So, just nevermind.
Sunday, January 03, 2010
Thinking about using itshidden.com
I was thinking of using the anonymous VPN service from itshidden.com. I was even thinking of paying for it, despite not knowing the reliability or trustworthiness of those on the other end. So I signed up and got this:
Tuesday, May 19, 2009
Review of new Seagate 500g 7200rpm laptop hard drive
When my 1 year old Hitachi laptop hard drive died in March, I started shopping for a bigger one. That's when I found the new Seagate Momentus 7200.4 model ST9500420AS with 500 gigs of space at 7200rpm.
At that time though, the drive was out of stock everywhere as Seagate seemed to have stopped production to fix some engineering problems. Since even now (May 2009) this is the biggest and fastest consumer 2.5 inch drive available, I decided to wait for it.
In the mean time, I read reviews on it, which were mixed. Some people who got their hands on one of the first run models reported them slow, noisy, buggy and hot. Other owners reported back that the drives were fine. Two more good reviews issued from barefeats and hardwarelogic.
After about 2 months of waiting, these drives were for sale once again, this time with updated firmware 2SDM1. This is the one I bought online from WiredZone for $133 with free shipping. It's just a brown box, egg foam and anti-static bag. No glossy fanfare, manuals or any of that. I don't know if that's typical.

Before evicting the old (warranty replacement) Hitachi 200g 7200rpm, I decided to take some crude benchmarks of it so I'd know whether the new Seagate was any better. Say goodbye to HTS722020K9SA00 Made in Thailand:

Hello Seagate Hecho in China:

After copying a bootable backup onto an external firewire drive with the excellent SuperDuper! cloning software, I was ready to swap drives. Disassembly instructions for the model 3,1 MacBook Pro are at iFixit. If you have a Bugs Bunny video, then you won't have to unhook the delicate ribbon cable that connects the keyboard to the motherboard.

After the swap, I booted from the external firewire drive and used SuperDuper! to clone back onto the new empty internal hard drive. Then a reboot and everything is running on the new Seagate.
Now, for the comparisons, which may not be quite fair because the Hitachi was almost full for the benchmarks, while the Seagate was mostly empty.
Boot Time
Xbench
Bonnie++
Hitachi:
Seagate:
dd
I ran the write in root "/" directory (and therefore had to use sudo) to avoid writing in my home directory, which is Filevault and would probably skew performance downward. The 1st dd in each section below is writing, the 2nd is reading.
The result of the tests showed that in addition to more than doubling my disk space with the new drive, it is also objectively faster than the old one, even at the same spindle speeds. However, this is probably just because the new one is mostly empty and the old one was mostly full. Performance will always be a lot better when data is on the beginning instead of the end of a mechanical drive.
The last bit of info to share is from SMART, accessed with smartctl from smartmontools. The Hitachi was in pretty good shape, aside from the strange value for Power-Off_Retract_Count. Don;t have a clue what that one means:
Hitachi SMART
The Seagate, on the otherhand, looked alarming when I first checked it out. I thought the drive was defective and was ready to send it back for RMA:
Seagate SMART
Raw_Read_Error_Rate, Seek_Error_Rate and Hardware_ECC_Recovered make it look like the disk is dying. Attributes 240, 241, 242 are nonsensical. After investigating though, it seems that these type of values on those attributes are just normal for a Seagate.
A few searches on these attributes will find many discussions where people are concluding that these odd values don't indicate a problem. Seagate also has a KB article basically warning users not to pay attention to those SMART values. Apparently they stuff their own proprietary values into the SMART circuits which only becomes meaningful when pulled through their "Seatools" disk analyzer software. Regular SMART software tools that follow the published SMART protocols won't be able to make any use of Seagate's stored raw values for those attributes. Incidentally, there is no Mac version of Seatools.
I've had my new Momentus drive running now for about 24 hours. Over the last 4 hours while I've been using the machine, I have heard a pretty loud "CLUNK" twice. Probably the heads parking or unparking for powersaving mode. The Hitachi never did that, but it's only happened twice and other than that, I can't tell the difference between this drive and the old one by noise, vibration or temperature. Tests indicate that there are no errors that other owners were complaining about this past winter with the older firmware rev, and it is a bit faster than Hecho in Thailand.
I guess it's a good one but I'll still keep up the SuperDuper! onsite and Crashplan offsite regimen.
