Showing posts with label Tech. Show all posts
Showing posts with label Tech. Show all posts

Tuesday, September 24, 2013

Wi-fi, fear-mongering, and pickles

Once again, I have to respond to a fallacious letter to the editor in my local paper, the Flamborough Review. And once again, it's by the same guy. This is the third of his letters I've responded to; the first was about teachers and the second was about vaccination. Here is the letter in its entirety:

The  idea of  “learning commons” in children’s libraries is a noble idea, although I am not an advocate of this kind of technology in primary schools.

We are distancing our children so far from the fundamentals that they will no longer have a foundation to build on.

Reading, writing, arithmetic and spelling has gone the way of the dodo. As a parent I am concerned, as are many others, that technology is beginning to replace the fundamentals. I can see it in the work my daughter brings home, and the work she doesn’t bring home.

Another concern is the use of Wi-Fi in primary schools. Our children’s exposure to electromagnetic frequencies (EMF) is a cause for worry. According to Dr. David Carpenter, director of the Institute of Health and Environment at the University of Albany, there is a great body of work that shows continued exposure to EMF effects changes in the ability to learn and remember. Last fall, the World Health Organization could no longer afford to ignore the research and deemed EMF to be a Class 2 carcinogen. The list of Class 2 materials also includes items such as asbestos, lead and diesel fumes. I am certain I would not send my child to a room full of diesel fumes, so how can I consciously send her to a room full of harmful radiation?

In 2011, biologist Andrew Goldsworthy gave a witness statement to a standing committee on health regarding the dangers of EMF. One of the most horrific statements from his speech was, “it was first shown by Bawin et. al in the ‘70s that weak amplitude radio waves can remove calcium from brain cell membranes. This destabilizes them, making them more likely to leak. This is important in the brain because the normal function of brain cells depends on the controlled passage of specific ions through the membranes. When they leak, ions flow uncontrollably…When this occurs in a fetus or young child, it retards brain development…Wi-Fi should be considered an impediment rather than an aid to learning and should be avoided, especially by pregnant teachers.”

The very governments and agencies mandated to protect us allow this kind of harmful technology to exist. We need to reduce or eliminate our exposure to as many toxins as we can, for our own health, and that of our children.

There is a parents’ group in Collingwood trying to get Wi-Fi out of their schools, yet officials are siding with Health Canada, which is ignoring its own scientific data. Please go to safe school.ca and read up on this issue. Some of the evidenced side effects include nausea, headaches, dizziness, attention and focusing problems, low blood counts, disturbance of the immune system and heart palpitations and racing heartbeats.

I will be asking the Hamilton-Wentworth District School Board for the results of their testing to see what levels my child is being exposed to.

Kevin Inglehart, Lynden

My only comment on the opening bit about education is that my sons are in grades 9 and 6, all in the Hamilton public system, and they are certainly learning the fundamentals as well as technology. They certainly learn things differently than I did thirty years ago, but that's to be expected. Perhaps this is a problem with the particular school or his daughter's teacher. It could also be a problem with his expectations and not with the school board at all.

But onto the other issue he raises, that of wi-fi routers causing health problems. This time, I'm not going to write a letter to the editor in rebuttal of this. I'm going to write my rebuttal here rather than submitting it to the Review. Submitting it would require making it fit for general consumption, and so I'd have to refrain from the sarcasm and ridicule that I really feel like using. I'd also have to shorten it since I'll probably write a lot here and the Review won't print it if it's too long. Quite honestly, I just can't be bothered to clean it up and make it short. Writing concisely is much more difficult than just spouting off; in the words of Blaise Pascal, "I have made this [letter] longer, because I have not had the time to make it shorter."

So, to business. First off, the EM radiation given off by a wi-fi router is called "non-ionizing" radiation, which means that it's not strong enough to remove electrons from atoms. This also means that it does not cause damage to cells. This is in contrast to ionizing forms of radiation, such as X-rays and UV rays, which do cause cell damage. Some forms of non-ionizing radiation (like microwaves) can heat things up and the heat can cause damage, but wi-fi signals are just not strong enough even for that.

It's true that electromagnetic radiation is considered a class 2B carcinogen by the World Health Organization (WHO). All that means is that it's on a list of things that have not been shown to be carcinogenic but require further study. Ken Foster, a professor of bioengineering at the University of Pennsylvania, says:

Saying that something is a 'possible carcinogen' is a bit like saying someone is a 'possible shoplifter' because he was in the store when the watch was stolen. [reference]

Here are some other things that are on the same "Class 2B carcinogen" list (the entire list is here):

  • coffee
  • asphalt
  • nickel
  • pickled vegetables
  • carpentry and joinery
  • chroloprene (also known as Neoprene, a synthetic rubber used in hundreds of products including clothing)
  • aloe vera
  • gingko biloba extract
  • talc-based body powder

Presumably Mr. Inglehart will be petitioning the school board to move the local Tim Horton's further away from the schools, to remove wood shop entirely, and to ban pickles from student lunches.

Asbestos and diesel exhaust, which Mr. Inglehart claims are on the type 2 list, are actually type 1. (Diesel fuel is 2B.) Lead is on the 2B list, but lead is known for being a neurotoxin, not a carcinogen.

I did visit the web site Mr. Inglehart suggested, and found many anecdotes describing how people became sick when they installed wifi routers in their home or school. But as we all know (don't we?), such anecdotes are scientifically meaningless. (One famous skeptical quote is "The plural of 'anecdote' is not 'data'.") There were also some studies that showed a possible association between cancer and cell phone towers – note that this is "possible association" not "proven causality", and a cell phone tower is not the same thing as a wifi router.

It comes down to this: unless you are a biophysicist specializing in this kind of research, you have to read what others have done and then trust someone. I haven't done the research myself, and I probably couldn't understand the details of the studies if you put them in front of me. But I do trust the World Health Organization, who says (emphasis mine):

In the area of biological effects and medical applications of non-ionizing radiation approximately 25,000 articles have been published over the past 30 years. … Based on a recent in-depth review of the scientific literature, the WHO concluded that current evidence does not confirm the existence of any health consequences from exposure to low level electromagnetic fields. [reference]

The Ontario Agency for Health Protection and Promotion says

After a decade of additional research, there is still no conclusive evidence of adverse effects on health at exposure levels below current Canadian guidelines.

and

…there is no plausible evidence that would indicate current public exposures to Wi-Fi are causing adverse effects on health. [reference]

Just like a lot of other conspiracy theories, this one is based on bad data, bad assumptions, and mistrust of the scientific community. Then you wrap it all up with scary words like "carcinogen" and stories about people getting sick, and give it to parents while implying that if they don't do anything about it, they obviously don't care about their children's health. If you do that, you might be able to convince parents that this is a real problem. That's why we have school boards considering getting rid of wi-fi, not because it's actually a problem.


I've seen a number of other letters to the Review from this same person. The majority of them are filled with fear-mongering and conspiracies like the "dangers" of vaccines and water fluoridation and that "banks and large corporations own and control the media". Most of them are just opinions and have no references, but some of them, like this one, have references to one or two articles or scientists who happen to disagree with just about every other scientist in the world. It's possible that he accidentally stumbled upon an article that describes the exact opposite of the scientific consensus and believed it wholeheartedly. But it seems unlikely that he's done this several times, so I am forced to assume that he simply mistrusts science and government, and believes in any conspiracy theory he hears.

I find it partially amusing but mostly irritating that these conspiracy believers (and many alt-medicine believers too) are all "mainstream science is wrong" and "mainstream science is covering up the truth" until they find a scientist who supports them, and then they're all "this person believes us and he's a scientist so he knows what he's talking about and you can trust him! And not all those other scientists! Just this one!" Sorry, folks, you can't have it both ways. Either you trust the scientists (or more accurately, the science) or you don't.


Update: I did end up writing a letter to the editor. Here it is:

I feel compelled to respond to Mr. Inglehart's letter, which contains half-truths and misleading statements, so that other parents don't concern themselves with a problem that does not exist. Wi-fi routers in our schools are not a cause for concern. There are certainly people who believe that they are, including a few scientists, but the vast majority of studies that have been done have shown no negative effects on health at all.

It's true that electromagnetic radiation is considered a class 2B carcinogen by the World Health Organization (WHO). What that actually means is that it's on a list of things that have not been shown to be carcinogenic but require further study. Other items on this list include coffee, asphalt, pickled vegetables, carpentry and joinery, aloe vera, and talc-based body powder. I don't hear anyone leading the charge against wood shop or pickles in school lunches.

