to a bank, stores the next 500 key strokes you enter along with the URL it saw, and sends it all to the bad guys, your bank account could be empty in the morning.

To avoid this, always run a good anti-virus program.  These can help reduce the risk that you are compromised, though they cannot completely eliminate it.  New viruses - ones not yet recognized by anti-virus software - are always popping up, so while they are a good defense, they are not perfect.  Still, they are a requirement.

Keeping your software up to date is critical.  Anyone still running IE6 or Windows XP is in serious jeopardy of having their identity stolen.  Old versions of any browser or operating system have similar issues, though.  If you are running Windows, consider running any browser other than Internet Explorer.  For a long time IE was the most used browser out there, and therefore the biggest target.  Security problems were often found in IE as a result of that market dominant role.  There are security problems in FireFox, Chrome and Opera as well, but they are different, generally less commonly encountered, and less likely to be taken advantage of.  Install one of those other browsers, keep it up to date, and use it for anything critical - like online banking - at least.  In my opinion, IE has improved, but not enough that I would trust it yet.

Another layer of protection comes from practicing "safe software".  That's an old term for being careful about how you handle data and move it between computers.  If you get an attachment in an email, don't open or run it, even if it comes from someone you know.  The sender might have an infected computer that sent you that email without his knowledge, and it could easily contain a virus.  If it is important that you view or run it, save it to disk, scan it with your up to date anti-virus software, and only proceed if it is clean.  (Some anti-virus software scans email attachments as they arrive, which is great, but caution is always best.)  If you are given a disk or thumb drive, scan all files on it for viruses too, before running or opening any one of them, for the same reason.  In fact, if you move a thumb drive or disk from a computer you don't trust to one you do, scan it for viruses before running or opening anything.  There are viruses that travel via thumb drives, for example, and can hide on the drive without affecting the files on it.

This may seem like overkill, but the number of infected computers is huge, and the number of security holes in any operating system or program is high.  You have to be as careful as possible to avoid infecting your computer with something that will give your passwords - and your identity - to someone else.  As a bonus it helps avoid viruses that do damage to your computer and files, so it is good practice in any case.

And while we're talking about these things, be extra careful about email.  Never "click through" an email to get to a website and login, even if you think it looks OK.  This is particularly critical for banking related sites.  The specific attack is called "phishing", and it is deceptively simple.

The bad guy sends you (and 10 million other people) an email that looks like it comes from your bank.  The return address is your bank, all the usual graphics are there, and so on.  You click on a link in the email and wind up at a web page that looks just like your bank's login page, so you enter your name and password.  What happens next doesn't matter, though, because you've just given your login details to the bad guys.  The email was a fake, and the web site didn't really belong to your bank.  You can bet they will be getting into your account quickly, though, and taking all the money they can get from you.  Or they might wait six months and hack you then, when you've totally forgotten about this incident.

To avoid this, do not click on links in an email, or at least don't login from pages your get to by clicking on links in email.  Bring up a browser window and enter the URL for your bank manually, then login and do whatever the email said you need to.  If you have any concerns about the validity of the email call the company in question on the phone - using a known number you got from someplace other than the email you're not sure of - and ask about it.

Sadly, there are other ways passwords are compromised, and some are harder for the average user to notice.

Some programs don't encrypt passwords when they go over the Internet.  Such systems are nearly as bad as putting your password in an email.  And if you use such a system on a wifi network you're totally hosed.  Reading packets on a wired network is pretty simple, and snooping other users on an open wifi network isn't hard either.  In short, know where your passwords are going, and be sure you are using HTTPS or other secure protocols to send them over the network.  Your browser will show you a lock icon if it is sure the site you are connecting to is using HTTPS.  If it isn't secure, be careful about entering your login and password.

Sadly, some sites use HTTP - an insecure protocol - for the login page, but use HTTPS to send the user name and password.  Thus, the page you appear to enter the login data into isn't shown to be secure by your browser, but the connection made to send the data to the server actually is secure.  I generally find these sites have a second login page that is fully delivered in HTTPS, and thus easier to recognize as secure.  Look for a link labelled "login" or something similar on the non-secure main page and see what you find when you click on that.  Complain to sites that don't obviously use HTTPS for their login page, so they will fix things to be more obviously secure.

