Font Size: A A A   Layout: Left | Right

greg hughes - dot net

Security, IT and anything else that matters... to me, that is



Saturday, February 02, 2008 2:53:08 PM (Pacific Standard Time, UTC-08:00) ( Random Stuff )

Some people I know who live in the city (Portland, Oregon that is) don't always "get it" when I tell them we sometimes get lots of snow out where I live. If it snows down in Portland even just a little bit, the place just shuts down. It's fairly ridiculous, heh. I suppose since I live relatively close, people just have a hard time imagining any significant snow in the vicinity. But it's all about the elevation.

Out my way you have to drive in the ice and snow, that's just the way it is. I grew up in northern New Mexico doing just that. Now, we do get snowed in up here sometimes, between the amount of snow and the wetness of it all on the steep hills. While we're nowhere near snowed in this weekend, it has dumped a fair bit since the sun came up this morning. Well, more like since it got light outside this morning... We're certainly not seeing any direct sunlight today. We've had similar (or deeper) snowfalls several times here in the past month.

IMG_2118

IMG_2121


Saturday, February 02, 2008 11:07:35 AM (Pacific Standard Time, UTC-08:00) ( Tech )

From the LiteOn people comes a great design for a mouse that I will gladly plunk down a few  bucks for if it ever makes it to the market. It received a RedDot Design Award, in fact. Here's hoping it finds a place in the real world.

mice2The Moldable mouse can be shaped into pretty much whatever form you like. Goodbye RSI and Carpal Tunnel Syndrome? Just change the shape now and then. We can hope!

Moldable Mouse is made of non-toxic lightweight modeling clay, covered with nylon and polyurethane blend fabric. It can be kneaded into any shape the user prefers, and the shape is self-retaining. By allowing a wide variety of hand positions when holding the mouse, it reduces repeated motions of the same posture, thereby minimizing the chance of common mouse-related injuries such as the Carpal Tunnel Syndrome. The click buttons and touch-sensitive scroll pad of the mouse are stick-on parts with built-in RFID (Radio Frequency Identification Device), which can be repositioned for maximum comfort.

The nylon and polyurethane blend fabric covering comes in a variety of colors. The texture of the material feels similar to silk, but is much more flexible. Its softness significantly increases the comfort level of the mouse over that of the traditional plastic versions. Patterns and graphics can be printed on the fabric to make the Moldable Mouse more visually appealing. The base of the mouse, made of 100% recyclable PC/ABS plastic blend, houses the PCB (Printed Circuit Board), laser optics and batteries. Reducing plastic usage to a minimum by using mostly non-toxic clay and fabric, the Moldable Mouse is also an ecologically responsible product.

(via Engadget, via Wired)


Friday, February 01, 2008 8:10:50 PM (Pacific Standard Time, UTC-08:00) ( Tech )

microsoft_yahoo The move Microsoft made this morning in publicly offering Yahoo! shareholders a pretty darned decent price per share to acquire the company was a fairly aggressive one, and honestly I've wondered for some time - along with everyone else - when someone would finally make the move. It just makes sense. With the announcement earlier this week by Yahoo! of it's financials and planned layoffs, the timing was about as perfect as it could get.

Everyone and their brother has blogged and commented on this, and I won't waste your time or mine telling you what I think (although I am interested in and have been thinking about the whole "how do you combine CardSpace and OpenID?" question, and there are some obvious and potentially very good answers to that one). Instead, I just wanted to point you to a well-written and (I think) good analysis by a few industry experts that was published today on betanews.com. I suggest you read it if - like me - you are at all interested in the deal and what it means.


Wednesday, January 30, 2008 7:46:31 PM (Pacific Standard Time, UTC-08:00) ( IT Security | Safe Computing | Tech )

Yahoo OpenID (click for the site) Today came an announcement that represents a pretty big step in the identity space. Yahoo! announced they have rolled out beta support for OpenID v2.0 and that Yahoo! is now a provider of OpenIDs. In fact, anyone who has a Yahoo! account can quickly generate a Yahoo! or Flickr-branded OpenID to sign onto any web site that supports OpenID v2.0 for authentication. That's 248 million accounts at Yahoo! that can now potentially be leveraged across the Internet for sign-on.

OpenID is an important standard that came out of the open-source community, which will likely change the way we provide identifying information and gain access to secured web sites on the Internet. It allows its users to have a single identity that can be used across different sites on the Internet. It also allows users to have the proper level of control over how they identify themselves and who they want to trust with that process.

