09 June 2007

CentOS 5 follow-up

I've had a week to play more with CentOS 5 on my laptop, and I've overcome a few of the shortcomings that were bothering me last time. It eventually occurred to me that I could use gnome-panel and its pager. That worked out pretty well, but actually I find that I like fbpanel even better. fbpanel is a lot like gnome-panel, but is a little more configurable. And the pager shows scaled-down versions of my wallpaper--not a big deal, but cool.

I was able to build grisbi from source, but I couldn't get OFX support to work. The libofx/openjade/opensp dependency hell was too annoying, so I just turned off that feature. OFX is a file format for financial records. Some financial institutions might be able to deliver your financial records in OFX format, and then you could import them into grisbi (if OFX support is built in). So my build might not be very useful for some people. It's not a feature that I've ever used, so I don't really miss it. I'm just glad to have grisbi working in CentOS 5. Leave a comment if you'd like the spec file.

03 June 2007

CentOS 5

I finally got around to trying out CentOS 5 yesterday (if you're not familiar with CentOS, it's a Linux distribution which is generally binary-compatible with Red Hat Enterprise Linux [RHEL]). Here are a few of my first impressions.

I installed CentOS 5 on my laptop. The laptop is about two years old, and it was nothing really special to begin with (1.67 GHz Athlon Mobile, 1 GB of RAM, video hardware which is probably way too lame for beryl/compiz).

The installation is different, in that you can no longer select 'full installation' or 'minimal installation' in the package selection screen. I really liked those features, and I'm sorry to see them go. Packages are now arranged in groups and subgroups, and you can select which groups/subgroups will be installed (but you can't select individual packages--at least, I didn't see how to). One of the subgroups probably more-or-less corresponds to the minimal install ('base system' or something, I think), and I suppose you can select all the subgroups for a full install. But it was nice having those as selection items in CentOS 4.

One of the big new features of RHEL/CentOS 5 is virtualization (they are using xen). I thought I'd try it out, so I selected the virtualization group in the installation process. This installs a xen-enabled kernel, and it's the default kernel (in fact, it didn't install any non-xen kernels). My laptop is rather noisy anyway, but the CPU fan typically ran two levels higher (faster, louder) than usual with the xen kernel, even when the laptop was idle. That was too noisy, so I installed a non-xen kernel package, and the CPU fan is now running at its normal less-noisy rate. So make sure that your computer has good cooling if you try xen.

There are lots of packages missing. This isn't an issue with a non-full installation: the packages just don't seem to be available at all. Not even in the CentOS extras or in DAG's RPMs. Here are a few examples:
  1. no xpdf and no gpdf (well, DAG has gpdf, but there's no EL5 build), just evince
  2. no xscreensaver (!): there's xlock, which isn't as cool, and DAG has an SRPM for xautolock (I had to remove the BuildRequires from the specfile), but I miss xscreensaver
  3. there's no EL5 build for audacity
  4. no grisbi (ouch)
And I had some trouble building some stuff I like. I use fluxbox, but I can't seem to build fluxter or fbpager, so I'm stuck with no decent pager program.

wpa_supplicant was installed as part of my package selection, but I couldn't make it work. I had to compile a newer version from source.

On the brigher side, it's got more current (than CentOS 4) versions of several packages: OpenOffice 2.0, PHP 5.1, MySQL 5.0, Apache 2.2 (which has mod_proxy_balancer: there was an interesting HowToForge article about mod_proxy_balancer recently).

But all in all, I'm disappointed in losing some of my favorite packages. Guess I need to quit whining and try to contribute specfiles.

31 May 2007

Theater e-Ushers

Saw this today and was mildly intrigued:

High-Tech Tattle-Tale Device Hits NYC Theaters

It's an article about how some NYC Regal cinemas are giving certain patrons the ability to page the management. So if you're one of these patrons and there's something wrong with the movie (sound, focus, etc.), you can page the management to send someone to the projection booth.

This can also be used to rat on unruly patrons, and this is the part that interests me. This is why I rarely go see a film in the theater anymore. It's not because theater admission prices are too high (they are), and it's not because Hollywood churns out utter crap in two-hour installments (it does). It's because I invariably end up sitting in front of some rotten bastard who thinks he's sitting in his living room, who can't keep his feet off my chair and can't keep his big mouth shut.

They just need to take this notion a bit further. If I'm watching a film and the guy behind me is talking back to the movie and kicking my seat, I want to push a button which does one of the following:
  • injects a harmless but potent tranquilizer into the noisy patron
  • closes a high-voltage electrical circuit connected to the noisy patron's chair
  • opens a trapdoor which sends the noisy patron down a metal slide and into a StarWars-like garbage masher, complete with a dianoga
The third option could be further enhanced if the movie could be briefly suspended while live footage from the garbage masher was projected on the movie screen. This would be especially effective in an IMAX theater.

26 May 2007

Firewalling NFS, testing SMTP

Yesterday I found a useful Web page explaining how to use Linux iptables to firewall an NFS server. Firewalling NFS is complicated, because NFS picks random listener ports when it starts up. But by following the instructions on this page, you can edit a few files to tell NFS which ports to use:

http://www.lowth.com/LinWiz/nfs_help.html

If you are using Red Hat (or something similar, like CentOS), you only have to edit /etc/modprobe.conf, /etc/sysconfig/nfs, and /etc/services. The only thing I'd add to this tutorial is that you can just put something like 'STATD_PORT=4000' in /etc/sysconfig/nfs, rather than hardcoding the rpc.statd port number in the nfslock startup file. Then you can use iptables to control access to the following ports (tcp and udp for each port): 111, 2049, 4000, 4001, 4002, and 4003. I actually had to reboot to get nfslock to start up on port 4001. Oh, well.

Another useful Web page shows how to run an SMTP session using telnet (you could also use netcat):

http://www.yuki-onna.co.uk/email/smtp.html

One useful application of this technique is testing the access rules of an SMTP server (for example, making sure you're not inadvertently relaying for certain hosts).

20070521 thunderstorm

Took a few pictures during a thunderstorm the other night, and here are a couple of my favorites:

00003

00005

06 May 2007

More photos (cool clouds)

I took some pictures the other day. It was a day with my favorite kind of weather: it was cloudy and cool, but not rainy. There were some horses in a nearby field, some wildflowers, and some pretty cool-looking clouds. The local topology really worked for me--very flat horizons made the photo contrast image-editing technique very effective.

Here are a few of my favorites.

horses and clouds

cool clouds

landscape w/ cool clouds

clouds and wildflowers

22 April 2007

Storm clouds

Have had some thunderstorms in the last few days. A few nights ago, I heard thunder, and was surprised to see clear skies when I looked out the window. When I stepped outside for another look, I found that the storm was sneaking up over my roof. Took a couple of pictures, which don't quite do it justice.

storm clouds

storm clouds

08 April 2007

grip, gtkpod, id3lib, grisbi

This is a post about some useful GNU/Linux programs I've recently discovered. I use CentOS, and RPMs for these packages are available from karan and/or DAG.

I bought a Sandisk Sansa MP3 player in late 2005. I don't know how I got through the workday before I did that. I've bought two more since then (a larger storage capacity each time). Sansas basically work like external USB hard drives, making them Linux-friendly: you can just drag-and-drop MP3 files onto them. The Sansa's firmware then reads the files' ID3 tags to display a list of available music (ID3 tags are bits of data in an MP3 file which give the artist name, album name, track title, etc.).

Sansas are not compatible with iTunes, and I haven't tried any of the other online music services--I just rip my own CDs to MP3 files. I use grip to rip the CDs. grip is basically a nice, feature-rich graphical interface to cdparanoia and LAME. It'll connect to a CDDB site (like freedb.org) to download album and artist names and track titles, rip the CD tracks to WAV files, then encode the WAV files as MP3s.

Although I can then just plug in my Sansa and start moving files around, it's nicer to have something to keep my music more organized. I use gtkpod for this. I keep all my music files on my PC, and then periodically change what I've got on the Sansa (the Sansa is 4GB, not large enough to hold my entire library). gtkpod is a nice program for displaying what's on my PC, what's on my Sansa, and changing out files on the MP3 player.

Although grip is pretty good about setting the ID3 tags on the MP3 files, it's not foolproof. The ID3 tags will occasionally have errors or be missing altogether. gtkpod has a feature for changing ID3 tags, but I haven't had much luck with this--it sometimes even causes gtkpod to crash. So I usually just use the command-line utilities in the id3lib package. id3info lists a file's ID3 tags, and id3tag and id3cp can be used to change them.

The last software package I want to mention has nothing to do with music. It's called grisbi, and it's a pretty good personal finance program. Although I've never tried Quicken or Microsoft Money, grisbi is probably pretty comparable. I use it to track my checking account. grisbi lets me define a list of transaction categories, and I can tag a transaction when I enter it. grisbi keeps up with my account balance and has features for bank statement reconciliation. It can also run reports, handle scheduled transactions (for things like automated drafts and deposits), and track multiple accounts. I've found it to be a convenient way of balancing my checkbook (much less error-prone than scribbling in the check register).

e-Voting Update, DST Lameness

This is mostly an update to last week's e-voting rant. The Diebold suit against Massachusetts is still in litigation, but it was dealt three significant setbacks this week:
  1. execution of Massachusetts' contract with Diebold's competitor will not be blocked
  2. Diebold will not be granted an accelerated discovery process
  3. and Massachusetts will be able to view Diebold internal documents
An enlightened judge. How refreshing.

