Showing posts with label computers. Show all posts
Showing posts with label computers. Show all posts

Monday, September 24, 2012

Oh Hi

Forgot you were there. Well, not really, I just keep coming up with hideous ideas for blog posts that I should not write in a million years. Seriously, nobody needs to read yet another political rant for the next two months.

But I Just. Can't. Stop!

I've also been kind of busy in meatspace. My house now has functioning hot water pipes, repaired drywall, a pane of glass which is not cracked, two new sets of blinds, a new cubby shelf, and a brand spanking new desk which my wife kindly purchased for our five year anniversary and which I will be putting together as soon as it gets here.

Five is the Wood anniversary, I'm told. Stop sniggering. I got her a jewelry box. It looks lovely.

My current desk is one of those small-but-serviceable metal computer desks that lets you sit at a terminal and not much else. It is falling apart because it was put together shoddily (by moi), or because it was manufactured shoddily in the first place. I can believe either or both. The keyboard tray is currently sitting at a 40 degree angle where my feet ought to go. I am ready for a replacement.

Does the Goodwill take a partially-assembled desk? It still works fine as a desk. Just not, you know, as a desk with a sliding keyboard platform thing.

Oh yeah, I also rebuilt my entire home network after my venerable wireless router (God bless the Linksys WRT54GS!) began dropping connections about every other day. There is only so many times in a week I am willing to pull the plug and count to thirty. I replaced the wizened blue box with an Airport Extreme, which means Apple hardware has finally penetrated my home infrastructure. (iPods don't count.) Setup was a breeze once I remembered to power cycle my modem, and my whole network now runs on a sexy MAC-filtered WPA2-encrypted stream of secured data. (Thank God for firmware updates, or my TiVo would still have me stuck on sad sad WEP.)

All of this, of course, is a distraction from what I'm supposed to be doing, which is Writing The Book. Or more properly, Prewriting The Book.

Everyone says you should outline, except for the people who say you should never outline, and I'm done listening to them because I always come out with something that bent at non-Euclidean angles halfway through. I don't believe a first draft should be perfect, but I do expect it to be coherent enough that I don't have to re-plot the entire book when I'm done drafting it.

Here's an example: I tried pantsing a Victorian-era monster mash that included all the classics: vampire, werewolf, Frankenstein's monster, the works. Then I found out halfway through that the original Wolfman, Larry Talbot, isn't public domain, he's a Universal property. But I was already halfway through the damn book! So rather than go back and fix it from the ground up, I just made another character the werewolf. And then that didn't work, so I made him not the werewolf. Without going back and editing anything.

What I ended up with was a manuscript where one character ceased to exist halfway through, and another character ended up acting like three different people. And the same thing happened to a few other characters - they grew and evolved into completely different people as I wrote, but because I was out to get the first draft done done done, I didn't take the time to go back and fix the cardboard cutouts they were earlier in the story. So when I finally got the draft done, I was stymied trying to figure out where to start revising. "From the beginning..." Yes, well, no. I needed to note down the needed changes, which meant nailing down what the characters were actually going to be like, which of the multiple-choice plots I was going to keep and which I was going to cut...

In short, I would need to outline the damn book as if I was starting from scratch. Better, I think, to just outline the book first, then write the first draft without letting it fly out of control halfway through.

I'm happy to report this has worked for some short fiction pitches, but I'm running aground on the latest book (which is not the monster mash - I'm leaving that on the back burner until I can do the necessary Victorian research). I don't think this is a fault of technique, but just me being too unmotivated to get notes down on paper. And maybe a minor fault of technique - I'm taking plenty of notes and jotting down ideas, but I haven't quite got everything organized in a way that makes sense to me yet.

But! Not giving up. That's what they want you to do. But unless I have a few epiphanies between now and November, I'm probably sitting out NaNoWriMo this year. I still think the challenge is great if you want to prove that you can be productive, or if you feel like testing yourself. But I keep generating 50,000 words of complete gibberish that falls apart on revision. I'd rather take my time, plan ahead, and get an ambulatory first draft I can eventually coax to full health.

Even if it takes a long damn time.

Monday, August 13, 2012

You Should Be Using Authenticators

UPDATE: Dropbox just enabled two-step authentication for its cloud storage service. It's still in beta, but I'd recommend checking it out.

Hi there. Do you have an account with Google? Do you play Warcraft, Starcraft or Diablo? Then this post is for you.

Don't use those services or play those games? Well you should probably read this anyway, because it's going to come up in a few years.

You need to use an authenticator.