One significant key to success for OpenID as a standard is adoption by a set of trusted identity "providers" - or OpenID-issuing organizations that people are comfortable with when it comes to asserting their identity information. With Yahoo! a large number of regular, everyday people can use their existing accounts to perform OpenID logins on any site supporting the standard. In the future, the hope is that other consumer-trusted providers will see the value of brand recognition that goes along with being the OpenID provider for consumers. Yahoo has me as an OpenID client now, which means every time I log onto an OpenID-enabled site and use that ID, I am by default thinking on some level about Yahoo! -- Pretty smart. It's time for banks, other financial service providers, and similar industries to seriously start thinking this one through. It's coming, and now is the time to be on the bandwagon.

Where can you use your OpenID to log in? Lots of places. There's a list of web sites over at myopenid.com, a service provided by Portland company JanRain. The people at JanRain have created some great software and services around the OpenID standard that businesses can use to leverage OpenID, and that enable social networks around the standard. It's pretty cool stuff.

Here's some basic information about OpenID from the Yahoo! OpenID provider site:

What is OpenID?

In a nutshell, the OpenID technology makes life simpler by having only one username and password to remember.

Once you have enabled your Yahoo! account for OpenID access, you only need to remember your Yahoo! ID and password to use hundreds of websites... So bid farewell to password spreadsheets and stickies all over your desk!

When you are on a web site that supports OpenID login, simply look for a Yahoo! login button. Or if you see a text box with an OpenID icon, simply type in "yahoo.com". You will be sent to Yahoo! to verify your Yahoo! ID and password, and then you will be able to continue on.

You can find out even more at openid.net (the OpenID Foundation), and it's worth pointing out that you can also get an OpenID from a slew of other organizations - after all, it's all about making it your choice. The OpenID foundation keeps a list of providers on its wiki and at this link.


Wednesday, January 30, 2008 8:22:19 AM (Pacific Standard Time, UTC-08:00) ( Humor | Random Stuff )

Via Jake at UtterlyBoring.com, the latest in the "Will it Blend?" series is here. Don't mess with Chuck Norris:

    

You'll find a bunch of humorous blender commercials at http://www.willitblend.com/. You can also buy the blenders there.


Tuesday, January 29, 2008 1:56:55 PM (Pacific Standard Time, UTC-08:00) ( Random Stuff )

Here's another "what's my brain doing to me?" piece of weirdness for you to try...

While sitting at your desk, lift your right foot off the floor and make clockwise circles. Now, while doing this draw the number 6 in the air with your right hand. Your foot will change direction and there’s nothing you can do about it. 

Reads: “While sitting at your desk, lift your right foot off the floor and make clockwise circles. Now, while doing this draw the number “6″ in the air with your right hand. Your foot will change direction and there’s nothing you can do about it.”

Hmmm. If you keep trying can you eventually overcome the natural tendency to change directions? I can't seem to do that.

(via Fitz and Digg)


Wednesday, January 23, 2008 3:21:31 PM (Pacific Standard Time, UTC-08:00) ( Tech )

I'm going to go off on a bit of a (somewhat grumpy) lecture here in hopes that people will stop long enough to listen. A little Gestalt therapy, if you will. Ultimately I hope at least one person recognizes a need and acts on it.

If I had a dime for every time I have personally seen this one issue bite someone in the backside, I'd be a rich man. There are a zillion things that can go wrong on a mission-critical network, but of those things there are actually just a few that account for a substantial portion of the issues that typically bring critical services down.

So, if you run a network and have not addressed the one issue I will describe below, please take the time out of your day to start a plan to remediate the problem ASAP. Along the same lines, if you are not sure where you stand with regard to the issue, or if you have never checked but you feel confident because everything works today and always has so it can't possibly be an issue... Again, please just take the time to inspect your infrastructure and put a plan in place.

I should also say that if I had a dime for every time I've said exactly what you just read in the paragraph above, I'd be a rich man. I lost count long, long ago of the number of hours spent watching people try to avoid - in any way possible - checking the obvious and addressing it. Usually that's due to those egg-on-face concerns that go along with being they guy who missed something so simple and critical (albeit not too obvious) when it came time to learn the detailed intricacies of running a high-availability network.

Okay, enough with the harshness. Time for the issue at hand.

The number one network mistake I have seen people make on IP networks, over and over again, is using the default settings on their switches and servers that cause the network interfaces to auto-negotiate the speed and duplex settings.

Seriously, if your requirement is to provide high availability and your SLAs require your services be up, do not neglect the critical (but often skipped) process of manually configuring your NICs and switches to the proper setting. Just because the interface says it's running 100mbps and full-duplex doesn't mean it's working, and when your network takes a dive and you start losing packets you'll be sorry.