Also, HR 811 is making its way through US Congress. HR 811 is an e-voting reform bill which, among other things, requires a paper trail to be an integral part of any e-voting solution. It also forbids e-voting machines to have wired or wireless Internet connections, and it requires that e-voting software source code be made publicly available. Signs of enlightenment in Congress--also refreshing.

And, to no one's surprise, it looks like the change in Daylight Savings Time accomplished very little other than to annoy computer system administrators. Like me. So much for Congressional enlightenment.

07 April 2007

Alternative Energy Sources

In the past few weeks, I've started reading about the environment and alternative energy sources. I'm starting to see that this is a very complicated issue with potentially far-reaching consequences.

An article came out yesterday which gives a very interesting summary of the current state biofuel production. It's a pretty long article, but I would recommend it to anyone who is interested. It paints a rather grim picture.

According to the article, a significant portion of US government funding into alternative energy is directed at the production of ethanol from corn. Although I'm pleased to see the US government taking an interest in alternative energy, corn-based ethanol is arguably not the best solution. There's probably not enough cropland on Earth to grow enough corn to rival the energy produced by burning fossil fuels. More importantly, using so much corn to generate ethanol takes away (and drives up the price of) an important source of food: this may begin to deprive many people in poor nations of a staple of their diet. I was especially appalled to read this in the article: "...filling the 25-gallon tank of an SUV
with pure ethanol requires over 450 pounds of corn -- which contains enough calories to feed one person for a year."

There is also evidence that using corn-based ethanol has only a small benefit over fossil fuels in the creation of greenhouse gases: "The full cycle of the production and use of corn-based ethanol releases less greenhouse gases than does that of gasoline, but only by 12 to 26 percent."

But the US government seems somewhat fixated on corn-based ethanol, due in part to the lobbying efforts of companies like the Archer Daniels Midland Company (adm). I don't like criticizing adm, because they're a big supporter of public television. But they make a lot of money turning corn into ethanol, and they carry a lot of clout in Washington.

The environment has gotten a lot of press lately, and I'm glad that awareness of these issues is increasing. But I'm starting to think that it's just not happening fast enough. I think we should all try to find ways to conserve resources and to help our governments find ways to better prepare for the future. I think the US and Chinese governments should start pouring money into researching and developing solar power, wind energy, and cellulosic biofuels (which is made from wood chips, trash, and other stuff no one wants).

This has turned into more of a rant than I intended, so I'll end with the addresses of a few interesting Web sites I've recently discovered (they all have RSS feeds):

Hopeless RSS Addiction

I have become hopelessly addicted to RSS.

RSS (really simple syndication) is a special data format (called XML) used to provide an alternate way of reading Web site content. Most blogs have RSS feeds, and the blog you're reading now is no exception:

http://mbrisby.blogspot.com/feeds/posts/default

RSS feeds aren't really readable on their own, but they're very powerful if used in an RSS reader. You 'subscribe' to a Web site's feed in your RSS reader, and whenever new content appears on that Web site, it shows up in your RSS reader. The advantage of this is that if you follow a large number of sites with feeds, you can see the updated content of all of them in your RSS reader, rather than having to visit all the sites individually: it's one-stop shopping for all your Web-reading needs.

This is a huge help to me, as I need to monitor lots of Web sites which post information about software updates. Without RSS I'd need to spend a significant portion of each day checking all those Web sites individually for updates. But if I subscribe to their feeds, the announcements just show up in my RSS reader.

This is also useful for keeping track of news Web sites (most of which have RSS feeds).

There are lots of different RSS readers, but they all work more-or-less the same way. You subscribe to a list of feeds in the reader, and the reader periodically checks each feed for new content. When a new item shows up in a feed, the reader displays the new item. If it's a new item on a news Web site, for example, you'll typically see the story's title and an excerpt from the story. The title is likely a link, and clicking the title takes you to the full version of that story on the original Web site. Once you're done looking at the new item, you tell the reader to discard it, and the reader doesn't show you that item any more (just new items). However, many readers allow you to somehow save interesting items, so that you can look at them later.

I've tried several RSS readers over the last year or two. First I tried the Sage Firefox extension. It's pretty cool, but because it's part of your browser configuration, it's only effective on your computer. If you're at a friend's house, even if your friend has Firefox with the Sage extension installed on her computer, her Firefox won't know about your feeds. And even if you subscribe to your feeds on your friend's computer (which may or may not thrill your friend), her computer will display a bunch of items which you've already seen (because her computer doesn't know which ones you've previously read).

The RSS reader in Thunderbird is OK, but it has the same set of problems as Sage: it's configuration and history are stored locally on your computer. So Sage and Thunderbird are fine, as long as you only read RSS feeds on one computer.

In an effort to learn more about RSS (and AJAX), I even wrote my own Web-based RSS reader (I wrote it in Perl w/ CGI::Application, and I used script.aculo.us for the AJAX), and I used that for several months. It ran on my home computer, to which I have a VPN connection from work. So I was able to read my feeds from work or home. While that was a big improvement, it didn't work if I was somewhere other than home or work.

So I recently started using Google Reader, and I think it's a great solution. It's full-featured, in that it lets you categorize your feeds and save items for later (you can 'star' an item), and it's accessible from any computer with an Internet connection. You just point a browser (Firefox, MSIE, whatever) at http://www.google.com/reader/view/, log in, and start reading.

If you need or want to keep track of a large number of Web sites (as long as they have RSS feeds, which unfortunately not all do), I highly recommend using Google Reader. As of this writing, I am using it to keep tabs on 58 Web sites.

01 April 2007

Trees

Took some pictures at work the other day. Trees are in bloom, and the colors were pretty impressive. My favorite picture in the set has purple-, brown-, and green-leaf trees in front of a deep blue sky:

trees in bloom

1 April Mayhem

I really hate April Fool's day. Until I remembered the date, I briefly believed a Slastdot post asserting that Mozilla is suing Microsoft for $1.4 billion over tabbed browsing, and I honestly can't decide whether or not to believe a post on The Energy Blog about cars that run on air.

*sigh* It'll be like this all day. Christmas for geeks.

31 March 2007

Recent e-Voting Developments

There were a couple of interesting e-voting-related items in the news this week.

The state of Massachusetts decided to purchase a large number of e-voting machines, and they solicited bids in order to select a vendor. They ended up choosing AutoMARK, a competitor of Diebold. Diebold, annoyed at losing a $9 million contract, is suing the state of Massachusetts. The term 'sore losers 'comes to mind.

The state of California is looking at imposing a very strict set of requirements for e-voting machines. These requirements are in fact so strict that no e-voting vendor may be able to meet them in time for the presidential primary in February 2008 (which is about four months earlier than in previous elections), which might mean that the election will be conducted with paper ballots.

The articles state that both decisions (Massachusetts' AutoMARK selection and California's interest in tougher standards) were motivated at least in part by legislation requiring voting facilities for voters with certain types of disabilities.

In a somewhat related story, the New York Review of Books published an article which contains some interesting speculation about the outcome of the 2000 presidential election had Florida prisoners been allowed to vote. This is a fairly long article, but it's one of the most thought-provoking things I've read in a while.

25 March 2007

Batman on Film

Last night I rented Batman Forever (1995, 'BF' hereafter, w/ Val Kilmer as Batman) and Batman & Robin (1997, 'BnR' hereafter, w/ George Clooney as Batman). I don't think I'd seen either (not in their entirety) since each came out. I vaguely remembered that neither was a particularly good film.

Turns out that my memory was quite accurate, if somewhat understated. Ewwww.

However, each had a couple of nice surprises that I didn't remember. BF has a pair of pretty good songs by U2 and Seal, although you have to slog through to the end credits to hear them. And Drew Barrymore and Debi Mazar make for pretty sexy window dressing as Sugar and Spice in BF. BnR has fun (albeit brief) performances by Vivica A. Fox and John Glover (he's Lionel Luthor in "Smallville"). And Uma Thurman is a very provacative Poison Ivy.

Otherwise, they're both pretty grim, and they don't hold a candle to Batman Begins (2006, w/ Christian Bale as Batman). I'm really looking forward to The Dark Knight (supposedly 2008, w/ Bale again).

Recent Reading

I've recently finished reading a couple of pretty good books. I just (a few minutes ago) finished The KILL BILL Diary: The Making of a Tarantino Classic as Seen Through the Eyes of a Screen Legend by David Carradine. Carradine turns out to be a pretty good writer. If you enjoyed the movies, you'll like this book. It has some interesting observations into the making of the films (which were evidently originally intended to be released as a single film).

And a few days ago I finished Weapons of Choice by John Birmingham. The premise is that a multinational naval armada from 2021 is zapped back in time to June 1942. This disrupts the battle of Midway, and the multinational fleet's presence begins to alter history. This is the first part of a trilogy. I liked it so much that I bought the other two books even before I finished reading the first (which ends with a pretty cool cliffhanger).

