Showing posts with label In the News. Show all posts
Showing posts with label In the News. Show all posts

Sunday, May 16, 2010

OSNews isn't OSNews

One of the tech sites I follow is OSNews. It was originally a website for...well, news about operating systems. Linux, Windows, OS X, etc.

A recent post was titled "Why OSNews Is No Longer OSNews." The editor outlines how OSNews shifted from news about operating systems into more general news about technology, Recent stories cover news about Adobe vs. Apple and H.265 developments and Microsoft Office changes, rather than developments about new kernel threading implementations in Linux or compatibility changes in Haiku.

The article was pretty good, and I'm not writing to rehash what Thom Holwerda wrote in the article. I am writing because as I read the article and ensuing comments, it actually dawned on me the scale to which computer technology has "standardized" and stagnated.

I became interested in computers and platforms in the dawn of home computing. I was born at the dawn of the birth of Apple Computer. I saw the introduction of the Macintosh. Okay, I didn't see it, but I was becoming aware of the world and computers in 1984 when the infamous ad debuted. The Internet was expensive, slow, and difficult for home users to get access to, so I relied on shopping in local department stores (remember when Sears mattered?) and magazines in bookstores to get news about computers, and Byte and Computer Shopper were chock-full of stories about AmigaDos and AmigaOS, OS/2, the fledgling pseudo-OS called Windows, various flavors of DOS, CP/M,...all sorts of technology goodness.

But gradually the stories about operating systems dwindled because companies closed down, markets dwindled, and eventually the biggest of the niche OS's like AmigaOS were relegated to hobbyist markets. Magazines started changing their focus into something more like Cosmo for geeks; "Win95 vs. OS/2 vs. NT! Which is Best For You?"

Fast forward to today and you have the situation that the OSNews article was discussing; hobbyist OS's are largely stagnant. Operating systems are basically, for practical purposes, down the the "big three" of OS X, Linux, and the Windows family.

Hobbyist OS's that I can name include MorphOS, FreeDOS, ReactOS, Plan 9, and Haiku. There are others, but for the most part, the number of installed systems are tiny. Really tiny.

The comments put the second part of the puzzle in place for me; people commented that in colleges, computer science majors didn't have to take compiler courses. Someone else said that more recently they went to a nearby college and the computer science majors weren't even taking courses on operating systems. I remember when I went to college that the debates focused on what the latest, most relevant computer languages were to teacher...Java? Python? Should we keep C++?

My daughter applied to the college I went to, so I was able to kind of revisit what was going on with their CS program. Basically, it's gone. The college is doing something more like an information technology track rather than a computer science degree that focused on data structures and how the system worked under the hood. This would be akin to people going to a vocational school for auto repair and learning more about body work and adding spoilers without going over how pistons or fuel injectors work.

Basically, we moved to a position in technology where the public has popularized particular platforms, and the focus has shifted into the more shallow but productive application of technology. We aren't teaching data structures or operating systems and more technology-oriented interest have nothing to do with the underpinnings of improving the computer platform, it's focused on applications and supporting Grandma so she can get her email.

I'd love the hobby OS's. I had an installation CD of BeOS when it was distributed to the public for the Intel platform. I disliked MacOS because it relied heavily on cooperative multitasking, and found it fascinating when Win95 introduced preemptive multitasking to the platform (except for the Win16 subsystem, and to a degree I guess the Win32 subsystem addon for Win3.11 had some elements of preemptive multitasking, but still...). End users just glazed over when told why these things mattered. They didn't care because they just wanted to play games and browse the web. While things under the hood improved with these features, they were quiet improvements and added largely because they improved the user experience without them knowing it.

What hobby OS's are out there are relegated to R&D departments (Plan 9) or are so hobby that they basically, for practical purposes, boot up and do little else unless you're using the machine exclusively as a platform for simple web browsing and email (if you're lucky). To get any actual work done you have to use one of the "big three" operating systems.

If OSNews only covered news for operating systems, they'd have new stories maybe once a month. There simply aren't too many people working on operating systems and those that are are working just on operating systems; I can't use it to accomplish things I use every day reliably, and without more development on applications the operating system is largely useless.

Basically one of the things that attracted me to computing as a career is dead. Commoditized. And it's a shame. My first computer was a Commodore 128, and my first PC was a 486sx 33 Mhz system with 4 meg of RAM. Today if you get a new computer to run Windows 7 you really need at least 2 gig of memory and a 100 gig hard disk. But I still remember running BeOS on an Intel system that was only a couple hundred Mhz and something on the order of 128 meg of RAM and it was able to render an animated OpenGL demo without any stutter or pausing. I was spinning a three-dimensional cube on the screen while each facet played a different movie file without stuttering. It was absolutely amazing that something with such a small amount of resources was able to pull this off.

