Sunday, December 19, 2010

Xfce? No, I don't Think So

I just checked the xfce site to see if their documentation situation has improved. They seem to be preparing the 4.8 release, with 4.6 in use, but the documentation is 4.2,. No way I'm going back to that--it appears to be run by a bunch of coders with no interest in the user. Thus, xfce developers, IMHO, are developing for themselves, but not for the wider Linux community. There's nothing wrong with that, but I think things like Xubuntu should be discontinued until someone thinks xfce is worth documenting.

Quick Note on Address Bar Auto-Completion

Firefox and Opera, by default, have a search field (it's a text field but Firefox calls it the search bar) to the right of the address bar. I've removed mine--it's redundant and cumbersome (or so I thought, but see point 3 below), and an information leak.

I often have students in my office for advising and typically go over their online records. This means they look at my web browser. This also means they can read titles of tabs (fine, so be it) and contents of the search bar. I'd hate to have a student read too much into the fact that I've recently searched for Shaun Cassidy. So in my office I removed the search bar and just open a new tab (^t) and hit the g key. This takes me immediately to Google.

(1) Most of my searches are Google searches. I played with Bing when it first came out, but Bing's results don't seems as good, and Bing seems to use a fair amount of client-side scripting, which I'd rather avoid. Google does too, but they already know everything about me.

(2) I may sometimes prefer a Wikipedia search or some such, but very often the appropriate Wikipedia page is near the top of the search results, so Wikipedia search is redundant.

(3) Doing a quick lookup for this posting led me to http://www.mozilla.com/en-US/firefox/search.html, which points out that one can select text and drag it to the search bar, which seems to work well. So my search bar is, at least temporarily, back in my Firefox window on most of my machines--just not the one in my office.

Arvind Goes to Washington

Arvind Narayanan (no, not that Arvind) just served on a 'Do Not Track' panel in DC, and writes intelligently about his experiences, e.g., on how the system in DC is not as effective as one might hope. Rather than paraphrase or summarize, I'll just point to the original article.

Blackboard 9 Usability and Security

It turns out that Firefox users can improve their browsing experiences within Blackboard and keep their local data a bit safer through the use of the AdBlock Plus extension.

A problem I've had for awhile--predating Blackboard 9--is that when editing content within a Blackboard text area, Blackboard pops up a requester asking me to give some piece of Java code complete access to my PC. Of course I always say no. However, Firefox and Chrome seem unable to remember this, though Opera can be instructed to always block such a request from a particular site. Firefox is happy to allow one to always trust signed content from a provider, but not to always distrust. Strange.

Anyhow, these two AdBlock Plus rules block the annoying content from UMBC's Blackboard installation:

|http://blackboard.umbc.edu/webapps/blackboard/content/webeq3.editor.InputControl
|http://blackboard.umbc.edu/webapps/blackboard/execute/webeq3.editor.InputControl

It appears that Blackboard wants access to all the data and applications on my PC on the off chance that I might want to run an equation editor. I'll go out on a limb, having never tried webeq3, and say I have better equation editing tools on my machine.

Avoiding the Worst of myUMBC

I was in a meeting a couple weeks ago, and the person doing a presentation made an offhand comment about having to click through "the useless myUMBC crap." A man after my own heart. He was talking about the media-heavy, irrelevancy-filled page at my.umbc.edu.

I avoid that page most days. Firefox, Chrome, and Opera begin showing possibly-relevant pages as soon as the user begins typing in the address bar (a much more useful use of auto-completion than one can find in office applications). IE probably does this as well. If I need access to web-based functionality hidden behind the dysfunctionality of myUMBC, I just start typing the word 'faculty' into the address bar. Usually the 'f' is sufficient to get me to the myUMBC faculty center, bypassing most of the garbage. Speaking of garbage, though, PeopleSoft is directly accessible from the faculty center, but that's another issue.

Ubuntu 10.10 Day 0

Yesterday I installed Ubuntu 10.10 on my laptop, and have a couple quick encryption-related comments.

I installed from the alternate install image. The standard image does not include encrypted LVM. It does, however, allow one to encrypt user home directories. Is this good enough? No.

(1) In Ubuntu, encrypting a user's home directory fails to protect users who lose their passwords. This could happen a number of ways. It happened to me once via shoulder surfing. Many people use the same password for multiple services--a bad idea. The user password and encryption pass phrase should be distinct.

(2) Users tend to use weak passwords. Hopefully they choose better pass phrases.

(3) With just the home directory encrypted, swap is in the clear. This is a well-known leak and part of why secure software generally overwrites passwords and keys in memory as soon as they are no longer needed. Garbage collection is not good enough for keys. In general any data could show up in swap, and so swap should be encrypted.

Friday, December 17, 2010

The WikiLeaks Furor

There has been an uproar about WikiLeaks in the press lately, and until recently I've felt that Wikileaks has done more good than bad, pointing out cases where the US (and other) governments have lied to their populaces, condoned torture, etc. I won't go into the ethics of the current batch of releases because there is simply too much to review, but I would like to make a few comments.

1) http://news.netcraft.com/ has been doing a great job of covering the back-and-forth of WikiLeaks availability, changes in their hosting and DNS services, etc.

2) Tonight I decided to spend a few minutes looking at the site. Among other things, I was interested in whether it would be difficult to get to. Two things worked right away. (a) Googling WikiLeaks led directly to 213.251.145.96 (registered to wikileaks.org in a block owned by OVH ISP in Paris), so the DNS is not necessarily needed. (b) Verizon's DNS service redirected me to http://mirror.wikileaks.info/, but some of the links at that site, e.g., the one to obtain a secure connection, did not work.