But if you're going to believe the WHO's "possible carcinogen" list, you should really believe the WHO when they say "In the area of biological effects and medical applications of non-ionizing radiation approximately 25,000 articles have been published over the past 30 years. ... Based on a recent in-depth review of the scientific literature, the WHO concluded that current evidence does not confirm the existence of any health consequences from exposure to low level electromagnetic fields."

More locally, the Ontario Agency for Health Protection and Promotion says "After a decade of additional research, there is still no conclusive evidence of adverse effects on health at exposure levels below current Canadian guidelines. ...there is no plausible evidence that would indicate current public exposures to Wi-Fi are causing adverse effects on health."

There is no point is spending more taxpayer money looking at something that has been studied this much when the overwhelming majority of the studies show the same thing - that there are no negative health effects caused by wi-fi signals.

Graeme Perrow
Waterdown

Tuesday, August 13, 2013

I am Two-Face to Maynard James Keenan's Joker

Last week, I bought a few music CDs. Like, CDs with music already on them. And not MP3s. I know, totally old school, but I'm an old school kind of guy. Anyway, a couple of them were from a band called A Perfect Circle which features Maynard James Keenan, the lead singer of Tool. I had never heard any music by this band, but I like Tool and Keenan has a distinctive and strong voice so I took a chance. But the band isn't what this is about.

A Perfect Circle - Thirteenth StepThe CDs I got were their first and second albums Mer de Noms and Thirteenth Step. On the back of the Thirteenth Step CD case, it says "Copy Controlled", which I assumed was some technology to prevent people from making copies of the disk. It never occurred to me that this would prevent the tracks on the disk from being ripped by programs like iTunes, because everyone uses iTunes or Windows Media Player or something like that, right? I mean, considering the number of iPods and other MP3 players out there (recent surveys say there are approximately 4.23 gazillion of them), no record company in their right mind would knowingly put technology on an audio CD that prevented it from being imported into iTunes. Would they? Yes. Yes, they would.

(Note that I'm giving the record companies the benefit of the doubt here. It's possible that they've done this so that people who wanted MP3 copies would be forced to buy the album twice. I'm going to assume that the copy protection is there solely to prevent piracy and not as a way to rip off consumers.)

Neither iTunes nor Windows Media Player can read the disk at all. I can't even play the disk on my computer. So now I have an audio CD that I legally own and yet I cannot listen to it on my computer or iPod. If I'm in the car, I could use the CD there (if it works on that player), but that means either leaving it in the car all the time or deciding in advance what music I'm going to listen to when driving. That's a pain, and avoiding that is the reason I bought an iPod in the first place. I sometimes listen to music at work through my iPod, but this album would be unavailable. The other A Perfect Circle album rips and plays fine. Keenan's voice is obviously a big part of it, but the songs are shorter than Tool, and a little more mainstream. There is far less ambient stuff – one of the songs on Undertow (a Tool album I also bought) (and successfully ripped) contains almost ten minutes of near-silence. But the band isn't what this is about.

So what are my alternatives? I've searched the internet and have found some instructions on how to rip such CDs, so I may try one of those. I could just buy the album digitally, but that means paying for it twice and since I haven't even been able to listen to it yet, I'm a little reluctant to pay again. But there's another alternative.

I could steal it.

Music pirate

I could probably search the internet and find an illegal copy of the album someplace and download it in ten minutes. Make no mistake, I realize that this is theft, but I already paid for the album, so the band / record company is not really losing out on anything if I download it. At least, I could use that logic to justify it to myself. But I'm not a music pirate.

I work in the software industry. The software package I work on is not a huge piracy target, but the concept is clear – people downloading SQL Anywhere and not paying for it are stealing from my company. Similarly, downloading A Perfect Circle would be stealing from the record company and, indirectly, the band members themselves.

I'm also a little gun-shy. A few years ago, I downloaded some torrents of TV shows (just episodes I missed of CSI or something from network TV, not PPV or anything), and I got an email from my ISP saying "we've been told that you're downloading copyrighted material. You'd better stop." I did stop, and so if I decide to look for A Perfect Circle's album online, I'm a little concerned that I'll get caught and they'll cut off my internet.

So integrity and fear means that I probably won't steal it. If the methods I've found of ripping the CD don't work, I'll probably just buy the damn thing online. I'll grumble and I'll complain, but I'll fork over the $10. And I'll probably buy their third album as well. But the thought of downloading a pirated copy of the album did cross my mind, and not just for a few seconds. I seriously considered it.

The record industry is trying to prevent piracy, but the method they've chosen (this type of copy protection) is making a non-pirate like me consider stealing the album. They have taken a law-abiding citizen who is against piracy and turned him into a potential criminal.

Talk about unintended consequences.

Thursday, June 20, 2013

My first business trip: Elizabethtown, PA

I have loved programming computers since I wrote my first program on my Commodore VIC-20 back in grade 9 (that would be 1982 – damn I'm old). I also got pretty good at it, which explains why I'm still doing it over 30 years later. Being a programmer has had many rewards for me over the years, and one of the perks (before Sybase/SAP, anyway) was travel. I worked for Microsoft in Redmond, Washington for four months on my last university co-op work term, and flew out there again a few months later for grad interviews. While working for Corel, I went to New York City for a day. I was only at Comnetix for three years, but while I was there I went to Boston countless times (roughly once a month for those three years, sometimes for weeks at a time), Washington DC, New York City (again, for a day), Ottawa, San Francisco twice, Naples Florida, and I would have gone to Spain for a project if I hadn't already had a vacation booked at the time. In my sixteen years at Sybase, I've only been on three business trips, all to Baltimore, but now that I have a family, I'm fine with that.

But my very first programming-related trip was to Elizabethtown, Pennsylvania. Now I know the programmers among you are wondering "Damn, Graeme, how did you score that?" This is a place that I would wager very few of you have ventured. And if you actually used the term score, you have definitely never been.*

When I was in grade 12 (this would be the spring of 1986), a few of us were asked by our computer science teacher Miss Gray if we wanted to participate in a programming contest run by the American Computer Science League. We would be given a few questions, and we'd have a limited amount of time to write programs to answer the questions. This sounded like fun, so we entered and did really well – well enough to garner a trip to the finals. And not just the Canadian finals, this was for high school students across Canada and the US. (Actually, another guy that went, Faisal, reminded me that we didn't actually make the finals, but some other team wasn't able to make the trip so we took their place.) The finals were held in, you guessed it, Elizabethtown, Pennsylvania. Five of us were chosen to go: me, Faisal, Glen M., Glen F., and Paul. Miss Gray and our school principal Mr. Peleschak came too.

Mr. Peleschak was an interesting guy. He was the principal of the school for our entire five years there. He was an older gentleman, very friendly, almost grandfatherly. He had a full grey beard and always wore a smile. Back in the politically incorrect past, every school day began with a recording of O Canada followed by the Lord's Prayer. (I remember being a defiant atheist and not bowing my head during the prayer. I was such a rebel.) There were numerous different recordings of the Lord's Prayer, all done by Mr. Peleschak himself, and all different in some way. For example, in some he said "forgive us our trespasses", others had "forgive us our sins", and still others had "forgive us our debts". His various forms of prayer earned him the nickname "The Pope". Note that this was not a Catholic school.

We all drove down in Mr. Peleschak's van, and I think I remember more about the trip down and back than the contest itself. iPods were still 15 years away, so a few of us brought tapes and Walkmans (Walkmen?) to listen to music. Mr. Peleschak said he would put our tapes in the van's tape player so we could all listen, but we'd have to alternate – one of our tapes, then one of his. This was OK with us, except that all of his were John Denver. I wasn't much of a John Denver fan at the time and after that trip, I'm still not. But I don't think Mr. Peleschak was much of a Triumph or Van Halen fan, so I guess we were all even. Mr. Peleschak also smoked a pipe, so now and again the van was filled with pipe smoke (though I believe he opened a window when he lit it). Certainly by the end of the drive I was sick of the smell, but I did have to admit it was better than cigar or cigarette smoke.

