Showing posts with label annoyances. Show all posts
Showing posts with label annoyances. Show all posts

Friday, June 25, 2010

Windows 7: Byte Me

I've had to play with Windows 7 in the workplace lately.

It's been...interesting?

First of all, Microsoft did improve heavily from Vista. Vista was frustration wrapped in a pretty eye candy shell, and no matter what you did to try and enjoy the candy the frustration was just itching to burst through and make you gag.

At least now it doesn't nag you quite as much.

That said, I've still had issues with Windows 7.

I hate not being able to easily run something as administrator. I find that I have to type "cmd" into the search bar and then right click on the result to "run as administrator."

We use a VNC server to remotely work on many of the desktops in our organization. Windows XP? It wasn't a problem. Under 7 (and Vista when we tested that abomination) we needed to run something like UltraVNC, because the version we were running isn't compatible with the security model used in newer versions of Windows.

I also was more than a little irritated when I could no longer run XLiveCD, a CD disc that has a standalone set of Cygwin tools and X Windows client for Windows. Pop in the CD, run it, and it allows me to secure shell into a Linux system at the office and run my mail client or other tools on my office system. Exit out, and there's no trace of anything on the client computer. Really handy for getting some work done in the field. Windows 7 won't allow me to run it, no matter what I've tried (compatibility settings, permissions, running as administrator...) How annoying!

Another item; I had to change some permissions on icons placed on the desktop of a system. They were icons for everyone, but because of the way my boss made a batch file the icons were placed in a directory for everyone to use under Users but the permissions were set to just the administrative user running the batch file. I went into Users (since documents and settings is no more) and went into all users (after I finally found the setting for showing hidden files and folders, since the file menu is gone now from Explorer windows.) I went into All Users, but even as an administrative user I couldn't get into the "desktop" folder.

I swore a few times and my supervisor came over. "Oh no, it's not there. Go up one and go into Shared." (It may have been Public, I'm recalling this from memory and am too lazy to look it up.) Sure enough, that folder had the Desktop folder for all users who log into the machine.

"That's stupid! The folder sounds like one used as a common sharing area for any user to share documents with each other..."

"I know. But that's what it is now."

Bloody @#$.

Then I had to reset the permissions by selecting the folder containing the desktop files and resetting the files from there, since I couldn't just select the files and tell it to change permissions to those inherited by the parent folder as I could under XP.

Then today I had an application that is niche, used by only a few of our users but "vital" (due to more mandates from outside our control) for their job function. The program looks for "Windows NT 4.0 SP 6 or higher", and installed .NET runtime 1.1, if that tells you anything about the age of the program. It looks like something shoveled together at the last minute and shoved out the door, then as long as the #@#% thing ran the company never bothered to improve it (hey, they have a contract to supply it and we're mandated to use it! So why should they improve it?!)

Can you guess where this is going?

I contacted the company, saying that we have this program that apparently has problems with Windows 7. Is there an update or patch?

"Nope. The workaround is to use a Windows XP SP 3 system until we get a chance to test it with Windows 7, maybe sometime next month."

Um...you're aware the Windows 7 has been released, right? And if you actually developed the product, you should have had a copy of the betas of Win7 to...I don't know...test with several months ago, yeah?

Great. Another company producing shovelware.

And I can't get the "compatibility" mode of anything to work with this piece of crud. Then I saw something that gave me hope! Windows 7 XP mode!

Basically, it's a virtual machine running Windows XP for backwards compatibility!

I downloaded the 500 meg installer from microsoft, installed the virtual machine software, then installed the update patch (MS actually had a convenient web page with a "install this, then install this, then install this...set of instructions and download buttons.) I was getting irritated that I had to run some "Authentic windows" verification program, several times for reasons unknown to me other than probably clicking the link too many times while it was pausing to think about whether it actually wanted to do what I told it to do, and finally everything installed!

Then I created a new virtual machine. Oddly enough it said for memory I could allocate 4 to 511 meg. I skimmed the wizard's instructions (don't most people) and just clicked "next"; it beeped at me with an error. Apparently the default memory size in the box was 512, despite the warning that it could only go up to 511. My supervisor wondered what was going on when I blurted out, "How fucking retarded is this thing?!"

He just shrugged and went back to what he was doing once I explained what Windows was doing again. Because really, how hard is it to check that error condition?

Fixed it, created the VM, and double clicked it, giddy with excitement that I may have found the solution to our problem. The computer hesitated, gave a busy pointer for a moment, then *blip*...blue screen of death.

The machine rebooted, and I tried again. *blam.* Blue screen of death.

Yes, I found a great Windows simulator here.

I slammed the desk with a fist and moved on to Googling the error. So far I found griping about problems with XP Mode on Windows 7, but no solutions. The last thing I did before leaving was upgrade the BIOS since it was an older computer, but haven't tested it again.

So what do I think of Windows 7? It has potential. It looks nice, it has great features, it's leaps ahead of Windows Vista, but it's still frustrating as hell half the time and the rest of the time it's mildly irritating. It's broken a lot of software, and if you're using software by developers that played loose and wild with best practices you'll be lucky if your software works properly.

There are those that would say it's just because I'm used to "bad habits" from Windows XP. Perhaps they are right to some degree. On the other hand, every irritation is one more reminder why I have come to prefer the Mac as my computing platform. It's not fanboy fanaticism or a need to feel superior to Windows users. It's because I find it far less frustrating to use and it doesn't get in my way even half as much as Windows.

Thursday, May 6, 2010

Lower Merion School District Spying Report Issued

The findings of an independent consulting company (Ballard Spahr, LLP) were released recently regarding the remote monitoring of student laptop computers by the Lower Merion School District. Already it spurs an outpouring of vitriol in comments from the smart masses who think they understand anything that is going on here. Personally I think there's a huge disconnect between the peanut gallery and their perceived intelligence.

The report, an approximately 70 page outline of everything that was leaking into the press and then some, basically said what I originally thought. The school district has a lot of idiots running it. Not in so many words and perhaps not for the reasons people would think, but they did some pretty spectacularly stupid things.

The biggest problem, of course, was the IT department hiding the presence of the tracking software. It wasn't so much that I can't relate to their desire to hide it from people in case they try to circumvent the protection; I work in IT. I know people could do that. But anyone with half a brain in IT knows that security through obscurity won't work well. The laptops, if stolen, could easily be wiped and reinstalled with a clean OS image, and the tracking software would be useless. They not only hid it was there, but apparently they tried to obscure the fact that the software was there even when rumors were swirling about its existence. That is a blatant lack of respect for the students and faculty. Whether you regard them as little vengeful monsters or not they still deserve not to be lied to.

A very close second (okay, maybe it's a tie) was the lack of an updated usage policy for taking technology home. There were no documents to disclose modified acceptable use policies for using the laptops at home versus on the school network nor was there disclosure about potential security and privacy issues in the documentation given to parents.

Everything else in the report seems to nick the school for lax and ill-codified policies, and not being fully forthright with administrators and board members.

As someone who has to work in IT, I think the two biggest sins were the lack of properly documented procedures and the hiding of the ability to monitor the laptops. The fact that administrators and board members didn't know about these things, or didn't understand it, were not the IT department's fault, unless they went out of their way to hide it.

Really...there is a point where someone needs to take responsibility for themselves. The board didn't know about it because they didn't care. Neither did the administrators. They all had a vague idea of this ability, if they've seen evidence from the "anti theft" systems. What the hell did they think it did? That this stuff runs on unicorn farts and fairy dust?

I deal with users all the time. They care about how and why their systems work about as much as you care about how your car engine works. The IT department didn't explain it to them because it was a waste of time to do so! I've dealt with users to whom I've explained a simple (to me) concept several times and they simply don't listen. I can repeat it until I'm blue in the face and it doesn't matter. So why and how would this IT department telling their school board about activating timed snapshots from a webcam and screen capture utility while logging the remote system's IP address to a central server make any fucking difference to them?

And lack of following formal policies? In most smaller businesses and schools and, I'd venture, government agencies, following strict, codified policies is a luxury. We always hold up best practices as an ideal but more often than not they're aspired to, not followed. Departments like those in public schools are under immense pressures from the powers that be to just get a task done, and if it's held together with duct tape and broken pencils then so be it. Doing it "right" takes money and time. They don't want it done right. They want it done now.

While some would say that's an excuse, it's more of an explanation for the culture that this attitude has fostered. More often than not if something works, then it's good enough, and it saves money. If it's actually bad enough to bite you in the ass later then it will be fixed then. Otherwise, good enough is good enough.

What I find interesting is that lack of citing personal responsibility by the peanut gallery. These kids were using school property and apparently treated it like their own property. It wasn't. I was floored when this story broke and people were raving about how they'd format the computers if their kid had brought one of them home; yeah, right. You can't. It's not yours. The school was extending it as part of an experiment in technology-based curriculum. And it's their computer. Not yours. Not a handout. Not your property.

I'd have trusted the laptop about as far as I could throw it. Any organization that "lends" you a thousand dollar piece of equipment, would surely have the right to inspect it for activity; porn surfing, games, inappropriate use, anything of that nature. What universe would you live in where you go to school, can't browse the web the way you want, can't play the games you want, but expect them to just hand over a thousand dollar laptop so you could surf porn at home on their dime?