In other words, the these hobby and research (and niche) OS's can do some really amazing things, but if they don't have anything to edit home videos or play podcasts, what am I going to do with it? How many half-rendered or unreadable web pages will I have to work around before it just annoys me too much to use it?

And without users, these projects stagnate and die off. There's very little variety.

This isn't necessarily bad; as technology has become more popular (i.e., dumbed down until the average teenager could waste an entire day playing flash games and sending pointless text messages to one another) variety becomes a detriment for support and usability. It's horrible, but the more choice you give people, the more confusing it is for people who don't love the platform itself. I can relate. I don't really give a damn about who and how my tires are manufactured or what kind of configuration my engine is in my car. I just want to get to the store and run errands without a huge cost. Same for computers. As the userbase shifted away from technology geeks and educated, savvy users to more general Mom and Pop users the operating system platform became more bland and general, and feature lists were focused more on eye candy than on multitasking and memory protection.


Computer technology is going the way of the wild west. When I first became interested in the tech I was voraciously digesting articles that explored the nitty gritty of memory protection and multitasking algorithms and what additional specialized hardware made the Amiga computer from Commodore rock the special effects industry. Today, computers are migrating into appliances that are supposed to be as easy to use as VCR's and microwave ovens and are cheap enough that if they break, the cost to repair them is often higher than simply buying a new one at Wal-Mart. They're becoming civilized and boring.

I'll continue to read what news articles emerge regarding Haiku or ReactOS or a new project that still shows signs of life. I would love to try out an operating system that is niche enough to address problems with my operating system platform of choice or introduce cool and useful features without having to sacrifice my ability to "get stuff done." And I hope that these mini-projects can inject some excitement to the profession (Plan 9 has some really really interesting concepts in it...now if only I could edit video or use it to enhance our IT infrastructure without users crying and whining that it doesn't run Internet Explorer, I'd love to play with it more.)

Otherwise I guess I'll have to either move with the times or seriously look at shifting careers. The excitement simply isn't there anymore. I guess that's one of the side effects of not inventing the future but rather moving with the passage of time.

Thursday, May 6, 2010

Lower Merion School District Spying Report Issued

The findings of an independent consulting company (Ballard Spahr, LLP) were released recently regarding the remote monitoring of student laptop computers by the Lower Merion School District. Already it spurs an outpouring of vitriol in comments from the smart masses who think they understand anything that is going on here. Personally I think there's a huge disconnect between the peanut gallery and their perceived intelligence.

The report, an approximately 70 page outline of everything that was leaking into the press and then some, basically said what I originally thought. The school district has a lot of idiots running it. Not in so many words and perhaps not for the reasons people would think, but they did some pretty spectacularly stupid things.

The biggest problem, of course, was the IT department hiding the presence of the tracking software. It wasn't so much that I can't relate to their desire to hide it from people in case they try to circumvent the protection; I work in IT. I know people could do that. But anyone with half a brain in IT knows that security through obscurity won't work well. The laptops, if stolen, could easily be wiped and reinstalled with a clean OS image, and the tracking software would be useless. They not only hid it was there, but apparently they tried to obscure the fact that the software was there even when rumors were swirling about its existence. That is a blatant lack of respect for the students and faculty. Whether you regard them as little vengeful monsters or not they still deserve not to be lied to.

A very close second (okay, maybe it's a tie) was the lack of an updated usage policy for taking technology home. There were no documents to disclose modified acceptable use policies for using the laptops at home versus on the school network nor was there disclosure about potential security and privacy issues in the documentation given to parents.

Everything else in the report seems to nick the school for lax and ill-codified policies, and not being fully forthright with administrators and board members.

As someone who has to work in IT, I think the two biggest sins were the lack of properly documented procedures and the hiding of the ability to monitor the laptops. The fact that administrators and board members didn't know about these things, or didn't understand it, were not the IT department's fault, unless they went out of their way to hide it.

Really...there is a point where someone needs to take responsibility for themselves. The board didn't know about it because they didn't care. Neither did the administrators. They all had a vague idea of this ability, if they've seen evidence from the "anti theft" systems. What the hell did they think it did? That this stuff runs on unicorn farts and fairy dust?

I deal with users all the time. They care about how and why their systems work about as much as you care about how your car engine works. The IT department didn't explain it to them because it was a waste of time to do so! I've dealt with users to whom I've explained a simple (to me) concept several times and they simply don't listen. I can repeat it until I'm blue in the face and it doesn't matter. So why and how would this IT department telling their school board about activating timed snapshots from a webcam and screen capture utility while logging the remote system's IP address to a central server make any fucking difference to them?