The contest was being held at Elizabethtown College, and all the competitors stayed in residences there. Faisal and I were in one room (foreshadowing our time at the University of Waterloo, when we were roommates or housemates for almost four years), the two Glens were in another, and Paul was the lucky one who got to bunk with Mr. Peleschak. Miss Gray got her own room. I have no memory of what we did for food, or even how many nights we were there. Everyone got a welcome package, though the only thing I remember it including was a baby blue frisbee with "American Computer Science League" on it. Outside the residence where we were staying was a large open area. I don't remember if it was a football field or just a big green space but much of the time we were there, there were blue frisbees flying all over the place. Twenty-seven years later, I still have mine (pictured above). The words have faded a little, but it's still functional. It takes a lot to break a frisbee, when you think about it.

The contest itself was a complete disaster for our team. Each team could request the types of computers they needed, and we asked for Commodore PETs, which were the computers we were using at school. When we arrived, we found that they had provided us with the right machines though an older model. But the problem was that they had a different language installed. The machines shipped with a version of the BASIC language, but our school computers were using Waterloo Structured BASIC**, which was BASIC with extra stuff added. We were forced to adapt to using regular BASIC, and while not a huge disadvantage, it was certainly frustrating and distracting. I don't remember where we finished exactly, but I have a feeling we might have had full solutions for one or maybe two of the five questions, and partial solutions for the rest. And I think "partial solution" is pretty generous. In short, we got smoked.

The way home should have been memorable, since we stopped at Hersheypark in nearby Hershey for a day of fun. But the only thing I remember about that part of the trip were the street lights in town (shaped like Hershey Kisses) and the fact that many of the street names were chocolate-related. I have no memories of the park itself, though apparently we played mini-golf, since Miss Gray wrote something in my grade 12 yearbook about that.

About a year and a half after this contest, I began my studies at the University of Waterloo, though I didn't choose computer science as a major until second year. I guess my next computer-related trip was to Seattle in 1991 to work at Microsoft. That trip was pretty memorable as well, but you always remember your first.


* – That was just a joke, really. I have no negative memories of Elizabethtown itself, though we made fun of the place while we were there because it was so small. We lived in a town of about 50,000 just outside of Toronto, a city of 4 million. Elizabethtown had a few thousand people and wasn't close to anything big. At one point we saw three people walking together and Faisal said "hey look, an Elizabethtown gang!"

** – This ended up being an interesting coincidence years later. Waterloo Structured Basic was developed by a company called Waterloo Computing Systems, which later renamed itself WATCOM. In 1994, WATCOM was acquired by Powersoft, and a year later Powersoft was acquired by Sybase. I started working for Sybase, in the same office where WATCOM was located and with many of the same people, in 1997. We've moved buildings but I'm still there, and some of the people who were on the languages team in the '80s are also still there though many have moved on and some have retired.

Monday, March 04, 2013

Facebook advertising

This is hardly a revelation but ads on Facebook are targeted, which means that Facebook looks over your profile and shows you ads that it thinks you'll be interested in. For the most part, it does a pretty decent job. I've seen ads for Rush and the Tragically Hip, both of which I like. I even once clicked on an ad for a musician that I had never heard of because the ad said he was similar to Dream Theater, which I also like. I've seen ads for programming jobs (I'm a programmer), guitar lessons (I play guitar – sort of), books that are along the lines of what I might read, and games that I might play if I were into video games at all.

The other day I saw an ad for a golf video game and another for golf equipment (I like golf), another about Blackberry tips (I'm an Android guy myself, but given my technical job and interests this is a good guess), one that said "Western graduate?" (yup), and another that said "Star Trek fan?" (yup) – all on the same page at the same time. I have to say I was pretty impressed with the ad selection.

I've even seen ads for lacrosse-related things. You may or may not be aware of my interest in lacrosse.

FacebookAd2

Just the other day, I posted a status about my garage door spring having died. A day later, I saw an ad for a company that services garage doors in my area. Neither Home Depot (where we bought the door) nor Rona service garage doors, so seeing this ad was perfectly timely. I gave the guy a call and he came out on Saturday to give me a quote. Thanks Facebook.

FacebookAd5

But it doesn't always work. I frequently see ads for "Find Mature Love – for Singles over 40". My status is clearly "married", so I'm not sure why it decides to show me that. I wonder if it takes into account the fact that my wife is not on Facebook.

Some of the ads are premium and show up regardless of whether they match anything in your profile, like these ones from a group that tries to get pardons for convicted criminals. I'm OK with this idea in general – if someone commits a crime, pays his or her debt to society, and is unlikely to re-offend, in certain cases granting a pardon may be reasonable. But the advertising people in this group may want to re-think the pictures they choose. I know this is totally judging a book by its cover, but I'm not sure I want these scary-looking people who have already committed crimes walking the streets:

pardonsFacebookAdFacebookAd4

I found it interesting that each of the ads (captured at different times) has a different "deadline". I'm not saying these deadlines are all meaningless and fake, but… oh wait, yes I am.

Many people complain about advertising on the web, but we all know that Facebook and Google and Microsoft and all these other companies aren't providing all of these services for free just because they're nice people. They're in it to make money. They can do it in a number of ways but the easiest two are (a) sell advertising, and (b) charge users to use their services. Most companies choose (a) because if you charge people directly to use your services, your services better be useful, reliable, easy to use, aesthetically pleasing, and popular, not to mention either unique (i.e. nobody else offers such a service) or the best available, otherwise who's gonna pay for it? But lots of people will use a web site that's free, even if it isn't the absolute best available. And having to sign into your account in order to do things like web searches is a pain (to say nothing of privacy concerns) so people won't do it.

But the only way a company is going to allow you to do stuff for free is if someone else is paying for it. You don't pay to listen to the radio, do you? Nope, because there are advertisers. TV used to work the same way, but now you pay the cable and satellite companies. Technically, they'll tell you you're paying for the delivery mechanism and not the TV content, so I guess it kinda still does work the same way. But anyway, if some advertising is what lets me use gmail and blogger and google and twitter and facebook and the majority of the rest of the web for free, I'm OK with that. As much as I like facebook, I'm not going to pay for it.

Sunday, February 24, 2013

Yahoo decides this mobile thing is a fad

According to All Things D, Yahoo has made a change to their company policy on working remotely. The new policy is, in a nutshell, don't. Employees who currently work remotely will have to either move so they can work in a Yahoo office or resign. This seems to apply to workers who work 100% remotely as well as those who work from home one or two days a week. Does Yahoo really not understand mobile yet? The entire point of the mobile industry is to allow people to do stuff wherever they happen to be – you don't have to go to your bank to do your banking. You can shop without going to a store. You can send email, surf the web, watch TV and movies, and listen to whatever music you want from anywhere. But Yahoo employees must be physically located in their offices in order to be productive? Really?

The reasoning Yahoo has given for making this decision makes little sense: they had lots of people who worked remotely and weren't productive. So instead of firing the unproductive workers or making them come into the office, they decide to punish all of the productive remote workers as well.

Many tech companies talk about hiring the brightest and the best. Google is notorious for their hiring conservatism; they'd much rather pass on someone good than hire someone who turns out to be a bad fit. Yahoo is obviously not concerned with this. It sounds like they'd rather hire someone who lives physically close to a Yahoo office (or is willing to move) than someone awesome who doesn't (and isn't). Maybe they have great people up the wazoo and have decided they can afford to lose some of them, which they will. Maybe this is a cheap way of getting rid of some employees without having to pay them severance. That strategy would only work if the remote employees are the ones you want to get rid of and you don't mind having some that you'd rather keep quit.

I work from home at least once a week (and more if there's nasty weather), and have for ten years. Even though I don't work for Yahoo, I take it personally when I read stuff like "Speed and quality are often sacrificed when we work from home". I obviously can't speak for everyone who works at home, but it's quite the contrary for me. I frequently get a fair bit done at home – at least partially to avoid this very stereotype. If my manager decides that I don't get as much done at home as in the office, he may decide to revoke this privilege, and that's a privilege I greatly appreciate and don't take for granted. I certainly have the occasional work at home day where I don't get much done, but I also have the occasional work in the office day where I don't get much done. I also have days both at home and in the office where I'm very productive. And this is all ignoring the fact that I work at least two hours longer when I work at home since I'm not driving to Waterloo and back.

I've done work in a number of different rooms in my house. I've brought my laptop and gotten work done in mechanic's waiting rooms, doctor's and dentist's offices, hotel rooms, friends' houses, my parents' and in-laws' places up north, and even a couple of Tim Horton's. Every SAP employee worldwide is given a laptop so that they can work remotely if necessary. If I worked for Yahoo, their company policy would ensure that none of that would ever happen again.