Use your damn brain!

There was one report of a girl who had taken the laptop into the bathroom to listen to music while she showered, and the parent was furious because the school may have seen his little high school princess naked. Huh?!

Damp, humid room...thousand dollar laptop...electronics...water. What the hell was it doing in that environment to begin with?!

To me, there were a number of failures here. From hiding the fact that this software existed to lack of formal CYA policies to cover proper usage of the laptops at home to a lack of common sense from the students and parents, there was a systematic failure that happened here.

The sadder part in my view is the ignorance of the peanut gallery. It's simply too easy to blame the evil school district and portray them as completely at fault while completely forgetting that there was also a bit of an attitude of entitlement, that reality has slammed down hard on the community realizing that these free toys weren't free. 

Tuesday, April 27, 2010

Microsoft Licensing: The Pain It Keeps On Rolling

I continued to set up the Dell machine from the other day. I started out my day at the office where I updated my supervisor on the installation, saying that the laptop couldn't be joined to the Active Directory domain because it was running Windows 7 Home, and apparently that ability is disabled in the home edition. I wasn't sure if he'd care because I thought the user was going to be using it primarily at home anyway.

"Nah," he said. "We have Windows 7 Professional and the licenses, just install that on it."

I sighed, packed up my shiny Windows 7 DVD (64 bit, since for some reason the home version of Windows 7 was 64 bit on that laptop with less than 4 gig of usable RAM...) and headed out to the office where I could work on that system.

I vaguely recall that Windows since Vista has been coming in a form where every version, and there are lots of them, of Windows is included on the install DVD. The different versions that cost you hundreds and hundreds of dollars between the lowliest, crappiest version to the least crippled version are all one in the same; they simply have functionality that is disabled or enabled depending on the license key you feed it.

Neat, eh?

Don't get me wrong with what I'm about to say. I personally hate using software that is crippled artificially. It was one of the reasons I initially moved to Linux; my desktop computer could act as a capable server, while Windows, despite being able to handle a modest workload, was throttled back in what it could handle simply because of a registry setting. Even though I never to my recollection was even maxing out the throttled limits I hated the idea that my system was crippled simply because of me not having more money.

At the same time, I understand and support that it is Microsoft's right to impose limits on their users, as we have to agree to the license in the first place and that license places these (irritatingly arbitrary) limits on the end user. That's why I moved to Linux instead of pirating Windows. It's their product. They dictate what can and can't be done with it.

That said, why is it that Microsoft seems to go out of their way to make a task as simple as installing our volume-licensed, legal copy of Windows 7 Professional over the default Windows 7 Home preinstalled on a Dell laptop?

Here's the thing; for the most part, choice is bad for ease of use. You give users choices, you make them think, you give them the opportunity to screw up. That counts against you in the ease of use department. Weird, isn't it?

Microsoft has outdone itself, going out of their way to make something as simple as licensing into a pain in the arse.

The DVD we have actually has two licenses printed on it. One is KMS and the other is MAK. KMS is their Key Management Service key, and MAK is their Multiple Activation Key. Two really long string of numbers and letters that belong to our business. The difference? The KMS key allows us to have an "in-house" server to handle activations more or less automatically, while the MAK key allows us to input the MAK key individually into systems that then call Microsoft over the Internet to activate. Both the MAK and KMS keys are types of Volume Keys.

Making sense so far?

The Dell laptop with Windows 7 Home apparently has a self-activated key already installed. I popped in the DVD with Windows 7 and told it to run Setup. Setup started chugging along, asking a couple questions, then  it got to the point where it asked if I wanted to upgrade or clean install. I said, upgrade! I already installed an antivirus and our full version of Office (after deleting some crappy trial version of Office that was on the system when we received it for configuration. Setup started looking at the drive and said, "Nope! We can't do that with this version of Windows! You have to run the Windows Anytime Upgrade from the start menu!"

Ah-ha! It does have all the versions of Windows, I just need to plug my key there!

I do a search, since the menu system in today's incarnations of Windows makes it damn near impossible to actually find anything now, for the Windows Anytime Upgrade utility. Run it, it asks for the key. I put in our MAK. It rejects it.

Apparently you need a special Windows Anytime Upgrade key in order to activate that function.

So now I have a licensed, pre-activated Home key, a MAK key, and a KMS key, and none of them do me a damn bit of good because I need a WAU key.

I swear, several times actually, and re-run the setup utility, this time telling it to nuke the C: drive and start over.

This time it worked. I had to spend most of the day reinstalling Windows (Professional, this time), reinstalling Office, reinstalling antivirus, and all the miscellaneous utilities that I had installed but wiped out in the full reinstall.

This wouldn't piss me off so much if I hadn't seen the alternative way to handle licensing. In Linux, there are no real restrictions. You may get a flash of the GPL license, but no key to enter, no restrictions on how you use the operating system (other than what the GPL enforces, which for most users is of no consequence).

On OS X, there are licensing restrictions, but Apple largely takes you at the honor system. Their attitude seems to be, if you put the operating system on hardware that's not ours and it doesn't work, you're screwed, buddy. Apple is largely a hardware company. They make money from their hardware and services. While they have restrictions on what you can and can't do with their software they don't go out of their way to make customers bend backwards while gargling Yankee Doodle Dandy on a unicycle in order to install their software on their hardware.

In the end it feels as if you buy their operating system just by having purchased the Mac. It doesn't bug you for software keys or activation. It just installs. The closest I've had to being locked out from an installer was trying to use a MacBook installer CD to reinstall OS X on an older system whose hard disk had failed. The install CD was keyed to work only with MacBooks, even though it was the version I had on the PowerMac before it died. I think I was still able to reinstall on the new hard disk by booting the Mac to Target Disk Mode and installing from there, as I recall.

No pestering. No nagging. Definitely no typing thirty-digit codes by hand. Maybe Apple just thinks it's not worth pissing off or frustrating customers for the possibility that someone will pirate their software. I had to take my mother-in-law's old G4 notebook in to an Apple store after the operating system became corrupt, and in the end they did a restore from a clean image. The guy at the Genius bar asked what version of OS X was on it.

How would I remember? I haven't looked at that system in probably two years. I can't remember what I wore two days ago, let alone what my mother in law had on her notebook. I guessed 10.4 judging from what I probably had on it when it became her system.

The Genius didn't ask for proof. Didn't hassle us at all. I think he was prepared to install whatever version I said (except Snow Leopard, since that didn't work on G4 Macs). Oh dear, they might lose $30 if I stole a newer version of their operating system! Instead, they made happy customers a priority over losing a drop in the bucket in change.

On the other hand I ended up losing most of a day of work because I needed to install from scratch Windows because I didn't have a particular type of key. Because the keys we paid lots of money for, legitimate keys, wouldn't work to do an in-place upgrade that would have taken ten minutes.

Thanks, Microsoft. One of the largest companies on the planet and you manage to make something as simple as installing your operating system a major hassle for a legitimate customer. Let me wave my "you're number one" sign at you without using my pointer finger. With both hands.

Wednesday, November 18, 2009

I Hate VISTA!

There are many things that factor into user-friendliness and it absolutely floors me that something like Vista was released so many years after Apple's OS X, an operating system that has been hailed as a shining example of user friendliness. I can understand many of the shortcomings of Linux in this area...it's largely developed by geeks that like to do what they can to prevent the average user from entering the sacred halls of geekdom, and creating pain among users is a secret handshake in our meritocracy.

But when you're the dominant operating system vendor with millions of users and millions and millions of dollars in R&D, what excuse do you really have for releasing something that is actually several times more frustrating than anything a bunch of geeks have (laughingly) "designed"?

I had to work on a laptop (yes, that I previously had worked on with Vista Home Edition) that was reported as saying that it "needed to update the antivirus but need administrator to do it."

Okay, shouldn't be hard. The antivirus is one that I'm not too crazy over because it, too, has in my opinion design flaws that drive me freakin' batty as well...Central Command's Vexira. However, I take the laptop and start to work.

I ended up having the laptop brought home. I spend some time trying to get Vista to find my wireless network (usually with XP it's a simple matter of clicking the wireless icon in the tool bar and selecting from a list, but this Vista laptops wouldn't show that to me). I eventually found in the networking control panel a line in English, in tiny print, telling me I can "find a network." Fair enough.

It found my (unsecured) wireless network. Join it. Warning: EVERYONE WILL SEE WHAT YOU'RE DOING!" Then it gave a button that didn't look like a button to continue on anyway. I thought it was a label of some sort...nope, just an awkwardly labeled button in the interface. I twitched a little.

It joined my wireless network, telling me the signal strength was excellent. I then right clicked on the Vexira system tray icon and told it to update. And waited. After a few moments I noticed a blinking task bar icon; click that, it tells me that there's a system notice. Click that, and the screen does the obligatory blanking-switch-to-system-screen. Told it to update, and it belches an error with the connection.

Huh?

Told it to "return to my desktop", leading to the laptop blinking a few times.

I was disconnected from the wireless. No reason why, just not connected.

I sigh and go through all the steps to reconnect and once again bring up the update interface on the "special annoy the hell out of the user" desktop.