And lack of following formal policies? In most smaller businesses and schools and, I'd venture, government agencies, following strict, codified policies is a luxury. We always hold up best practices as an ideal but more often than not they're aspired to, not followed. Departments like those in public schools are under immense pressures from the powers that be to just get a task done, and if it's held together with duct tape and broken pencils then so be it. Doing it "right" takes money and time. They don't want it done right. They want it done now.

While some would say that's an excuse, it's more of an explanation for the culture that this attitude has fostered. More often than not if something works, then it's good enough, and it saves money. If it's actually bad enough to bite you in the ass later then it will be fixed then. Otherwise, good enough is good enough.

What I find interesting is that lack of citing personal responsibility by the peanut gallery. These kids were using school property and apparently treated it like their own property. It wasn't. I was floored when this story broke and people were raving about how they'd format the computers if their kid had brought one of them home; yeah, right. You can't. It's not yours. The school was extending it as part of an experiment in technology-based curriculum. And it's their computer. Not yours. Not a handout. Not your property.

I'd have trusted the laptop about as far as I could throw it. Any organization that "lends" you a thousand dollar piece of equipment, would surely have the right to inspect it for activity; porn surfing, games, inappropriate use, anything of that nature. What universe would you live in where you go to school, can't browse the web the way you want, can't play the games you want, but expect them to just hand over a thousand dollar laptop so you could surf porn at home on their dime?

Use your damn brain!

There was one report of a girl who had taken the laptop into the bathroom to listen to music while she showered, and the parent was furious because the school may have seen his little high school princess naked. Huh?!

Damp, humid room...thousand dollar laptop...electronics...water. What the hell was it doing in that environment to begin with?!

To me, there were a number of failures here. From hiding the fact that this software existed to lack of formal CYA policies to cover proper usage of the laptops at home to a lack of common sense from the students and parents, there was a systematic failure that happened here.

The sadder part in my view is the ignorance of the peanut gallery. It's simply too easy to blame the evil school district and portray them as completely at fault while completely forgetting that there was also a bit of an attitude of entitlement, that reality has slammed down hard on the community realizing that these free toys weren't free. 

Sunday, March 28, 2010

The Merion School Spy-On-Kids-With-Webcam Case

Wow.

Every once in awhile I get hit with a story that leaves me scratching my head and saying to myself, "What the hell were they thinking?"

This particular scratching came from the story pertaining to the Lower Merion School District. The best summary thus far of the events comes from Philly.com. The gist of the story; kid had a school-issued laptop at home, gets called into the office, and the assistant principal confronts the kid with a picture taken by the laptop's built-in web camera showing him with "pills" and accuses the kid of drug activity.

Um...

The school had software called LANRev installed on the laptops for theft control. If a laptop is stolen, then it's "tagged" on a server and the laptop tries to "call home" to record the IP address as well as record snapshots from the web camera and screen activity.

The student's family apparently turned around and filed a lawsuit for invasion of privacy, and from there poo was hitting all sorts of ceiling fans. Students had noticed the webcam light randomly blinking on and off at various times and were told this was a "glitch," that they could ignore it.

Now it's time for all sorts of indignant cries to rise up from the choir...

For example, one parent saying that the computer could have taken pictures of his daughter when she took the computer into the bathroom as she showered. Huh? Isn't that like cooking bacon in the nude? Why would you take a thousand-dollar laptop into a humid, wet room while you were showering? You do know that electronics don't like water, right? (this link gives the example in the transcript of the podcast) My daughter is nearly 18 years old and I wouldn't hesitate to whack her on the back of the head if we spent a thousand dollars on a computer for her and she took it into the bathroom while she showered.

But this does bring up a legitimate concern, namely the ability for someone to get pictures of kids in their rooms in various states of undress. This would then bring the school (or system administrators) into the nasty territory of child pornography.

Hmm...

I'm personally torn on the issue. I've read the excellent writeup by Stryde Hax on his blog here, and I think I understand his viewpoint. Unfortunately it's not really a balanced view on the situation (as is his right to present on his own blog, of course; he I think he has been very understanding of dissenting viewpoints in my opinion and am glad for what he has contributed to the story since most involved seem to prefer throwing out non-constructive or vindictive opinions without any actual content to justify the viewpoint, while Stryde has been very good at articulating his view.)

Here's my take.

People have a right to their property, and to protect said property from theft. If I'm robbed, I am damn well justified in being angry at the violation of my privacy and have a right to be angry at having someone steal my sense of security.

I think I should be allowed to set my computer to do whatever I want. It's mine. If I want it to take pictures and upload them to a server, I should be allowed to do so, as long as there's no intent to violate someone's rights (having my computer take pictures of me during the day or pictures when it's stolen is legit in my book, but having it programmed to take pictures because I'm planting it in a locker room is clearly wrong.)