What's an authenticator? It's a thing that makes your accounts effectively hack-proof. See, there are three things you can use to log into something:

1. Something you know.

2. Something you have.

3. Something you are.

Most websites just use the first one: if you know your username and your password, you can get into the website. That's fine, except it means that if somebody else knows your username and password, they can get into the site just as easily, and seriously mess you up. If you're in any doubt about that, just read this post from Mat Honan, who watched his entire online life (and most of his hardware) get fried because somebody got ahold of his account information.

Now, you can take steps to prevent this sort of thing: use stronger passwords, use different passwords for every account, make sure you don't release any personal information (like the last four digits of your credit card) that an attacker could use to bluff his way into your account. Those are good things to do no matter what, and I encourage them. But it doesn't change the fact that somebody could figure out what your password is and walk right into your banking information.

What's the solution? You guessed it: an authenticator.

An authenticator is something you have: a physical token that generates a random number every few seconds, in most implementations. After you enter your username and your password, a website will ask you for your authenticator code. You just enter the random number that's currently on your authenticator, and you're in. If somebody doesn't have the authenticator, they can't get into the account. Simple as that. It's called two-factor authentication, and it kicks the pants out of your old username and password combo.

(In case you're curious, something you are refers to biometrics: fingerprints, retina scans, DNA sampling, biopsying your liver for a chemical analysis... stuff like that. It does get used for high-security facilities, but it's not very useful on the web.)

Authenticators used to be pretty limited, but more web services are making them available for their customers. The big two right now are Google and Battle.net, the service that runs all of Blizzard's games.

Can I be blunt? If you're using either service, turn on two-factor authentication right now.

I've been hacked before. It sucks. One thing I don't think I've mentioned before, though, is that my Blizzard account has been broken into. Twice! Jerks wanted to use it to make level one dunces and run around the World of Warcraft shouting "GOLD HERE $20!!1!" That one didn't turn out so bad, because I caught it quickly, I didn't actually play WoW at the time, and I actually got a bit of free play time once I got the account unsuspended. (And I quit again when the time ran out. WoW is a hideous time sink.)

Still, I didn't want to get hacked again. I do enjoy Starcraft quite a bit. So when I saw that Blizzard was offering two-factor authentication through a phone app, I jumped onboard. The app was free, quick to download, and worked just like I described above. And if I hadn't had a phone, I could have bought a physical token direct from Blizzard for only $6.50 that would have worked the same way.

There is no excuse whatsoever not to use one of these tokens.

Now, Google was a different case. My job doesn't permit cell phones in the office, so I assumed setting up two-factor authentication meant I wouldn't be able to check my email, or anything related to my Google account, at work. It didn't seem worth the trade-off, so I chose less security.

But after reading what happened to Mat Honan, I decided to bite the bullet and set up an authenticator. And it turns out those concerns I had were completely unfounded. See, if you don't have your authenticator on you, you can print out a sheet of one-time passwords to keep in your wallet or somewhere else on your person. You get ten at a time, and they all work the same as an authenticator (but only once - after you use one you throw it away). So if you lose your phone, or you don't have it available, you can still get into your account.

You do have to do a little extra work if you use Google Chrome, Outlook, Google Music Manager, or a few other services that aren't web-based. But even factoring those in, it took me less than an hour to set up the authenticator across all my services. And honestly? Compared to what could happen if someone broke into my email account, it's worth it.

I'm also very much hoping that other big Internet companies follow Google's lead soon. A few sites leverage Google's actual service: LastPass, WordPress, a few others I think. But I'd really love to see Amazon and Apple and Microsoft throw their weight behind this idea. Imagine! In a world... where you don't have to worry about having your email, your photos, your videos, your bank accounts compromised?

Good God! Why haven't banks jumped all over this? I mean there are limits to the problems two-factor authentication would solve for a bank; you can't fix corrupt and stupid, but how many accounts get compromised through the web in a month, let alone a year? Bankers: Get on this!

And if you're reading this, and you're using any service that supports two-factor authentication: Turn it on. Do it right now. You'll be doing us both a favor, and helping to make the world a better place. Salud.

Sunday, July 10, 2011

The Dropbox TrueCrypt Paranoia Corollary

Well, it's a week now since I started using TrueCrypt to encrypt all of my files on Dropbox, as detailed in my last post. And, I'm sad to say, after one week I'm ready to drop the encryption and go back to using Dropbox, um... unprotected. I've got a few reasons why:

TrueCrypt adds extra steps. I'm annoyingly fragile when it comes to getting into a writing frame of mind. Most anything can distract me at a critical juncture, be it a Corgi jumping in my lap for attention or that pile of laundry I forgot to pull out of the washing machine three hours ago. So having to find and mount a TrueCrypt volume before I can find and open the Word document I want to work on can actually stop me from opening that Word document. And I can't have that, now can I?