SAME @#% ERROR. I returned to the regular interface and check the network connection. Disconnected.

I tell the bloody thing to reconnect, and this time "remember the network" and "connect automatically".  This time the notebook connected and stayed connected.

That wasn't the end of the problems, but my gripe here is about Vista, not Vexira. I don't understand why the connection was:
A) so awkward to connect to in the first place.
B) kept disconnecting without notice.
C) had so many @#% clicks to find, establish, and re-establish.

This was on top of the issue with having to switch desktop modes a few times and having the display click and clack as it changed back and forth (resetting video modes? Redetecting the display? I don't know; from the user perspective, all I know is that it ticked me off having to repeatedly go through that annoyance).

I'm a big believer in preventing friction in a user experience. I do what I can to minimize this friction; one thing I do to make it as least annoying as possible is to secure my systems from intrusion and monitor my network usage while removing encryption from my wireless network to make it friendly to the myriad devices we use. This should have made connecting to my wireless network a simple matter of "show available networks, select, connect." So why wouldn't this @#$% notebook connect and stay connected?

Once I told it to "remember the network" and "connect automatically", it stayed connected long enough for me to get a dose of hate for Vexira. The wireless network worked without issues for my wife's Mac. My own Mac hasn't had issues. My iPod hasn't had issues. So unless something is flaky with that notebook's hardware...which hasn't been reported (although possible)...it tells me that my headaches were Vista-related.

It's almost like Vista was going out of it's way to make this three times more difficult than it needed to be! Another checkmark on why I hate Vista. Supposedly Windows 7 improves this dramatically. Me, I'm not so sure I care. There's an Apple ad that pokes fun of the "it has none of the problems Vista had...it has none of the problems XP had...it has none of the problems Windows 2000 had..." There comes a point where I just don't care anymore. When the track record goes this far down, when the experience just fails so hard and far, when I've switched to another platform altogether and found it to be a huge improvement to my ulcers...

I. Just. Don't. Care.

Pay me to try Windows 7, and I might try it. If not then I'll wait until I absolutely need to deal with a new set of headaches.

Tuesday, November 10, 2009

Tech Support With a Tinge of Irritation

I just got a call from family for another round of tech support. I always realize after the fact just how irritated I sound when I get these calls.

It's a tough situation to be in. Of course there's my much mentioned personality disorders. But I also have tech support obligations at my day job. For many years I get calls for the same issues, over and over, usually dealing with people who are unhappy to begin with because they broke or lost something on their computer or can't be bothered to read and comprehend a statement on the screen. More often than not it's something that they called about a few months ago. Same issues. Over and over. And I dutifully repeat myself. Over and over.

I've heard many times how often tech support is a burnout job. No one stays sane in that position for long. And I've been doing it a long time. Repairing. Swapping. Answering repetitive questions. Educating over and over, the user never quite comprehending.

Worse, I'm normally regarded with a feeling of disdain. The movies make this stuff look simple. Why can't I just type a few words into the keyboard and have it work? I mean, The Matrix, The Net, the latest Die Hard, Wargames...they made it all so simple. Maybe I should pull a Tron and just jump through the screen and make it work for them. It's a simple job, making them wait longer while I decipher what the hell they're talking about is just irritating them. I must be doing it on purpose.

Better yet, tell me how you're not a computer person. Or how stupid computers are. How you hate them. I love hearing how my college investment and years of work were all pointless. And I'm still obligated to help you.

Then my family and friends want help. At work, we generally know what the systems have, how they work, how the network is configured. I generally know what you're supposed to be doing to get your documents. What applications, generally, you're running. When you are calling from home you've installed games, you've altered settings, I can't see what you're seeing. I need to rely on your descriptions. I need to strain to remember what you're running. Sometimes I remember. Sometimes I can't remember what I wore yesterday.

They get frustrated. I'm already irritated. It never ends well. They get free service at the price of putting up with my terse commands and repetitive issuance of directions. I remind myself that technology doesn't dance to the stroke of keys for them the say it does for me. I feel swells of anger at them not being willing to help themselves by working on basic functions like knowing where they put the damn files they created. I feel waves of frustration at their descriptions of things I can't see but need to know in order to instinctively discern the true nature of the problem. Then I have to remind myself once again...I don't know things they specialize in, they don't know things I specialize in.

Frustrating. And I always regret sounding like the ass after the fact. Maybe someday I will find a better coping mechanism. sigh.

Thursday, November 5, 2009

Why Ask "Are You Sure?"

Joel Spolsky mentioned the question of why programmers bother having applications ask for confirmation from users before performing some task. He said that it seems to serve only one purpose; to make the user feel guilty.

The reasoning as I remember was that users, not being "computer people", don't know what to do when confronted with a confirmation. They don't care to know. They trust in the programmer...the "computer techie people"...to know what's best, so they just go ahead and confirm whatever it is that pops up.

So he said that the only reason to do it was to make them feel stupid. This way they confirm whatever it was that pops up, then find out it deleted something or did something they didn't mean to do, then know that they had the confirmation warning them not to do it and they said to do it anyway.

"Oh! I'm an idiot! I should have chosen something else!"

Personally I'm not sure that users feel stupid about making a mistake. They just blame the application, programmer, or "stupid computer". Maybe some feel like idiots, but I'm thinking they're not in the majority.

I hate those stupid confirmations. Users don't read confirmations or licenses or any of the "user friendly" crap that is thrown into Windows (do any tech people use the "friendly" control panel? I immediately switched to the old style while using XP).

I prefer having a straightforward set of tools that do what I want. Clear labeling for buttons, straightforward questions and queries that leave no ambiguity about what happens when you select yes or no (OS X is famous for eliminating a lot of the ambiguity from their selection dialogs), having a simple way to navigate the interface instead of five ways to accomplish one task...those are hallmarks of good design. Any roadblock you throw up in a workflow is a bad thing; users tend to not read them anyway! Even if they did, they claim they didn't understand it. So they just trust that the programmer selected sane defaults and click right through them.

I think this is what Mark Shuttleworth calls a papercut...little things that aren't bugs, per se, but added up create a bad user experience. It's a waste of bits and annoying as hell when you just want to get something done. I truly wish that there was a way to have an operating system that possessed an interface that doesn't try whatever it can do to get in your way with inane and worthless dialog boxes.

Is there any reason to have an "are you sure?" dialog box or other cutesy abstractions to the system? Maybe for things that are blatantly destructive (About to format volume C: in 10 seconds...), but other things...I'm not so sure. Anyone have experiences or opinions to share?

Wednesday, October 28, 2009

The Abomination that is Windows Vista

I recently had cause to work on a system that another department had ordered a few years ago with Windows Vista Home Basic on it.

It reminded me all over again of all the things I hate so passionately about Windows Vista.

I recently blogged about my trials and tribulations involving the fact that there's no default administrator account while I had to reset the password for the default administrative user on the system in question. It was irritating, but followed the trend of other operating systems; "hide the administrative user behind another layer so people who don't think before hitting Enter will have another hurdle to cross before destroying their system."

The more I worked with this computer, though, the more agitated I became. The computer wasn't really a slouch. It was a core 2 duo with a gig of RAM. Yet I booted it, it would pop up with a welcome screen. Log in. Goes black. Comes back up. Flickers back out. Comes back up. I think at a couple points in the troubleshooting I turned off the computer accidentally, thinking that it had crashed when it went black for more than ten seconds.

My first computer ran DOS and Windows 3.1 on a 486SX-25 processor and 4 meg of RAM. That system even ran a beta of Windows 95. 4 meg of RAM. The is like comparing an 86' Chevy to the starship Enterprise. And Vista was killing it.

I had to reboot it several times over the course of upgrades. The upgrade mechanism was infuriating. There was very little feedback; it would sit at the prompt that it was checking for upgrades at 0% for ten or fifteen minutes at a time. When I thought it had crashed, it suddenly jumped to 40% complete.

Other times it would come up and say I had 4 optional addons (after several rounds of updates completed). Done? Nope. I clicked "check for updates" (again) and it suddenly found another couple of updates waiting.

I was even more agitated earlier when it installed a whole group of updates...twenty or thirty...then I attempted to install Internet Explorer 8. It wouldn't. The install program would just "disappear", no warning, no nothing. I downloaded it four or five times.

I broke down and downloaded the standalone installer to another folder and ran it from there. It failed, this time leaving a link on the desktop with a potential fix. Between that and checking my trusty friend Google, I was told to check Windows Updates first. Then there was a little note saying that Vista with SP1 didn't need this, and IE8 would install fine with Service Pack 1 installed.

No...service...pack...one?

I went to Microsoft's site and downloaded a FOUR HUNDRED MEGABYTE service pack. And installed it.

Then installed IE 8.

You can rightly assume there were three or four reboots involved.

And I nearly screamed when it said there was another 200 megabytes of updates waiting for me after those were installed.

I had to attempt to install those updates about four times. Each time, some installed, others failed due to some vague error. A reboot and retry would yield a little more progress.

You can rightly assume that I was getting more and more agitated at this.

After all these updates, Windows Updates decided that there was a service pack 2 waiting for me.