Along the same lines, never assume that one half of one percent of packet loss is no big deal. Seriously, if you are seeing retransmits on your network interfaces, something is likely wrong. Also, chances are that .5% loss is not being scattered evenly across your traffic. It may all be happening at once in bursts, and that hurts - a lot.

Again, if I had a dime for every time I (or someone working with me) recommended inspecting the interface settings, recommended changing them, and flagged interfaces where traffic analysis showed data transmission loss that was obviously causing network apps to fail... Well, let's just say it's amazing how hard it is to convince some people that their network is the cause of the issue.

Why am I being so blatantly blunt about this? Because I hope that the message will carry, that administrator egos will be set aside, and that people will understand that the real-world evidence based on years of actual experience, proven over and over again, bears out the fact that this will eventually happen to you if you have not already taken the steps to ensure it doesn't. Don't let that happen. Protect that ego now, rather than waiting for it to be damaged.

Finally, don't fall prey to the idea that just because you have high-grade HP, IBM and Dell Servers and Cisco switches that the money you (smartly) spent negates the need to set things up the right way, or that these vendors have everything figured out for you and set as defaults. Point of fact, this issue occurs just as often (if not even more so) with your expensive, data-center class hardware. In fact, Cisco switches have been somewhat famous for requiring intervention of the manual-configuration type. They even have a troubleshooting support article here that you can refer to for your configuration needs.

You have been advised. Now go do something about it. And forward this to every network administrator you know. The network (and ego) you save may be theirs. :)


Wednesday, January 23, 2008 12:38:52 PM (Pacific Standard Time, UTC-08:00) ( Tech )

sharedview1 I recently set up a Windows Live Workspace beta site, and while doing that I saw a program that I had not realized was available before, called SharedView. It's a program that is currently in beta (the release number as of this writing is beta 2), and it's a simple and effective app that lets you share your desktop or applications with someone else and lets the participants grant control of their computer desktop to others in the session. It's integrated into the Office Live Workspaces for collaboration purposes, but it's usable for a variety of purposes.

I didn't download the program immediately, but was intrigued by what Microsoft had put together. Then, as fate would have it, the next day my mom sent me a IM via my mobile device (she sharedview3really is pretty tech-hip for a retiree, heh), telling me she had a little computer problem and needed some help. In the past we've tried to use remote desktop services and the help-request functions in the MSN/Live IM client, but firewalls always seem to get in the way and performance has tended to be lackluster. Anyhow, in the process of trying to solve the computer issue, it  often becomes too complicated to try to solve it via text messages, so in this case I hooked up my laptop, downloaded the SharedView client and set up a SharedView session with my LiveID account and pointed her to the download so she could join the session using my email address and a passcode.

Within a few short minutes she was online and in the SharedView session and I was able to see her desktop. I liked that I was able to point to things on her desktop and she could see what I was pointing at, without having to take control away (this feature is called Personal Mouse Pointers). Nice feature. When it became necessary, she easily (and intuitively, without specific instructions from me) granted me control and watched as I walked her through the fix, explaining it along the way. Several times I handed control back to her so she could do part of the tasks.

In the recent past I've paid for similar services from other companies that also work well. Some of them don't rely on an installed program like this one does, but the SharedView app download is small and simple and works well on sharedview4 either Windows XP SP2 or Vista. I'd like to see it offered as a click-once app to easy use (at least as an option, if this type of app can even be deployed that way).

One of the great tests of success in today's software utility market is usability. One way I gauge the usability of an app is via watching my mom use it. If she can pick it up without much prompting, it generally passes. If she can't figure it out, chances are others can't either, and so it fails. SharedView met the expectations of that litmus test. Another great example of meeting the usability requirements and needs of the average user is Windows Home Server, which I started using in my own home not too long ago and about which I have written a couple times. There's some true-quality stuff coming out of Redmond right now for the average user, and that's good to see.


Friday, January 18, 2008 2:45:22 PM (Pacific Standard Time, UTC-08:00) ( Personal Stories | Random Stuff )

bolts-pats Over the past year I have become more and more aware of the value of doing some of those things that I've always wanted to do, yet have never quite gotten myself to execute on. I certainly have my limits, but I've worked to push myself a bit and to welcome this likely-midlife-crisis with open arms -- just jump right in and live a little. What the heck, eh?

So, this weekend I'm flying with a friend to Boston and we're going to the playoff game between the Chargers and the Patriots for the AFC championship. A couple lucky tickets combined with frequent flier and hotel credits make for a cheap relatively affordable weekend of fun. We were darned lucky to be able to line it all up last minute with flights and rooms available purchased with mileage credit, etc. The idea didn't even cross my mind until right after the Chargers beat the Colts last weekend.