The school laptop program is giving students school property. This cannot be emphasised enough because people like to conveniently forget that part of the story. The schools is lending property to students. My feeling is that because the laptop isn't mine, and isn't under my control, I'd trust it about as far as I absolutely must and after that it's shut down. The laptop was supposed to be used for schoolwork, not texting friends, browsing the web for porn, or anything else the personal computers are used for, even email that isn't school-related. Anything you do can be recorded and used against you later. I have yet to understand why people can't get that through their heads; just as employers own the computer on your desk at work and can browse your mail and monitor your Internet use, schools have the same rights on their network, and unless it's spelled out otherwise you should reasonably assume those Big Brother rights extend to a laptop you don't own.

I think that a school should be able to do whatever they can for gathering evidence to bust people for stealing expensive property, and taxpayers should support it since this ultimately is funded by the taxpayers. Losing laptops and breaking them and treating them like crap doesn't get them fixed for free. Someone foots the bill, even if the path for the money is convoluted to the point where kids don't understand that Mommy and Daddy may end up having to pay more in taxes because they can't be more responsible with school property.

BUT...

There are caveats to the case. The computers were meant to bridge the digital divide; every kid has a computer with which to do schoolwork under the laptop program, and that meant as they implemented the program that every kid was basically required to use the school laptop to get through their classes. In other words, there wasn't a choice in the matter. They had the laptop, and it was apparently spying on them at times. Again I wouldn't have trusted them for anything not school related; I'd use the laptop for school, and use my own computer for my own personal use. This isn't necessarily an option for kids that don't have computers of their own, and I understand that. But I'm still torn on that as another issue because it seemed that many of the kids that can't afford even a $300 computer manage to afford a cell phone. Priorities. But that's not the topic at hand.

Also, the school denied that the laptops had the ability to take pictures of the kids and spy on them. It's one thing to have the ability, it's another to hide the fact that it can be done. According to the Philly.com story, representatives from the student council asked administrators about this and were basically ignored when they voiced privacy concerns; from the sounds of it the administrators stuck to the story that it was a "glitch" causing the webcam light to come on. Totally unethical.

The Philly story also points out what was possibly the biggest bonehead move on the school's part. The user agreement that the kids and parents had to sign was just the old boilerplate used in past years for using the Internet in the school, nothing new or updated related to using school computers at home. Dude, liability 101...were you all asleep at the wheel here? Where was the tech with half a whit of common sense who stopped to say that maybe you should have special rules in place for kids carrying thousand-dollar equipment around, especially knowing that kids treat school equipment like crap since, "Hey, I didn't pay for it! It's FREE!"

Most parents don't seem to know just how much liability schools have to cover their arses for. When a teacher sees or overhears anything, anything, they have to report it to higher ups or they can be responsible should something happen to said kid. Kid has a bruise around the neck resembling fingers? Kid have unusual cuts on the arms, or marks that look like something was injected with something? Or maybe they heard some passing talk about a kid being coerced into oral sex? These things have to be reported to administrators or authorities.

So if I were there when discussing issues in rolling out these laptops, one of my concerns would be that these things are virtual black boxes for collecting data on kids and that would put technicians into a potentially dangerous situation with knowing "too much." Troubleshooting a computer and running across browsing history involving abortion, drug use, parents raping sons or daughters...sure, chances are slim, but in a litigious society there is little room for "we'll deal with it if it ever comes up" and hope for the best. With the addition of taking pictures of the computers in homes, you can be sure to bet that I'd worry about collateral damage; pot plant in the background? Parent or sibling walking in the background half-nude from the shower? It's a can of worms I'd not want to deal with.

More than that, where are the checks and balances? The article states that the system was only used if requested by administrators at the high school or higher-levels. That isn't good enough. There should have been an iron-clad method for controlling who gets to use this and view the collected evidence, not just within the school but by a third party, such as the local police department. Better yet have the police involved each and every time the system is used.

Side note-the school apparently is saying that the police department did know about it, because the pictures are uploaded to a website where they can view the collected evidence. The retired police chief was quoted as saying he knew nothing about it. Another case of police being...surprise...technology-tarded, nodding their heads when told about what they can do when in fact they had no clue what they were agreeing to? Or is the school lying? Or are the police covering their own behinds?

These seem like common sense cover-your-behind issues that should have been dealt with at the outset of the program.

Of course there are little details that are squeezing out as the story develops. Worse, the details that do leak out are mostly one-sided, as the school plays the stoic "lawyer advises us to say nothing so we're not commenting" game while the kids and parents are shooting off whatever details they want, true or not. For example, there's no full explanation for why the theft-tracking was activated on a laptop that the school knew the particular student had in his possession. There is also a rumor that the kid wasn't using drugs, he was actually eating Mike and Ike's candies, which if it's true is going to be a definite story for the hall of embarrassingly stupid mistakes.

The Philly.com story also has some more background on the details of the kid and his history with (mis)using the equipment. According the news story, his family never paid a required $55 insurance fee before taking the laptop off campus, and the laptop in the question was a loaner unit because he had broken at least two laptops. It then went on to say that the theft tracking features were turned on because the school suspected the student had taken the computer home when he wasn't supposed to, in which case it would be considered "stolen."

...of course, it was just laziness and/or lack of procedure that would lead them to turn on the picture taking features, as the only thing needed to prove the laptop was removed from campus was that it "phoned home" to the school's server after hours from an IP that belonged to a home network.

No doubt the case is going to continue to contort and twist as more details leak out. The federal authorities are now involved to see if there are civil rights that were violated, and congressional representatives are trying to score points by calling for an investigation (really, with all the waste in government, is it necessary to waste time grandstanding on this when there's already a court system being involved?) Everyone is now in spin control mode, doing what they can to cover their own arses and justify missteps.

What is clear is that the school was engaged in unethical behavior. Had I had a hand in the program, I would have encouraged openly telling students that yes, there are systems in place to keep them from being stolen. Students are issued laptops with ID numbers that are registered, and they are responsible if said laptop is broken or disappears while in their care. It has been my experience that kids treat technology as if it's disposable if there's no consequence for destroying it; they need to have encouragement from parents and school alike to take care of the equipment.

I also would have made it perfectly clear with an updated technology policy what is expected from students and parents charged with the care of the laptops. That would include notifying them of the possibility of photos being uploaded remotely as well as what the laptops could be used for. How they could have been so negligent in this is truly mystifying.

But life is 20/20 hindsight and this district will have a black eye for a long, long time. They will be known for many years as a district that deviously spied on kids and because of that they will have a long and hard road to travel in rebuilding what trust they had among students, parents, and probably teachers. They'll also have an interesting time if they are found guilty in the courts and end up paying a large settlement to this kid's family and as a consequence raise taxes on residents in the district...

Friday, November 6, 2009

A Video Game that Deletes Your Home Directory Files

Created as an art project, Lose/Lose is a Macintosh game that looks a bit like that 80's classic Space Invaders. The difference is, as is warned explicitly on the author's home page, each alien you kill will delete a file in your home directory.

The story made its way to AppleInsider.

I've already railed on users not bothering to read directions or popups and warnings. This program is clearly a joke on people who don't bother to do so.

However a second twist came up in that several antivirus firms are classifying it as malware and a trojan. They claim that other people may take the program and repackage it without the warnings of dire consquences so that people will delete their files

First, this is silly. The vast majority of malware authors out there are working to make money now. They do it by taking over the machines in order to blackmail other users (give us money or your drive is encrypted), commandeer user's computers to remote control them in order to blackmail other users (give us money or you will suffer a denial of service attack), and commandeer user's computers to remote control them in order to overwhelm anti-spam efforts (turn computers into zombies that send spam). Oh, and I'd be remiss if I didn't mention the take over the computer to record files and keystrokes so they get your login information to banks and corporate sites.

Overall, the key to malware authors getting profits from ignorant users is to not get caught on the computer. If you disable the computer, they can't get money. They can't resend spam. They lose a zombie on their network of controlled machines. So unless it's a targeted attack, repackaging something that deletes home directory files is nothing more than digital vandalism (or a serious middle finger of misplaced anger at ignorant users to teach them a lesson).

In other words, it's a waste of time for malware authors.

On the other hand antivirus authors love this crap. "It's evil!" they laugh. "It'll destroy your computer! Plus it adds another signature to our database to increase the number we can post on our site so we look better than our competitors...

They know damn well it's not a serious threat.

Ken Thompson (if you don't know the name you're obviously not a computer person...just saying...) wrote a wonderful paper called Reflections on Trusting Trust wherein he described a compiler that was altered so it added a back door to the Unix Login program. He said that people normally audit the human-written source code to programs and trust the compiler, the program used to turn that source code into machine code. His alteration added a back door to the Login program and also had the ability to recognize when it was compiling a new version of the compiler, adding that backdoor-compilation-code to the new compiler as well.

In other words, this program questions trust. In order to install a program on the Mac (or Linux or Windows now) you have to authenticate as an administrative user. "Yes, I want to do this."

The problem is that you're normally installing programs from people you never met. You didn't write it. You didn't audit it. What's to stop the new trial software you downloaded from the webbertubes from uploading your financial information in the background while you're playing? If you granted it administrative access when installing the program, absolutely nothing will stop it.

Users simply trust that there's no chance (or a very slim chance) of that happening. They trust the authority of Those That Know More About This Shit Than I Do(tm).