Dear SAP/Sybase: I'd advise against this strategy. The goodwill that you'd lose from your employees would vastly outweigh any potential (and purely theoretical) productivity gains. Not only does it limit the people you can hire in the future, but I know of a few people who'd likely quit. In fact, I know of one brilliant engineer who you'd lose because he lives far away from the office and works from home a lot. And trust me, you really don't want to lose this guy.

Yes, that's right – you'd lose Ivan. Oh, and I'd probably be outta there too.

Disclaimer: I am not speaking for Ivan, nor am I making any kind of ultimatum to SAP/Sybase. Just saying that I disagree with this policy.

Thursday, March 15, 2012

Dumbest spam ever

I received a spam email this morning with the subject "Summary of junk emails blocked – 1 Junk Emails Blocked". It was ironically intended to look like a report from some kind of spam filter saying that an email was blocked. There were a number of links on the page for how to manage lists or configure your settings for this non-existent application. I knew it was spam because (a) it didn't mention what spam application or web site it was using (I'd expect that in big letters across the top), (b) I have never signed up for any such service, (c) my company used to have a similar service but stopped it a few years ago (and this wasn't it), and (d) the email was sent to an old email address of mine that I no longer use but still works.

But the real giveaway that this was fake was that all of the links in the email go to the address 192.168.0.22:10080. Any address beginning with 192.168 is what's known as a private address, which means that it's a special address that's only accessible from another machine on the same network. By "network" I don't mean the Internet, I mean, basically, the collection of computers connected to your local router. My machine currently has the IP address 192.168.0.108. Posting your IP address on the internet for all to see might be considered a security risk, but there is no security problem with posting private addresses because unless you are connected to my network, you can't get there. Not because I'm clever and have set up fancy rules or anything, just because that's the way TCP/IP addressing works.

So if I were to click on a link in this spam email, first of all you'd have my permission to come to my house and smack me upside the head. Secondly, nothing bad would happen in this case, because for it to work, there would have to be a machine inside my network with that address, with an HTTP server listening on non-standard port 10080. The odds of there being a machine on my network that just happens to have that IP address and just happens to have an HTTP server listening on that port and just happens to have evil software running on it are beyond remote. The only other possibility is that some hacker has already penetrated my network, set up a machine with that IP address and an HTTP server complete with malware, and then sent me a spam email to get me to visit that machine. This is unlikely as well – you've already broken in, why bother with the spam? This is like breaking into a bank in the middle of the night, then calling a bank employee from the inside, and while pretending to be the bank manager, asking him to unlock the front door. You don't need the front door unlocked, you're already inside.

dumbpeople

The most likely scenario is that the people who created the spam email are idiots. They set up a server on the internet that they wanted you to connect to (that had malware or whatever on it). Since they set up the server in the first place, it's likely on their local network and the way they connect to it is through the 192.168 address. That's not the way the rest of the world would get to it, but they didn't know that. The result is that they have sent out this spam email (and likely paid to do it) and will never get any hits, even from people who do foolishly click on the links.

Couldn't happen to a nicer bunch of guys.

Monday, December 05, 2011

Followbots

Like everything else online, the bots have invaded Twitter. Most of the time these are harmless but there are some spammy ones out there too. There seem to be two kinds of spam on twitter: the spam accounts that follow you hoping you'll follow back, and the spam accounts that mention you in a tweet along with a link to their web site. Luckily, Twitter has a very easy way of dealing with either one – you can simply block the account and report it as spam, all in one simple click. I have no idea what happens after that but I don't really care; once I've done that on a spam account, I never see tweets from it again.

There are thousands of bots out there scanning the millions of public tweets that stream by every minute looking for keywords. Say you have a business selling spatulas. You have a twitter account for your business, where you announce sales and new products and have discussions about current issues in the spatula industry. You obviously want to get as many followers as you can, and one way to do that is to follow as many people as you can. But who to follow? You can follow your friends and tell them to mention you in tweets and hope to get some followers that way, but that's generally slow. An easier and more effective way is to set up a bot.

You'd create a bot to look for the word "spatula" in any tweets, and automatically follow the account that tweeted it. Once you do, there are basically three possibilities: 1. They mindlessly follow everyone who follows them, and so they follow you back. 2. They are interested in spatulas and follow you back. 3. They are not interested in spatulas and just included the word "spatula" in a one-off tweet (and really, who hasn't?), and do not follow you back. Oh well.  This is a fine idea, and seems to work well for many businesses. I've got lots of followers who are obviously doing this (including at least three in the past week), since they are very specific business-related accounts that have nothing to do what I generally tweet about, but are related to a particular word or phrase that I used. Here are some of the more fun ones:

  • pronunciation – I posted a link to an article I wrote on how to pronounce a bunch of lacrosse players' names, and a couple of hours later, I'm being followed by "a simple resource for everything related to pronunciation".
  • fire suppression – I mentioned that a former lacrosse player now works in the "fire suppression" industry. I was shortly followed by a company that makes fire suppression equipment.
  • motorcycle helmet – A friend rides a motorcycle and I happened to use the phrase "motorcycle helmet" in a tweet. I'm soon followed by a motorcycle helmet store in California. I don't ride a bike myself, and live several thousand miles away, so they are unlikely to get any business from me.
  • wind power – this was a while ago so I don't remember the details, but I mentioned something about wind power and was subsequently followed by a company that specialized in wind power solutions. They must have gotten bored with me since they don't follow me anymore.
  • homeopathy – I tweeted something about homeopathy (the word "bullshit" was likely included), and was followed by a couple of homeopathic practitioners. I think they immediately realized their mistake and unfollowed. I'm pretty sure the same thing has happened with "chiropractor" and "acupuncture".
  • iPad – mention iPad in a tweet, and people wanting to "give" you or sell you iPads will come flying out of the woodwork.
  • domain name – I asked a friend in the business about how to acquire a no-longer-used domain name and was followed by a company that sells cheap domain names.
  • crossover – This is the funniest one. The National Lacrosse League has a new rule called the "crossover" rule. With the new rule, four teams from the East division and four teams from the West division make the playoffs unless the fifth place team in the West has a better record than the fourth place team in the East (there are only four teams in the East). In that case, the fifth place Western team "crosses over" into the Eastern division for the playoffs, taking the place of the fourth place Eastern team. I mentioned the new crossover rule in a couple of tweets, and was followed within minutes by at least three car dealerships. Only one still follows me.
  • perl – I mentioned perl in a tweet a couple of years ago and was instantly followed by an account for a perl blog. Oddly, one of the writers on that blog is named Graeme.

Last week, I started an experiment. I tweeted that I love spatulas to see if I would get followed by @spatulacentral, Your ultimate source for spatula news and information! No such luck.

Sunday, October 23, 2011

Tweetdeck vs. MetroTwit vs. Seesmic

Twitter is one of the most popular web services anywhere, but once you become fairly active on it, I find the web site itself is impossible to use. If you follow lots of people (I follow a little over 300), one single stream of tweets is just too much, and trying to keep track of conversations or random people mentioning you is next to impossible. Luckily there are numerous applications out there designed to make this easier. Most allow you to separate your stream into multiple columns so you can put the people you're following into various groups; for example, I have a group with techie people (Scott Hanselman, Joel Spolsky, Leo Laporte, and the like), another group with people I've "met" online through my interest in pro lacrosse, another one for other sports people (Bruce Arthur, Dave Hodge, Down Goes Brown), and so on. This makes it much easier to keep up. You can also add a column for direct messages or mentions so those are easy to see. This makes having a conversation with someone on Twitter possible, where replies to you from others don't get lost in the deluge of tweets.

I tried three of the most popular such applications: Tweetdeck (now owned by Twitter itself), MetroTwit, and Seesmic, and made some notes on each. Note that there are lots of options in both Twitter and these applications that I never use (eg. tweeting from multiple accounts, trending topics, Foursquare, LinkedIn, etc.) so I can't comment on those. For each one, advantages/drawbacks are ordered roughly in order of importance to me.

Tweetdeck and Seesmic also have web versions that allow you to do much the same things as the desktop apps, but through a web interface so there's nothing to install. I didn't investigate these at all.

Tweetdeck

Tweetdeck is the first Twitter application that I used, and I used it for about a year so it's the one I'm most familiar with. It handles multiple Twitter accounts and you can add accounts from Facebook, Foursquare, LinkedIn, MySpace, and Google Buzz (why?) as well. I really only used Twitter. I occasionally updated my Facebook status through Tweetdeck, but only when I wanted to set my status to something and tweet it at the same time, which was rare.