For those not intimately acquainted with American Football, the winner of the game we're going to will play the winner of the NFC championship imagegame in the Superbowl in a couple weeks. the Patriots are undefeated this year, and I certainly hope San Diego shows up and makes it a fun game to be at.

The temperatures in the Boston area Sunday are supposed to be in the teens or lower 20's (Fahrenheit), but hey it could be a lot worse. The NFC championship is being played in Green Bay, Wisconsin (Packers vs. the Giants) and the temperatures there are supposed to be considerably lower, with a wind-chill in the hell-frozen-over range. ESPN has a great article on cold-weather football with lots of good trivia for anyone interested.

And before you ask... No, I'm not going to spend the incredible amount of money it takes to go to the Superbowl these days. That's why they make HDTV. :)


Thursday, January 17, 2008 7:10:11 PM (Pacific Standard Time, UTC-08:00) ( Tech )

widows_home_server_logoWow, I sure have been making use of my HP MediaSmart Windows Home Server since I acquired it late last year, and to be honest I have not really even scratched the surface. With 64-bit client support coming soon, I am excited about the future, too.

After working with a bunch of music, video and image files over the past few weeks, not to mention computer backups, the single 500GB drive that it came with is both a little small and represents a single point of failure that I realized I don't want to take a chance on. So, I logged onto newegg.com last weekend and ordered a 1TB Western Digital SATA2 hard drive at a great price. It arrived today,and I slapped it into one of the three open trays and slid it into the slot. Within half a minute the drive showed up in the Home Server console and I was able to add it to the storage with a couple clicks and a two minute waiting time:

OneTerabyteAdditionHomeServer

What a slick and fool-proof process they've come up for adding drives in Windows Home Server. Anyone can do it. It's great stuff, and the add-on community is thriving - There's a whole slew of community-created programs that you can install on your home server to add functionality. It's quite useful and a lot of geeky fun.

With the addition of community programs and the overhead of the additional HP software, the memory's a bit short. So I have a 2GB sick of RAM sitting on my desk, wait for me to decide if warranty risks of taking it apart to beef up the RAM are worth it. Do I dare?


Tuesday, January 15, 2008 7:16:41 PM (Pacific Standard Time, UTC-08:00) ( Mobile | Tech )

image Well, it's finally happened. Apple has released iTunes v7.6.0.29 along with the iPhone v1.3 software, adding support for syncing with 64-bit Windows Vista in this new version. So, I have updated the iPhone (and lost my custom apps at least for now as a result) and am a happy camper. Relying on the aging Mac Mini desktop to sync was not working well for me. Now I can sync to my notebook.

Apple plans to introduce formal support for third-party apps through their own developer program next month, so I will happily wait a little while and hope for my couple of apps that I liked (especially the iFlix NetFlix manager app, one of my recent favorites).

There are some great enhancements, especially in the Google Maps application. Check out some of the new capabilities here in a Apple video tour of the January '08 update.

I left my iPhone at home one day last week when I drove to Portland for a day of jury duty followed by time trying to meet up with other people I know. I didn't notice until I was halfway to the city that I had forgotten it, so it was too late to go back and get it. All afternoon I realized how much I rely on my phone for regular daily stuff and how much others rely on my having it with me, as well.

Now I just have to sync up my purchased stuff from the iTunes Store and get the Audible account moved over. After that, I'm golden!


Friday, January 04, 2008 10:26:31 AM (Pacific Standard Time, UTC-08:00) ( Home Servers | Tech )

I wrote before about my new HP MediaSmart Home Server, as well as the fact that there is no 64-bit client support available yet. In the end, it seems the Microsoft Vista team had to make a change to the OS to fix an unrelated issue, and the cascading effect of that change was that certain native backup capabilities on 64-bit windows clients (upon which Home Server relied) got broken. All that happened while Home Server was in development.

Well anyhow, looks like the CES show will be the place where HP will announce a soon-available client for 64-bit Vista. I'm happy, because Windows Home Server and the HP MediaSmart hardware and software are pretty darned great stuff, if you ask me.

So - Thank you in advance, HP. The AV software from McAfee (note that Avast! also recently released a AV package for WHS), enhanced media streaming and other features will be nice to take a look at, as well. Good deal!

News and some detail can be found here:


Wednesday, December 19, 2007 8:09:45 PM (Pacific Standard Time, UTC-08:00) ( Random Stuff | Things that Suck )

Merry-Freakin'-Christmas from Blockbuster. NOT.