Classifying Lose/Lose as malware (or potential malware) is silly and a waste of time. Any jackass that is worth their programming salt would come up with a better version than some retro 80's video game to attract more users rather than spend the time reverse engineering this little game, and even if they didn't, the time invested in removing the warnings would still probably not take much more to alter the compiled program so that it won't trip the signatures in the antivirus programs.

Hell...I could email a script to someone telling them to execute it and all it does is "rm -fr /". Got a signature for that, vendors?

The fact is that uneducated and ignorant users will always be a weakness in the system. There is no bringing them up to speed because they're not interested. See the number of cars that are on the streets in the US? How many of them don't know how to change a tire? Which, arguably, is one of the simplest tasks for car owners yet a rather important thing to know when they have a flat and are on their way somewhere. Lots of people have computers, they're ubiquitous, many people have come to rely on them for various tasks in their lives...yet they sure aren't flocking to the computer section of Barnes and Noble to learn how to properly maintain their system. Most of the time I'm lucky to find a user that even runs Windows Updates on their system.

So what's the summary here?
A) Users won't read warnings.
B) Antivirus vendors will do anything to look good.
C) If I can get you to install a program on your computer, you're not secure. You're probably fine. But you're not secure.

Monday, November 2, 2009

Karmic Koala Released!

Great news, Ubuntu 9.10, called Karmic Koala, has been released!

I upgraded my workstation at work and my home workstation and so far haven't had major issues.

It took about four hours over a dedicated connection to do an in-place (read: told 9.04 to upgrade to 9.10 instead of formatting and reinstalling a clean version) upgrade. Probably would have gone faster if I tried using a CD image to upgrade, but I haven't tried that. I just opened the update-manager and clicked on the button that said a new release was available; upgrade-manager handled the rest.

While it upgraded I couldn't help but think about the people that are upgrading to Windows 7. People are trying to grab release candidates, downloading pirated versions, paying hundreds of dollars for a store copy, or having to buy a new computer to get the latest version of Windows.

Usually the upgrades go fairly well, but when the upgrade goes wonky...I get especially mad, because it usually means I paid to get screwed. I paid money to lose my time in the upgrade, have hassle in trying to get things working, and basically I paid to create a headache for myself (whether the upgrade went well or not I still lose time in the process of upgrading). I also get more irritated at the idea that I paid for the operating system only to run into later headaches with the OS, but that's another topic.

Karmic, on the other hand, is Ubuntu Linux. Free. It has some irritations and quirks; it's not perfect and I would never claim it was. And I was upgrading to the latest and greatest version without paying anything but time. If something broke, I lost time. Not money. No expectation of support, and no resentment at a company charging me to get stabbed with such expectations.

My upgrade went well both times with one minor exception; one irritation with Ubuntu has been the network manager. It sucks. Never seems to work right. So the first thing I do is install Wicd, which drops in palce and replaces the network manager. My work system kept everything just fine, while my home system replaced Wicd with Network Manager again, and lost my static IP entry and thus broke my port redirection from my home router. I came home, checked out what happened, and told Synaptic to reinstall Wicd and all worked fine again.

I'm still experimenting with Karmic to see if things that quirked and broke in the previous release work in this one. Some of my compiz graphics coolness would malfunction or barf on my home system so I had to turn it off; now I've reactivated some of the goodies to see how well (or horrible) it works now. My work system used to lock up if compiz effects were left on too long. My home system just had weird application crashes. I upgraded before Halloween and so far it seems to be working better.

Canonical (the company behind Ubuntu) has integrated a new cloud-storage system so I could, if I wished, upload 2 gig of data for free to a storage area on their servers that then I could access from any other Ubuntu system or use a web browser to download documents and files to other systems. Not something I see me using, but maybe in the future something will come of it since Apple has been trying to leverage their version of cloud storage with Mobile Me and Microsoft has a trial system in place as well.

Canonical also changed the software installation system. Right now it's mostly eye candy changes, not something overly functional, and they're expecting the next release (probably next April) to include greater functional changes to the installation system so users can find and install software more easily.

Other than that, it's a lot of incremental usability and bug fixes. Nice touches, nice refinements, and best of all, I didn't have to pay for the upgrade. As soon as it was ready I clicked a button and got it.

I'm sure most Windows users I know will be upgrading soon. They usually do as soon as they need a new computer, since then it's preinstalled...

Tuesday, October 13, 2009

I Hate Blogger Usability Bugs (and Website Bugs in General)

I've spoken about neat features with Blogger involving pre-writing blogs and posting them with a "Scheduled" feature so I can write, say, blogs for the next three days and have them automatically appear. I can take a weekend off while still keeping content flowing.

But there are real glitches that, to put it lightly, tick me off.