10 March 2007

More on passports and e-voting

A recent article from The Register describes some passport-cloning research (these are UK passports). These people were able to read and clone the RFID data while the passport was being mailed to the owner, before he/she even had the chance to take possession of it.

And it looks like Diebold is thinking of getting out of the e-voting business. I guess they think that all the bad press about security problems in their electronic voting machines has damaged their image. So rather than trying to improve the technology, they'd rather just dump the whole thing. So scads of expensive e-voting machines would remain in service (because municipalities blew their budgets buying them in the first place, and may not be able to replace them for a while), with a big question mark over the prospect of future support and updates. Classy.

25 February 2007

Tiny RFID tags

The BBC has an article about recent innovations in the miniaturization of RFID technology. The image at the top of the article is particularly astounding: these RFID chips are smaller than the width of a human hair. The very image suggests the possibilty of putting RFID tags in someone's hair gel and using the tags to track that person. That statement no doubt sounds paranoid, and maybe it is. But the fact that these things are getting so small means that surreptitiously distributing these devices is getting easier.

better-than-wholesale e-voting machines

Wired has an article describing a method one computer science researcher is using to acquire e-voting machines for security analysis: he bought them cheap off eBay. No background check, no non-disclosure agreement, nothing. And by cheap I mean he paid $82 for $25,000 worth of Sequoia e-voting equipment (that's a 99.672% markdown).

Although the Wired article claims that the research finds these machines to be more secure than products from competing companies, the researcher's Web page about his evaluation paints a dimmer picture.

17 February 2007

Media collection software

linux.com has had articles about a couple of media collection programs called gcstar and data crow. They're similar in concept: both are databases for your CDs, DVDs, books and such. Each allows you to enter your collections with searches of amazon.com, imdb.com, etc. So if you have a copy of X2 on DVD, you can type 'X2' in the search field and it'll retrieve the cast list, cover art, plot summary, and other stuff.

gcstar is built on Perl and gtk2, and data crow is built on Java. So both are more-or-less cross-platform (they run on Linux, Windows, and probably OS X).

Both also allow the user to add loaning information to records. If you loan your copy of X2 to someone, you can make a notation of that as part of the X2 record. And both let you import and export your data (gcstar seems more flexible in this regard, in that it supports a fairly wide variety of formats).

I've tried both, and I'm finding gcstar to be more reliable. data crow is pretty crashy, and I gave up on it.

Some drawbacks to gcstar are that you can only select one item from the results of a search. If you have several Star Trek DVDs and you run a search for 'star trek', you can only select one of the search results to add it to your collection (you have to run a separate search for each Star Trek DVD you own). It would be nice if you could do Ctrl-click to pick Wrath of Khan and The Undiscovered Country if they both show up in the search results (data crow actually lets you do this).

And gcstar also has gtk tooltips which pop up when you mouse over the items in your search results. These tooltips sometimes make it hard to click on the search result that you want.

And it seems that the current version of gcstar (v1.1.1) is less than completely compatible with the version of the Gtk2 Perl module currently available in CPAN (v1.142, 21 January 2007). To make it work, you have to comment out the set_row_separator_func() and set_focus_on_click() calls in a couple of gcstar modules. Lame.

I actually prefer the data crow interface, but it kept hitting out-of-memory errors. I had to restart the application pretty frequently. That was beyond annoying. So for now I'm using gcstar.

14 February 2007

RFID passport

My new passport arrived in the mail today, and it's got an RFID tag in it.

Crap.

(Here's my previous whining about passports.)

13 February 2007

Huge hole in the water

This is one of the coolest things I've seen in a while. You know that hole near the top of your bathroom sink which keeps it from overflowing? They put those in some reservoirs. I would love to see one of these in person.

ssh security features

ssh offers ssh keys as a nice alternative to password authentication, and putty is a pretty cool ssh client for Windows. There's a good tutorial on howtoforge which discusses many of the features of the putty suite including key generation (puttygen) and putty's ssh-agent (pagent).

And as the above article mentions, the PasswordAuthentication option in sshd_config can be cleared to force the use of ssh keys (password authentication will be disabled).

AllowUsers is another good sshd_config option. It can be used to provide a list of users who can connect via ssh. Any user not in this list can't connect by ssh. It's good for defeating ssh scans which try a few passwords against common account names (like root, guest, etc.). Another trick that might help dodge ssh scans is to run ssh on a port other than 22. The ListenAddress sshd_config option can be used to run ssh on some other (non-standard) port.

A nice trick for your ~/.ssh/authorized_keys file is to specify source hosts from which you can connect using certain keys. If you have the following in your authorized_keys file, then the key in question can only be used for connections from the hosts listed in the from list:
from="this_host,that_host" ssh-dss ...key data... USER@HOST
(This is discussed in the 'AUTHORIZED_KEYS FILE FORMAT' section of the sshd man page.)

Finally, the denyhosts project claims to be able to do dynamic edit to the tcpwrappers files (/etc/hosts.deny) when dictionary attacks are detected. It would probably be really useful for a server with lots of ssh users that need to log in from anywhere/everywhere.

10 February 2007

Checksum verification of large downloads

When you download software, the vendor often provides a checksum or a digital signature. If you download the software and then compute the checksum (or verify the signature), you're reading through the download twice. If the download is large (like a Linux kernel source archive or an ISO image), it can take a long time. Here's a way to do both at once.

If the vendor provides an MD5 checksum, try this:

wget -O - http://www.example.com/large_file.tar.bz2 |\
tee huge.tar.bz2 | md5sum

The -O - option tells wget to write the download to standard output, rather than to a file. Piping that to tee writes the download to a local file (huge.tar.bz2) and to standard output, and this is piped to md5sum: the checksum is printed to the screen.

You can do the same trick for an SHA-1 checksum (or any other digest supported by openssl):

wget -O - http://www.example.com/large_file.tar.bz2 |\
tee huge.tar.bz2 | openssl dgst -sha1

If the vendor provides a detached signature, you can do a similar trick. As an example, let's use the bzip'ed 2.6.0 patch file for the Linux kernel and the corresponding signature file. First grab the signature file, then the patch file:

wget http://www.kernel.org/pub/linux/kernel/v2.6/patch-2.6.0.bz2.sign

wget -O - http://www.kernel.org/pub/linux/kernel/v2.6/patch-2.6.0.bz2 |\
tee patch-2.6.0.bz2 |\
gpg --keyserver pgp.mit.edu \
--keyserver-options auto-key-retrieve \
--verify patch-2.6.0.bz2.sign -

In this case, you're piping the download into gpg, telling it to verify the data coming in on standard input (the '-' at the end) against the detached signature file. The --keyserver and --keyserver-options items tell gpg to fetch and import the key if necessary (this example uses pgp.mit.edu as the keyserver, but there are lots: type 'keyserver' into a search engine).

09 February 2007

Norah Jones' new album

If you get a chance, go pick up a copy of Not Too Late by Norah Jones. As much as I like her first two studio albums, I think I like this one even more.

31 January 2007

destroying democracy the easy way

A recent slashdot post caught my eye. It involves two of my favorite topics: e-voting and lockpicking. According to the slashdot article, Diebold (a company which makes e-voting machines) recently posted, on their own freaking Web site, high-quality images of the key which can be used to unlock the access panels on their e-voting machines. The images were apparently good enough that it was possible for someone to make a quick trip to Home Depot, buy a metal file and a few blanks of the right kind of key, file the keys to the correct shape, and start unlocking Diebold machines.

Word to the wise: next time you feel like photographing your keys (and let's face it, who doesn't love photographing their keys?), put the pictures in a scrapbook on your bookshelf, not the Internet.

flickr: more 'screw the users!' from yahoo

Yesterday photo-sharing Web site Flickr (owned by yahoo) announced some changes which have angered lots of their users. Each flickr user will have to start signing in with his/her yahoo account username/password (lots of users currently log in with a flickr username/password, so they'll have to change), and there are some new limits being imposed on flickr data (there will soon be a limit of 3000 contacts and a limit of 75 tags per image).

I only recenty started using flickr, and have used my yahoo account for all of that time. And the new limits don't affect me. So this isn't too big a deal for me personally. But it's another example of arbitrary changes imposed with little or no warning or user involvment, much like the recent utter ruination of yahoo TV. Not everything they do is horrible: I like the new yahoo mail (beta). But if they keep alienating their users, they may find that their shiny new upgrades aren't that good for business.

Image inputs in MSIE7 -- revisited

My previous post was a whinefest about image inputs in MSIE 7. This problem turns out to be worse than I thought. In that post, I said that the problem could be circumvented by taking either of two measures, one of which was changing to a submit-type input element. Today I found out that this solution is inadequate, because the name/value pair are still not sent in the POST data if you hit return rather than clicking the submit button.

<* input type="submit" name="ick" value="gakkk" />

If you actually click the submit button in a form (in MSIE 7) containing the above code, then the ick/gakkk pair will be included in the POST data. But if you just hit the return key in the form (which is how I typically submit forms), the ick/gakkk pair won't be sent.

So, I'll have to stick with the other corrective measure and put the ick/gakkk pair in a hidden input, replacing the above HTML with this:

<* input type="hidden" name="ick" value="gakkk" />
<* input type="submit" value="MSIE 7 blows" />

Crap.

09 January 2007

Image inputs in MSIE7

I saw a post in the last couple of days saying that <* input type="image"> doesn't work in MSIE7. I've recently been working on a project which happens to have one of these elements. I tested it in MSIE7 today, and sure enough, it doesn't work. But it's broken in a very subtle way.

The element in my project looks like this...

<* input type="image" name="ick" value="gakkk" src="button.jpg" />

...and the interface to which this form POSTs looks for the ick field. Looks to me like MSIE7 just doesn't send any name/value data in one of these elements when the form is submitted. All the other form fields make it into the POST data, just not the ick/gakkk pair.

Either of the following seemed to make it work as expected:
  1. turning the input element into a normal type="submit"
  2. moving the ick/gakkk name/value pair into a hidden input element in the form
I don't know if this is a bug in MSIE7 or if it is intentional behavior. The W3C HTML4.01 recommendation for the input element lists the name and value attributes, with no obvious (to me) exception for image-type input elements.

*sigh* Just one more stupid thing I have to remember when designing Web applications.

07 January 2007

Ice storm aftermath

Pictures taken after an ice storm in Versoix, Switzerland. The icicles on the trees are pretty amazing.

This was posted on digg.com, where several of the commentors said that since the ice blew in off Lake Geneva, it's not really an ice storm. Whatever. It's a lot of ice.

Brrrrr.

30 December 2006

superhero/supervillain quiz

There's a pretty cool quiz at http://www.thesuperheroquiz.com/ which tells you which superhero you most resemble. I turned out to be the Hulk (70% likeness). This puzzled me until I remembered answering "all the way YES" to "do you anger quickly/easily?".

After you take that quiz, there's a link to find out which supervillain you most resemble. Looks like I have an 86% correspondence to Dr. Doom: "Blessed with smarts and power but burdened by vanity." (That latter part might sting if it were less accurate.)

28 December 2006

gmail backup

Today there was a report of some data loss for 60 gmail users. They lost all their mail, their address books, etc. Lame.

This prompted me to look into methods of backing up my gmail account. Looks like it's a simple as changing a gmail setting (enabling POP3) and setting up a POP3 account in your favorite mailer (Thunderbird, Outlook, ...). It's a straightforward procedure. It takes a while to download all your mail the first time, and thereafter it just downloads new messages. It probably wouldn't allow a user to restore a mangled gmail account, but it would at least provide an external backup of all the messages. Unfortunately, it doesn't look like this process preserves message labels.

And it looks like you can export your address book, too: click 'contacts' (left-hand panel) and then click 'export' in the upper-right.

18 December 2006

vmmouse for Linux VMWare guest

I decided to give Ubuntu a try to see what all the fuss is about. But I wasn't ready to install it on my laptop (I'm in the middle of a project in which I rely quite a bit on the laptop), so I decided to try Ubuntu in VMWare server on my desktop. Ubuntu installed OK, but the mouse didn't work well: I had to click in the VMWare window to make the mouse work in Ubuntu, and then I had to press Ctrl-Alt for VMWare to release the mouse (to use it anywhere outside the VMWare window). It was doing this even after I installed VMWare-tools.

That's a real drag, all the more so since that doesn't happen when running Windows XP in VMWare (the mouse 'just works': you can just roll the cursor in and out of the VMWare window and it works as it should).

The trick is to install the 'vmmouse' driver (which comes with VMWare-tools) in X.org in the Linux guest. (This solution comes mostly from a post by 'zaroff' on the Ubuntu Forums.)

After installing Linux in VMWare server, click VM->Install VMWare Tools... on the VMWare menu. This makes Linux think you've just mounted a CD with a couple of files on it (the 'CD' will probably show up on the desktop). Unpack the .tar.gz file, cd into the vmware-tools-distrib directory, and run the vmware-install.pl installer.

When I did this, I found that when the installer re-wrote /etc/X11/xorg.conf, it didn't put in a DefaultDepth directive in the "Screen" section, and I had to add a DefaultDepth 24 line to that section.

Next you need to install the vmmouse driver. A good start is to run the following inside the vmware-tools-distrib directory:
find . -type f -name 'vmmouse*'

You need to copy the correct vmmouse driver (depending on what version of X.org your Linux guest is running) into the X.org input modules directory. For an Ubuntu 6.10 Linux guest, I needed to copy the XOrg/7.0/vmmouse_drv.so to /usr/lib/xorg/modules/input. (A friend was having the same trouble running a CentOS 4.4 guest: he needed to copy XOrg/6.8.x/vmmouse_drv.o to /usr/X11R6/lib/modules/input/.)

Next you need to make 2 changes to /etc/X11/xorg.conf:
  1. add Load "vmmouse" to the "Module" section
  2. change Driver "mouse" to Driver "vmmouse" in the "InputDevice" section
Then restart X (or reboot).

Fedora Legacy Project Closing

I maintain several front-line servers (exposed to the Internet) which have run Fedora Core 3 (FC3) for a couple of years, and I have relied on the Fedora Legacy Project to provide security updates for those servers. The Fedora Legacy Project is a community project providing security updates to versions of Fedora and Red Hat which are no longer supported by Red Hat.

The project has gone above and beyond, and I'm grateful for their efforts.

Last Tuesday (12 December 2006) they quietly announced that they will no longer be providing updates for FC3, FC4, or any other damn thing. I say 'quietly', because I didn't hear about for nearly a week. I don't think it made digg, Slashdot, or any of the other technology-related Web sites that actually have RSS feeds. I'm not upset that they ended support--I'm happy that I was able to run that Linux distribution (especially one as volatile as Fedora) for as long as I did. But for the support to dry up with no warning (at least, I didn't see it coming), and for me to get that news less than a week before the holiday break at my work, really sucks out loud. Now I have to bust my hump to install a operating system with some measure of support on all those servers before Friday.

Thanks for all the advance notice! Happy freakin' holidays!!!!!

17 December 2006

Downloading YouTube ...

Saw this yesterday and thought it was cool. The All-In-One Video Bookmarklet lets you download videos from YouTube, Google Video, and a number of other Web sites. You save the bookmarklet (go to the above link, and then on that page right-click on the All-In-One Video Bookmarklet link and pick the bookmarking option), go to the Web page of a YouTube/Google/whatever video you want to save, and then hit the bookmark. You'll get a page which allows you to download the movie in one or more formats.

If you want to try this out, here's a link to a short and funny video about a cat with depth perception problems (remember that you'll have to go save the bookmarklet first). That video makes me laugh out loud every single time (I think it's the sound that really does it for me).

ePassports

For months I've been reading about these new passports. And for months I've been meaning to go get a passport, in hopes of getting the old kind. I'm probably already too late.

The new passports have RFID chips in them. RFID stands for radio frequency identifier. An RFID chip is a small device which transmits short-range signals which uniquely identify the transmitter. This sort of thing has been used for years for stuff like electronic toll collection systems. You have an RFID transmitter in your car so that you can roll through the toll booth without stopping to pay. The toll booth electronically records your passage, and you get billed later.

Unfortunately, RFID raises all kinds of security and privacy concerns. RFID tags are useful, because they can be read so easily. No physical connection (like swiping a credit card or ID badge) is required: proximity is sufficient for an information exchange. But this means the information can be collected by someone other than the intended recipient. It's been shown over and over again that information stored in RFID tags can be read surrepticiously with inexpensive, off-the-shelf equipment. A recent example involves RFID chips in sneakers.

And now they're putting these things in passports, and the same kinds of remote information retrieval have been demonstrated. Government agencies implementing these technologies say that it's safe. But what else are they going to say? They've invested a lot of money in these systems, so they're not necessarily objective or fothcoming.

One of the things in my job that really annoys me is the "Ooooh, shiny!" mentality: people see something new, and they want it just because they thing it's cool, not necessarily because it's a good idea. This is the feeling I get about RFID in passports. I think people are jumping on a bandwagon without taking the time and effort to do reasonable risk analysis.

A number of interesting RFID countermeasures have surfaced:
Bruce Schneier has a good write-up about the new passports.

10 December 2006

Maritime movies: eating and crashing

A couple of interesting posts made it to digg.com homepage overnight. One concerns a company which makes tables for boats. These 'capstan' tables are expandable, like a rectangular table which can be enlarged by adding leaves. But these tables are round, and they get bigger or smaller just by rotating them. Check out the movie clips. (Here's the digg post w/ comments.)

The second clip shows an accident in which a boat crashes into a bridge (apparently no one was hurt). This is a moving bridge--I saw one of these at OSCON in Portland. This one isn't a drawbridge, but a 'lift' bridge: the motorway lifts straight up using cables and pulleys, leaving room for the ship to pass underneath. When watching the video, pay close attention to the bridge at the beginning of the clip. (Here's the digg post w/ comments.)

09 December 2006

interesting pictures

I took a couple of weird pictures recently.