Not too long ago I wrote about Blockbuster's sudden and substantial rate increase. People were upset, me included. I begrudgingly gave in, however, and started paying the $7.00 increase - from $17.99 to $24.99 - per month for unlimited in-store exchanges and three mail rentals at a time.

BlockBusterLetterDec27th A few minutes ago I got a very "friendly" email from Blockbuster, letting me know some of the great rentals they have available in the first paragraph, encouraging me to exchange movies in the store in the second paragraph, and then pretty much putting it to me without so much as kissing me first in the third paragraph. Here is exactly what it said (click the image on the right to see a screen shot of the actual email with the section highlighted):

"To continue to bring you the unmatched convenience of both online and in-store DVD rentals, your monthly subscription fee will change from $24.99 to $34.99. This adjustment† will go into effect on your next billing cycle on or after December 27, 2007. The benefits of your subscription plan will remain the same."

So, in the time span of about four to five short months, my monthly cost has gone from $17.99 to $34.99 per month (in other words, roughly doubled) and the services I get for the money are less (since I no longer get the two coupons a month for movie or game rentals that I got for a couple years before their August price and service change).

"Ok, but that's the last straw."

As soon as the month I have already paid for runs out mid-January, I'm dumping this mess. Goodbye Blockbuster. Hello Netflix. I feel like I have to encourage everyone to do the same. This is - in my opinion - not a consumer-friendly company. I know they need to make a profit, and I was willing to support that. But dragging your customers through this kind of mess is not the way to do it. Believe me when I say I'd likely have been willing to spend more for better service (or at least consistently good service in both the store and online, which I don't get today), had a reasonable rate increase been effectively sold to me.

If some kind of miracle happens between now and January 18th when my account runs out and Blockbuster changes their plans, I'll consider sticking around. But it won't happen. This appears to be just more of the same decisions. It's too bad.

If you received an email, feel free to make use of the comments here. What does yours say? What do you think? What - if anything - will you be doing about it? If you agree with me and want to share the sentiment, you can link to http://www.boycottblockbuster.com/, which points to this page.

Time to stand up and say something.

Added -- Some other comments made on other blogs:

And, via Gizmodo, a humorous visual that effectively captures the essence of the situation...

 

I also noted that new subscribers to Blockbuster (people who go there today to sign up for the first time) will be recruited under the "old" pricing plans, as they have not changed the information on the web site. That seems a little disingenuous, if not completely dishonest, doesn't it? Click the image below to see a fill-size screenshot of their pricing page on the site as of the morning of December 20th. I'd hope they'd at least get this problem fixed soon (unless they don't intend to increase the prices for new customers, of course).

blockbusterpricesdecember19list


Wednesday, December 19, 2007 6:00:44 PM (Pacific Standard Time, UTC-08:00) ( Personal Stories | Random Stuff )

Here we are again, right up against the holidays and I am not ready yet... as usual. On Friday afternoon I'll be jumping in the truck and starting the drive from Portland to Colorado, where my mom and step dad live - as well as my brother and niece, two stepbrothers, and related extended family. My mom had knee replacement surgery just yesterday (which she says went well according to the doc), and so there are a couple important and good reasons to be down there this Christmas.

My good friend Cory, who lives in Portland but whose family is in Minnesota, is going to make the road trip with me and we're going to spend a couple/few days on the slopes in the Keystone area after Christmas before we head back. We're pretty excited and looking forward to the trip. We were going to travel by air, but decided to drive instead for a number of reasons. Renting a four wheel drive in Colorado that week is obscenely expensive as it turns out, and we plan to be in places where it's likely necessary. By the time all is said and done, it's a little less costly and we get to spend more time in Colorado if we drive. Plus we have not done a road trip this year, and we have this tradition thing to keep up.

I recently obtained a HD video camera that I have not used yet beyond taking it out of the box, charging the battery and making sure it works, so I will be taking that with me. Maybe I will do some filming on the slopes and see how HD video does when making YouTube videos or something fun like that. I better do some quick research to see how to best deal with the video for web publication.


Wednesday, December 19, 2007 5:53:25 PM (Pacific Standard Time, UTC-08:00) ( Personal Stories | Random Stuff )

Nothing brightens and warms the heart during the holiday season quite like a summons demanding appearance at the United States Federal Courthouse for jury duty. I received my official letter of "congratulations" (yes, they actually use that terminology) in the mail today. I have to appear on the morning of January 8th.

I hope it's not one of those trials that never ends. Fingers crossed. :)

Actually, I believe in the importance of the jury system and take seriously the duty. It's just such a schedule crusher, is all. Luckily I have nothing specific planned that week (or the next), or at least nothing that can't be kept flexible.



Add/Read: