2006-12-08

(malware,DRM,quotes) CIO Blogs - Musings on Vista

http://blogs.cio.com/musings-on-vista

Another great article from my favourite CIO columnist. Again, nothing we haven't read in other places, but he brings it together very succinctly and clearly.

Some quotes [text in brackets is mine]:

Overall, Microsoft delivers client operating systems whose virtues make end users happy and whose vices cause problems for IT.

...

It's addressed some of the problems in XP in ways that end users are likely to see as intrusive and inconvenient. In other words, they've bandaged their vices in ways that will wound their virtues, which is a poor strategy.

...

There's only one problem with this situation [Trusted Computing] -- changing hardware will break the end-to-end chain of security and result in an inability to access the data (see here, particularly page 2, for an interesting discussion of the implications of Trusted Computing and hardware).

...

I would hate to be the IT help desk person who has to explain to an end user that because the motherboard of the computer went on the fritz and the backup encryption keys aren't available, all data on the machine is lost.

...

I know that no end user is going to see this functionality [DRM] as helpful in his or her daily life. This seems like functionality put into the system not to serve the actual user, but to appease a powerful constituency that, through money and legislation, can bring more pressure to bear than can individual users. I predict an uproar around DRM when Vista rolls out, and a widespread rejection of new-gen media on PCs due to the onerous requirements.

2006-12-04

Love and Marriage

The other day there was a toastmasters club meeting in the office, where one of the table topics was "Love before Marriage, or Marriage before Love?"

My first question, considering both my sense of humour and the fact that I'm an incorrigible flirt, was "does it have to be with the same person?"

Good joke. Or was it a joke? Maybe I was serious ;-)

But it got me thinking. A lot of my younger friends have just gotten married or are about to take the plunge, and -- while I will always behave like an immature, childish, almost juvenile, brat, and I will always be proud of it -- I can't really escape the fact that I am actually 44.

So here're some thoughts on the subject, and some free advice. Buddha had the great insight that desire is the root of all suffering. In terms of human relationships, I'm sure the specific desire is the desire for importance. Also called ego :-)

And everyone knows that ego comes from being insecure. [And no, I don't mean that type of "insecure"!]


It seems to me that, in terms of relationships, there are 4 types of people in this world.

  1. most insecure: no deep feelings at all, even if she seems very friendly and vivacious to a casual observer. Will never trust anyone enough to open up or appear vulnerable. Always on her guard.

    Love before marriage? No way! Just hope that there will be some love after marriage. And pray that she marries at least a type 3 or a type 4!

  2. somewhat insecure: has feelings and is capable of lots of love, but is very very guarded. Can morph temporarily into type 1 if there's a problem! Won't tell anyone when she's hurt -- swallows it all and burns up inside.

    Sounds like a stereo-typical girl? Believe me, I've seen guys like this too!

    Love before marriage only with a type 3 or a type 4.

  3. still a little insecure: enough that he can't admit it even to himself :-) Projects an overwhelming image of confidence and mastery over everything.

    Finds it very difficult to say "I need you" to anyone. In fact, anything sentimental is accompanied by a joke -- sort of like an escape clause!

    Even a type 2 may wonder if he has any feelings at all. But if you're a type 4, you will quite easily see that he needs you but just isn't saying it, and that he does have feelings deep down but will not show them, and so you'll probably be fine!

    Most definitely "love before marriage" material, but he won't push it if things don't work out, so he may well end up with an arranged marriage. Just hope it's not to a type 1 :-(

  4. hardly any insecurity: can happily, without an ounce of diffidence or reluctance, tell someone "I need you" :-) You always know where you are with him. Cannot hide his feelings if his life depended on it.

    Appears to be much more vulnerable than the others because he gets hurt easily, but that's only because his hurts are more visible, and he has no qualms about telling you he's hurt. In fact the other types are more vulnerable, because they can get hurt and not even realise it themselves :-(

    This type can't even think about "marriage before love" without breaking into a sweat :-) It has to be "love before marriage".


No prizes for guessing which combinations are better than others :-)

In fact, it is my theory that in every love marriage there is at least one type 4, or both type 3. Other combinations do not seem capable of leading to what is usually thought of as a love marriage.

And I'm not saying type 4 is the best or type 3 is better than type 2, etc., in the long run. One you get married there're all kinds of behavioural traits and attitudes that you don't see earlier, and that will drive you up the wall regardless of what "type" the person is -- carelessless, forgetfulness, attitudes towards money or work, family, importance of parents, religiousness, etc., etc., etc., ad infinitum.

Many of those aspects can be just as important as ego.

2006-12-01

(religion) The Dilbert Blog: Atheists: The New Gays

http://dilbertblog.typepad.com/the_dilbert_blog/2006/11/atheists_the_ne.html

Best quote:

Ask a deeply religious Christian if he’d rather live next to a bearded Muslim that may or may not be plotting a terror attack, or an atheist that may or may not show him how to set up a wireless network in his house. On the scale of prejudice, atheists don’t seem so bad lately.
And yes, he was joking about Bill Gates running for President. I'm sure of it...