The other day I was about to leave my apartment for work, and I saw this just outside my door. The faucet was dripping, and it made a cool-looking ice stalagmite:
ice stalagmite

And the other night I was throwing away a beer bottle (yes, I'm destroying the environment--talk to my state legislature), and it made a funny sound when it landed. When I looked at the trash can, I saw that the bottle had landed on the edge, and the bottle's tip had come to rest on the table. I thought about computing the odds against this, but then decided just to go get another beer.
beer bottle balanced on trash can

I'm in Dilbert

A co-worker referred me to the 22 November 2006 Dilbert cartoon, and I thought it was pretty funny.

03 December 2006

Yahoo TV Completely Ruined

I've used Yahoo TV listings for years. They changed it the other day, and the new version is utter crap. It used to be simple and fast. Here are a few of my more vitriolic gripes:
  1. the page loads a little bit at a time as the user scrolls down the page: so browser searches don't work, and it's very slow
  2. you can only browse in 3-hour increments: if a show starts prior to the current 3-hour block, you can see that something is showing, but you can't see what it is
  3. it doesn't remember that I only want to see my favorite channels: it defaults to showing every channel offered by my cable provider
Two digg posts about this have made it to the front page, and there's a post on Yahoo's blog about the change. The comments on all three of these are overwhelmingly critical:
I'm really hoping they'll change it back (or at least make it suck less). I admit to being generally inflexible: I typically don't like change under the best of circumstances. But this is pretty disappointing. There are several other sites offering online TV listings. Guess I'll switch to whichever one pisses me off the least.

11 November 2006

Lockpicking Guide

Locksport International (LSI) has created a pretty interesting guide to lockpicking. It talks about the techniques of picking locks and how to make the tools:

LSI Lockpicking Guide (HTML)

LSI Lockpicking Guide (PDF)

There's also lockpicking101.com, a set of forums about lockpicking.

10 November 2006

248 ways to annoy people

I thought this was pretty funny:

http://www.dbooth.net/internerd/annoy.cfm

#216 is my favorite, with #185 a close second.

03 November 2006

Interview w/ Slackware's Patrick Volkerding

I used the Slackware distribution of GNU/Linux for several years. It was my first distribution, and I think it's a really interesting project. That distribution's creator, Patrick Volkerding, recently sat for a 90-minute interview with the Linux Link Tech Show (direct MP3 download). I'd never heard his voice before. It's a good way to waste an hour-and-a-half.

Griffith Observatory Reopens

Looks like the Griffith Observatory reopened today after a $93 million four-year renovation and expansion project. It was closed during my visit to LA a few months ago, which was disappointing. Oh, well. Maybe next time.

28 October 2006

Perils of e-Democracy

The following article details some of the hazards of electronic voting. It's somewhat long, but it's very interesting (and a bit frightening):

How to steal an election by hacking the vote

I especially like the default password of '1111' on the voting machines, and the fact that this is probably still the password on a large number of these machines. And the fact that the same key (the same little chunk of metal) will access the memory card on every single machine.

22 October 2006

20 Worst Video Games of All Time

The following article lists what the author things are the 20 worst video games ever...

http://seanbaby.com/nes/egm.htm

And the reason I think this is blogworthy? I had a copy of the #1 game as a kid. Yeah, it sucked.

04 October 2006

Season 3 premiere of Lost

I watched the season 3 premiere of Lost tonight.

I bought season 1 on DVD a little over a year ago having never before watched the show. I was hooked after about 2 episodes. But by the time I finished watching season 1, season 2 had already started. I didn't want to come into the season partway, so I just didn't watch season 2 until I bought that on DVD about a month ago.

So tonight was the first time I'd watched Lost in prime time. I gained two pieces of insight from the experience:
  1. Lost rocks
  2. commercials suck
I'm just hoping that season 3 of Lost is better than season 3 of Alias.

13 September 2006

*NIX directory listing into MSExcel

Today a co-worker asked me to help him prepare a report of email accounts on a Linux box running postfix. He wanted a list of the inboxes, their sizes, and their dates of modification. He wanted it in a text file that he could import into a spreadsheet program. After some experimenting, we came up with the following:


ls -lt --time-style=long-iso /var/mail/
| grep -v ^total
| awk '{ print $5 "," $6 , $7 "," $8 }'
| sed -re 's/$/\r/'
> /tmp/mail_list.csv


The -lt argument to ls gives the long listing and sorts by modification date (in descending order), and the --time-style=long-iso argument ensures that the timestamp format is uniform for all files (without it, you might get one timestamp format for files younger than about 6 months and a different format for older files).

The slash at the end of /var/mail/ is also important, as /var/mail is often a symlink to /var/spool/mail/, and ls -l /var/mail lists the symlink rather than the contents of the referenced directory.

ls -l of a directory typically produces a line resembling total NNNN (where NNNN is some integer) at the beginning of the output, so the grep -v ^total filters out any line starting with 'total'.

The awk command pulls out the 5th, 6th, 7th, and 8th columns of the space-separated text and formats the output as CSV (comma-separated variable). A couple of lines of output might look like this:

41951950,2006-09-13 05:29,root
723,2006-06-13 14:37,martinez


The sed filter inserts a carriage return character (\r) in front of each newline, giving the text DOS line termination (saves us the extra step of running unix2dos on the output file).

Finally, the output is redirected to a file which can be downloaded via an SFTP client and then opened in MSExcel by simply double-clicking on the downloaded file.

12 September 2006

Unholy Version Control

Not long after lunch today my Subversion repository hit revision number 666.

My first instinct was to draw a pentagram on my computer monitor in goat's blood. It then occurred to me that I had neither a readily-available supply of goat's blood nor the means to acquire any.

It also occurred to me that drawing a pentagram on my monitor in goat's blood might make it difficult to use my computer and that my employers might find the whole thing somewhat difficult to understand.

So I just pushed along to #667.

11 September 2006

_Lost_ season 2

Last night I finished watching Lost season 2 (I bought it on DVD last week). Wow. Can't wait for season 3 to start (looks like that's on 4 October).

_Manhunt..._ by James L. Swanson

The other day I finished reading a really good book called ManHunt: the 12-Day Chase for Lincoln's Killer by James L. Swanson. I never knew (or didn't remember) that Booth wasn't acting alone: he was the ringleader of a larger conspiracy whose original plan was actually to kidnap Lincoln and take him into the Confederacy. Then when Lee surrendered at Appomatox, Booth and his co-conspirators changed their plans and created a scheme to kill not just the President, but also Vice President Johnson and Secretary of State Seward--all on the same night. In fact, General Grant was supposed to be attending the play that night in the same box as the Lincolns. If Grant hadn't changed his plans, he might have been there when Booth attacked.

It was a fascinating book. It appears to have been very well researched, and the author has a gift for narrative prose (this is coming from a reader who typically has trouble being interested in reading historical accounts).

06 September 2006

Video of 'bumping' locks

Today I found a video demonstrating the 'bumping' technique (see a previous post of mine). It looks frighteningly easy.

http://video.google.com/videoplay?docid=-5177213949300140850

02 September 2006

LA trip

I went on vacation with friends to LA about a month ago. It was a fun trip. I flew out with L, K, A, and M on Saturday 5 August to LAX. We rented a car and drove to Valencia, where we met H and R.

I've uploaded some of my pictures from the trip to a Flickr set.

We went into Hollywood on Sunday and walked up and down Hollywood Boulevard. It was pretty cool seeing the stars on the sidewalk. I especially enjoyed the Kodak and Grauman Theatres.

Hollywood Boulevard

We ate at the Wolfgang Puck restaurant (Vert) in the Kodak Theatre. If you get the chance, try the chicken salad.

On Monday, K, L, A, and M went to Six Flags (Magic Mountain), and H, R, and I took a day trip. This was probably my favorite part of the vacation. It was very relaxing and beautiful. We had lunch at a little French restaurant in Ojai, and then we stopped and took a few pictures of the lake at Ojai. Then we went to Santa Barbara and spent an hour or so on the beach. Santa Barbara is really pretty, and I think I'd like to go back and spend some more time there. We also walked around in Ventura for a couple of hours before heading back to Valencia. That night, H, R, L, A, and I had dinner at a great place in Valencia called BJs. They have really good beer.
the lake at Ojai
the Santa Barbara beach

We spent Tuesday at Universal Studios. My favorite part was the Waterworld show. I hadn't seen the movie, because I'd heard it was pretty bad, but the live show was awesome. (I've since watched the film. Wow, it's really terrible.) I don't usually do roller coasters (translation: never), but L convinced me to ride the Mummy. It's an indoor coaster, and it was pretty fun (except that the woman sitting next to me desperately needed a shower, and she kept elbowing me in the face). We rode it twice and got pictures. We took the studio tour, and that was very cool. It was neat seeing the outdoor sets that I've probably seen in scores of movies and TV shows. That's an impressive amusement park--it's really huge.