Finally, in the realm of things that weaken your security, don't use the same password for multiple accounts.  If you do, and it gets compromised, you have a major problem.  If the login and password you used for your yahoo email account can get the bad guys into your bank, or the account you have to manage your airline rewards program, well, you brought the trouble upon yourself.  Using different passwords is critical.  Yes, it is a problem to manage and remember all those passwords, but it is a critical step to keep your data - and identity - secure.

Security of any type begins by keeping your important login information safe.  How paranoid you want to be is up to you, but the risks described here have gotten people in trouble - in real life - for years.  How many spam emails have you gotten from someone you know?  The password for some email account they have was compromised - probably in a way described above - and was used to send that spam.  It happens all the time, and sending spam is probably the least bad of the things that might happen as a result.

Even if you're careful about who you share your passwords with, the computers you work on, and so on, an account can still get stolen.  At this point we're talking about passwords themselves and how they get cracked, which is a whole different kettle of fish.

How Passwords Get Cracked:

A cracked password is one that someone figures out in some technical way, possibly by reversing the encryption, or (more likely) by guessing likely passwords until they find one that works.

In general it isn't the NSA (or some similar foreign government agency with a zillion dollars and lots of time) who wants into your account.  Instead it's some kid in the Ukraine who wants to empty your bank account, or some "friend" who wants to ruin your day.  These people have no budget to speak of, and won't bother to wait 250 years for a computer program to reverse your password.  So they go after the simple stuff and hope to get lucky.  It turns out there are lots of simple things they can do to get into your accounts, and your choices can make things easier or harder for them.

Some of these methods won't look easy to you, but they are actually pretty simple.  In many cases you can get programs to do these things for free - or very little money - in the darker corners of the Internet, and the good guys use very similar tools to check the security if networks, computers, and passwords all the time.  Also note that some are used in combination, but for simplicity I describe them individually.

The first approach is to try obvious passwords.  Many studies report that lots of people use really simple passwords, which means the hacker can try a few dozen passwords and often find a way in.  Some examples of bad passwords include: "abcdef", "password", "qwerty", "12345678", and so on.  It turns out that any simple thing for you to type or remember is just as simple for someone else to guess.  In any given system a large percentage of accounts are vulnerable to this sort of attack.  If 20% of gmail users have really obvious passwords, the only real problem is figuring out which of those gmail accounts the bad guys want to break into, right?

Another thing they can try is a dictionary attack.  It is easy to get a list of words - a dictionary - and try them all.  The bad guys try logging in with your user name and each word in the dictionary as the password until it works.  The chances of success are high because so many people use real words as their passwords.   Near the top of this article I said that any single, real word is a weak password.  Now you know why.   It can take a while to break in if they are logging in from a remote computer, but they don't do it by hand.  Instead they use a computer program to do it.  This kind of attack is disturbingly simple and effective.

There are tricks to make a dictionary style attack work faster.  If the bad guy can get the list of user names and encrypted passwords, for example, then he can look for weak passwords much more quickly.  An insider can get that data for him, a security bug might expose the data, or a poorly secured computer system might make the password table available to an earlier attack.  Once they have the table, they simply encrypt an entire dictionary once and compare the results with all the encrypted passwords in the table.  Any matches they find become hacked accounts because they know both the login name and the original password. I am simplifying a lot, but this does happen.

If someone wants to get into your account specifically, and not just any account on a system, they can try things related to you in particular.  If they know your birthday or anniversary, the names of your spouse, children, and pets, the kind of car you drive, and things like that, those turn out to be likely passwords.  Trying a bunch of them may get them into your account because so many people use things related to themselves as passwords.  Also, many of those things are regularly used as answers to security questions, which are asked when you forget your password and want to reset it.  More on that later, but if the bad guy can get the system he's hacking to reset your password to something new, he's gotten in (or kept you out), so keeping personally identifying information private is always a good idea.