2006-11-30

(process,funny) Six Sigma

Best stuff I've seen on Six Sigma in a long time:

http://slashdot.org/comments.pl?sid=208900&cid=17033026 says/asks:

Six Sigma -- I find it hilarious. Basically, they took the work of Walter Edward Demmings, widely regarded as the driving force behind Japan's industrial turnaround, repackaged it, and called it "new". Demmings cane up with "kaizen" or the process of continual improvement. Basically, no process is complete unless it has a feedback and improving mechanism

For anyone who is an expert: What has six sigma added to this paradigm?

Then http://slashdot.org/comments.pl?sid=208900&cid=17033512 replies:

Bureaucracy.

At least in GE's implementation of Six Sigma. They found a way to take what is essentially the engineering version of the scientific process, wrap it in so much red tape that it is unworkable (a 12-step process that really had 15 steps) , and put it in the hands of every worker in the company. Originally they gave bonuses for doing it, but eventually they took those away and declared "Thou shalt not get a raise without a Six Sigma Project." What ended up happening is that people refused to make any process or product improvements unless they were part of somebody's (preferably their own) Six Sigma project.

It was ridiculous. You ended up with one person optimizing a part of a process, while the person in the next cubicle was eliminating the entire process in favor of a more unwieldy one. Then, six months later, somebody else would start a new project that essentially put the original process back in place. Of course the problem was that they were using a distinctly product-oriented procedure, and trying to use it to solve process problems.

Don't even get me started on the math. They would assume normal distributions for everything. Never mind that one of the steps was to prove normalcy. If that test proved it wasn't normal, you were instructed by your "Black Belt" to assume normalcy anyway -- even if a Weibull distribution was clearly the correct choice (like in timed exercises). Idiots, I say. And then they had PHB's (called "Black Belts" and "Master Black Belts") trying to tell engineers how to do math, when they didn't even know how to use a simple Q test. If they saw a data point that didn't support their theory, they just called it an outlier, and deleted it.

You'd think after nearly two years of not working at GE, I wouldn't get so wound up about it. I guess as an engineer, it really gets my goat when people use math improperly.

[I normally don't copy entire tracts of text, preferring to just give the URL and leave it at that, but in this case it seemed necessary and useful...]

2006-11-21

Schneier on Security: BT Acquires Counterpane

http://www.schneier.com/blog/archives/2006/10/bt_acquires_cou.html

Bruce Schneier's Counterpane Security has been acquired by British Telecom.  Read comments on this page.  In particular, I like Bruce's nomination of "Best blog comment ever", which shows the difference between security as theorised and security as practised :-)

Hilarious!


2006-11-17

(religion) The Church of the Non-Believers

http://wired.com/wired/archive/14.11/atheism.html

Thanks to a former colleague ( http://diviya.blogspot.com/2006/10/one-post-too-many.html ) for the link.

Nice article, worth a quick read. A bit long-winded, and there is much that even agnostics and atheists will disagree with, since it seems to explore all sides equally :-)

But it's too philosophical and too abstract for my taste.

I'd appeal more to personal experience with religious people, though I agree that would be difficult to convey in an article. Your parents, your friends, relatives, and colleagues at work affect you much more directly than Khomeini or Pat Robertson.

I've always maintained that it is not religion, but the overt display of religion, and organised religion, that are the problems. I don't know how far that's true, but it certainly seems that way to me.

Overtly religious (this is almost always the same as "overly religious", but there are exceptions here and there) people eventually acquire a selective humility. They are humble to their God, and pretty egotistical and nasty to the rest of the world.

Of course, they have no clue they are even egotistical, let alone nasty -- they'd be stunned if you told them, and probably die of a kernel panic if you managed to prove it to them! (Fortunately it's practically impossible to convince them, so we will never be guilty of murder!)

In most cases they have lost the capacity for self-introspection that is needed to realise what they are doing to the other person. They are so immersed in their God that they can never say to themselves "what if I'm wrong", because it automatically means the same as "what if God is wrong"!

In fact, they seem to really and truly believe that they have a direct line to God. It's essentially the same thing that makes "Muslims" like Khomeini issue fatwas against Rushdie or "Christians" like Pat Robertson call for the assassination of Hugo Chavez. Overtly religious people issue fatwas every day, whether they realise it or not, and whether they say them out loud or not.

On the other hand, my experience has been that atheists (and the very few covertly religious people I know) are pretty nice people!

That, to me, is the biggest reason for advocating, if not atheism outright, at least the suppression of religious exhibitionism.

PS: I think the author of the article must be a nice guy. His article ends: "...no matter how confident we are in our beliefs, there's always a chance we could turn out to be wrong." :-)

2006-11-13

finally, competition for George Lazenby

Daniel Craig!