Version: 0.38.2

Advantages:

  • A global filter hides tweets you don't want to see based on hashtags, other content, user, or application. This makes it easy to ignore useless Foursquare tweets.
  • The colour scheme is nice – dark background (but not too dark) with white text
  • There are versions for Windows, Android, and iPhone.
  • Pops up a little window for images from twitpic, yfrog, lockerz, and others, as well as for youtube videos.
  • Easy to click on a user or tweet and jump to it in a browser if you want to
  • I like the little whistling sound it makes for notifications.
  • You can follow/unfollow people right from the interface and even modify Twitter lists.

Drawbacks:

  • Columns are not resizable. This means that you have a maximum of six columns on a 1920x1200 screen if the window is maximized (and you can't see all of the sixth column). Any more than that and you have to start scrolling horizontally. I hate that.
  • Rearranging columns is silly – you have to click little arrow buttons to move columns right or left one position. You can't just grab the top of the column and drag it to where you want it to be like you would expect. Dragging columns works in both MetroTwit and Seesmic.
  • To mark a tweet as read, you either click on a tiny little dot on the tweet, select "Mark tweet as seen" from level 3 of a nested menu on the tweet, or click the "Mark all as seen" button at the bottom of the column. Not at all intuitive. I got around this by simply clicking "Clear all" at the bottom once I'd read everything to mark then all as read and remove them from the column entirely – though once you've done that, you will never see those tweets again through Tweetdeck.
  • If you've marked all the tweets in a column as read but not cleared them, there is no obvious indication that there are new tweets. Unread ones have a little dot next to them, but it's hard to see and not obvious at all. (This is why I clear out the whole thing.)
  • If you see a reply to someone but want to see the rest of the conversation, you can click on the "in response to" in the tweet (this feature was also not obvious). However, this link shows up on the same line as the username, date and time, and application used (eg. "Twitter for iPhone") so it's not always visible. If you can't see the link, I have found no way to get Tweetdeck to show the conversation.

Drawback specific to the Android version:

  • If you haven't updated in a while, you have to scroll through everything to get to the top. You can click on the title bar of a column to automatically scroll, but it still actually scrolls and if you have several days worth of tweets to scroll through, this can take a while. I couldn't find an obvious way to simply jump to the top or mark everything as read.

 

MetroTwit

A couple of weeks ago, I had a problem with Tweetdeck popping up a weird empty "Updating" window that never went away. (It got fixed the next day.) This was not a big deal at all, but I tweeted about it anyway. A friend responded and told me that he had tried MetroTwit and had never gone back, so I decided to give it a try as well. I had a tough time ordering the advantages below since the top six are excellent features.

Version: 0.9.0.0

Advantages:

  • Columns are resized as they are added so if you only have a couple, they're wide but if you have lots, they're narrower but still all fit on the screen – no horizontal scrolling. This is fabulous. I have seven columns and can see them all easily. I haven't tried more but I assume if you have too many it will eventually either not let you add more or will be forced to make you scroll.
  • A big number appears at the top of each column telling you how many unread tweets are in that column, though I've occasionally seen situations where the number is off by one.
  • Clicking on a tweet marks all tweets below it as read, so you can mark an entire column as read by clicking the top one.
  • A mark appears in the scroll bar for each column indicating where the most recently read tweet is.
  • The most recently read tweet has a line and arrow at the top to indicate "you've read up to here". Very nice.
  • You can have the application's icon change to include a count of unread tweets or replies or messages or whatever. I have it set to replies only so I can glance at the icon on the taskbar to see if I have any unread replies.
  • If you hover over shortened links you will get a tooltip containing the real URL.
  • Images from yfrog, twitpic, etc. will pop up in the interface when you click on them. I prefer the way Tweetdeck pops up a window to display images, but this isn't bad.
  • The link to see the rest of a conversation is always visible and obvious (i.e. it's a link on its own line that says "View conversation").
  • All three apps will autocomplete usernames when you type a '@' but MetroTwit will also autocomplete #hashtags, choosing from those that you've previously used as well as current trending ones.

 

Drawbacks:

  • When you minimize the app, some more tweets come in, and then you restore the window, the columns sometimes show the latest tweet, sometimes they show the most recently read tweet, and sometimes they show some random tweet that may be in between the two, or one that may be days old. It seems random which one happens – consistency would be good. This happens when you close and restart the app as well.
  • No built-in filters, so no way to get rid of Foursquare tweets. There is a filter from something called proxlet.com, but I haven't tried it yet.
  • The scroll bar is very narrow and it's hard to grab the scroller thing.
  • You can follow/unfollow people but I couldn't find a way to modify lists from the application. I generally do that from the twitter.com web page anyway. I only list it here because Tweetdeck can do it.
  • Not quite as easy as Tweetdeck to click on a user and jump to that user's page in a browser. It's two clicks instead of one.
  • The dark colour scheme is very dark, and the white one is hard to read. I prefer Tweetdeck's colours.
  • Twitter only. No support for Facebook, LinkedIn, etc.
  • Doesn't handle multiple Twitter accounts. Apparently this is "coming soon" but may only be available in the not-free "Plus" version.
  • Windows only. No Mac/Linux version, and no mobile versions.
  • There is an ad (OH NOES! ADVERTIZING!) at the top of one column. It's a different colour than other tweets and you can't get rid of it, but it's not really a huge deal. You can pay for the app ($14.95 Australian which is roughly the same in Canadian or US) to upgrade to "MetroTwit Plus" to make the ads go away.

 

Seesmic

I had nothing but problems with Seesmic. I installed it a few months ago and was less than impressed. I uninstalled it a day later. When I decided to write up this article, I couldn't remember what I didn't like about it, so I re-installed it and tried it for a while. "A while", in this case, turned out to be about an hour. I've given it a few more chances since then but they've always been short and frustrating.

First off, there were authentication issues. I authenticated with Twitter, but when I stopped and restarted the app (required to disable most of the myriad of plug-ins that were automatically installed and enabled (grrrrrr...)), I had to authenticate again. But this time the authentication failed – numerous times. I tried shutting down the app and trying again with no luck. I checked to make sure the Twitter site itself was up, and it seemed fine. After about ten minutes I tried again and everything was fine. Note that I was copy-and-pasting my password from KeePass so it was not a case of simply mistyping the password. This hasn't happened since then, so perhaps it was a one-time thing.

Version: They call it "Seesmic Desktop 2" but the version number was 1.2.0.1891.

Advantages:

  • It lists retweets other than my own. If a user I follow retweets a user that I don't follow (i.e. a "real" Twitter retweet, not just adding "RT" in front of the text), I'll see it in Seesmic but I don't think I will in either MetroTwit or Tweetdeck.
  • You can create a Seesmic account and it will do extra stuff like be able to synchronize your configuration among machines. I did not do this, so I can't comment on that feature.
  • Windows and Mac versions as well as Android and iPhone.

Drawbacks:

  • The columns don't resize.
  • Each tweet that you haven't read is marked with a little yellow circle, which goes away when you click on the tweet or select "Mark all as read" from the menu at the top of the column. But that's the only way to mark things as read. Not quite as bad as Tweetdeck, but worse than MetroTwit. You can clear out the tweets marked as read (i.e. empty the column), but when you close the application and start it up again, they all come back.
  • There are two buttons in the bottom left panel with no indication of what they do. One looks like a solid rectangle, the other a series of smaller
    rectangles but when I click on either of them (they seem to be mutually exclusive toggles), there were no obvious changes anywhere. There are no tooltips or text anywhere to indicate what they're for.
  • There didn't seem to be any way of determining or controlling how often it refreshes the feed. I could find no way of manually causing a refresh either.
  • At one point I had a Home column (i.e. my entire Twitter feed) plus a Sports column, made from a list I have. Several users in the sports list had unread tweets in the Home column but not in the Sports column. The tweets did show up in the Sports column some time later, but it didn't make sense to me that one column was updated while the other wasn't.
  • If you right-click on a tweet, there is a large list of things you can do (i.e. reply, retweet, block user, etc.). There is a little menu at the top of each column but if you right-click there, you just get a small and useless Silverlight menu.
  • Bug – when I tried copy-and-pasting my Facebook password, it seemed to think I was pasting in several hundred or thousand characters, as the password field kept scrolling horizontally for 10-15 seconds. My password is 8 characters long and when I typed it rather than pasted it, it worked.
  • There were about 10-15 plug-ins automatically installed and enabled. I disabled all but about three of them.