If someone is really serious they might try calling you and claiming to be from the company whose site they are interested in, and ask you for your password directly, as part of some security check.  If you fall for it, you might give them the password yourself.  Or they might claim to be doing a survey and ask for the number of people who live with you, their genders and first names.  Now they have additional passwords to try.  They might call your friends and associates at work and ask questions about you, again leading to possible passwords.  They could also call your system administrator at work, pretend to be you, and ask that the password be reset, at which time they can get into your computer because they are told (or even pick) the new password.  This is called a social attack, and while it isn't common to do this to get into someone's Facebook account, it is often used to get into more important systems.  Corporate or government espionage can happen this way, as can people trying to get data from the police or other organizations with information that isn't publicly available.  Celebrities suffer these sorts of attacks as well.

To avoid most of these issues, the best defense is a good, strong, password, one that you've told no one else, that isn't associated with you in any way, and which is hard for a computer to figure out.  Any particular system may impose limits on your password choices, but the basic ways in which you can create strong passwords are pretty simple.

How To Create Good Passwords:

The best passwords are hard for computer programs to guess or figure out, but easy for humans to remember.  That leads to some obvious choices in password selection.  The longer the string, the harder it will be for a computer to reverse the encryption process, for example, so longer passwords are better.  Non-words are always better than using a single word, but multiple words is good, particularly if they are unrelated.  Using special characters, numbers, and mixing case makes the password that much harder to guess - or reverse - too.

The system you are working with may impose limits, though, many of which are particularly stupid.  Maximum length limits are a problem; older systems often limit passwords to 8 characters, for example.  Some systems won't allow spaces or non-alphanumeric characters in passwords, or perhaps just a few special characters are possible.  These sorts of systems are making your life less secure, so consider just how much you need to use them at all and avoid them if you can.  Where you have to use them, though, you have to work within their rules.

If the system has no length or character limits of any significance, you can create long passwords by using multiple real words strung together:  "zebra goldfish piano golf".  While that is just four real words, all in lower case, that phrase of 25 characters is not in any dictionary, so it isn't subject to a dictionary attack, and it isn't associated with me in any way, so it cannot be guessed from my personal information.  In addition, even though it uses only lower case letters, it's long enough that reversing the encryption on it will be very hard.  This technique - stringing together a few normal words that you can easily remember - is a powerful one, and it is recommended if the system you are using supports it.  Note that you should not use words related to the system in question, either; "password for yahoo mail" is a poor choice for your yahoo mail account.   Also note that the spaces are optional: "PeanutSystemFlagCthulhu" is a perfectly good password.

If the system you're using requires shorter passwords, the best technique I have encountered is to use the first letters of a phrase, often with some substitutions or case changes.  For example, if I remember the phrase: "This is my password.  It should be longer."  I can use the first letters to create my password: "TimpIsbl".  If I want to I can substitute something like a number 1 for an i, and perhaps a $ for an s, creating: "T1mpI$bl".  These kinds of passwords work well on systems with limitations on length and/or characters allowed.  They are not easily guessed, provided the phrase is well chosen and unrelated to you in any way, and can contain as much character diversity as whatever system you're using allows.  Pick a phrase that you will remember easily, make a couple of substitutions in it, and you're done.

Whatever you do, don't use a single, real word as a password, and don't use anything easily associated with yourself, your family, your history, or the system or company the password is related to.

Here are some other things to avoid while creating passwords:

Managing multiple passwords is a challenge, so some people use passwords that are related in some way to help remember things.  This can work, but can also introduce risks, so be careful.  If all of my multi-word passwords are of the same form:

        password 4 email
        password 4 bank
        password 4 shopping

they are much less secure.  If one gets compromised, the bad guys might start guessing at the other passwords I use with some success.  Thus, patterns in your passwords should be avoided.

Some systems require you to change your password regularly.  In my opinion this is a really poor choice on the part of the system administrators, but it does happen.  Many people using these systems can't remember their passwords since they change so often, so they do one of a few things to help remember them.  Often they write them down somewhere, resulting in a list of passwords that they just add to as they change, and making their password available to anyone finding the list.  Alternately they may use change some part of the password each time but leave the rest the same.  This can result in much less secure passwords, commonly involving dates:

        MayPassword
        JunePassword
        JulyPassword

and so on for a system requiring monthly changes.  These sorts of passwords are less secure than a good password that is unrelated in any way to the user (even if that password changes much less often) and they regularly get written down too.