3) Some of the calls for the US government to launch web attacks against WikiLeaks are largely over the top and naively stupid. I wouldn't be surprised to discover attempts to hack into their database or their servers, but the idea of launching DDoS attacks against ISPs and hosting services in the US, Europe, and elsewhere is just silly. The US launching cyber attacks against France and Russia? Not a good idea.

4) I read one leaked dispatch, http://213.251.145.96/cable/2009/08/09BRASILIA1017.html. This is tagged "UNCLASSIFIED//FOR OFFICIAL USE ONLY." One phrase I really like is advice to the USG (US Government, I suspect), "speak softly and carry no stick." The article talks about attempts to keep the Brazilian government from authorizing pharmaceuticals in Brazil to produce generic versions of AIDS drugs, in other words the bureaucratese seems to suggest that the US government is more interested in corporate profits than in dying Brazilians. Not a big surprise.

This is exactly the sort of thing US (and Brazilian) voters should be aware of, and also not the type of leak causing much of the uproar.

Saturday, November 20, 2010

Guilty Until Proven Innocent

CCBC-Catonsville has barred a veteran from campus for a piece he wrote for an English class, received an A on, and was encouraged by his instructor to seek publication. In it, he talks about the appeal of killing. This is very different from saying he will kill in the future.

Many of these veterans have gone through hell and many are having trouble re-integrating with life stateside, especially with the economy in its current state. Now it appears that community colleges also require them to be dishonest in their writings or face threat of losing access to campus, education, and perhaps a future career.

The Baltimore Sun article: http://www.baltimoresun.com/news/bs-md-veteran-suspension-20101121,0,1268392,full.story

Sunday, October 24, 2010

Verizon Violates DNS Standards

Verizon is in violation of DNS standards. When I type the address www.foo.bar.baz.no, assuming there is no such server in Norway, I am redirected to http://searchassist.teoma.com/. Interestingly, I see correct behavior if I leave out the www, "Server not found".

Friday, October 1, 2010

LinkedIn, Maybe Worth it Again

Some time back I said that LinkedIn was no longer worthwhile since every visit required a log in, which made every visit take longer than it was worth. Sometime in recent months this situation was remedied, and so a quick visit to LinkedIn in again a quick visit.

XKCD #800 Features The Game

Beautiful Dream


According to Wikipedia, the rules of the game are

  1. Everyone in the world is playing The Game. (Sometimes narrowed to: "Everybody in the world who knows about The Game is playing The Game", or alternatively, "You are always playing The Game.") You cannot not play The Game; it does not require consent to play and you can never stop playing.
  2. Whenever one thinks about The Game, one loses.
  3. Losses must be announced to at least one person (either by using a statement such as "I Lost The Game" or by alternative means).

These rules were written by someone with rather weak logic. I'm in the world (more-or-less), I know about the game, and I have never played the game nor do I think I ever will. I'm thinking about the game right now, but I do not acknowledge any loss, other than the time to type this. I will likely think of the game again at some point, but I won't tell anyone I lost the game, so I won't be playing the game at that point, either.

I imagine that as I type this, some twit is twitting "I lost the game."

Tuesday, September 28, 2010

OpenOffice Inserting Page Breaks

I've been using OpenOffice more than usual lately (and still greatly prefer emacs/LaTeX for speed and accuracy). One annoyance has been inserting page breaks: Insert|Manual Break|Page Break. Very clumsy and slow. There's no hint regarding an equivalent shortcut adjacent to the menu item, so I tried ^L--it is the standard ASCII page break character--but no joy. Googling led to http://www.oooforum.org/forum/viewtopic.phtml?t=35045, where Bhikkhu Pesala suggests ^enter (or control enter for newbs). Thanks Bhikku.

Why can't we have a finance minister like the Swiss?



Or directly from youtube: http://www.youtube.com/watch?v=lylgA7DWBXU

Thursday, September 23, 2010

Alert! Alert!

UMBC police are using a false alarm as an argument that we should sign up for text alerts. I guess the argument is "See, we sent out another useless alert. Don't you want to be sure you don't miss any of this irrelevant information?"

This country has been running scared since 9/11/01, and the situation a couple years ago in Blacksburg didn't help. But enough is enough, and "e2campus" is too much. We're expected to sign up to be alerted for events of near-zero probability, so almost any e2campus alert will be a waste of time.

> September 23, 2010
>
> To: The UMBC Community
>
> Fr: Mark Sparks, Chief of Police
>
> Re: False Report of a Shooting on Campus
>
> This morning, Baltimore County Police responded to a 911
> call of a possible shooting in front of the Retriever
> Activities Center (RAC) within about two minutes of
> receiving the call. Both police agencies did a thorough
> search of the RAC and surrounding area and found no evidence
> of a shooting through the search or citizen interviews on
> the scene. The call was apparently unfounded, and is being
> treated as a False Report call by the Baltimore County
> Police Department.
>
> An e2Campus text alert was sent out once the UMBC officers
> developed enough information about the call, to tell the
> campus the nature of the call and that it was unfounded.
>
> Members of the campus community are encouraged to sign up
> for e2campus, an emergency alert text-messaging system that
> will permit the University to notify subscribers to any
> campus-related emergency (such as potential campus safety
> hazards or campus closures due to weather). It is compatible
> with mobile phones, Blackberries, "smart phones," satellite
> phones, e-mail, wireless PDAs and pagers. Normal
> text-messaging rates apply. There are no additional
> charges. Sign up for this important service today at
> http://my.umbc.edu/go/alerts.