If you didn't know, most service packs roll previous fixes right in. So if you install service pack 2, you already have all the fixes that came before it. That way you don't have to install service pack 1then 2. You install 2 and get all the fixes since the operating system was released up to that point.

I was incensed and furious. What kind of braindead monkey designed this update system?

All this time I was working on getting the antivirus working. In the corporation we use Vexira antivirus from Command Central. It's not my favorite.

Vista doesn't seem to love it either. I right click on the tray icon and tell it to update itself. The update console doesn't come up. Instead some "interactive service dialog" pops up. Click it, and it takes me to some kind of privileged desktop that hides the things I was actually working on so I can see the antivirus update console.

With a heavy sigh I told it to start updating. It dutifully began downloading a new version of the antivirus. The computer sat for about a minute.

And went dark.

Another "flicker out"? WTF?

I moved the mouse and the login screen pops up. It said my administrative user was "already logged in", but...huh?

I couldn't find any way to shut that off. Unless I keep moving the mouse while in that "interactive desktop", the @#% thing would drop me to the login prompt after a minute or two.

This didn't happen at the regular desktop. Couldn't find a setting to stop this from happening in power settings or desktop settings or the user account.

I would have checked the local user policies, but because of Microsoft's crappy ranking system of their operating systems they don't include the policy editor with their home edition of Vista. Same operating system as their "business" operating system, but artificially crippled by cutting out utilities that could actually help the users in need of troubleshooting...another reason I moved to Linux in the first place. If your system couldn't act as a server it's because the hardware or software couldn't handle it, not because of someone's idea of a fair market or sales policy found posted in their colon or some other artificial limitation in the software.

Supposedly Windows 7 fixes a lot of the usability snafus and glitches. I hear lots of praises for it. The problem is, I don't care. I've had enough frustrations with Windows. I've spent years finding workarounds to various glitches in Windows 2000, then XP, and now I'm expected to leap again with Windows 7.

I'll do it because eventually I'll have to. But I can't enjoy it anymore. I used to be enamored by technology; I loved jumping into the theory behind multitasking operating systems and handles and filesystems. I used to devour articles in Byte magazine that compared various operating systems and how they worked and compared to each other in architecture. I think I still have magazines in storage that had information on the great OS/2 vs. NT debates.

But today it's no longer a question that interests me. The arguments don't focus on usability or architecture so much as how much the OS can be dumbed down for users; the Vista control panel tries to communicate in plain English concepts that for tech people would be much better served with straightforward checkboxes and text boxes for values. I don't need handholding and friendly web-like links asking if I'd like to change my password, thank you.

There aren't any companies really trying to innovate in operating systems. There are three; Apple's OS X, Microsoft's Windows, and Linux. That's it.

There is a convergence in features and eye candy that suck up resources like crazy. I remember my old computer was perfectly adequate for my tasks. Today you couldn't even get a common OS distribution to boot on a system with those specs.

I've played with BeOS, AmigaOS, Linux, MacOS, OS X, DOS (MS, IBM, Novell), Windows from 3.0 to 98 (we don't speak of ME), NT from 3.1 to Vista, Netware, and several small and hobby OS's like QNX and ReactOS and others too small to name here. Today most of the projects are gone. Except, of course, for Windows, Linux, and OS X.

Vista was a reminder of what I hated about this trend. Technology is exciting today with new devices; the Kindle. The Nook. The iPod and iPhone. The web. Operating systems are so bland and commodity that they're not really even worth looking at anymore.

When operating systems frustrated me before it was because of my own limitations and lack of knowledge. I had to expand my understanding of how the system worked in order to bend it to my will. Today the frustration is being designed into the operating system. "Are you sure you want to run this?" "Do you really want this program to run?"

Or all the times I'm searching for a function that disappeared from the previous version of Windows. It's infuriating when I know what I'm looking to do and can't because I have to interpret the "natural language" version of the interface.

Or I have to click to open the C: drive, then confirm that yes I want to see this files, then click on Program Files, and again confirm that I wanted to see the contents of the folder.

At that point I really can't help but re-examine my job duties. It's one thing when I can't get something to work because I'm lacking information. Learn more about LDAP. Learn more about TCP/IP. Learn about priorities and file handles and applications to monitor I/O. Read read read. But to have an operating system act like it knows more than I do, and actively get into my way when I'm trying to configure it or set something up?

I'm tired of it.

And now Microsoft is promising, just as they did with Vista, that Windows 7 is better than anything they've released before.

Yeah, right. I'm going to go back to my corner and browse the web with my iPod.

Tuesday, October 27, 2009

Windows XP SP3 v. 3264 (Or, "The pre-release version of Remote Desktop Connection has expired...")

Here was an interesting problem today.

I was working on an "import" for a client. By import, I mean this computer technically belonged to another agency that is working within our network because of a leasing arrangement; we didn't set up the machine, but it was on our domain, authenticated to our domain servers, and ran some software we run because it's expected that we babysit the system and maintain it while on our property, but the computer itself isn't owned by us. Clear as mud?

The machine itself was somewhat decent. One of those budget E-Machines, 2.x Ghz with a gig of RAM. Decent enough for most users online chores, running Windows XP. I was annoyed at it since it won't run X on a RIP Linux CD (just keeps stuttering to the command prompt, and xsetup doesn't seem to like the video chipset).

The user ended up needing a home directory set up so they'd not be tranferring a 400 meg profile with them (who's the genius at MS that designed it so that "my documents" was part of the profile? If a home directory is defined, why not make it *automatically* point to that location instead of forcing admins to hack away at settings to redirect it? Stupid stupid stupid...)

No problem. Just open up the RDP client...start,...programs...accessories...click on the client. Voila! What the hell?

"The pre-release version of Remote Desktop Connection has expired. To download teh full version of Remote Desktop Connection, go to Windows Update or contact your system administrator."

Um...okay. Run Windows Update. Nope...no update available there.

Wait, did it say pre-release? I checked the version of Windows. It was Windows XP Pro SP3 v. 3264. I did a double take at that...what's the v. 3264?

Google. It's running a release candidate for service pack 3? Who's the chucklehead that did that? And inflicted it on a technology illiterate user? These are wedgie-deserving offences. Worse, if this draws into a problem where I'm going to go all Hulk on someone.

Google for a fix to the terminal issue. @#%...replace  a couple files under Windows' System32 directory. Didn't work. Replace two .mui files under en-us in the system32 directory. Still no joy.

Weird...

I pulled a copy of the ginormous service pack off our network share and run the setup. Goody. Takes forever, but it actually ran without complaint, and in the process fixed the RDP client. Know what else it fixed? A small flood of back hotfixes and security updates labelled for service-pack-3-no-freakin'-RC-version.

I don't know if the company behind those Walmart special E-machines installed a @#$% release candidate service pack or if their "tech person" did it, but anyone that installs a BETA of a SERVICE PACK on a user's system that is then turned out into the world to fend for themselves should be stabbed with shards from broken DVD's.

If you encounter that weirdo message about the RDP client expiring, try reinstalling SP3. The full version. Not some crippled beta.

Monday, October 26, 2009

Windows Vista and the Administrator

Well, I'm typing this on the eve of Windows 7's release and by the time you read it it will have been out for a month. Nearly.

It's being hailed as the next big thing, perhaps even big enough to erase that abomination that was Windows Vista.

I had occasion recently to have to work on a laptop running Vista Home. Most of the systems where I work are still running Windows XP for two reasons; it works (relatively) well on the cruddy hardware we have, and it is nowhere near as infuriating as Windows Vista.

My task was to clear a password for an administrative user on the laptop because the admin password had been lost.

Believe it or not, this is normally ridiculously simple. I boot with my trust RIP Linux CD, mount the hard disk, and then run chntpw to wipe the password. Reboot to Windows, log in. Done this hundreds of times with XP and have had no problems. Easy peasy.

Given that Vista is largely XP with more hassles layered on...well, okay, given that Vista is still the same basic code base as XP, it still uses the SAM portion of the registry to save password data. Shouldn't be any issue with wiping the password.

I booted, mounted the drive, checked for a /mnt/sda3/windows/system32/config/SAM file, and ran chntpw. Rebooted.

Um...where's the administrator?

Turns out...THERE ISN'T ONE! Surprise! On me!

By default the administrator account is turned off. Instead there's an administrative user account used by the system. Otherwise you have to go and enable it on Vista Home using a boot disk and command prompt. Check it out here.

So apparently I cleared a password for a user that doesn't work. @#$%

I was irritated. This was one of the few constants I have counted on in my administrative duties, having an administrator account available. Systems fall off the domain, systems have issues that necessitate a login to the local machine, now it doesn't work quite right.

I shouldn't be quite so irritated. Many Linux distros have started moving away from having the root user enabled, forcing you to instead use sudo to gain privileges. Ubuntu does it and OS X does it, both of which I use constantly.

I guess my main peeve is that those are systems I use. I know them. I generally can find my way around under the hood. When your job means having a system dumped on you with no back history available and the directive to get it working, though, this adds another layer of frustration since now I have to figure out another piece of the puzzle just to log into the damn thing.

