Sticky Postings
Observations on Everything
Although "It's Fixed in the Next Release" is a mantra from software development (or rather technical support), the intent here is to apply the phrase to a broader context, for example, "It's fixed in my next reincarnation." This broad interpretation means that the entries here cover vastly unrelated subjects.
If you're looking for a tightly focused blog with short, pithy entries, you are in the wrong place (although there are some). Here, blogging is about content.
I have done one thing to make things easier on non-technical readers. All of my comments that deal with specific aspects of software development are in a category that doesn't show up in the main list. you have to select It's a Code, Code World to see these posts.
Friday, August 15. 2008
"Joomla!" had an extremely serious security issue arise earlier in the week. I'm pretty deeply involved in the project, and I happened to be on the Bug Squad chat when the news broke. The issue was not a SQL injection problem, as many sources have assumed but reported as fact. Ironically, it had to do with defeating a session security feature. The security problem was a programming error. "Joomla!" goes through extensive procedures to defend against SQL injection, and from version 1.5 onward, such a vulnerability in the core code is highly unlikely. [Extensions are another matter. I strongly recommend that users only install open source extensions that have either been audited or that have broad community support.]
Even though this problem caused a fair bit of damage, I'm very proud of how the "Joomla!" team responded to the problem. This was a worst-case scenario: the exploit was published with no advance notification, and it was dead simple to implement.
The first we heard of it was a post on the Dutch "Joomla!" forums. One of the Bug Squad team mentioned this in chat on August 12th at 15:50 EST. We immediately took steps to verify the issue, and then once confirmed, to remove the details from the forum post. A patch was made available for testing at 16:10. A full package release was made available for testing at 18:19. Announcement of the release was made on joomla.org at 18:57, and by 19:40 update packages were also available. That's three hours and 50 minutes from report to full public release. If that's not a record I'll be surprised.
What is distressing is that a large number of security focused sites reported this as a SQL injection vulnerability, along with a variety of other erroneous or misleading information. Almost a week later, many have corrected their errors, but several have not. Considering that the "Joomla!" team responded so quickly, and that complete information was posted as the first item on the joomla.org web site before the exploit became widely known, this suggests that many of these sites simply repeated each other's misinformation, rather than taking even the smallest steps to verify the report.
Granted a sample size of one event is not sufficient to draw conclusions, but if this is any indication of how "trusted" security information sources behave, then it is no wonder that whole security field has a serious credibility issue. These kinds of reports are extremely serious matters, with a lot of potential for damage. Certainly the timeliness of information is critical, but hopefully not at the expense of accuracy. The security community has a deep obligation to perform the simplest verification of facts before rushing to publication.
Thursday, August 7. 2008
I kind of like republican Presidential candidate John McCain — as a person. He seemed to have great personal integrity until last week, when his campaign started running attack ads against his Democratic opponent, Barack Obama.
Unfortunately for him, this ill-advised manoeuvre seems to have been engineered by a bunch of old dinosaurs who are completely out of touch with the reality of the Internet. I guess nobody told them that big television advertising dollars no longer get you exclusive access to the attention of the populace. Oops.
The McCain ads sandwiched Obama's image with those of Britney Spears and Paris Hilton, deriding him as a mere celebrity, not ready to lead. I've always maintained that Ms. Hilton plays her public image as a lot dumber than she really is (don't get me wrong, I'm not giving her Rhodes Scholar either), and this week Paris Hilton shot back at the use of her image in that ad.
Analysts have said that the main advantage of the McCain ads were that they got widespread news coverage, and that having segments of them lead the news gave them huge extra exposure at no cost. Unfortunately for them, it looks like Hilton's spoof, likely shot for a few tens of thousands of dollars and featuring McCain being referred to as "wrinkly white-haired guy", is going to get almost as much exposure.
In general, I think attack ads are crass and desperate (particularly when run by a party that is in power outside an election, but that's another post entirely), and it's good to see them backfire. The only real downside of this parody is that there will probably be an embarrassingly large number of ballots filed in November with Paris Hilton as a write-in candidate.
To conclude, here's the Internet 101 summary for anyone contemplating an attack ad:
In a wired world, be careful about where you lob the muck. It's a lot easier to fight back than you think.
Monday, June 9. 2008
This weekend the Toronto Star announced the death of the SUV. One of the reasons this came up has to be the closing of the General Motors truck assembly line in Oshawa. It seems that as the price of gas gets above about $1.25 per litre (or $4/gallon in the U.S.), the number of people who "need" an unsafe gas guzzling SUV drops off pretty quickly. Now these same people "need" to unload their luxury land barges. There's nothing like a flexible definition of needs.
This is a good start. There's going to be a lot fewer road trips in the family road boat this year. Some people will argue that this is a bad thing, that families should be able to get out there with their kids to see all that this vast country has to offer. These people haven't actually seen a family in one of these vehicles. The parents are happily enjoying their time "together" while each kid is in their own isolated space with individual DVD players and noise-reducing headphones. They see as much of the countryside in their basements. Besides, a lot of travel options remain open. Our geography is every bit as dramatic from a train. Better yet, on a train it's a lot easier to get your kids to come out of their multimedia shells and look at something without risking a major accident.