Wednesday we moved from Valencia to Santa Monica, and we drove out to Burbank to see a taping of "The Tonight Show." That was really interesting to me. They filmed it in real time, so the whole thing just took an hour or so. The band (with Kevin Eubanks) played during the commercial breaks. I was amazed at how small the set is. They really make it seem much bigger on the show. Mariska Hargitay was supposed to be the first guest that day, but she cancelled due to a family emergency. I hadn't heard of the guests who did appear: a rather forgetable actress, a very forgetable musical guest, and an interesting fellow named Travis Pastrana, who did a double backflip on a motorbike at the X Games.

Thursday we just hung out on the the beach, lounged around at the hotel, and checked out the Santa Monica pier. That night we ate a delicious meal at
Sushi Roku at Santa Monica and Ocean.
Santa Monica beach at twilight

Friday we drove from LA to Vegas. We'd planned to fly, but that was just a day or so after the terrorist scare. None of us wanted to deal with airport security, and it was just a four-hour drive, so we braved the heat and headed into the desert. It wasn't what I expected. I guess I was expecting the Sahara with nothing but sand and dunes, but there were plants and mountains. It was really quite beautiful. We stayed at the Golden Nugget that night. E and D met us there, and it was really great seeing them. That night we walked around on Fremont Street and saw the light show.
desert near Las Vegas

Then Saturday A, H, and I flew home. We expected trouble at the airport (because of increased security measures), but it was no big deal. I think M said it was less than 30 minutes between our arrival at the airport and getting through security.

28 August 2006

Nightmare

Just had a nightmare. I don't remember much, but I remember that there was a woman, and she was some sort of time paradox. If I were to encounter her, it would somehow erase my own history--I'd never have existed.

I woke up, and she was standing in my room, talking to me.

That's when I actually woke up, because I think I was moaning and crying out.

What do you do when even your nightmares are stupid?

26 August 2006

Defeating locks by 'bumping'

This is probably one of the most interesting things I've read in a while. It's about defeating consumer-grade locks with a method called 'bumping', which I guess is somewhat similar to picking, but supposedly faster and more reliable. Assuming the accuracy of the article, it's scary how easily these locks can be nondestructively defeated.

http://www.engadget.com/2006/08/24/the-lockdown-locked-but-not-secure-part-i/

At any rate, I learned a lot about how locks work.

28 July 2006

OSCON day 5

Short day today (just two morning sessions after the keynotes). Damian Conway gave a very funny keynote about patents. He's a really good speaker.

My first session was "Extreme Perl Makeover" by Peter Scott. This was another 'best practices'-type talk. The speaker suggested a couple of useful-sounding Perl modules: Text::Outdent sounds good for doing HERE documents without having to move them over into column 1, and Inline::Files lets you have several separate data sections after __END__.

Next was "Perl Hacks You Never Knew Existed" by chromatic. Just about everything he said went right over my head. But his talk got me interested in the Attribute::Handlers and Attribute::Method modules, which implement the subroutine attributes that I've seen in Catalyst and Class::Std. I managed to overcome the urge to get chromatic to sign my new copy of Perl Testing: A Developer's Notebook.

27 July 2006

OSCON day 4

One of this morning's keynote speaker was a fellow named Jason Scott. He made a documentary about the online bulletin board systems of the 1980s. His Web site is www.textfiles.com.

Some pretty cool sessions today. The first was "Subversion Best Practices" by Ben Collins-Sussman and Brian Fitzpatrick (both from google). A lot of what they said I'd gotten from the documentation. But they talked about a couple of features I hadn't heard of: autoversioning and autoprops. And they described a neat trick involving making the document root of a Web site be a working copy of a project, with a hook such that the working copy is updated whenever there's a change in the repository.

Next was "Low-Maintenance Perl" by Perrin Harkins. Most of his talk was along the lines of "don't do this in your code". Most of the things he discouraged were things I hadn't heard of or knew to be generally 'bad'. So that was somewhat encouraging. Damian Conway and Larry Wall were both in the audience--if this made the speaker nervous, he didn't show it.

After lunch (which was provided by OSCON [Aramark]), I went to "SQL Outer Joins for Fun and Profit" by Bill Karwin. He solved several interesting problems with outer joins. He used a syntax that I hadn't really seen before: he put row-elimination statements in the ON clause, stuff I'd only ever seen in WHERE clauses. He pointed out that the WHERE clause isn't evaluated until after the join, so it's often quite beneficial to eliminate rows in the ON clause (fewer Cartesian products that way).

Next was "Writing Maintainable Code with PHP" by Laura Thomson from OmniTI. I actually found her point of view a little puzzling. She said that, in general, she doesn't like frameworks, database abstraction layers, or templating engines. As I've come to rely pretty heavily on the latter two and am interested in starting to use the former (I have yet to find a PHP framework that I don't hate), I have trouble understanding how code which doesn't use any of those components is more maintainable than code which does delegate those tasks. But overall I thought it was a good talk, and she made lots of good arguments for creating a set of coding guidelines for your organization (how variables are named, how code is indented, documentation templates, lots of other stuff).

Then there was "Understanding ZFramework" by John Coggeshall. I confess that I sort of zoned out after I learned that the Zend Framework requires PHP 5 (I'm kind of stuck with PHP 4). However, it looks like ZF has a nice input validation component written by Chris Schiflett.

Finally, I went to "The Conway Channel 2006" with Damian Conway. He talked about a couple of modules he's been working on: List::Maker and Contextual::Return. C::R looks particularly cool. It does what wantarray() does, but also distinguishes between the different possibilities in scalar context (a string, a number, a hashref, an undef, etc). The module has lots of neat features and is very flexible.

Powell's bookstore was one of the exhibitors/vendors, and they were offering a 35% discount. So I bought a copy of Perl Testing: A Developer's Notebook. It's ordinarily around $30, and I got it for around $20.

And I talked to my high school buddy for around an hour. Sure enough, he's getting married. It was really good talking to him. I hope I'll be able to go to the wedding.

26 July 2006

OSCON day 3

Started the day by learning that my workstation at work probably has a bad hard drive. When my officemate rebooted it, he saw those two magic words...

kernel panic

Oh, well. I've (probably) got good backups.

I attended several sessions today. The first was about compiling a kernel to improve speed (only the drivers you need) and security (so a cracker can't load kernel modules--the speaker advocated a monolithic kernel, if possible). The speaker (Steve Suehring) mentioned a security-related patch called grsecurity, which sounds interesting. I wonder how it compares to the openwall kernel patch (hmmm, guess that's just for 2.4).

Next was "Maximum Netfilter" by Michael Rash of Solirix. He talked about several netfilter-related programs. fwknop does something called single-packet authentication, which is a more secure (albeit less convenient) version of port-knocking.

Then I went to "The Madness of AJAX" by Andrew van der Stock (it was about AJAX security). That was actually a little scary. Not because of anything that I've coded or something a co-worker has coded (I don't feel the need to run home and rewrite a bunch of AJAX), but the speaker did several demonstrations which were just spooky. Looks like several of the PHP AJAX toolkits have significant input validation problems, which are a little too reminiscent of register_globals. I'd like to buy a book on the subject, but there don't really seem to be any books on AJAX security (too new, I guess).

I finished out the day by attending the Perl lightening talks (a bunch of 5-minute presentations). It was sort of a strange potluck, punctuated by a rather bizarre performace called "A Perl module installation in 5 unnatural acts". But it gave me a few things I'll want to read about later: App::Ack (source code searches), Perl::Critic ('use strict' on methamphentimines), and stubmail.com (a re-implementation of SMTP by the SPF guy).

And I got voicemail from an old high school buddy of mine. Haven't heard from him in nearly 5 years. I suspect that he's renewing contact to send me a wedding invitation (good for him, if that's the case [good for him, in any case]). Maybe we'll be able to stay in touch this time.

OSCON Day 2

Another couple of tutorials today. The first was "Advanced Perl DBI" by Tim Bunce. He showed up 15 minutes late, which was fairly annoying. But it was otherwise a good session. I learned lots of interesting and useful things. For example, fetchrow_arrayref() is faster than fetchrow_hashref(). And not a little bit faster, but several times faster. I like the convenience of fetchrow_hashref(), so that I can reference column values by name, rather than array index. But I learned that I can get much the same effect (and much more efficiently) using fetchrow_arrayref() and bind_columns().

I also learned that the DBI has built-in profiling capabilities, and prepare_cached() can be used in place of global statement handles.

The afternoon session was about testing Web applications. Part of the tutorial was about Grinder, a free load-testing tool (apparently, most such tools cost obscene sums of money). It looks pretty hard to use, but might be helpful. But most of the session was about a unit-testing tool called Selenium, which is also free. By contrast, it looks pretty easy to use. I downloaded it and ran the default test suite in Firefox. Two of the tests failed: they dealt with popup windows, which Firefox blocks by default. I then disabled popup blocking and re-ran the suite, and all the tests passed. Pretty cool.

Looks like my workstation at work has gone crazy. The kernel thinks that all the filesystems are read-only. I can't even reboot the thing remotely--I'll have to get my officemate to do it manually tomorrow. I never had this problem with Slackware, but I've now seen it three times with RedHats (twice on Fedora and once on CentOS). I'm wondering if it's LVM. I've never actually really used LVM features (like resizing a partition), so maybe I should go back to normal partitions.

The restaurant here in the hotel has an amber ale on draft called Drop Top. It's yummy.