TrueCrypt nerfs Dropbox's versioning system. An obvious point I think I mentioned before, but as long as my files are in a TrueCrypt volume, Dropbox can't version them individually. For the most part, I haven't had to take advantage of this feature. Still, I've done enough development work with Subversion to know I damn well want it.

TrueCrypt slows down my syncing. I noticed this right from the get-go: with TrueCrypt, it takes Dropbox about a minute to two minutes to sync any update I make to the files in it. It's not enough to be unusable, but it's just enough to get annoying after awhile, especially if I just want to turn my computer off and go to bed after a save.

TrueCrypt actually makes me more paranoid. This is the biggie. I don't keep anything on Dropbox I would mind people looking at. Mostly it's backup copies of eBooks, evidence of CISSP CPEs I've earned, and my manuscripts. Now, it's conceivable that Dropbox is going to steal all of my shit and do nefarious things with it, but I can't imagine what. The same goes for any random hacker who breaks into my account. At worst, I'd expect to get hit with some jerk deleting everything in my Dropbox, which is why I keep offline backups.

Now, with TrueCrypt, I get the added fear that my encrypted volume might get corrupted, either from bouncing it between operating systems or by forgetting to sync updates to the volume in the correct order and having Dropbox introduce a mess of file errors. I've made that kind of screw-up before, and I don't want to do it again and have it blow away all of my files.

So, no more TrueCrypt, at least not with Dropbox. I may go back to using it to encrypt some things down the line - an In-Case-Of-Emergency file, for example - but right now it's worth more to me to have an easy time using Dropbox.

I'd go into the annoying filename quirks I ran into when I copied everything out of my TrueCrypt0 volume, but the Corg0i just jum1ped int0o my lap and star1ted1 licking my keyboard. Stop that Lina!

Sunday, July 3, 2011

The Dropbox TrueCrypt Paranoia Conundrum

I've been using Dropbox for months now to back up my important files to the Mystical Cloud that drifts through the Internet. Aside from one minor wrinkle of a file conflict (which I easily resolved), it's done sterling service. My files are backed up across multiple computers and their associated backup hard drives, not to mention the Dropbox servers themselves. Losing my work in a catastrophic incident should, theoretically, be impossible.*

But over the last couple of weeks Dropbox has gotten some bad press. Aside from the security breach (see "bad"), none of this is really a surprise; if you put your data on somebody else's computer, they are going to have to protect themselves legally in some fashion. And because copyright law is a hydra with infinite heads and a bad attitude, even an innocent company is going to look bad trying to comply with it.

That said...

The security breach did bother the heck out of me. I don't know of anyone who'd want to look at my files with malice in their heart, but I also didn't know anyone who'd want to run up a $300 bill on my Amazon account. Shit happens. And while all of my files are perfectly innocent**, I still feel less than clean knowing that someone could be looking at them right now with their filthy eyes...

Enter TrueCrypt. My files are now wrapped in one big, ambiguous blob of encrypted data, one that no one is liable to crack open in the next decade without the correct password. So I am, relatively speaking, secure.

But can I still be productive?

TrueCrypt bundles your data into what is effectively an encrypted hard drive. With the right password, you can mount it and edit everything on it just like any other filesystem. So what's in my Dropbox account now is one big file that is 1.99GB in size. There are some issues with this:

Syncing. The initial upload of this file took a good three hours. Fortunately Dropbox does bitwise syncing, so it only needs to resync the bits of the file that change during an edit. I opened up a Word document and added some text, and Dropbox updated it in about a minute.

Syncing again. The encryption works fine if I only edit the file on one computer at a time. Since that's what I do anyway, this is no big deal. But if I forget and let my systems get out of sync, I'm going to wind up with a 4GB conflict that could potentially corrupt my data. So be careful with those edits, m'kay?

Nerfed features. Dropbox allows you to access your files from the web, but not if they're in one big encrypted blob. Ditto for sharing files with other people, or versioning them. Happily I'm not using these features anyway and don't plan to start.

So this isn't a perfect solution. Still, I think it's a happy balance between ease-of-use and security, which is all I can ask for.

And if it turns out to be more annoying than I bargained for, I'll store my files in my data dog instead.



*This is tempting fate. I'm certain some alien intelligence with a global-scale EMP generator is reading this and giggling.