Conclusion

On the desktop, I've moved over to MetroTwit. It has resizable columns, and tells you at a glance how many unread tweets you have in each column without having to clear the column, and changes the application icon to indicate how many replies are unread and makes it brain-dead easy to mark tweets as read. Lots of big plusses. However, I tend to keep my Twitter application open but minimized most of the time, and the scrolling behaviour I described earlier is annoying. Big minus. When I bring up the application (whether starting or de-minimizing), ideally I'd like the columns to automatically scroll, showing new tweets, until the most recently read tweet is visible at the bottom with the unread tweets above it, and then stop scrolling. This way I can instantly see the oldest ones I haven't seen, and then continue to scroll up as I get to the newer ones. Actually I'm not sure what Tweetdeck does in this respect, since I always clear the column (because it's not obvious which tweets I haven't yet read).

I wouldn't touch Seesmic with a 39 ½ foot pole. It seems like beta software that got released too early. Maybe I'll try it again in a year or so to see how it's improved.

I still use Tweetdeck on Android because there is no MetroTwit for Android (or iPhone).

Friday, October 07, 2011

Facebook changes and rumours

From Twitter:

Scientists: Hey, I think we discovered particles that travel faster than the speed of light. World: OMG new Facebook!

Facebook made some changes to their interface recently, and just like every other time they've done this, a bunch of people lost their minds. There were postings about how to get the old interface back by changing your locale to the UK, and I heard the tired old calls of "if it ain't broke, don't fix it". There were even petitions demanding that Facebook change it back. These petitions will never work.

It's not that Facebook doesn't care what its users think, it's just that they have so many users that they have to cater to the majority. If you make a petition telling Facebook that you hate the new format and demand that they change it back, and you get thirty five million people to sign it – the entire population of Canada – and print it out and drop it on Mark Zuckerberg's desk, do you know what he'll say? He'll look at the 35 million signatures of people who hate the interface and say "This means that ninety five percent of our users love it! Success!"

Meet the new Facebook, same as the old Facebook

Of course, two days after the change, the postings all stop as people become accustomed to the new interface, realize that everything they've been used to is still there though perhaps in a different place, and that the new interface really isn't so bad after all. Everything is once again fine in the Facebook world until the next time they make a change, at which time people will lose their minds once again – because Facebook has changed away from the interface they complained so bitterly about the last time.

Ever notice that the people that complain the most about the Facebook changes are those who update their status fifteen times a day and are the least likely people to leave Facebook? Facebook knows this, which is another reason they don't worry about the complaints. I'm not making judgements about people who are on Facebook a lot – I am quite active on Facebook myself, as well as Twitter, and I have my own blog fer cryin' out loud, so I'm not about to criticize others for wasting spending a lot of time online.

Regarding the "If it ain't broke, don't fix it" – do you really want Facebook to keep the same interface and features forever? That's not the way the software industry works. We software engineers are always looking for ways to make our product better. Sometimes this comes from adding features that have been requested by customers, other times it's stuff we come up with ourselves. (Make a note of that word "customer" – I'll get back to that in a minute.) Facebook engineers are no different – they want to improve the customer experience. Their problem is that many people are using Facebook twenty times a day and become accustomed to how it looks and how to do things. When that changes, people are suddenly uncomfortable with something that they've been comfortable with for a long time. The fact that they have seven hundred million users also guarantees that no matter what change they make, millions of people won't like it, and we all know that people who don't like something are more likely to comment on it than those who do. How many postings did you see talking about the Facebook changes and how great they were?

Does Facebook have privacy problems? Sure they do. I used to know exactly what the defaults were and how all of that worked, but Facebook has added new features and changed things often enough that now I don't know what happens by default. I have found in the past that once you change your security settings to be something different from the default, new features tend to be off or more private by default, while if you have never touched your settings, everything's wide open by default. I don't know if it's still that way and that topic is beyond the scope of this article. I did want to mention it to acknowledge that Facebook is not perfect – for those people who read this article and think I'm some kind of Facebook fanboy who would never say anything negative about them.

You will never pay for it

Another rumour that I've seen a bunch of times is that Facebook is soon going to start charging people to use the site. I can guarantee you that these are rumours are false. Facebook will always be free. You will never need to worry about paying Facebook anything as a customer. Why? Because you're not the customer. Facebook is not in the business of building a social network, they are in the business of selling advertising. They built a social network in order to attract people to their website, and they sell those pageviews to advertisers. You are the product Facebook sells. They make far more money selling advertising than they would charging people to use their web site, since they know that a large percentage of the well over half a billion users they have would not pay for the service. Classmates.com never understood this.

So don't worry about rearranging your finances to have an extra few bucks a month for Facebook, and don't worry about how you are going to keep in touch with your friends in Texas or Scotland or Italy or Japan without Facebook. Will it be around forever? Who knows. But it's the most popular web site in the world right now, I don't see it going away any time soon, and you'll never have to pay for it.

Wednesday, June 01, 2011

Parental Control Software and Big Boobs

My kids (ages 11 and 9) are getting more and more familiar with the internet, and enjoy spending time on the computer. Mainly they play games and watch funny YouTube videos ("Simon's Cat" is their favourite), but a few times Ryan has mentioned facebook and chat rooms and instant messaging and such, and they are both heavily into a game called Minecraft, which is all the rage these days. They have gone to message boards and watched videos on how to mod the games, and recently Nicky wanted help in downloading a mod which required modifying .jar files. There's enough scary stuff on the internet that I'm getting less and less comfortable with them just perusing at their leisure, so I looked into various parental control software packages.

Step one was made a couple of years ago and was amazingly simple. I set up a free account on OpenDNS.com and changed my router to use it for DNS rather than my ISP. Not only is it faster, but they have controls that filter various categories, so I selected things like porn, nudity, adware, dating, gambling, hate, and a few others. It doesn't mean that it's impossible to get to these sites, just that if you try to get to bigboobs.com, the DNS server will simply not tell you where it is. (bigboobs.com is just an example I grabbed chose at random. Not surprisingly, it turns out to be a real web site.) The DNS setting is done on the router, which means it applies not only to the computers, but the Wii, Ryan's iPod Touch, and anything else we add in the future. That was a very easy first step and blocks a fair bit of the stuff I don't need my kids seeing. As part of research for this article I actually went to bigboobs.com to make sure OpenDNS was blocking it. It wasn't, so I had to fix my OpenDNS settings. I guess I will have to visit bigboobs.com periodically from now on, just to make sure everything is still working. With OpenDNS, I mean.

Step two has been ongoing for a while, though it seems to be at least temporarily solved. I'm looking for a software package that will allow me to monitor and limit my kids internet usage. I first tried a free solution from Blue Coat Software called K9 Web Protection. It looked pretty good, but I couldn't make it work at all. I installed it, rebooted the machine, and got nothing. I wasn't able to connect to the internet at all, and every time I tried to run the administrative program, it crashed. During the uninstall procedure, it brought up a window and asked me why I was uninstalling, so I told them. To their credit, a Blue Coat support guy responded via email within a day or two and sent me a newer version to try. It had the same problem only this time when I uninstalled it and replied to the original email, I got no response. Strike one.

The next one I tried was Kidswatch. I installed the trial version and it seemed pretty extensive. It allows you to limit exactly what times you are allowed to log on to the machine, what times you are allowed to use the internet, what web sites are blocked, what types of web sites are blocked (i.e. social media, online shopping, etc.), all kinds of stuff like that. The list of options is actually pretty impressive. It can also send you daily or weekly email reports of internet usage – which web sites were visited, how long was spent on each of them, stuff like that. It can send you immediate emails if a site is blocked or certain keywords are found on web sites, chat rooms, or IM sessions. This sounds great, but I started getting false positive reports all over the place - unless Ryan is doing google searches for "Megan Fox boobs" while sitting right next to me. It reported that he went to facebook when he didn't, it reported all kinds of other web sites he didn't visit and searches he didn't perform. It ended up being more trouble than it was worth.

I had been using the free trial of Kidswatch for a week or two, not sure yet whether I wanted to buy it or not. It's not that expensive – $45 allows you to install the software on up to three computers. But then I got an email saying "we've noticed you've downloaded our software but haven't bought it. If you use this code, we'll give you a $10 discount". I know this is standard practice in many industries, but it seemed backwards to me -- if I had originally been thrilled with the software and had bought it right away, I wouldn't get the discount? It's the same with banks – the loyal long-time customers who never consider switching banks pay the highest mortgage rates, while the people who threaten to move to another bank pay less. That doesn't seem fair to your best customers. Anyway, I didn't end up buying it because of all the false positives. Strike two.