Telling your system administrators that password rotation is a bad idea will probably get you nowhere, though, so be a good citizen and pick a new, good, password each time, preferably using one of the methods given above, and read on to learn a bit more about how to manage large numbers of passwords.

How To Manage Too Many Passwords:

I don't know about you, but I am lucky to be able to remember the number of my own cell phone, so a huge list of passwords is a real problem.  And in this day and age that huge list is all too real. Keeping them straight is a significant challenge, one that I am not certain we have resolved just yet.

Still, there are at least a couple of approaches for this sort of thing.

The first is to avoid passwords entirely whenever possible.  If an online shopping site gives you the choice, don't create an account with them.  Yes, it means you'll have to enter your data every time you come back, but you also won't have to remember another password.  An added benefit is that they may not keep any permanently stored data about you, which means there is less chance of having your data compromised if their servers get hacked.

The alternative is to create a throw-away login every time you use a site, and never come back to it.  You can use a random string as your password and not remember it at all.  If they need an email address, remember that many email systems let you add a dash and additional characters to your email address, so you can give them something unique, and later filter out all email from that site if they start sending you spam.  For example, if your email address is foobar@gmail.com, you can tell a website that your email address is foobar-xyz@gmail.com.  Then, after your business with the site is finished, you can add a filter in gmail to get rid of anything sent to foobar-xyz@gmail.com.

If you really want to sever the connection between you and the site, though, create a whole new email address with any of the free email systems, use it for one or a few transactions or sites, and then delete it.

And while you're thinking about this, you don't have to give most sites on the Internet real data about you.  They want your birthday?  Tell them you were born on January 1, 1902 and are thus well over 100 years old.  How will they know it isn't true?  Remember that any personal data you let out is something that can be used against you, to hack any less than perfect passwords, or as part of a concerted identity theft effort.  If there isn't a good reason for the site to have that data, don't give them anything real.

But even using those tactics we still have too many logins and passwords to remember.  The list is long: banks, shopping sites we use a lot, places we pay bills to, information sources, and so on, not to mention the inevitable systems at work.  In these cases you cannot create a new account each time, and thus an alternative is needed, and that alternative is called password management software.

Password management software gives you a way to store all your passwords in a safe, encrypted format.  You get at them using a master password, and then once that system is running you can copy your user names and passwords and paste them into the login pages of websites you use.  When you exit your password management system it locks up your list of passwords in an encrypted format that, in theory, only you can get at.

The security of all password management software requires that your computers are up to date and virus free.  Anything that can run at will on your computer and/or log your keystrokes means you have no security, so always, ALWAYS, patch your computers and keep your virus scanner up to date.

There are at least 2 kinds of password management software:
  • It may be installed on your computer
  • It may be a service you use over the Internet
Software installed on your computer means that no one other than those with access to your machine has any chance of getting your passwords, so it is potentially safer.  On the other hand, you can't get to your passwords from multiple computers, so if you use more than one it may be less useful.  Do an Internet search for "password manager" to find programs available that do this sort of job.  Compare them for features and read reviews before making a choice.

An online password manager does the same job as one you install on your local computer, but it is a service provided by a company, and it requires an Internet connection to use.  That may seem like a drawback, but remember that if you need passwords you're probably online already, so it generally doesn't matter.  Online services of this type let you access your passwords from more than one computer - you just need to remember your master password to get in - but your data is stored on their servers, not your local machine.  I suggest looking for services where all encryption is done on your local computer before any data is sent to the servers.  That makes the data more secure, but it usually means that the service provider cannot recover your data if you forget your master password.  A search for "online password manager" will find these services.  Again, compare carefully before making a choice.

Both locally installed and online password managers let you save user names, passwords, URLs, and often other data associated with each login you're storing.  They have user interfaces that let you copy a password without displaying it, making it impossible for someone looking over your shoulder to see what your passwords are.  Many have tools to generate new, strong, random passwords for you, so that you can create unique passwords for each site you use.  Some have the ability to automatically log you in to sites as well.  Once you store the URL and the needed login data, you can get the tool to bring up a new browser window automatically logged in to the site of your choice, usually with just one mouse click.