**Pay no mind to that donkey in the corner.

Tuesday, March 15, 2011

Living in the Cloud

About a year ago, maybe longer, it became pretty obvious that my desktop PC was not long for this world. I think it was when my hard drive suffered a total failure. For the second time. Or maybe when all the fans in the tower died on me. For the second time. Either way, thank God for backup drives and what little common sense I have.

Last week I decided to bite the bullet and shell out for a shiny new computer, specifically a Dell laptop. I'd been weighing the merits of buying a Mac, but ultimately I couldn't justify spending an extra $400 or more for the privilege of running OS X on overpriced hardware. Sure, a MacBook Pro looks sexy as hell, but I can make do with a Dell and put more money towards a down payment on a house.

Anyway. Today the laptop arrived, and for all the crap I've given Microsoft about Windows Vista, I'm loving Windows 7 right now. My setup experience has been brilliant. I just turned on the computer, typed in my name, told it how to connect to my wireless network, and boom I can log into my desktop and start customizing to my heart's delight.

First customization: Set up a user account for my wife. (Letting her play with the laptop helped me justify carrying a credit card balance again.)

Second customization: Notice that I somehow typed in "Davod" instead of "David" when I was setting up my display name, and end my evil twin's bit-encoded existence.

Third customization: Install free antivirus software and Google Chrome, because I am a big boy and I use a big boy's browser now.

Fourth customization: Delete all the Dell crapware from my system. McAfee trial, already gone. Dell toolbar, gone. eBay application (wut?) gone.

Then I get to some sort of backup software, and I remember Dell telling me I should back up my operating system up right away. Some niggling doubt tells me to look for the Windows 7 reinstall disc.

It's not there. And now I'm scared.

* * *

Cloud computing makes my life easier. That brilliant installation I mentioned earlier? Part of that is thanks to The Cloud. I installed Chrome on my new laptop, and it synced up with my Google account and imported all of my bookmarks and preferences from thin air. I set up Dropbox and downloaded all of my writing, wallpapers, and eBooks in minutes. I installed iTunes and... well, I'm still moving all of my crap over from my new computer. (Apple hasn't quite got The Cloud down yet.)

But there are perils in The Cloud, oh yes there are. What's stopping Chrome from using my bookmarks to launch targeted ad warfare directly at my brain? What keeps Dropbox from stealing all of my shit and running off into the night?

And why should Dell ship me a recovery disc for my operating system when, at this point, most all of my data is living on about twenty computers distributed throughout the country? "Hell," they say, "the bastard geeks just use those discs to get around our advertisers' crapware in the first place. And don't forget about the software pirates! Let them go out and buy their own discs if it's so damn important!"

From a business standpoint this makes sense. I'm betting Microsoft gives Dell a killer discount if they don't ship physical media with their computers. And let's face it, the pirates made a killing trading those Windows recovery discs all over the place.

But damn it, I want to own the operating system I run on my PC

(by which I mean I want to own a physical copy of the software on some form of media, such as a DVD or flash drive, along with a license to install said software on one or more computers which I also own, so long as I do not distribute said software to other persons)

so that if, God forbid, the whole computer dies in a horrible magnet accident or viruses eat my desktop, I can pull something out of a drawer and rebuild the thing from scratch. I do not want to back up and restore Dell's crapware from a thumb drive I don't own.

And things are going to keep moving in this direction. As bandwidth becomes cheaper, we'll start to see entire operating systems that are streamed right off the Internet. Your files won't live on your computer - they'll be off in The Cloud, safely stored and duplicated on a fleet of high-end servers, and triple-encrypted to keep the hackers out. You'll be able to jump onto any old piece of hardware you like, from a friend's computer to a library terminal, and within minutes it'll be like you're in the comfort of your own home.

Until you forget to pay the license subscription, or the Imp of Perversity misplaces your account information, and you're at the mercy of Google or Microsoft or Apple or Comcast or the FCC. And then you'll be begging with the rest of the Unpersons in a big crowd in a cold February day, and every few minutes you'll pull out your iPhone 15 and forlornly look at the screen that says "Operating system not found. Please contact customer support." But you can't get a clear signal because all the VoIP bandwidth is being eaten by people watching Justin Bieber's comeback video on YouTube HD3D Interactive.

And I sense I've gone sideways somewhere, so to sum up: My new laptop is awesome, crapware sucks, and I'd like my damn Windows disc back before it's too late. Now here's a picture of Lina celebrating her 3rd birthday.


Don't look at me like that. I didn't let her drive.