I decided to find out what would happen if you have a brain fart and forget that September has 30 days. I scheduled an entry for September 31st.

The intelligent thing to do is for the application to see that you scheduled something for 9/30+1 day, and wrap it to 10/1 automatically.

This doesn't work. It publishes it immediately. That review for Diet Myths I did on 9/13? It was supposed to be today's entry.

Oh! I'll go back and edit the date so it appears later on. No harm, right?

No dice. I could probably delete the post and put it in as a new one, but otherwise...nope. Oh, it changed the date alright. On 9/13, when I wrote it the entry was still there but the blog entry was still visible. It just had the date set to 10/1 at the top.

Argh! So what then? Every day it stays at the top, since the date is set in the future, and visitors to the site will see it every day as my most recent story?

Not only is it bad form but my Aspergian mind would probably warp itself until it imploded at seeing something so out of whack. I immediately changed the date back to 9/13 and kept two blog posts for the day, resigned to the fact that I would just have to have it appear earlier than I planned. I filled in the entry that it was supposed to take with a bitching rant on poor usability. This entry.

Seems like Blogger would be better fleshed out. Apparently not. So if you're taking advantage of the pre-dating and pre-scheduling features of Blogger, keep in mind it's too stupid to adjust for your mind farts when it comes to dating items.

Along the same line glitches and bugs can occur in more serious forms. I noticed a bug in my primary bank's website. I was logged in checking on funds for paying bills, a really wonderful fun activity. I saw my wife hadn't transferred funds in yet. I asked her about it, she sighed, signed in on her computer, and transferred some money in so I could pay bills.

I viewed my accounts. No money changed. I viewed account details, and I saw the amount she transferred in; but it wasn't showing up under the totals. I switched views, refreshed, everything. The amount she transferred showed up under details but would NOT show up under available amounts. I logged off the bank site and logged back in, then everything showed up just fine.

Apparently the bank software doesn't handle changes made to the joint account when the two owners of said account are manipulating it at the same time. This is a DEFINITE possible exploit, and given enough time I'm sure there's some way to use this information to a black hat hacker's advantage. At a bare minimum it shows some poor programming protection for the site, and it also is annoying as hell to think they didn't think that it would be possible for a joint checking account to be accessed by the owners at the same time, and apparently it may have issues with handling changes in amounts showing up properly.

I'm sure there's plenty of behind-the-scenes reasons that this is a problem. I don't care. For the end user, this shouldn't be an issue.

That's the end of my complaints for web applications for now. It's a little scary that sites accessible by so many on the webbertubes could possibly take advantage of glitches, bugs, and outright security holes on websites holding my personal information. At worst, they're annoyances, like the one I found in Blogger. It's elementary that the application should compensate for something as simple as the user screwing up a date, and when there's a mistake it should be able to know that the user is trying to schedule the entry to show up in the future and thus if the date is greater than the current date, hide the damn thing. At worst, the site is showing a potential condition that can be taken advantage of, like the one I found with the banking site. It could be innocuous but glitches like that in the hands of math and logic geniuses can lead to some really interesting exploits (don't believe me? Read the story about Mac keyboards having their firmware exploited. Yes, that's right, your keyboard would be used to spy on you.)

Friday, July 10, 2009

I Would So Totally Go For an Electric Car

There are people who relish in complaining about the Obama administration, and while he hasn't created a Utopia of America his policies apparently are having some beneficial effects on companies working on "green" products. In this case, electric cars.

There's a cool new concept vehicle being created by a company called XP Vehicles, Inc. that is called the Mini Utility Vehicle.

The MUV may be a relatively inexpensive car because it uses 70% fewer parts than the average car.

Yeah. Seventy percent.

Plus it's lightweight. Because it's partly inflatable.

Four passenger, 125 base miles per charge (or you can get a module that will extend the range to 300 miles), totally electric, weights less than 1,400 pounds, top speed of 85 miles per hour and does 0 to 60 in 8.5 seconds.

And did I mention it's partly inflatable?

The seat, dashboard, and internal structure and carrying racks are inflatable or mesh suspension. And with fewer parts that should translate into fewer parts that can fail, lower manufacturing costs and lower maintenance cost. It "refuels" using lightweight removable battery drawers that you take with you to recharge inside your home. The XP has motors built into the rear wheels, and the first cars to market are expected to have two rear hub motors and a motor controller. In other words, no transmission.

The article says that their target market is an age group (29 to 32 year olds) that are getting their first car but they found often can't afford a home, and insurance companies don't want to cover vehicles that need cords running to them. So...drawers of batteries that you can carry easily.