There's another package called NetNanny which is supposed to be good, but I haven't looked at it. It's the most expensive though - $40 per PC. I was almost ready to install this one when I asked around on Twitter and someone said that they were "just using the free Microsoft one". I didn't know there was such a thing, but there is – Windows Live Family Safety.

Vista and Windows 7 have parental controls built in, so you can limit when you can log in to particular user accounts as well as the total amount of time they are logged in per day or week. This package adds more stuff, allowing you to set up multiple computers to have the same limits, modify these limits from anywhere, as well as adding web filtering (general categories as well as specific sites), game and program restrictions (eg. I have Skype and the webcam software blocked) and contact management if your kid uses Windows Live. It can monitor IM activity if you use MSN Messenger, but not other IM software. It would be nice if you could allow the child to log onto the computer at certain times but not use the internet, but that doesn't seem to be an option. You also can't combine the time restrictions with the web restrictions, so you can't say "Allow minecraft.net on weekends but not Monday-Friday".

So this is what we've been using for a few months, and it's pretty good. If I run into problems with the Windows Live stuff or I need more functionality than it provides I may give NetNanny a try, but I'd want it on at least two computers, and I'm going to have to be damned sure that it's going to do what I want before I spend $80 on it.

Friday, May 20, 2011

Macs suck too

If you're a Windows user who has ever been infected by malware, and you've posted about it on facebook, twitter, or a blog, some Apple fan-boi has likely told you "That wouldn't have happened if you used a Mac!" There is some truth to that, but the implication that Macs are inherently safer or more secure than Windows machines is simply false.

Please don't take any of this as a rant against Apple in general or Macs specifically, or believe that I think Windows is far safer than Mac OS X. I don't own a Mac, but I love my several-year-old iPod as well as my son's iPod Touch (way more than my wife's Walkman). I've used Macs a number of times in the past few years and damn, they're slick. Apple has by far the best visual design team in the world – things generally just work the way you expect them to and in some cases, even better.

I'm primarily a Windows developer, and I've written tons of software for Windows over the last twenty years. I am slightly less experienced when it comes to Macs, but I have plenty of experience on other unixes, and modern Macs aren't that different. I have done some Mac work in recent years, and in my previous job I worked on NeXTStep, which was essentially the predecessor to Mac OS X. If you're comparing the unix systems of the 90's with Windows 95 or 98, then yes, you can certainly say that the Windows operating system itself is less secure, because security just wasn't a consideration when those systems were created. Unix was built from the beginning to be a multi-user operating system, and so there had to be separation between different users on the same machine, and between normal uses and super users. But Windows was designed to be a single-user OS, so the assumption was that you were doing everything, and since this is your machine, you should have access to everything. Multiple users, administrative privileges, and even things like file permissions were added later and for a while, there were lots of things that just didn't support these features very well. But over the years, more and more software was changed to use the new security features, and Microsoft gradually deprecated and then completely disabled the old insecure methods of doing things. I know we at Sybase had to make changes to our software to deal with security-related changes when new versions of Windows were released.

Right now, when it comes to spyware, viruses, worms, or things like that, I can't really argue the fact that if you are using a Mac, you are less likely to get infected than if you are using a Windows machine. But the reasons for that have nothing to do with how safe the operating system is. There are two primary reasons:

  1. Macs are simply less popular than Windows. This doesn't mean that they're inferior, but if you look at market share, Windows machines make up almost 90% of all the machines out there. If you're going to write a virus that will take over a machine for use in your botnet or have it scan a machine and send you somebody's credit card information, why would you write your virus specifically for a computer that only 5% of all computers are running? You'd write it so that it could infect as many people as possible, and that means Windows. I know of no viruses (virii?) that affect the BeOS operating system, but is that because it's completely secure? No, it's because nobody uses it.
  2. Mac users are generally more computer-savvy than Windows users. We all have a brother or cousin or mom or Aunt Helen who knows nothing about computers but has one just for email and browsing facebook (and installing fifty browser toolbars). How many of those people own Macs?

Every year at the CanSecWest computer security show in Vancouver, they have a contest called "Pwn2Own" where contestants try to find and exploit security vulnerabilities in various pieces of software (usually browsers) on various platforms. The winner wins the hardware they broke (hence "Own" in the name) as well as cash. The contest began in 2007, and the only platform broken that year was the Mac, though it looks like it was a Mac-only thing at the time. Every year since, it's definitely been a multi-platform contest, and every year (2008, 2009, 2010, 2011) the Mac is one of the first platforms cracked. In 2011, it took five seconds. It shouldn't be surprising that Apple software developers are just as likely to write buggy software as the rest of us.

As the platform becomes more and more popular, people are indeed beginning to write viruses for the Mac. This one ironically poses as anti-malware software in order to get people to install it, just as many Windows malware programs do. This might be a good time to remind people that a web page cannot detect viruses on your computer. If you see a banner on a web site saying that your computer is infected (or your computer isn't running as fast as it could) and you should click here to install something that will fix it, they are lying.

I find it ironic that Mac people keep advising their friends to get Macs in order to be safer. If people keep doing this, two things will happen: Apple's market share will increase, and more and more non-techies will be using Macs. This will make Macs a bigger target, and more malware will end up being written for Macs. The act of telling people to use Macs for safety is actually making them less safe. So if you're an Apple person who's constantly telling all your friends that they should be using a Mac, it's really in your own best interest to shut the hell up.

Tuesday, April 12, 2011

Cloud computing is like groovy, man

I downloaded a package from sourceforge.net this morning and saw an advertisement for a whitepaper from IBM on cloud computing. This line in the ad intrigued me:

CloudComputing

I wonder what kinds of cloud computing initiatives IBM was working on in 1971, when TCP/IP (the protocol used by the internet) hadn't been invented yet?

Thursday, March 10, 2011

Bye Bye Bell

During a recent conversation at work, a colleague (John) mentioned that his phone bills are usually under $10/month. I thought about our $60+ phone bills (not including mobile) and asked how on earth that was possible. He said that he uses VOIP and not only does he pay almost nothing, but he gets more features than Bell supplies. Again I asked how, and he pointed me at voip.ms. After a little research, I decided to try it out. It's working now, but getting everything working was far from simple.

VOIP, for those of you who don't know, is short for Voice Over IP, which basically means your telephone service is provided over your internet connection. As long as you have broadband always-on internet service, you can use it to provide telephone service as well. In my case, I pay $1.99 per phone number and then 0.5¢ per minute per call (both incoming and outgoing). Note that there are no long distance charges, so a call to friends around the corner costs the same as calling the other side of the country – but a one-hour call costs all of 30¢.

To make this work, I first needed to sign up for a voip.ms account. This was free and very easy. Then you need something to convert your phone signals into internet traffic; in my case I bought an analog telephone adapter (ATA) from Linksys. My research for this purchase was not exactly extensive – it consisted entirely of asking John which one he bought, and then buying the same one. I plugged the device into my router and then plugged a phone into the adapter. Guess what? No dial tone. This made sense, since I hadn't told the adapter how to get to the voip.ms server, nor did it have a phone number for me to use, which means that I have some configuring to do.

(Attention technophobes – you might want to skip this paragraph.) The adapter supports both a web interface and a phone interface. The phone interface is minimal and cumbersome - I had to pick up the phone and dial * four times and that gave me a voice menu. The menu options (not many of them) are listed in the manual and everything seemed very cryptic. Luckily there is also a web-based interface, which would make life a lot easier, but getting that enabled was a bit of work as well. The adapter had already been assigned an IP address by DHCP, but to get the VOIP stuff working, I had to open ports in the firewall which requires a static IP address. I entered a key sequence to disable DHCP and another to assign a static IP address, and then another to enable the web interface. Then I hung up and went to the IP address in a browser. Success! Now I could modify all the settings. Except that there were a zillion different settings, each with meaningless (to me) acronyms, and I didn't know what the settings were supposed to be.

The web interface was orders of magnitude easier than the phone interface, but even so, you'd be lost without a good knowledge of telephony terminology. Unfortunately, I don't have such knowledge. I eventually found a description of how to configure my particular device on the voip.ms page. Once that was done, things should have worked, in theory. To test it out, I ordered a new phone number (what they call a "DID") from voip.ms, which cost me $1.99 / month. It gave me a Waterdown number (area code 289) instantly, and I was able to make outgoing calls. Incoming calls required a little more configuration but with more help from John, I soon had that working. I then started the process of moving my existing phone number over from Bell, and a week and $25 later, that was done. I cancelled the temporary number, physically disconnected the Bell line, and away we went.