It goes back to usability. One of the strengths of the Mac was that Apple was the most anal retentive companies about how their system appears and how your application looks and behaves. If you ask the user what word is in the upper left corner, it's going to be the active application. In Windows you have to guide the user ever so gently into figuring out which menu bar is highlighted to figure out the current window that is active. Menus may or may not follow the same order (you can imagine the calls and hair loss after Office 2007 was released with their wonderful redesigned ribbon bar for a menu...)

The ability to have a quick and easy way to log in was something I took for granted. No matter which head twitch configured the system or what knob had screwed it up, I could use administrator on the local machine to log in. No more.

I read that windows 7 continued the new tradition. Just another reason to want to cry some days in the tech pits, I suppose. It would be different if more people were knowledgeable about the tools they're misusing, but such is life.

In case you're curious, which you might not be, I did get into that system. I figured out which user from the menu was the admin user and then booted back to rip, and this time used chntpw with the -u parameter to specify the username whose password I wanted to erase. Voila. Worked.

*sigh*

Sunday, October 25, 2009

The Mac Isn't Always User Friendly

I really like using the Mac. I recommend home users look at using a Macintosh if they don't have a specific reason to use a PC. They tend to be safer and easier for people to use, and in the end, users don't care about the politics of their operating system. They just want to surf for games or porn and read email. Usually, anyway.

But just as every Batman has his movie Batsuit with nipples and every Star Wars has a Jar Jar, even the best Macintosh has it's horrible albatross. Albatrosses. Albatrossi?

I'm fighting one right now. In order to connect to the network at work from home, I have to use the accursed Cisco VPN client. I hate it. I hate it, I hate it, I hate it. I had in on once long ago and it screwed up my network configuration. I eventually tried using it again and while it seemed to work okay (after getting the correct version, since the version on the router and the version on the computer have to match within certain specifications or it just magically would fail...seems encryption standards apparently aren't standard enough to survive small revisions in version numbers) I am now getting an error about not being able to find an active network connection over which to connect, so the client wouldn't start.

I Googled (over my interface that the Cisco client insists isn't there) and found references to restarting the VPN subsystem from the command line. Okay...tried...can't find it. The logs say it doesn't know anything about that service. Oh dear...

Another reference I found online said to repair disk permissions. This seems to be the new "rebuilding the desktop" for the Mac (if you know that reference you're either a longtime Mac user or a true geek at heart). Seems that every bloody time I find an issue on the Mac the first thing suggested is to repair disk permissions.

What? I've been using Linux before X Windows was run by default at startup. That's right, I had to actually configure X and type "startx" at a command prompt. Both Linux and OS X are, under the hood, a form of UNIX (purists would no doubt get their panties in a twist at that, but tough. For my purposes here it's true enough) and they both use similar forms of permissions on files. I don't recall EVER having to run a utility to fix permissions on Linux. I don't have files randomly changing their permissions. So why is it that under OS X it seems to just decide, arbitrarily, to change permissions on random files?

There doesn't seem to be any rhyme or reason to it.

What I really wish I could do is just run SSH to create my tunnels for what I need to do. The boss said that the Cisco VPN client was superior and decreed that SSH would be cut off. "One less possible vulnerability".

The result has been, for me, far more headache. Not only do I need a special client that is available for certain clients (I think there's sort of a Linux version. Maybe. As long as I am running a certain range of libraries and dependencies that match to their client software) but that same client software seems notoriously flaky and problematic. I have yet to see why this is superior to the old way of using methods that are open standards.

Excuse me while I go rock in my corner while waiting for my "repair permissions" to complete and then hope that it works after a reboot...

Saturday, October 17, 2009

Common Sense...Where Did It Go?

Here's a question that burns me. What has happened to common sense?

Maybe this is more of a venting than anything else. The rational part of me says that people do things that seem to lack common sense because I'm not seeing the world through their eyes with their priorities. Maybe my mechanic thinks the same thing about me not seeing the importance of rotating my tires. I don't know.

But some things still just floor me.

I work in IT, as you know. I repair systems and do maintenance and half a dozen other things that are considered gruntwork done by someone off the street even though 99% of the coworkers profess they aren't "computer people" and have no idea how to do what I'm doing. Irony is a good friend of mine.

I was doing a set of updates on a coworker's system. She left the room to do something else, and I had happened to have a schedule to keep (namely wanted to take care of some things at home so I couldn't be an hour and a half late as is often the case). Plus my boss likes making me feel like dirt if I'm "wasting time" by not doing multiple repairs at the same time. So I figured I'd try it his way and let him have the "I told you so" moment.

A reboot of the laptop in question came up and said there were still more updates. This time? Service Pack 3 for XP. I didn't even realize this person hadn't reported it was out of date by this much. She'd apparently had it at home during upgrade times for so long...yikes!

So I started the update. For those who don't know, service packs are big. They're really big. Like on this laptop we're talking an hour of work. So I hit control-alt-del, locked the workstation, and went to another room to get two more tasks checkmarked off.

(Note-locking the workstation means that when the user comes back, it says they have to hit control-alt-delete and log in as the administrative user because the system is currently in use, and if you log in with administrative privileges it warns that the other user will be logged out and unsaved work will be lost).

I didn't think much of it. The user is college educated. She surely can read. I left and came back an hour later, hoping to have it at a point where I could basically button it up until the next day or so to complete other minor updates that wouldn't take anywhere near as long (hopefully).

I came back to a computer that was shut off.

She apparently came in and shut everything off. Mid upgrade.

Again, if you don't know...service packs replace a lot of SYSTEM files. As in, if it was partially working on the system and you shut it down, it could no longer boot. If she shut it off during a file operation, it could have damaged the filesystem as well. Basically she rolled the dice to find out if her computer was completely and utterly screwed up now.

She ignored the warning.

She ignored the fact that I was doing upgrades (she knew I was working on it).

She didn't put two and two together that if I had locked the system and left, I was planning on coming back.

In short, my boss didn't get his I Told You So moment and I had an extra hour of work re-applying the service pack, grateful that the computer still booted after she had cut it off mid-upgrade. I got home an hour later. As usual. And a bit more ticked with yet another reminder of why I spend so much time babysitting systems when doing upgrades instead of looking productive.

Not reading these warnings are right up there with leaving pee on the lip of the toilet seat. It's common sense. Wipe it up. The warning is right there, you knew I was working on it, don't mess with it. The analogy isn't perfect since there are times where you might not notice the pee on the seat thing...but Windows, for all its flaws, will still tell you that the user is still logged in and give you a warning about unsaved work. For the love of $Deity pay attention and think. It's too easy and common for people to just disregard anything "computerized" as being out of their league so they reflexively dismiss whatever it's doing as too complicated. I'm not asking you to give the pros and cons of cooperative vs. preemptive multitasking, just to stop and use your college educated mind to decipher a warning on the screen. Or at least take it to someone else who would know! You have no idea how many people will call the help desk and just say "The computer is giving an error thing," with no elaboration. What does the error thing say? What were you doing?

I'm not magic. I'm not in the movie world where hackers can control airliners using a magic set of commands from a secret supercomputer in the bowels of the Pentagon, and I sure as hell can't divine what your issue is with a few keystrokes and the description consisting of "it gave an error."

Please...I wish people would just take a few moments to use a little more common sense. I'm paid to fix problems with the computer that you don't want to deal with. But still, I really wish you'd give an accurate summary of the problem with what is presented to you...at a minimum, the actual error message, not a paraphrased listing of jargon that you are making up as you go along. Or read the error message for a moment and see that maybe, when it says that a particular user is logged in already, think that it's in the middle of doing something that maybe you shouldn't play with.

I'm venting and I know it. Maybe others out there have had similar experiences, only in different fields. Please share! I'd love to know that this isn't a tech-only phenomena. Or at least not feel like I'm the only one having these issues.

Tuesday, October 13, 2009

I Hate Blogger Usability Bugs (and Website Bugs in General)

I've spoken about neat features with Blogger involving pre-writing blogs and posting them with a "Scheduled" feature so I can write, say, blogs for the next three days and have them automatically appear. I can take a weekend off while still keeping content flowing.

But there are real glitches that, to put it lightly, tick me off.

I decided to find out what would happen if you have a brain fart and forget that September has 30 days. I scheduled an entry for September 31st.

The intelligent thing to do is for the application to see that you scheduled something for 9/30+1 day, and wrap it to 10/1 automatically.

This doesn't work. It publishes it immediately. That review for Diet Myths I did on 9/13? It was supposed to be today's entry.

Oh! I'll go back and edit the date so it appears later on. No harm, right?

No dice. I could probably delete the post and put it in as a new one, but otherwise...nope. Oh, it changed the date alright. On 9/13, when I wrote it the entry was still there but the blog entry was still visible. It just had the date set to 10/1 at the top.

Argh! So what then? Every day it stays at the top, since the date is set in the future, and visitors to the site will see it every day as my most recent story?

Not only is it bad form but my Aspergian mind would probably warp itself until it imploded at seeing something so out of whack. I immediately changed the date back to 9/13 and kept two blog posts for the day, resigned to the fact that I would just have to have it appear earlier than I planned. I filled in the entry that it was supposed to take with a bitching rant on poor usability. This entry.

Seems like Blogger would be better fleshed out. Apparently not. So if you're taking advantage of the pre-dating and pre-scheduling features of Blogger, keep in mind it's too stupid to adjust for your mind farts when it comes to dating items.