24 July 2006

OSCON day 1

I'm at OSCON this week. I flew here yesterday (without incident). There were at least three other OSCON'ers on the DFW->PDX flight. The goodies aren't as cool this year: the bag is a canvas tote (we got nifty backpacks last year), and there were no really fun toys inside. Oh, well. I registered early, so I got the _AJAX Hacks_ book.

The wireless access is pretty spotty. I remember it being more reliable last year. Maybe it'll improve as the week goes on. The internet connection in my hotel room didn't work yesterday afternoon, but it's good now (it's how I'm doing this).

My room is a lot smaller this year (which is fine). But it's a nice view--I can see Mt. Hood. We actually flew right past Mt. Hood on the way in yesterday (I was surprised by how close the plane flew to the mountain).

This morning's tutorial was MySQL optimization. It was very informative. The speaker took the approach of optimizing queries over server configuration tuning (although he talked about that, too). Lots of good information. Looks like there's a possible InnoDB replacement engine coming out later this year called Falcon--that's good news, in case Oracle changes the InnoDB licensing or something (that came up in a question this morning--the speaker [Jay Pipes] said that it's "business as usual" for two years).

This afternoon was 'Higher-Order Perl' by Mark-Jason Dominus. He's really funny. The first half of the talk was really good (lots of the second half went right over my head). He talked about iterators, which was very interesting (good alternative to File::Find). He started his talk (which he gave barefoot) by throwing two chairs off the podium.

13 June 2006

Perl's Class::Accessor

If you find yourself writing a Perl module for a class with a large number of attributes and a correspondingly large number of accessors and mutators ('getters' and 'setters'), you might want to try Class::Accessor. With Class::Accessor as a base class, your module can just declare its attributes, and Class::Accessor will generate all the accessors and mutators (and the constructor) automatically.

(Your Perl distribution may not include Class::Accessor, in which case you'd need to install it from CPAN.)

Here's an example of how you might use Class::Accessor:

package MyPerson;
use base qw/ Class::Accessor /;
MyPerson->mk_accessors(
qw/
fname
mname
lname
birthdate
address
/
);

1;

Then in your Perl program:

use MyPerson;

my $person = MyPerson->new(
{
fname => 'Homer',
mname => 'Jay',
lname => 'Simpson',
birthdate => '1 January 1970',
}
);

my $birthdate = $person->birthdate(); # $birthdate is now '1 January 1970'
$person->address('742 Evergreen Terrace, Springfield'); # sets the address attribute


Note that you didn't have to explicitly write a constructor--your code just gives new() a hashref of the attributes you want to set.

You can now even use MyPerson as a base class. Another package can inherit from MyPerson and add its own attributes:

package MyCustomer;
use base qw/ MyPerson /;
MyCustomer->mk_accessors(
qw/
billing_address
shipping_address
/
);

1;


The documentation for Class::Accessor is worth reading--it offers ways to declare read-only and write-only attributes (the former would only have accessors, and the latter would only have mutators).

04 June 2006

Lightswitches are evil

I really hate standard lightswitches.

Evidently, I have this irrational, deep-seated aversion to touching lightswitches. Dunno why. But when I want to turn one on or off, I just naturally swing at it with the intention of barely and briefly touching it with my fingertip.

Trouble is, I usually miss. Which angers me. So I swing at it again, only harder, to punish it for evading me. So, of course, I miss again, which angers me more. This continues until I typically end up hitting the lightswitch with a shoe or something.

If I had any sense, or if I were a normal person, I'd just calmly and sanely sweep my whole hand down (or up) over the lightswitch. But that apparently entails more physical contact than my neurosis can withstand.

Maybe I need one of these: http://www.gogglemarks.net/index.php?action=display&tag=fightswitch

28 May 2006

Recovering Grammer Snob

I just read June Casagrande's _Grammer Snobs Are Great Big Meanies_ (Penguin, 2006). It's a guide to avoiding common grammatical errors and to dealing with people who think they know more about the English language than they actually do.

The book is awesome: very helpful, and very, very funny. It's only about $14 retail, and worth every bit. I borrowed it from the library, but I'm going to buy a copy. (The book has a website at http://www.grammarsnobs.com/.)

Here are a few notes (to myself) that I jotted down while reading the book.

'correct' (perhaps not unanimously):
e-mail
website
preventive (not preventative)
'entitled' for rights/privileges, 'titled' for the name of a book

The _Chicago Manual of Style_ (used for books) recommends using the Oxford comma. The _AP Stylebook_ (used for newspapers [and, arguably, blogs]) recommends omitting the Oxford comma. (The Oxford comma is the second comma in the following sentence: This blog is simultaneously pedagogical, pedantic, and pedestrian.)

Newspapers tend to use _Webster's New World College Dictionary_ (too bad for colleges of the old world), and books tend to use the _Merriam-Webster Collegiate Dictionary_.

A screed is a long discourse. And a cool word.

Use 'which' for nonrestrictve clauses, and 'that' for restrictive clauses:
  1. This blog, which has a silly and misleading title, will be useful and/or interesting to a very small number of readers (on a good day).
  2. The _Best of Blondie_ CD that I bought last night is really bitchin'.
'prurient' means interesting (even lurid). 'purient' (to my dismay) does not appear to be a word at all. (I blame dog food manufacturers.)

24 May 2006

Web 2.0 URLs w/ Apache

(Yes, the term 'Web 2.0' is ridiculously overhyped.)

Let's say you have a Web application which takes two optional GET variables v1 and v2. Let's assume that v1 is always an integer and that v2 is always a character string. We'll also assume that a DirectoryIndex index.php directive has been applied:

http://www.example.com/somedir/index.php?v1=27&v2=hello

And let's say your application has an administrative interface in an 'admin' subdirectory:

http://www.example.com/somedir/admin/admin.php

Try putting the following in your Apache configuration (this assumes that mod_rewrite is enabled):

RewriteEngine on
RewriteBase /somedir
RewriteRule ^admin - [L]
RewriteRule ^(\d+)/([a-z]+)/?$ /somedir/index.php?v1=$1&v2=$2 [L]
RewriteRule ^([a-z]+)/(\d+)/?$ /somedir/index.php?v1=$2&v2=$1 [L]
RewriteRule ^(\d+)/?$ /somedir/index.php?v1=$1 [L]
RewriteRule ^([a-z]+)/?$ /somedir/index.php?v2=$1 [L]

(You could put this in an .htaccess file if your Apache configuration applies an AllowOverride FileInfo directive to this part of your content area.)

You application should now be accessible by any of the following URLs:

http://www.example.com/somedir/hello/27/
http://www.example.com/somedir/27/hello/
http://www.example.com/somedir/hello/
http://www.example.com/somedir/27/
http://www.example.com/somedir/

The first and second URLs should set both variables, the third URL should set v2 only, the fourth should set v1 only, and the fifth should set neither (the fifth URL should still run the application because of the DirectoryIndex index.php directive).

Of course, it doesn't have to be '27' and 'hello'--it can be '42' and 'foobar', or whatever.

And your admin interfaces should still be accessible as before (the dash in the 'admin' RewriteRule means 'no alteration').

In the example I've used PHP as the hypothetical Web application, but the language doesn't matter--this is all Apache magic. But if you want to test this with some PHP code, try this in index.php:


header('Content-type: text/plain');
$v1 = '';
$v2 = '';

if ( isset($_GET['v1']) && $_GET['v1'] ) {
$v1 = $_GET['v1'];
printf("v1 is %s\n", $_GET['v1']);
}
else {
printf("v1 not set\n");
}

if ( isset($_GET['v2']) && $_GET['v2'] ) {
$v2 = $_GET['v2'];
printf("v2 is %s\n", $_GET['v2']);
}
else {
printf("v2 not set\n");
}

_X-Men: The Last Stand_

I got to see a preview screening of the new X-Men movie last night. It was awesome. Overall I think I enjoyed the first two films more. I think they tried to do too much and introduce too many characters in this film. But it was still awesome. I even liked Kelsey Grammer as Beast (I didn't think I would).

Make sure you stay until the bitter end. Sit through the credits, and don't leave the theater until the projector turns off.

04 May 2006

Perl programming in joe

I do a lot of Perl programming, and I use joe (Joe's Own Editor). I've defined a few macros that I found pretty useful when scripting. Just add the following macro definitions to your .joerc file (do a text search in .joerc for 'Macros:', and add the lines there-ish):

:def comment filt,"sed -e \'s/^/#/g\'",rtn,tomarkb,markk,prevpos
:def uncomment filt,"sed -e \'s/^#//g\'",rtn,tomarkb,markk,prevpos
:def perltidy bof,markb,eof,markk,filt,"perltidy",rtn,bof,markk

comment ^K 1
uncomment ^K 2
perltidy ^K 3

The first macro comments out a section of text by putting a '#' at the beginning of each line of the section. To use it, just go the the beginning of the section you want to comment out and do 'Ctrl-K b', move to the end of the section and do 'Ctrl-K k', and then do 'Ctrl-1'. It'll comment out those lines, disengage the block (so that the section of text will no longer be highlighted), and return the cursor to the previous position (probably the end of the section of text).