At that time though, the drive was out of stock everywhere as Seagate seemed to have stopped production to fix some engineering problems. Since even now (May 2009) this is the biggest and fastest consumer 2.5 inch drive available, I decided to wait for it.
In the mean time, I read reviews on it, which were mixed. Some people who got their hands on one of the first run models reported them slow, noisy, buggy and hot. Other owners reported back that the drives were fine. Two more good reviews issued from barefeats and hardwarelogic.
After about 2 months of waiting, these drives were for sale once again, this time with updated firmware 2SDM1. This is the one I bought online from WiredZone for $133 with free shipping. It's just a brown box, egg foam and anti-static bag. No glossy fanfare, manuals or any of that. I don't know if that's typical.

Before evicting the old (warranty replacement) Hitachi 200g 7200rpm, I decided to take some crude benchmarks of it so I'd know whether the new Seagate was any better. Say goodbye to HTS722020K9SA00 Made in Thailand:

Hello Seagate Hecho in China:

After copying a bootable backup onto an external firewire drive with the excellent SuperDuper! cloning software, I was ready to swap drives. Disassembly instructions for the model 3,1 MacBook Pro are at iFixit. If you have a Bugs Bunny video, then you won't have to unhook the delicate ribbon cable that connects the keyboard to the motherboard.

After the swap, I booted from the external firewire drive and used SuperDuper! to clone back onto the new empty internal hard drive. Then a reboot and everything is running on the new Seagate.
Now, for the comparisons, which may not be quite fair because the Hitachi was almost full for the benchmarks, while the Seagate was mostly empty.
Boot Time
| Hitachi | Seagate |
|---|---|
| Apple Logo: 51 sec Login Window: +33 sec Total: 84 secs | Apple Logo: 16 sec Login Window: +40 sec Total: 56 secs |
Xbench
| Hitachi | Seagate |
|---|---|
| Results 43.50 System Info Xbench Version 1.3 System Version 10.5.6 (9G55) Physical RAM 4096 MB Model MacBookPro3,1 Drive Type Hitachi HTS722020K9SA00 Disk Test 43.50 Sequential 79.03 Uncached Write 108.92 66.88 MB/sec [4K blocks] Uncached Write 110.86 62.73 MB/sec [256K blocks] Uncached Read 40.92 11.98 MB/sec [4K blocks] Uncached Read 125.34 62.99 MB/sec [256K blocks] Random 30.01 Uncached Write 9.76 1.03 MB/sec [4K blocks] Uncached Write 97.19 31.11 MB/sec [256K blocks] Uncached Read 77.83 0.55 MB/sec [4K blocks] Uncached Read 130.73 24.26 MB/sec [256K blocks] | Results 52.73 System Info Xbench Version 1.3 System Version 10.5.6 (9G55) Physical RAM 4096 MB Model MacBookPro3,1 Drive Type ST9500420AS Disk Test 52.73 Sequential 119.09 Uncached Write 164.42 100.95 MB/sec [4K blocks] Uncached Write 146.68 82.99 MB/sec [256K blocks] Uncached Read 65.58 19.19 MB/sec [4K blocks] Uncached Read 183.84 92.39 MB/sec [256K blocks] Random 33.86 Uncached Write 10.73 1.14 MB/sec [4K blocks] Uncached Write 171.66 54.96 MB/sec [256K blocks] Uncached Read 80.56 0.57 MB/sec [4K blocks] Uncached Read 148.96 27.64 MB/sec [256K blocks] |
Bonnie++
Hitachi:
Version 1.93c ------Sequential Output------ --Sequential Input- --Random-
Concurrency 1 -Per Chr- --Block-- -Rewrite- -Per Chr- --Block-- --Seeks--
Machine Size K/sec %CP K/sec %CP K/sec %CP K/sec %CP K/sec %CP /sec %CP
arf.local 16G 297 97 52023 18 24538 9 332 95 55015 11 105.9 10
Latency 80374us 687ms 610ms 121ms 213ms 4029ms
Version 1.93c ------Sequential Create------ --------Random Create--------
arf.local -Create-- --Read--- -Delete-- -Create-- --Read--- -Delete--
files /sec %CP /sec %CP /sec %CP /sec %CP /sec %CP /sec %CP
16 6111 55 +++++ +++ 9257 61 367 8 +++++ +++ 151 4
Latency 76653us 920us 79744us 333ms 1399us 414ms
Seagate:
Version 1.93c ------Sequential Output------ --Sequential Input- --Random-
Concurrency 1 -Per Chr- --Block-- -Rewrite- -Per Chr- --Block-- --Seeks--
Machine Size K/sec %CP K/sec %CP K/sec %CP K/sec %CP K/sec %CP /sec %CP
arf.local 16G 293 96 90295 32 36049 14 343 98 91548 20 164.4 13
Latency 134ms 388ms 217ms 85474us 132ms 1942ms
Version 1.93c ------Sequential Create------ --------Random Create--------
arf.local -Create-- --Read--- -Delete-- -Create-- --Read--- -Delete--
files /sec %CP /sec %CP /sec %CP /sec %CP /sec %CP /sec %CP
16 5313 56 +++++ +++ 5567 41 320 8 +++++ +++ 149 5
Latency 106ms 200us 151ms 497ms 380us 322ms
dd
I ran the write in root "/" directory (and therefore had to use sudo) to avoid writing in my home directory, which is Filevault and would probably skew performance downward. The 1st dd in each section below is writing, the 2nd is reading.