Password management tools are important if you have to manage many different accounts, but they all suffer from the same weakness: the master password.  If that password gets compromised, all the passwords you have stored in the service or software are at risk.  For that reason it is critical that you treat that master password with care, and that it is as strong as you can possibly make it.  Never, under any circumstances, share it with anyone, and don't write it down.

I'm not going to recommend a password manager program.  Doing so is beyond the scope of this document, and individual requirements vary substantially, but there are quite a few choices available.

Other Thoughts On Passwords:

Many online systems make use of so called "security questions" as part of a password reset system.  Basically they let you select one or more questions and tell them what answer to expect when they know who you are, and then later - if you forget your password - they ask you one or more of those questions and will do the reset if you provide the expected answer(s).  The problem with these systems is that they are inherently weak as most users deal with them.  Maybe you're given a choice of the following questions:
  • What is your mother's maiden name?
  • What was the name of your first pet?
  • Where were you born?
  • The last 4 digits of your social security number
And you give them answers like:
  • Marx
  • Groucho
  • Tuskaloosa
  • 1234
The problem, of course, is that none of that data is secure in the modern world, and yet each one of those answers is, effectively, a password, and should be treated like one.  Of course that data is easy to remember, but by this point in your life how many people know where you were born, or the answers to any of those other questions?  If you're like most of us the answer is a lot of people know these sorts of things, and many of the rest of those answers can be searched for on the Internet for little or no money.

For some reason it seems like almost every company I deal with uses the last 4 digits of my SSN to confirm my identity, and with genealogical web sites abounding, mother's maiden names are common knowledge.  In fact, the answers to most of the usual security questions are a very simple social attack away from being compromised, if they aren't already commonly known or easily searchable.

What to do?  Treat those questions just like they ask for a password, not as a request for specific data.  The computer will never know that your mother's maiden name isn't really "Cg6y_t@$fg", but the bad guys won't know that was what you answered that question with either.  Of course, now you have yet another password to remember, and this one is going to get even less use than the regular password you use to get into the site, but if you're using a password management system which lets you take notes, you can log the security questions and your chosen - nonsense - answers there, for lookup when you need them for some reason.

This may seem like a lot of effort, but it is easy to disrupt people's lives - and sometimes steal their money or identity - using password recovery systems.  Don't treat them lightly.

Another place where we get lazy - and risk compromise - is by letting our web browsers store passwords for us.  This is very convenient, of course, and at times it is just fine.  If your browser remembers your password for the local newspaper, perhaps, and it gets compromised, someone can read articles and maybe post comments as if they were you.  Not necessarily a big deal.  Things get worse, though, if your browser remembers your amazon.com password.  Now a thief can login and order things using the credit card numbers you have saved there, possibly costing you real money and time.  And if your banking passwords are stored in your browser, well, you might just as well leave your keys in the car and the engine running all the time.

Browser based password storage is fine for sites with essentially no risk as a result of a stolen computer.  But if there is anything important on a web site, don't ever let any browser store the password for you.  You have to remember it yourself, or use your password management system to keep track of it.  Anything else is asking for trouble.

And, of course, never use browser stored passwords on a shared or public computer.

ATM PINs are among the worst possible passwords in existence.  If they're limited to 4 digits there are only 10,000 possible PINs, which is way too tiny a set.  Sadly, though, ATM networks often don't deal with longer PINs.  I encountered this once, years ago, while travelling overseas.  My ATM card worked just fine in the US with my longer PIN, but was useless in ATMs where I was.  I only figured this out once I was over there, of course, and I had to go into banks to get cash.  Hopefully the banks will get a handle on this, but always be extremely careful with your ATM card.  Once lost it is a high speed route to an empty bank account.

In Summary:
  • Create good, strong passwords using the initial letters of a phrase or several unrelated words strung together.  In either case additional security comes with some character substitutions into upper case, numbers and special characters.  Be sure your selected phrase or words aren't related to you or the system in question too.
  • Never share your passwords with anyone, deliberately or otherwise.
  • Never use the same password for multiple sites.
  • Consider using password management software if you have too many passwords to remember.
Welcome to the modern world.  Ain't it fun?