I'm a little leery of the promises before it can be delivered since this article states: "The battery drawer array features racks that can be easily removed from the car and consumer class batteries like those in an iPhone. XP will give consumers the option of taking the battery drawers out of the car and up to your house, apartment or hotel on something similar to little Razor scooters or over your shoulder."

I don't know if they mean that the batteries are like those in the iPhone or if it's a method similar to the iPhone or if the battery cells are iPhone-sized, but in general, don't compare the positives of a battery technology with the iPhone. iPhone batteries aren't replacable by the owner. It's a big sore spot for iPhone owners. Whether it's what you mean or not it's like casually mentioning that some sociopathic serial killer had a beard while telling someone you thought you'd grow a beard. Bad association.

The only trouble I see is that people tend to be...well, sheep. If something is different, something that their neighbors or people in their community aren't using, they won't want to try it. So despite this vehicle using cutting edge tech it will need a big initial wave of positive customer experiences in the introduction to market or it will very much flounder. It will need to hit the ground running with good experiences and very low cost then ride a wave of people seeing benefits of ownership over time to have continued sales. If the car is as inexpensive to buy and maintain over time as the article is promising then I would love to get one.

In the end promises are promises and reality is something else entirely; we'll not know much of anything until it is actually available on the market. Hopefully we'll see something more from XP in the next couple of years...

Friday, July 3, 2009

More on Thinking Before Sending Your Computer Out

Here's another wonderful story that people don't seem to learn from. A teacher was found with child porn on his laptop. He apparently was watching the videos "after hours" at the school.

Let's be perfectly clear: I'm not condoning child porn. Actually this post isn't about porn at all. What it's about is the general idea that someone has data that they probably should have kept private...would you advertise it if you were taking part in a crime? Duh...and instead of taking steps to secure that information, he sent the computer to be repaired without giving any thought to that data.

After working in a repair shop I saw the kinds of things that people had on their computer without thinking about who would see it. Everything from passwords to financial data to (legal) porn. Believe me. Do you really want someone you don't really know suddenly finding out what kinks you're into?

Take a couple minutes to think about these things:
Does your computer have your passwords saved to your bank?
What does your browsing history say about you?
Are you the only one with access to your "family" computer? Do you know what Junior is doing on the computer?
Have you ever audited chat logs?
Email...you aren't one of those people that exchanges racy or risqué emails with friends or immediate family, are you? Because in most cases those emails aren't kept encrypted...
Is your email set to automatically allow logins? Are you getting bills or information sent to those email accounts that you don't want shared?
Anyone send pictures to you or have you stored images on the computer that may be...compromising? Think about this from different perspectives. More and more often teens are finding out the consequences of allowing their party pics to be viewable on the Internet, and job seekers discover that picture of them their friend took barfing into a toilet at an underage party doesn't win brownie points with prospective employers.
Are you sure there's nothing you mind being passed around?
Are you sure all your music and videos on your computer is legal? The RIAA would love to make an example of you if it isn't.

Scarier yet...are you sure that you don't have spyware or malware on your computer that is downloading and sharing illegal material (such as child porn) on your computer without your knowledge??

There are steps that can be taken to minimize risk, such as encrypting your home directory or hard drive. Many people will say that they have nothing to hide or don't care if someone sees their embarrassing photos. That still doesn't explain what's going to happen if malware was transferring illegal material using your computer and that tech at the computer shop discovers it...do you really want to take a chance?

Sunday, June 28, 2009

Private Data From the Government: Ironic Edition

People rarely stop to think about their data. I always found it amusing...working in a repair shop I have more than once run across data that you'd think from the average Joe that had walked in wouldn't be downloading. I've had calls while working with an Internet Service Provider asking how to get an accidental wallpaper image removed before the caller's wife came home (you shouldn't have clicked the "set as wallpaper" while staring at those, sir...). And yet these people don't give a second thought to the data they're exposing when they send their computers off for repair to some stranger.

Turns out than in most bureaucracies the problem still remains, usually due to oversights, overwork, understaffing...but in the end, the problem still remains and there are "incidents".

The part that is sad is that even for people like me who do take time to think about these issues there is plenty of data on me through the government and various businesses (you know those cards you use for discounts at stores? They don't do that out of kindness, boys and girls...your shopping habits are worth big money) and I have no control over what is done with those records.

I just wanted to remind everyone of this after I ran across this story here about American government information being found on a hard disk purchased in Ghana (that's a country, in case you're an American where ignorance is a freedom we tend to like taking full advantage of...HA!). For $40. The data included, among other things, information on government contract information. Awarded because of the ability of the vendor to keep date secure.

The vendor is Northrop Grumman. You may of heard of them. They do a lot with our defense department...one of the big names in the world of toys that make things go boom.

They blame it on a vendor they hired to securely dispose of their hardware. The third party vendor doesn't know how it happened.

Whoopsie.