| Hitachi | Seagate |
|---|---|
| $ sudo time dd if=/dev/zero of=/Volumes/Macintosh\ HD/test bs=1024k count=16384; 17179869184 bytes transferred in 319.400409 secs (53787875 bytes/sec) $ time dd of=/dev/null if=/Volumes/Macintosh\ HD/test bs=1024k 17179869184 bytes transferred in 305.974147 secs (56148107 bytes/sec) | $ sudo time dd if=/dev/zero of=/Volumes/Macintosh\ HD/test bs=1024k 17179869184 bytes transferred in 188.208635 secs (91280983 bytes/sec) $ time dd of=/dev/null if=/Volumes/Macintosh\ HD/test bs=1024k 17179869184 bytes transferred in 180.531769 secs (95162581 bytes/sec) |
The result of the tests showed that in addition to more than doubling my disk space with the new drive, it is also objectively faster than the old one, even at the same spindle speeds. However, this is probably just because the new one is mostly empty and the old one was mostly full. Performance will always be a lot better when data is on the beginning instead of the end of a mechanical drive.
The last bit of info to share is from SMART, accessed with smartctl from smartmontools. The Hitachi was in pretty good shape, aside from the strange value for Power-Off_Retract_Count. Don;t have a clue what that one means:
Hitachi SMART
Model Family: Hitachi Travelstar 7K200
Device Model: Hitachi HTS722020K9SA00
Serial Number: 080830DP0470DTGP3MMC
Firmware Version: DC4AC77A
User Capacity: 200,049,647,616 bytes
Device is: In smartctl database [for details use: -P show]
ATA Version is: 8
ATA Standard is: ATA-8-ACS revision 3f
Local Time is: Sun May 17 23:31:07 2009 PDT
SMART support is: Available - device has SMART capability.
SMART support is: Enabled
SMART Attributes Data Structure revision number: 16
Vendor Specific SMART Attributes with Thresholds:
ID# ATTRIBUTE_NAME FLAG VALUE WORST THRESH TYPE UPDATED WHEN_FAILED RAW_VALUE
1 Raw_Read_Error_Rate 0x000b 100 100 062 Pre-fail Always - 0
2 Throughput_Performance 0x0005 100 100 040 Pre-fail Offline - 0
3 Spin_Up_Time 0x0007 176 176 033 Pre-fail Always - 1
4 Start_Stop_Count 0x0012 100 100 000 Old_age Always - 200
5 Reallocated_Sector_Ct 0x0033 100 100 005 Pre-fail Always - 0
7 Seek_Error_Rate 0x000b 100 100 067 Pre-fail Always - 0
8 Seek_Time_Performance 0x0005 100 100 040 Pre-fail Offline - 0
9 Power_On_Hours 0x0012 100 100 000 Old_age Always - 342
10 Spin_Retry_Count 0x0013 100 100 060 Pre-fail Always - 0
12 Power_Cycle_Count 0x0032 100 100 000 Old_age Always - 192
191 G-Sense_Error_Rate 0x000a 100 100 000 Old_age Always - 0
192 Power-Off_Retract_Count 0x0032 100 100 000 Old_age Always - 42954326020
193 Load_Cycle_Count 0x0012 100 100 000 Old_age Always - 8991
194 Temperature_Celsius 0x0002 130 130 000 Old_age Always - 42 (Lifetime Min/Max 14/47)
195 Hardware_ECC_Recovered 0x000a 100 100 000 Old_age Always - 0
196 Reallocated_Event_Count 0x0032 100 100 000 Old_age Always - 0
197 Current_Pending_Sector 0x0022 100 100 000 Old_age Always - 0
198 Offline_Uncorrectable 0x0008 100 100 000 Old_age Offline - 0
199 UDMA_CRC_Error_Count 0x000a 200 200 000 Old_age Always - 0
223 Load_Retry_Count 0x000a 100 100 000 Old_age Always - 0
The Seagate, on the otherhand, looked alarming when I first checked it out. I thought the drive was defective and was ready to send it back for RMA:
Seagate SMART
$ sudo smartctl -s on /dev/disk0
SMART Enabled.