Update 9/26/11: my friend David Clunie posted a blog post about this video, that discusses some of what I talk about above.  Thanks David!

Friday, July 31, 2009

No, I don't "Tweet"

Here's another in a series of posts that will almost certainly offend some of my readers. I apologize up front, but I stand by my premise...

Yes, I am something of a Luddite, but that doesn't mean I'm completely nuts. Lately I am starting to think certain uses of technology are simply a bad idea. Consider:
  • Twitter
  • Facebook
  • Power Point in the school
All of these suffer from a single major issue: they encourage tiny thinking.

Yes, I know that Twitter has become a major news source, and yes that's a good thing. It may even be a democratizing influence, but all kinds of technologies with a few good uses suffer from huge drawbacks. I'm not going to make a list by way of example. If you can't come up with a few genies that did both harm and good when let out of the bottle you're not trying.

Put plainly, Twitter actively discourages complex thought. Far too many Americans can't string even a few words together. If the current generation grows up communicating in ultra compressed text snippets I really don't want to think about where we'll be. I am certain I won't like it though.

Facebook looked interesting to me after I started using it, and there are a lot of people I simply don't see that often. Our hectic lifestyles mean I'd never know what they are up to without Facebook or something like it. Lately, though, I've encountered something I don't like: people are mirroring their incomprehensible twitter feeds into their Facebook status updates.

Maybe I'd understand them if I did nothing but follow Twitter and/or their lives in depth, but I have a wife, a job, dogs to take care of, and things to to in the real world. Trying to understand these cryptic messages typed in on phone keyboards from the middle of nowhere isn't going down well with me. In truth I could probably ignore those - possibly by disabling the feeds from the guilty - but there's a related trend, and it's just as disturbing: short, pointless, repeated Facebook status messages.

How often do I need to know that someone is tired, or is going to bed? The minutia of daily life is just that: minutia. Tell me about the important things - or even the semi important things. Did you get a new job? A new house? Get engaged or divorced? Celebrating something important or had an epiphany of some sort? Great! Share away. Tell me about your kids, the things that made you whoop for joy or scream in despair. I'm fine with all that, and I will whoop or cry with you. I'll even do my best to support you when you're down. Just please don't use the vast resources of the Internet to tell me you're home from work.

Years ago I heard a story on the radio about a pathological diarist. He documented every little thing in his life: what he had for lunch, at what time, where he sat while he was eating it, what he was going to next (after updating his diary), and so on. As I recall he was in his 40s or 50s and his diary was many, many books, all full of hand written, pointless drivel about nothing. I pitied the guy, and I suspect that vast diary will be thrown in the trash when he dies. No one is going to care, and all that effort is wasted.

I feel somewhat similar about people I know telling me (and all their other Facebook friends) they had green beans with dinner. Part of what causes these kinds of status updates - besides most of us (myself included!) having nothing important, relevant, or useful to say the vast majority of the time - is that the silly status box is so small. Facebook doesn't limit you to a tiny comment like Twitter, but the interface encourages it, and recent design changes at Facebook indicate they're moving farther in that direction. Yet again a powerful tool is helping make all of us - or at least its users - less capable of complex thought.

I must admit I've posted pointless status updates myself many times, but I am trying to stop it now. Actively working at it. Feel free to tell me this blog post qualifies as the same kind of inane babble, but at least I am trying to address a complex topic - something I care about - and am doing so in whole paragraphs, with real thought behind them. (Or the closest analog to real thought I can achieve.)

The last item on my list - Power Point use in schools - is just as bad, and just as dangerous to the future. An entire generation is growing up thinking that the best possible communication path is animated bullet points that slide into place on a screen with sound effects. "The Panama Canal is in South America. Click! Ships go through it. Click! The US helped build it. Click! And that's my presentation. Can I get my 'A' now? No? But I wrote the right number of bullet points and I had pictures and everything!"

How many avid readers do you know? How many of them are kids?

What about writing? Does anyone you know write more than a hundred characters with regularity? Probably not.

Nothing encourages thoughtful, intelligent communication anymore, and the technologies listed here are radically changing the way we communicate whether we like it or not. I am not optimistic about the direction of that change.