The second macro does just the opposite by uncommenting a section of text.

(You could probably replace the '#' in the macro definitions with a pair of forward slashes for programming in PHP or JavaScript.)

The third macro applies the 'perltidy' program to the entire file (not just a highlighed section). Of course, you'll need perltidy installed for this to work. It's in the Fedora Core extras, and the project home page is http://perltidy.sourceforge.net/.

14 April 2006

the Golden Ratio and the Fibonacci series (Perl program)

I've been re-reading Dan Brown's The Da Vinci Code lately, and I was intrigued by the Golden Ratio and how it relates to the Fibonacci series. The Fibonacci series is such that each term is the sum of the previous two terms:
1, 1, 2, 3, 5, 8, 13, ...

The ratio of consecutive terms in the Fibonacci series converges on the Golden Ratio, which has a value of approximately 1.618. It also shows up in a geometric analysis of the pentacle. These properties are discussed in mathematical detail on the following Web pages:

the Golden Ratio
pentacle geometry

I wanted to see this from a computational point of view, so I wrote a quick Perl program to compute the Fibonacci numbers and ratios out to around 100 terms. The program prints out deviations from the Golden Ratio, and the output shows a near-zero deviation after less than 40 terms.


#!/usr/bin/perl -w

use strict;
use diagnostics;

my $NUM_ITERATIONS = 100;
my $GOLDEN_RATIO = 0.5 * (1.0 + sqrt(5));

my ($previous_term, $current_term) = (1, 1);
my $iteration_number = 1;
while ( $iteration_number <= $NUM_ITERATIONS ) {
my $new_term = $previous_term + $current_term;
my $ratio = $new_term / $current_term;
my $deviation = abs($GOLDEN_RATIO-$ratio) / $GOLDEN_RATIO;
printf "% 3d: %e\n", $iteration_number, $deviation;
$previous_term = $current_term;
$current_term = $new_term;
$iteration_number++;
}

06 April 2006

seeing 'svn diff' output while editing the commit log in joe

I use subversion and I use the text editor joe (http://sourceforge.net/projects/joe-editor/). I've got the following in my ~/.bashrc file, so that joe is the editor that's launched when I type 'svn commit':


export VISUAL="/usr/bin/joe"


(export SVN_EDITOR="/usr/bin/joe" also works, if you've already got VISUAL set to something else.)

I like being able to look at the output of 'svn diff' while I edit the commit log entry, and I've found two ways of doing this (I'm still figuring out which I like better).

The first way is to redirect 'svn diff' to a file, edit the file (putting the log entry in the file), remove the 'svn diff' output from the file, and then use that file as the log entry when committing:


$ svn diff > ~/commit.txt
$ joe ~/commit.txt
(compose the log entry at the top of the file,
and delete the 'svn diff' output)
$ svn commit --file ~/commit.txt
$ rm ~/commit.txt


The second way is to pull the 'svn diff' output into the editor below the 'This line, and those below, will be ignored' line. Then I just compose the log entry at the top of the file and then quit-and-save. In fact, this can be done with a joe macro. Try adding this to the 'Macros' section of ~/.joerc:


:def svndiff eof,insf,"!svn diff",rtn,bof
svndiff ^K 4


Then, next time you want to commit, just type 'svn commit' and do a '^K 4' in joe. That'll add the 'svn diff' output at the bottom of the file and return the cursor to the top of the file.

The second approach requires fewer keystrokes. The only drawback I've noticed is that if you decide you want to abort the commit and you've already saved your edits, you need to be sure to delete the svn-commit.tmp file before exiting joe, or the commit will proceed with whatever's saved in the svn-commit.tmp file.

28 March 2006

grabbing HTTP headers

Sometimes it's useful to inspect the HTTP response headers from a Webserver (for example, to know if the Webserver is running Apache, IIS, or something else). Most Web browsers have some sort of 'Page Info' feature which will display the response headers. But it's often more convenient to do it from the command line.

The text-only browser lynx has a nice feature for this. Typing the following command will dump the HTTP response headers to the screen without displaying the content of the www.example.com homepage:

lynx -dump -head http://www.example.com/

wget can also do this. wget ordinarily downloads the Web content to a local file without displaying response headers. The following will show the headers and discard the content (-S displays the headers, and -O diverts the output here to /dev/null):

wget -S -O /dev/null http://www.example.com/

The curl utility can do much the same thing (note that this is a lower-case o to specify the output destination, and there a bare hyphen after the -D, indicating that the headers should be written to stdout):

curl -D - -o /dev/null http://www.example.com/

netcat offers a fourth way of getting the headers by allowing you to hurl a custom HTTP request at port 80 on the Webserver:

printf "HEAD / HTTP/1.0\n\n" | nc www.example.com 80

The previous example would only work for HTTP. For HTTPS, you can do a similar trick using the s_client mode for the openssl utility (this example uses an HTTP v1.1 request, which requires a host request header):

printf "HEAD / HTTP/1.1\nhost: www.example.com\n\n" \
| openssl s_client -ign_eof -connect www.example.com:443


The -ign_eof keeps the connection open so that the s_client will see the printf output: this also requires manually closing the connection (Control-C should do it). Additionally, you may get certificate verification errors from openssl. If so, try specifying your system's certificate authority bundle (which contains the public keys of a list of trusted certificate authorities, and which may be in a different location that this example):

printf "HEAD / HTTP/1.1\nhost: www.example.com\n\n" \
| openssl s_client -ign_eof \
-CAfile /etc/pki/tls/certs/ca-bundle.crt \
-connect www.example.com:443

24 March 2006

sorting files by modification date

At times I've found that I need to sort the contents of a directory by modification date. If all the files are in a single directory, 'ls -lt' will do the trick. But it's not so easy if the files are scattered through an arbitrarily complicated directory structure. So I've saved the following shell script in ~/bin/file_epoch.sh (and made it executable w/ 'chmod 700 ~/bin/file_epoch.sh'):


#!/bin/bash
file_name="$1"
mod_time="`/bin/ls --full-time \"${file_name}\" \
| awk '{ print $6,$7; }' | cut -d'.' -f1`"
epoch="`date -d \"${mod_time}\" +%Y%m%d%H%M%S`"
echo "${epoch} ${file_name}"


The script takes a single filename as its argument, and the output is something like this:

20060324152639 /path/to/some/file

Then when I need to sort the files, I just do this:


find /path/to/directory/structure -type f \
-exec ~/bin/file_epoch.sh {} \; | sort -rn


This runs the script on every file in /path/to/directory/structure, and piping the output to 'sort -rn' sorts the files in chronological order (from newest to oldest).

22 March 2006

current year (e.g., for copyright) in TT2 templates

If you are using the Perl Template Toolkit and want the template always to display a copyright notice giving the current year, just include the following in your template:

&copy; [% USE date %][% date.format(date.now, '%Y') %]

It uses the Template::Plugin::Date plugin.

Using GPG as a password wallet

I have too many passwords. In fact, I make many of my less-used passwords by grabbing the first 10 or 12 characters of output from something like this:

dd if=/dev/urandom bs=1k count=1 | md5sum

So I get passwords like '1758dbed4331'--no way I'll remember that.

For a while I tried using a nice text-based password wallet program called the Password Management System (PMS--yes, it's a very unfortunate acronym). I learned about this from a Linux Journal article by Marcel Gagne. I built it from source and used it on FC3 for months.

Then I upgraded to FC4. I rebuilt PMS from source and tried reading the previous PMS data files (two data files in my home directory, as I recall). I kept getting segmentation faults. PMS on FC4 worked OK on new data, but it wouldn't read the old data. Some weird incompatibility in the libraries, I guess. So I had to build PMS on another FC3 box, run it, and copy-and-paste all my passwords out of PMS and into a text file. Lame. Hella lame.

So now I just stick with that text file, but it's encrypted by gpg:

gpg -c passwords.txt

When prompted, I gave it a good password. Now, when I need to look up one of my passwords, I just do this:

cat passwords.txt.gpg | gpg | less

Because the output is in 'less', I can even do text searches (each username/password pair is accompanied by some text describing where the password is used). When I've looked up whatever password I need, I just hit 'q', and I'm done.

trick for hosting large DVD ISOs on Apache

I recently needed to make a large file (a DVD ISO) available from a Webserver running Apache. The ISO was around 3.1GB, and Apache wouldn't serve it (the file wouldn't even show up in the mod_autoindex listing).

So I split up the original file into smaller chunks:

split -b 1073741824 huge_DVD.iso

This created 4 files called xaa, xab, xac, and xad. The first three were 1073741824 bytes each, and xad was around 31MB. I renamed the files (in order) to huge_DVD.chunk1, huge_DVD.chunk2, huge_DVD.chunk3, and huge_DVD.chunk4.

I posted the 'chunks' to the Webserver along with a text file containing the SHA1 checksum of the original file. The original file can be reassembled and its checksum computed in a single read by running the following command (after downloading the chunks):

cat huge_DVD.chunk* | tee huge_DVD.iso | openssl dgst -sha1

17 March 2006

bad blogger, no cookie

I haven't been very good at updating this silly thing, have I?