$ sudo smartctl -a /dev/disk0
Device Model: ST9500420AS
Serial Number: 5VJ079ZE
Firmware Version: 0002SDM1
User Capacity: 500,107,862,016 bytes
Device is: Not in smartctl database [for details use: -P showall]
ATA Version is: 8
ATA Standard is: ATA-8-ACS revision 4
Local Time is: Wed May 20 00:42:19 2009 PDT
SMART support is: Available - device has SMART capability.
SMART support is: Enabled
...
SMART Attributes Data Structure revision number: 10
Vendor Specific SMART Attributes with Thresholds:
ID# ATTRIBUTE_NAME FLAG VALUE WORST THRESH TYPE UPDATED WHEN_FAILED RAW_VALUE
1 Raw_Read_Error_Rate 0x000f 118 100 006 Pre-fail Always - 184273167
3 Spin_Up_Time 0x0003 100 100 085 Pre-fail Always - 0
4 Start_Stop_Count 0x0032 100 100 020 Old_age Always - 2
5 Reallocated_Sector_Ct 0x0033 100 100 036 Pre-fail Always - 0
7 Seek_Error_Rate 0x000f 100 253 030 Pre-fail Always - 139058
9 Power_On_Hours 0x0032 100 100 000 Old_age Always - 24
10 Spin_Retry_Count 0x0013 100 100 097 Pre-fail Always - 0
12 Power_Cycle_Count 0x0032 100 037 020 Old_age Always - 5
184 Unknown_Attribute 0x0032 100 100 099 Old_age Always - 0
187 Reported_Uncorrect 0x0032 100 100 000 Old_age Always - 0
188 Unknown_Attribute 0x0032 100 100 000 Old_age Always - 0
189 High_Fly_Writes 0x003a 100 100 000 Old_age Always - 0
190 Airflow_Temperature_Cel 0x0022 062 052 045 Old_age Always - 38 (Lifetime Min/Max 28/41)
191 G-Sense_Error_Rate 0x0032 100 100 000 Old_age Always - 0
192 Power-Off_Retract_Count 0x0032 100 100 000 Old_age Always - 0
193 Load_Cycle_Count 0x0032 099 099 000 Old_age Always - 3798
194 Temperature_Celsius 0x0022 038 048 000 Old_age Always - 38 (0 22 0 0)
195 Hardware_ECC_Recovered 0x001a 045 045 000 Old_age Always - 184273167
197 Current_Pending_Sector 0x0012 100 100 000 Old_age Always - 0
198 Offline_Uncorrectable 0x0010 100 100 000 Old_age Offline - 0
199 UDMA_CRC_Error_Count 0x003e 200 200 000 Old_age Always - 0
240 Head_Flying_Hours 0x0000 100 253 000 Old_age Offline - 70690866724884
241 Unknown_Attribute 0x0000 100 253 000 Old_age Offline - 2076453070
242 Unknown_Attribute 0x0000 100 253 000 Old_age Offline - 2307582568
254 Unknown_Attribute 0x0032 100 100 000 Old_age Always - 0
SMART Error Log Version: 1
No Errors Logged
SMART Self-test log structure revision number 1
Num Test_Description Status Remaining LifeTime(hours) LBA_of_first_error
# 1 Short offline Completed without error 00% 21 -
# 2 Extended offline Aborted by host 90% 21 -
# 3 Extended offline Aborted by host 60% 9 -
# 4 Extended offline Aborted by host 50% 2 -
Raw_Read_Error_Rate, Seek_Error_Rate and Hardware_ECC_Recovered make it look like the disk is dying. Attributes 240, 241, 242 are nonsensical. After investigating though, it seems that these type of values on those attributes are just normal for a Seagate.