Along the same line glitches and bugs can occur in more serious forms. I noticed a bug in my primary bank's website. I was logged in checking on funds for paying bills, a really wonderful fun activity. I saw my wife hadn't transferred funds in yet. I asked her about it, she sighed, signed in on her computer, and transferred some money in so I could pay bills.

I viewed my accounts. No money changed. I viewed account details, and I saw the amount she transferred in; but it wasn't showing up under the totals. I switched views, refreshed, everything. The amount she transferred showed up under details but would NOT show up under available amounts. I logged off the bank site and logged back in, then everything showed up just fine.

Apparently the bank software doesn't handle changes made to the joint account when the two owners of said account are manipulating it at the same time. This is a DEFINITE possible exploit, and given enough time I'm sure there's some way to use this information to a black hat hacker's advantage. At a bare minimum it shows some poor programming protection for the site, and it also is annoying as hell to think they didn't think that it would be possible for a joint checking account to be accessed by the owners at the same time, and apparently it may have issues with handling changes in amounts showing up properly.

I'm sure there's plenty of behind-the-scenes reasons that this is a problem. I don't care. For the end user, this shouldn't be an issue.

That's the end of my complaints for web applications for now. It's a little scary that sites accessible by so many on the webbertubes could possibly take advantage of glitches, bugs, and outright security holes on websites holding my personal information. At worst, they're annoyances, like the one I found in Blogger. It's elementary that the application should compensate for something as simple as the user screwing up a date, and when there's a mistake it should be able to know that the user is trying to schedule the entry to show up in the future and thus if the date is greater than the current date, hide the damn thing. At worst, the site is showing a potential condition that can be taken advantage of, like the one I found with the banking site. It could be innocuous but glitches like that in the hands of math and logic geniuses can lead to some really interesting exploits (don't believe me? Read the story about Mac keyboards having their firmware exploited. Yes, that's right, your keyboard would be used to spy on you.)

Saturday, September 26, 2009

Should You Call Or Email?

I do a lot of tech work. Support-type functions. Repairs. Fixes. Configurations.

I'm also wired with the Aspergian mind. That doesn't help with being patient with people when they don't listen.

But this topic isn't just for people like me. It affects everyone to some degree.

See, one of the high-on-list peeves is when people call on the phone for something that they could have emailed about. It drives me nuts because whenever the phone rings and I answer it, it draws my attention away from what I was focusing on. Even if it's just to answer a quick question, it takes me time to get refocused on what I as doing before the phone interruption.

The part that really steams me is when they call, the person they want to talk to (there's others on the multiline system I'm sharing) isn't available, and they say, "That's okay, I'll just send them an email."

Then WHY DID YOU CALL?

If it's not something you need an immediate answer to, email it. It gets neatly queued to be handled when I have time to handle it. I have a paper trail. I have a reference.

You interrupted me because a phone was handy and you had a brain fart?

Ugh.

Then I have to try to refocus on the task at hand. For tech people, once you're "in the groove" you tend to be more efficient, and interruptions lead to mistakes, possibly bad ones if I'm doing something that could affect others (mail server alterations, anyone?)

So here...if you have something you want to communicate, and it isn't something that requires an immediate answer, email it. Ask yourself: "If the person I want isn't available, will I just email the message to them instead?"

If the answer is yes, EMAIL IT. We'll thank you for it. Or at least not curse you for forcing me to figure out what the hell I was working on before you called.

Saturday, September 12, 2009

Overnight Delivery in Just Four Days

I recently had the good fortune of discovering my CPU cooler's fan had seized up. If you're unfamiliar with the internals of your computer, modern processors get hot. Very hot. Like, burn your bare finger hot. If allowed to stay that hot, it seizes up and dies. Or with today's processors they have a sensor that triggers when they overheat and the computer goes into thermal shutdown...*bloop*.

The CPU cooler is a radiator that is designed to pull heat off the processor and circulate it out of the case. On my particular computer the cooler with the radiator baffles is bigger than my fist, and mounted on it is a fan to push air through the baffles and keep the processor at a cool 50 degrees Celsius, give or take, depending on the load I'm putting on it.

Well, without air circulating through the baffles, the thing will heat up. Fortunately my computer, built by Puget Systems, is built like a tank. The freakin' thing warmed up, but not enough to kill the processor. Nice work! It had enough redundancy with cooling inside that the system was kept safe. My computer has a case with a clear panel on the side, so I just looked over and saw that the fan was seized up.

It happens over time. Dust, age, worn bearings...fans die.

A side note-while waiting for the new part, I installed a program to read temperatures and display them on the panel at the top of my Linux system's desktop. I had temps...but what was too much? I emailed Puget and asked them, along with current numbers. Their techs emailed me back the next business day with assurance that the numbers were well within tolerance. I emailed back a thank you, and they emailed again telling me, "Hey, no problem, any other questions don't hesitate to let us know." This computer was purchased a few years ago...they still were uber-responsive to me as a customer. Strong incentive for me to look to them for my next set of systems, if I don't go with a Mac-centric home...

Anyway, I ordered a new one on NewEgg, a great source for techie toys. Exact same model cooler. This was a Thursday night. I specified, next day UPS, expedited order. Cost me a total of $65...twice as much as the cooler alone.

My wife said I probably wouldn't get it on Friday. I didn't.

I got it Monday night.

Oddly enough, I'm still going to be billed for overnight delivery.

In a time when packages could be tracked to the point when they're dropped on my porch, why am I paying for what I'd like my delivery to be, instead of what the delivery ends up being?

I shouldn't have to pay overnight when I didn't get it for FOUR days!

Am I the only one that thinks this makes some sense?

Friday, September 11, 2009

What Is That Program Doing? Or, Why Is This System Using So Much Memory!?

First, let's get a quick concept out of the way. When dealing with computers, new sysadmins have to understand that when it comes to a system compromise (a computer gets hacked), the system cannot be trusted. It's like asking a person to objectively assess their mental state; when you ask a person's brain to evaluate itself, it's going to be biased and distorted. Similarly, when a person cracks a computer system, they can alter the programs and filesystem so that if you run utilities to show network connections, running programs, etc., the altered files will hide the unauthorized activity.

Pretty simple, yeah?

So how do you see unauthorized activity? If your computer was hacked and is now sending spam email...which is network activity...but if you run utilities everything is showing up as normal (because the altered files are hiding the unauthorized network activity), the computer can hide what's going on, but a second system on the network that is monitoring network activity will see all the activity. In other words, your hacked computer may have its fingers in its ears yelling, "LA LA LA LA LA" but a third party system will still see what that computer is doing.

You add a layer of abstraction to watch what's going on, and in the process you can learn a bit about what is actually going on with your computer.

Now...the topic of of the post.

I have been working with a technology called virtualization for some projects at work. It's really great stuff...it lets you create computers that exist only in software, letting you install and configure multiple computers that run on just one system. Schizophrenic, but very very handy for people like me that have to run print servers, web servers, and file sharing servers in an organization among other things because I can consolidate those systems onto one or two actual physical systems (with tons of RAM and disk space).

In the process of running tests to migrate some of our physical systems to virtual software systems we moved a printer server. This is a Windows computer whose entire job on our network is to spool print jobs and dole them out to our many many printers scattered around several buildings. Not uncommon in businesses to have printer servers configured in their network for easier management.

Normally we'd think that this isn't a huge task, either. Most of the time a server like this would sit largely unused; I mean, it just sits waiting for someone to send a print job, render it then send it to the appropriate printer. It's not crunching numbers to predict the weather.

"But Barry," you ask, "What does this have to do with hackers and second computers to watch what a system is doing?" Glad you asked. See, when you run a full-on virtual server system...in this case what's called a type 1 hypervisor...you get an abstracted view of a computer; memory use, disk use, network use...and so you can get a quick overview of what the computer is doing that ordinarily you wouldn't get to see with a physical computer.

What I saw was that out of (more than five, fewer than ten systems) on our virtualization server the printer server was taking up nearly 800 meg of memory and shooting between first and second place for CPU usage and network usage, depending on what the other systems virtualized on the testbed were doing at that point. What in blazes is it doing?

I logged into the machine and ran a wonderful tool from the sysinternals suite called Process Explorer (free download...I highly recommend the sysinternals suite of software to ANY system administrator or troubleshooter). From there I could monitor process (program) names, the command line from which they were running, memory and CPU usage, etc.

I found a couple things of note. First, the converter program I used to automagically convert the physical machine to a virtual machine runs a service that carries a large footprint of memory; now that the system was virtual, the converter program isn't needed. So I removed that program from add/remove programs and memory use for that virtual image dropped over 100 megabytes.

Second, the computer is running a database program as well as a Bash shell spawning Java. Huh?

In case you didn't know, Bash is a shell program that runs normally under a Unix system (like Linux), not Windows.

Process Explorer told me that both the database and the Bash shell (and in turn the Java system) was tied to a Dell utility tied to Openmanage. Many mental scars remind me that OpenManage is a set of utilities made by Dell for managing their servers...usually it has functions for things like monitoring fans and CPU temps, rebuilding RAID arrays, etc. etc...generally a headache to sort everything out and get working in the proper combination for your system. At least, that's my experience with it.