Cool options available with voip.ms:

  • You can set the name and number for call display. For example, when I call someone, I can set it so that their phone displays 867-5309 and "Jenny".
  • I get emailed every time someone leaves a voicemail. A .wav file is attached containing the message. When I dial the number to get my voicemail from home, I don't need to enter a PIN.
  • I can set up a dialing rule so that I don't need to dial '905' for local calls.
  • If there is no answer (after a time period that I choose), I can:
    • go to voicemail
    • forward the call to another number (for example, my cell phone)
    • play a recording
    • give a busy signal
    • hang up
    • give a "this number is not in service" message
    • give a "this number has been disconnected" message
    • do nothing
  • If the line is busy, I can choose any of the above options as well, and it doesn't have to be the same as if there's no answer.
  • I can set up any number of phone numbers that all ring on my phone. These numbers can be anywhere in North America, and it would be a local call for people there. For example, I can set up a phone number in Huntsville (for $1.99/month) that my parents and Gail's dad could call locally, and it would ring here. Nobody would pay long distance for that call.
  • I can have the ring sound different depending on who's calling or what number they dialled. In theory. John tried this, however, and couldn't get it to work.
  • I can add numbers into my local address book for speed dial on any phone. If they call me, I can set the name that's displayed. This is handy, for example, because our cell phones always show up as "Unknown name" and the boys don't answer the phone unless they recognize the name. (They haven't memorized our cell numbers yet.) So I added our numbers to the address book and now my cell comes up as "Graeme cell".
  • I can set up multiple mailboxes and a "digital receptionist". For example, I can say "Press 1 to leave a message for Graeme, 2 for Gail, 3 for Ryan, and 4 for Nicky".
  • I can put calls into a calling queue, complete with hold music. "Your call is important to us, and is being held in priority sequence. Please hold for the first available Perrow family member."
  • I can set up a "ring group" so that when a call comes in, both my home phone and my cell phone ring, and the first one to answer get it.
  • I can make rules for specific numbers, so that telemarketers get the "This number has been disconnected" message, or some go straight to voicemail without ringing the phone.
  • I can do almost anything above differently based on time of day. For example, I could say that between 11pm and 7am, only ring twice before going to voicemail, otherwise ring 5 times.
  • I can get a complete list of every incoming and outgoing call, and how long it was. There are a number of graphs available, showing things like call lengths and total cost.
  • 911 works, although it does not automatically forward our street address to the 911 operator. It also costs $1.99 / month extra.
  • Other than 911, all of the above options are free included in the price.

Drawbacks:

  • The 911 thing I mentioned. It works, but we have to tell the operator our address. Not a big deal.
  • No call waiting, but I don't care. We didn't have it for many years and only added it recently. I don't remember why we even added it - we usually just let the second call go to voicemail.
  • If we're doing a lot of internet stuff, like the boys are watching YouTube videos or I'm watching a lacrosse game, call quality could drop. John said he's noticed this a few times but not often.

As I said, it was non-trivial to get everything set up, and the ATA device cost about $60, and moving the phone number cost $25. But if I end up with $10 monthly phone bills rather than $60+, those extra costs get covered pretty quickly. We've only been live for four days, but I have not noticed any drop in voice quality. And if nothing else, damn it's cool.

Monday, October 18, 2010

The Guild

While listening to Wil Wheaton's podcast a few months ago, he played an interview he did with Felicia Day, creator, writer, and star of The Guild, a web comedy series (a TV show but only available on the web). I had never heard of The Guild, but Wil did a number of guest appearances on it and kept talking about how great it was, so I thought I'd give it a try. The Guild is undoubtedly one of the funniest shows I've ever seen, on or off TV. The writing is brilliant, the characters are hilarious, and there are even shocking plot twists and cliffhanger moments that make you look forward to Tuesdays. Each episode is only 6-8 minutes long, and a new episode is released every Tuesday. A "season" lasts for about 12 weeks and season four just finished last week. I started watching The Guild when I was off work, so I managed to catch up with all of seasons 1 through 3 in a couple of days, and during season 4 I tried to watch it every Tuesday night.

The Guild is about a group of six people who play some kind of online game, similar to World of Warcraft (which I've never played). Note that you don't need to know anything about gaming (I don't) to enjoy the show. The game has taken over their lives and they even use each other's game character names when talking in real life. In fact, of the six of them, I only know the real name of one of them – Clara, because her character name is also Clara. Oh wait, Bladezz's name is Simon but even his sister calls him Bladezz. The other characters (except Tink, I believe) have had their real names mentioned, but only a couple of times. The main six characters are part of a guild known as The Knights of Good, meaning that they play together as a group and fight against other guilds. The guild members are:

  • Codex is the main character, played by Felicia Day. She's a single woman who's very insecure and always concerned with what the other guild members think of her.
  • Zaboo is a young man of Indian descent who is good with computers but has no social skills whatsoever. (When he moves in with Vork, Vork tells him, "Men only shower together when there's more than one shower.") He lived with his very controlling mother until season 3 when he moved in with Vork.
  • Vork is a 40-something balding guy who is extremely cheap and follows rules to the letter. He's the leader of the guild.
  • Tinkerballa (known as Tink) is a bit of a mystery. I believe she's a med or pre-med student, though her personal life is pretty much off-limits to the other guild members. I don't think they even know her real name. Tink is beautiful and not only is she well aware of this, she uses it to her advantage whenever possible.
  • Clara is a stay-at-home mother of three (or two, depending on the season – one seems to have vanished) very young children, who she routinely ignores while playing the game. Her husband, George aka Mr. Wiggly (named after.... um, never mind) once joined the guild temporarily but was completely inept at the game.
  • Bladezz is a high school student who works at a local burger joint, "Cheesybeards". Bladezz is always making off-colour sexual comments and was described in a recent episode as "skeevey". Good word.

The Axis of Anarchy is another guild that the Knights of Good are constantly battling with. Their leader is Fawkes, who has a strange love/hate relationship with Codex. Fawkes always has this little "I'm smarter than you but I suppose I can bring myself down to your level" smirk on his face when he's talking to someone. Fawkes is played by Wil Wheaton, who does a great job of playing an evil yet oddly charming douchebag.

When I first started watching it, I assumed that it was done as a web series because it wasn't good enough to be picked up by one of the big networks. <sarcasm>Because you know, the sitcoms that are shown on the big networks are all really good. cough $#*! My Dad Says cough</sarcasm> But it looks as "professional" as any network sitcom, the actors are all really good, and as I said before it's very funny. If it were a network show, they'd have to expand it to 22 minutes per episode, and tripling the length of each episode would likely water it down too much. Having a "live studio audience" watching the taping of each episode would not make the show any better, and God help Felicia Day if she were to add a laugh-track.

Being an internet-based show aimed at geeks, it is a little surprising that the website for The Guild is so confusing. If I were to design it, I'd have a page for each season and links to each episode in that season all in one place, so it's easy to find episodes. There is a blog that has a page for each episode, but that bumps you off to Bing where the episodes are hosted. Once you're there it's not easy to find other episodes – the "related videos" on the right seems to be a random assortment of episodes from all the seasons. One page I went to (season 4 episode 10) had a link to season 4 episode 5 instead so I had to start poking around until I found the right episode. From the time I started looking to the time I was actually watching the right episode was at least five minutes – should be a matter of seconds.

But being an internet-based show aimed at geeks, it is not particularly surprising that there is a fan podcast for The Guild. It's called Knights of the Guild and features a guy named Kenny who is a member of the crew, though he hasn't mentioned (in the few podcasts I've listened to) exactly what he does. After every episode, he does a "companioncast" during which he interviews many cast and crew members and talks about that episode. This is recorded right after the episode was filmed, which is months before it actually airs. Most of these interviews are pretty interesting, though some are kind of Chris Farley-esque. "Remember when <event> happened? That was soooooo funny" isn't much of an interview question. It does seem a little weird to have a 90+ minute podcast about a 7-minute episode, but whatever, it's fun.

I suppose The Guild is not for everybody, but I think a lot of internet geeks like myself (I have a blog, I use twitter, and I use terms like "epic FAIL") would love it. As I said, you don't need to be a gamer (or even a geek) to like the show, but if you're a gamer or a geek, give it a try at watchtheguild.com.