Continue reading "RIP, SUV: Gas Prices Are "Getting There""
Thursday, May 29. 2008
This one probably isn't new, but it's worth noting. An associate recently got this bogus "security warning". Appropriately named "irony", the message warns the user that "Security Center has detected Malware" and directs the user to a site where they can download a patch. Click on the image for a full sized version.
The "patch" will install malware on the user's computer. At least they can't forge the link as belonging to Microsoft, but this could easily fool an unsuspecting user.
Thursday, April 24. 2008
This is simple and effective. If you suspect that the company who is calling you is not legitimate, ask the caller for their web site address.
If the call is a fraud attempt, the "agent" probably won't be able to give it to you. One of these things will happen:
- They won't "remember" it. For extra bonus fun, ask them if their sales manager knows it.
- They'll give you a legitimate site that isn't theirs. Ask them to hold on while you pop it up. If that doesn't make them hang up, ask them where the information relating to their offer is. They might tell you it's an exclusive offer that's not available on the web, but if the site has nothing that seems to be related to the offer, it's a big warning that they're not telling the truth.
- They'll give you a fake site that is theirs. This would be pretty stupid on their part, since it would provide the authorities with a path back to them. Do a search on the site to see what the world has to say about them. If they're not in the search index, then the site was probably set up a few days ago. More sophisticated users can do a whois lookup on them... look at the registration date. Also if the site owner is masked for privacy, you can be sure it's not a large established company. Either way, report the site to your local authorities as soon as possible.
These fraud schemes depend on leaving the smallest possible trail back to them. Legitimate businesses want to open as many possible channels of communication with their potential customers as possible.
So it's as easy as this: no web site equals no legitimacy. Protect yourself.
Sunday, March 30. 2008
Earth Hour has come and gone. Overall it was pretty successful: the statistic I heard was that electricity consumption in Ontario was down by 8%.
What does that mean? From a pragmatic viewpoint, not a hell of a lot. From a political viewpoint, it's pretty significant. I don't have the numbers that project the percentage of the population that participated, based on an 8% reduction, but I'll guess it's somewhere between 15% and 25%.
That's a lot of people sending a message. At this point it seems the big environmental problem is politicians. Most individuals get it, most corporations get it, but the politicians, who can actually manage the process of real change, just aren't there yet.
Maybe having as many as one in four voters demonstrate their commitment to change through Earth Hour will be enough to wake them up. I'm not holding my breath though.
Thursday, March 27. 2008
There was a time when the events unfolding in Tibet would have caused rapid worldwide outrage, followed shortly by a flood of withdrawals from the Olympics.
But that was when China was of little economic importance.
I am dismayed at how flexible our collective principles are when it comes to the economy. It seems that the only time when a political leader has to be concerned about minor trifles — say for example, killing off a few tens of thousands of people from that pesky tribe next door — is when they're not either producing oil or keeping those same tribe members working 16 hour days to make cheap clothing.
So it is with China. Most of the West is enjoying a great standard of living(*) thanks to China. Their leaders know this well. They may even be rubbing it in our faces. Or maybe they're just rubbing the 1938 games in our faces and laughing.
Are we going to actually support the principles of Human Rights and take a stand? What, and pay more for consumer goods as a result? In the pocketbook versus principles battle, it looks like pocketbook wins, no contest.
If politicians are unwilling or unable to act, it's up to the people. A small step though it may be, I'm opting out of the Olympics this year. This summer I'll be watching something else.
There's also a few companies who have lost my business: Coca-Cola, GE, Johnson&Johnson, Lenovo Group, McDonalds, UPS, Panasonic, Swatch, Samsung... at this point, the Olympic logo on any product is an icon for "don't buy me".
Last but not least, there's a Facebook group that expresses similar sentiments. I don't agree with everything they say, but they're close enough and are the largest of a handful of similar groups. Join them and be counted.
* I mean this in the "wow, this is inexpensive" sense, not in the formal economic sense.
Friday, March 7. 2008
Two interesting things about viral marketing:
- In a lot of cases, you can't even be sure if there was originally a marketing intent behind it.
- Just about any business can wind up as the subject of a viral "buzz".
That's any business, even including a Sand Road Venture Capital firm. Take a look at this " Anti-Portfolio" from Bessemer Venture Partners.
I've had that link sent to me via IM twice today. That's buzz.
Why does it work? It's true, it's funny, and it's out of the box. Every VC I've met to date seems to like to put forward the image of near-prescient infallibility. Openly admitting to your mistakes, and naming names is an utter reversal of this image-making. It is so novel and unusual that it's immedately worth passing along. Not only that but it instantly humanizes the entire firm and makes them seem like the sorts of people you'd like to pitch to first.
Its both superb and brilliant — be it intentional or not.
Monday, February 25. 2008
It's interesting how often the question of online versus traditional shopping comes up. A friend asked me this earlier today and I gave him the same answer I've been providing for a decade now.
These days the response seems reasonable, but back in 1998 it was heresy. It used to be guaranteed to make a room full of start-ups and venture capitalists go dead quiet. Of course back then we were in the middle of the dot-com boom, when somehow geeks who don't like daylight managed to convince everyone that their concept of a good shopping experience was somehow universal.
So here it is:
Continue reading "Online Shopping versus Traditional Shopping"
|