So I go into add/remove programs to remove the OpenManage software, since now that the system is virtual there really wasn't any Dell hardware for it to manage.

Surprise! I was wrong. Apparently at some point someone installed an OpenManage component for managing printers! It wasn't small either. In the add/remove programs there was a listing for "Dell Printer Software" and for "OpenManage Printer Manager", each of which was taking 1.6 gigabytes in storage space on the hard disk. Each. Not both together.

But since some departments wanted Dell multifunction printers on the network and I didn't install it I don't know if these software packages are something that are needed so I can't really just tear through and uninstall those programs without dealing with the possibility of Nasty Consequences(tm).

Apparently Dell tries to cut some corners to make their software more portable between Linux and Windows by using Java (I'm speculating since I'm not too thrilled with OpenManage software, so I don't install it on my Linux systems on Dell hardware). Part of their software workflow involves using a program called Cygwin to do something with logging or some management task; Cygwin is a port of Unix utilities to run on Windows (that's why I saw Bash running). You can run tools like Secure Shell or awk or sed or ls...many many many scripting and administration utilities...on Windows that normally you'd only see on Linux. Process Explorer popped up lines in the process list as some of these scheduled tasks were periodically popping up thn disappearing, no doubt adding to the memory and resource use of the virtual machine. To be clear, Cygwin has it's place and I think it's great when properly used. I've also seen it installed on systems that suddenly start spiking CPU usage because of one of the programs using Cygwin libraries (in that case, SSHD running on Windows as a service).

What lessons can we learn from this little educational field trip?
  • Generic is good. Addon software is bad. Backed up by anecdotes on the StackOverflow podcast, that CD that came with your camera/printer/device should not be installed unless you have no other choice but to use it to get the device to work. Many modern operating systems include drivers to work various media devices, or for devices like HP printers, you often can go right to the website and download just the driver, without all the addon crap that will bog down your computer with extra programs that you don't need (or know what they're really doing).
  • Virtualization can give you tools that will both teach you about using your system and open your eyes to some things your computer(s) may be doing in the background without your knowledge. There's no reason that a printer server should be sucking down resources like this one was except that it had some poorly optimized software installed that it probably doesn't need.
  • Third party utilities like the Sysinternals Suite can help you track down oddball activity on your system (or insights on how things work) for free. There are tools that tell you what's connected to the system over the network, which program is writing and reading the hard disk, which program is hitting what part of the registry, and many other useful tools. Try it out if you run Windows.
  • Audit your system once in awhile to see what's actually installed and what it's doing. If it's not needed, free up the drive space by uninstalling that program. Use Google to figure out what the programs are. Part of what contributes to your computer slowing down over time is having programs running in the background that take up space in memory and access the network and you probably don't need them. Become familiar with your system and it can help save you aggravation down the road...also it'll help you later on when you notice something that should not be in that process list running, so you can tell when something is out of the ordinary on your computer. Process Explorer even includes tools for you to Google process names from a menu, making it even easier to learn about what your system is doing!
Windows isn't the only platform to suffer from bloated, inefficient and/or poorly designed software, but since Windows has the majority of users who are non-technical in interest and nature it is the platform with developers who get away with creating shovelware much more often. Fight it by not using it. I'm not referring specifically to Windows, although I encourage not using that too...but rather don't use the bloated crap that comes as trinkets and addons that only serve to bog down your computer. Don't install software from CD's that came with your new tech toys unless you must; try plugging it into the computer first to see if Windows or Linux or the Mac recognizes the hardware and installs the necessary drivers for you first. Then you're using native tools and not someone else's idea of how you should use their tools (and sometimes screw up your system in the process). Check your computer and screen it for odd behavior and find out what those processes in the background of your system are doing so you can get rid of software that is slowing your computer without justified cause.

Anyone have any stories they'd like to share?

Sunday, September 6, 2009

The iPhone Vs. LG Voyager

It's official. The iPhone 3GS has smashed records for AT&T and Apple.

I would love to have an iPhone but the only carrier in the US is AT&T and I'm already quite invested with Verizon. Every carrier has horror stories associated with them, but in our relations with Verizon we've had good luck with customer service as well as technical service.

AT&T didn't come into our area with coverage until late in the game and when they finally did put in tower coverage the coverage was unreliable and spotty.

In other words, they left a bad taste in my mouth after seeing how they ran their business. If you followed my blog you know how I feel about businesses that seem incompetent with their customer relations.

I'm told that they're better today. I don't particularly care. There's a similar effect for restaurants. It's quite common for a restaurant to work long and hard at building a loyal number of regulars, but it takes only one bad experience to lose a customer forever.

That doesn't mean I don't wish I had an iPhone. I have an iPod Touch, the iPhone's close cousin, and I owned a Verizon LG Voyager. The iPod gives a pretty close experience to what an iPhone is like in most areas other than actually calling and texting (and a couple other features like taking photos and GPS, since the hardware isn't available on an iPod). The iPod does give the computer integration, music, podcast, and touchscreen as well as close form factor to the iPhone as well as the app store integration. It runs the same operating system as well.

Having used both the iPod Touch and Voyager, I can tell you that the interface to the iPod is light years beyond the Voyager and it's Verizon technology kin.

The touch interface on the iPod is responsive and probably three to four times more accurate than the Voyager's.

The app store on Apple is convenient and makes the iPod more flexible. Yes, Apple acts as the gatekeeper for all applications on the iPod and you won't (intentionally) find porn-based applications on the iPod/iPhone, but overall there are a simply huge number of various applications to choose from and they aren't tying you directly to Apple's brand overtly. Verizon requires you to do everything through Verizon and they're quite limiting in what I could and couldn't do on their phone.

The iPod allows for wifi access. Not so sure about Verizon's phones. It's not on the Voyager.

The iPod/iPhone was integrated with my computer. I could back it up and sync data easily with my computer, without having to find some kind of accessory kit with the proper cable for use with my particular phone. There are even applications to allow you to explore and navigate your iPhone/iPod from your computer. My Verizon phone was very much a separate accessory; it is as if Verizon is afraid of diluting their brand by allowing the customer to have any control over the product.

The only place I preferred my Voyager was the tactile keyboard. I could type significantly more quickly than on my iPod. However I could learn to work the iPhone's key display in a pinch (on the Voyager you almost had to get proficient with the full keyboard; the touchscreen was horribly inaccurate and lagged, making it nearly impossible to use.)

The Voyager was barely usable with the touch screen. For anything more complicated than viewing text messages I often had to drop to using the keyboard to get anything done; I can't count the number of times my phone thought I wanted to edit or view a contact entry when I was trying to get the damn thing to scroll. The iPod? No problem. If anything the iPod was almost too responsive, the screen just begged to be touched. The Voyager was so finicky and glitchy that it was just the opposite.

I don't know if it's a problem with Verizon just not "getting it" or if they're so stuck in some paranoid business model of controlling the brand rather than creating a great customer experience that limits them so much. Verizon has a great network, I've had excellent luck with coverage. The services offered by their website have worked well for us.

Now I just wish they had good products to match those services. I'm hoping that at some point Apple will cut their exclusivity with AT&T and create a product with Verizon...so far Verizon has show zero ability to "get it".

Friday, August 21, 2009

Windows 2008: I Hate You

I recently had the joy of installing Windows 2008 Server at work in preparation to migrate an older server application to it. I put off moving to or using the latest versions of Windows because I read of many of the headaches for sysadmins that lay in store (in case you want to relate a little, ever use Vista? Well, 2008 is Vista with server capabilities, and a few consumer interface items stripped out...but keeping most of the security problems).

In my two days using it, I ran into this short list of things that truly annoyed the bejebus out of me.