Here's hoping he is also a 1-shot wonder like George :-)

2006-11-07

Schneier on Security: Perceived Risk vs. Actual Risk

http://www.schneier.com/blog/archives/2006/11/perceived_risk_1.html

Very serious article, but I was struck by the very humorous way he describes a natural human characteristic:

The brain is a beautifully engineered get-out-of-the-way machine that constantly scans the environment for things out of whose way it should right now get. That's what brains did for several hundred million years -- and then, just a few million years ago, the mammalian brain learned a new trick: to predict the timing and location of dangers before they actually happened.

Our ability to duck that which is not yet coming is one of the brain's most stunning innovations, and we wouldn't have dental floss or 401(k) plans without it. But this innovation is in the early stages of development. The application that allows us to respond to visible baseballs is ancient and reliable, but the add-on utility that allows us to respond to threats that loom in an unseen future is still in beta testing.

The rest of the article is equally engrossing -- and it's a pretty short article so go read it.  (Don't be fooled by the size of the scrollbar in your browser window; this is because there are dozens of reader comments below the article)

2006-11-02

(funny,quotes) Why I (still) cant stand Emacs :-)

...and probably never will.

An old tagline comes to mind: Emacs is my operating system, Linux is my device driver!

Anyway, here's a very nice article from my favourite Linux site, with some quotes below. The author, Jon Corbet (editor of LWN) is well known for his dry humour as well as his objectivity. Few people who profess to use emacs as much as he does would make the kind of digs that he has taken in this article!

http://lwn.net/SubscriberLink/206916/8f7cb0a9f19cad56/

Some funny (and some not so funny) quotes, with occasional comments from me in square brackets:

The addition of an IRC client would have been useful, but this is Emacs, so they added two different ones.
...
The wrong key sequence can occasionally lead to hallucinogenic results, to the point that there is a special command ("view-lossage") to answer those "how the hell did I make it do that?" questions.
...
Even some relatively trivial customizations require typing in Lisp code, which, for some strange reason, not everybody wants to learn how to do. [well Duh!]
...
There is also an entire branch in the physical therapy field dedicated to the treatment of little-finger injuries caused by excessive Emacs use.
...
There is a new "calc" mode which is truly scary in the things it can do. [I don't even want to know what that means...]
...
There is a built-in spreadsheet with all the usual features and some unusual ones - like the ability to enter cell formulas in Lisp.
[A spreadsheet inside a text editor? What's next, a flight simulator?]
...
The current NEWS file gives a lengthy overview of the changes - though somehow it omits the important addition of a Tetris game.
...
And vi simply lacks a number of more advanced features; it was never meant to contain mail clients, RSS readers, calendars, or psychoanalysis programs.
[the last one I can answer: using vi will not drive you insane, so no psychoanalysis is needed!]
...
Emacs is an interactive user interface development environment which happens to be very good at editing text.
[aaah -- I get it. The Lotus Notes of text editors :-)]

2006-10-24

User Education and Security

http://news.com.com/Security+expert+User+education+is+pointless/2100-7350_3-6125213.html

"Might it be so that we use the term and concept of user education as a way to cover up our failure?" he asked a crowd of security professionals. "Is it not somewhat telling them to do our job? To make them be a part of the IT organization and do the things that we are bound to do as a specialized organization?"

I don't know how many of my readers think about security all the time! Heck I don't even know if I have any readers :-)

But this is an interesting topic. In a long-term way, I think I agree with Mr Gorling -- the need for user education is clearly a technical failure at some level.

I tend to compare things to the physical world a lot. In the physical world, we're used to different levels of security. Take "documents" for instance -- we keep important financial/property documents in an inner room, and probably under some sort of lock and key. Things that are less important (like receipts, warranty cards, bills, small amounts of cash) are kept in a slightly more accessible but still quite safe place. Finally, things like books, magazines, newspapers, etc., lay around pretty much anywhere (and cause fights with the wife if she is a cleanliness freak, but that is neither here not there ;-)

Don't you think the security problems we're seeing are mainly because on his computer, unlike in his house, we have not given the user enough "rooms", and he's essentially forced to put everything in one room or (worse) one "shelf"?

A small example: within my workgroup, we allow people to access random websites only through Firefox. If they use IE, they are restricted to a whitelist of URLs that we assume we can trust. This is one type of separation, and I am sure it has helped us tremendously over the past few years it's been implemented.

Personally, I have even toyed with the idea of running two copies of the firefox browser -- one with my normal userid where I do anything I please, and one under a very rarely used userid which I will use only to access my corporate intranet portals, my bank, etc. -- yet another form of separation (although, since I use Linux, maybe I'm being too paranoid).

For ordinary users, it ought to be possible to create something like this using Linux live CDs that is easily accessible/usable, and provides excellent security against all sorts of trojans and viruses (most of which cannot work when you use a live CD, because you're booting from a CD each time).

Example implementation: there are 3 icons on the desktop to switch between "rooms", and built-in intelligence (with a list of "important" URLs that is updated from the net) to prevent him from accessing, say, www.citibank.com if he is in a low-security room, or vice versa, prevent him from accessing unlisted sites when he has switched to a high-security room.