I ran a chkdsk (check disk) on the drives to repair any potential damage after a power outage that outlasted the UPS (I know, what were the odds?). Ordinarily, you run chkdsk at bootup, you can check the results by looking in the logs for messages from WinLogon. I searched for five minutes through the list without finding it...because now it was under something called WinInit. In a way this was funny, since I wondered "Wininit gonna work right for a change??"...say it out loud if you don't get it.
Almost every site, including Windows Updates, including innocuous sites that I've visited for years, including common sites for additional software...required me to add it to a "trusted sites" list. Sometimes it wouldn't even tell me it needed it, some redirect or addon simply wouldn't work. It's an additional step that I don't need when I'm under pressure to get the server working and get things configured.
VNC doesn't work. It's a neat program from www.realvnc.com (which has a free edition) that allows you to remotely view and control your desktop console. It's a convenient way to get to the console, whoever's logged in...we often use it for remote troubleshooting. It has its own password mechanism so it's not reliant on the password for a particular Windows user. "But Barry, why use that when you can use Remote Desktop? You get two client licenses included!"-easy. If Administrator is logged into the console downloading something, and then I RDP in and log in administrator, due to idiot licensing restrictions my login will kill the other session. So if something is being worked on at the same time...poof! Gone. VNC just brings up the remote console because it's remote control, not remote access. Anyway, VNC comes up with an error that Windows won't allow it to run because it's an interactive process. Nice. Really nice.
They changed the Management Console. I used to be able to right click on "my computer", go to manage, then from the top of the tree right click on the "local computer" and from there enter the address of another Windows system on our network so I could view services, system logs, etc...well, no more! Windows 2008 uses the "Server Management Console". And I can't connect to other systems from it! How handy is that?! Well, it's not. Thanks to some other people who were annoyed at this they already solved the problem...I just created a batch file on the desktop that contains the line, "start compmgmt.msc", launching the old fashioned management console from which I can actually manage other systems.
The system logs on the server like logging a message about licenses being validated by WinLogon. Um...who or what is it validating against? Why...? I'm always a bit skittish about software "phoning home". We are using a server, with potentially sensitive data on it. Maybe it's just validating against something on itself, maybe to one of our Active Directory servers, I don't know. But it's annoying me.
Creating a share seems to get more of a burden with each release of Windows. I had to use a wizard now to create a simple share; Wizards are supposed to be a good idea for helping new users with tasks that may be unfamiliar. But wow..."provision share"? I wasn't sure what it wanted me to do with that at first. The familiar route...right click the folder I want to share and select sharing...now takes you to a mini-wizard that would not let me change the name of the share, which I needed to do. I believe I ended up going through a submenu in the server manager to create the share I wanted...through a bigger wizard. All I would like is to right click the folder, have a list of tabbed options, and go from there. Why is that so !@#% difficult? This is Windows Server, sharing is a very basic and common task for server admins. Why must it be a topic for a wizard, without a choice to not suffer through a @#$$ wizard interface? Or worse, an inconsistent interface, since there is more than one wizard to go through for sharing?

Maybe these are just initial impressions and I have to adjust to it. But my first impression was that it was a pain in the arse. VNC didn't work on it. Security notifications keep popping up, even for Windows Update! And common tasks have to be relearned. This is progress? You must seriously have to love the Microsoft Kool-Aid to embrace newer versions of Windows. I find it to be an giant pain to deal with...

Anyone else have similar experiences? Or reasons I should love this version of Windows? Please?

Tuesday, August 18, 2009

Windows Security Identifiers

This is another edition of Fun With System Administration.

Of course, by "fun" I mean I want to choke myself with a SATA cable.

See, much of my day job involves interacting with Windows systems, and there is never any shortage of reasons for me to pull my hair out.

The latest issue involves the Security ID, or SID. See, Windows, unlike Linux, identifies users and machines with a really long string of numbers and letter called the SID. Even though you might have a friendly username (like, say, your name...) when you go to use the computer in the background Windows knows you by a really long string of numbers. Your human-readable name is an alias of sorts.

Remember, I said users and machines have a unique ID associated with them.

The problem is that we have situations where we have to clone machines to go out to different offices. We take a machine out of a batch of identical systems; we install Windows, configure special software options and printers and various drivers, then we create an image of that machine that we then can copy down to all the other machines in hopes of saving time not having to remember every Windows and Office update and special software package.

Part of that procedure involves running NewSID, a free utility that will change the name of the computer and the SID so the machine gets a unique ID associated with it.

In the Wikipedia article it said:
Now the truth is that when the computers are joined into a domain (Active Directory or NT domain for instance), each computer has a unique Domain SID which is recomputed each time a computer enters a domain. Thus there are usually no real problems with Duplicated SIDs when the computers are members of a domain, especially if local user accounts are not used. If local user accounts are used, there is a potential security issue that is the same as the one described above when the computers are members of a Workgroup but that affects only the files and resources protected by local users, not by domain users.

Now...our users are on a domain! Maybe we don't have to worry about it!

I made note of it and had cloned several machines before remembering to actually test it. The latest NewSID will tell you the current SID for the machine; I looked at two systems on the domain and they both matched. Joining the Active Directory domain doesn't alter the machine's identifier as I thought.

Apparently the Access Control List that controls file ownership and such is associated with the user's SID, and in theory there shouldn't be an issue with this. But on reflection I didn't want to risk it.

Nuts.

So it was my own fault for not testing more thoroughly but it is one more reason to hate Windows...Linux doesn't use machine-specific ID's on the network outside of their name. Windows lets you change names but hides the fact that the name is just a superficial shell over a long string of gibberish (okay, it actually means something as the article tells you, but still...) and it's that string of gibberish that is actually significant; plus you need a special tool to alter it.

Another annoyance with Windows...it doesn't include the tool to alter these sort of fundamental parts of the operating system that can cause problems. You can get NewSID for free but it was actually a third party tool written by Mark Russinovich, hired by Microsoft after he released a lot of useful tools for Windows.

The lessons to be learned?

  1. Don't assume. Test. Even if it takes more time which results in becoming less popular with your boss because you're taking that extra time...because it's going to save you the time it takes to fix your time-saving shortcut.
  2. With Windows, even though you'd think changing names and ID's and such would make the machine unique on the network, it might not. There are underlying functions that Microsoft actually had the brains to abstract away from the users since they didn't need to know about it...only they didn't put any obvious ways to check on or monitor those abstracted functions until it's too late and you have a new mess to try fixing.
  3. Don't assume that just because there's some fundamental part of Windows that needs administration you'll have the tools included to fix those fundamental parts. Find a tool and save it somewhere that you can access that tool later on.
  4. Windows is a major pain in the rear.
I think that pretty much covers it...

Sunday, August 9, 2009

Information Rot on the Webbertubes

One of the roughest parts of working on the Internet is dealing with information rot.

I've been recently digging through what it would take to create a high-availability cluster of Linux systems; essentially a way of taking two or more systems and configuring them to provide a service (like a web site, for example) that appears to be one computer but in reality when one computer fails...motherboard bursts into flames...the other computer takes over and continues to provide the service in a nearly uninterrupted manner, enough that most users aren't aware there's been a problem.

Putting it like that makes it sound simple but it's not.

Information rot is the name I coined for the issue I ran into when researching the task. I've come to see it as a reason for techies to be a little more understanding when they spew vitriol at newbies who don't RTFM or Google for a solution before asking mailing lists for the answer to an issue that has already been answered three times in the past two weeks (to be fair, though, it seems many still don't do that first).

Here's an example of what I ran into. Some people set up clusters and put information into what's called a HOWTO. Just as the name implies, it is a document that tells you HOW TO do what they did. A recipe for setting up a cluster similar to what they did, in this case.

In order for computer B to know that computer A has had a problem (and so computer B must take over A's role), there is a bit of software called Heartbeat whose job it is to periodically check the other machine's health by answering a network query.

Since the first heartbeat software was released for the project it has since had a series of changes made; there was a version one, then a major second version, then it became another program called Pacemaker.

Now when you're trying to create a cluster to meet your own set of needs it means finding information on bringing a lot of related-but-not-tied-togther programs to work towards a common goal (your project needs). It means going through a lot of HOWTOs and home pages and program man pages.

But clusters aren't found in everyone's basement; of all the people who do create a cluster only a fraction of them bother sharing their experiences and information as tutorials, and then they often don't update them anymore. Many of the documents...instructions, HOWTOs, mailing list anecdotes...will have instructions with disclaimers saying, "This is how you do it with version one...version two has this ability built in, so click on this link to see how to configure that. Note that with Pacemaker you should disregard these and go to this link telling you how to do it the "right" way with Pacemaker, unless you're running in compatibility mode with version one Heartbeat..."

That's if you're lucky.

Sometimes you find instructions that refer to software that is just plain out of date so the author doesn't put any notes about versions in it at all, leaving you scratching your head why the commands aren't working for you the way they worked for the author of the document.

It's not just with trying to configure a cluster that I've run into this. I had the same issues with setting up proxy servers (speeding up and filtering web browsing for a large site) and mail filtering for a large number of users (sending email through a filter that decided what was spam and what wasn't while blocking certain senders and blocking certain attachments). The technology behind filtering and even the mechanisms for rerouting networks in Linux changed over time and so I had to puzzle out what documentation was relevant to the version of software, and the mix of software, I was trying to use for the task! Part of the problem with working in technology is that this shift occurs constantly and we're expected to change with it.

It's gaining not just knowledge of what is available as an option but the need to gain an understanding of each component so you can truly apply that solution to meet the needs of the client, whether that client is yourself or another business or department. Often it seems as if users think that tech people just have a store of knowledge that can be tapped into like a human Google and it simply doesn't work like that.

Ever ask a tech person a question that seems very simple on the surface, but in reality is far more complicated? My favorite one is when someone asks me what computer they should get. Seems simple, like asking what their favorite color is. But I can't give them a simple answer if I'm being honest.

I'd need to know what you're going to use the computer for, what your experience level is, what kind of software you really think you absolutely have to use. Are you a gamer? Just an Internet browser? And your budget? All of those are factors in the decision. A Mac can't be beat for people doing audio and video editing at home or just web browsing and email. Windows systems are cheaper (in price and quality, usually). Would your use include a lot of travel? Or do you just like commuting from home to the local book shop with wifi? A netbook might fit...or do you need a true desktop replacement class notebook? Data redundancy or backup?

While this seems like veering away from the concept of information rot, it is related in that both reflect the difficulty in gaining in-depth comprehension of the solution you're seeking.

Google can only point you to knowledge. It's up to you to find wisdom.