A few searches on these attributes will find many discussions where people are concluding that these odd values don't indicate a problem. Seagate also has a KB article basically warning users not to pay attention to those SMART values. Apparently they stuff their own proprietary values into the SMART circuits which only becomes meaningful when pulled through their "Seatools" disk analyzer software. Regular SMART software tools that follow the published SMART protocols won't be able to make any use of Seagate's stored raw values for those attributes. Incidentally, there is no Mac version of Seatools.
I've had my new Momentus drive running now for about 24 hours. Over the last 4 hours while I've been using the machine, I have heard a pretty loud "CLUNK" twice. Probably the heads parking or unparking for powersaving mode. The Hitachi never did that, but it's only happened twice and other than that, I can't tell the difference between this drive and the old one by noise, vibration or temperature. Tests indicate that there are no errors that other owners were complaining about this past winter with the older firmware rev, and it is a bit faster than Hecho in Thailand.
I guess it's a good one but I'll still keep up the SuperDuper! onsite and Crashplan offsite regimen.
Monday, December 08, 2008
use jQuery AJAX to create options in a dropdown menu
If you love to hate Javascript, that half-breed, amateur-magnet language, and every onload() and eval() you ever saw, then jQuery just rained on your parade. Now, with jQuery, so many things are elegant and easy - the opposite of everything you've ever known about Javascript.
Here's how to populate a select menu's option list (values and labels) with data retrieved from an AJAX request. The impatient may jump to a working demo to see if this is even what you want. Maybe you were searching for some sink cleaning product.
Materials:
Here's the markup that we start with (page.html): A form with an input field, select menu and a button that will trigger our script. In this example, a user enters a zip code in the input box and clicks the button. That will trigger an AJAX request to another resource, sending the zip code and retrieving a bunch of shipping options, which will then magically fill the dropdown menu.
Notice that there are no Javascript functions strewn into the markup as tag attributes (no onclick(), no onmouseover()). That's because jQuery separates code for behavior from code for presentation. All the jQuery code will go in the "head." From high up there, it can hook into the DOM using only its patent pending "selectors."
So now let me show you what to add inside the "head" tag in order to load jQuery on the page, and then jQuery code to write that will do all the work.
First, a tangent: Normally, you would download the jQuery.js libraries from jQuery.com onto your own webserver, and serve them to your visitors from there with a "script src" tag. That's fine if you want to do it that way, but there's another option to direct visitors get those libs from Google instead. There are a lot of good reasons for offloading this job, so I leave it to you to read about it. In this example, that's what we're doing.
So, first, add this inside your head tag (before or after title tag) to get your visitor to load the jQuery libraries:
Now the browser understands jQuery. All the rest of your jQuery code can come next, in separate script tags, still in head:
That's it. When the user clicks the button, an AJAX request is sent to script.php, and the response is used to rebuild the shipping_method dropdown menu. Prices appear inside the options list before your very eyes. If you want to see a working demo, check here
You may also want to copy this, name it "script.php" and save it on your server in the same directory as the html page above. It outputs a canned JSON answer that the jQuery code will use to make the select options.
When pasting the above PHP script into your editor, if your server does not have the json_encode() function (PHP version < 5.2) then be careful to NOT let your editor (like pico) wrap the long line dummy JSON string with hard line breaks. Hard returns in that data structure will break the fragile thing and your AJAX callback function will not execute.
It is still Javascript, after all, what did you expect?
Here's how to populate a select menu's option list (values and labels) with data retrieved from an AJAX request. The impatient may jump to a working demo to see if this is even what you want. Maybe you were searching for some sink cleaning product.
Materials:
- 1 webpage that loads jQuery and makes an AJAX request (page.html)
- 1 script that receives the AJAX request and answers it (script.php)
Here's the markup that we start with (page.html): A form with an input field, select menu and a button that will trigger our script. In this example, a user enters a zip code in the input box and clicks the button. That will trigger an AJAX request to another resource, sending the zip code and retrieving a bunch of shipping options, which will then magically fill the dropdown menu.
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">
<head>
<title>jQuery ajax demo populating select dropdown menu</title>
</head>
<body>
<form>
Zip: <input name="zip" type="text" size="5" maxlength="10" id="zip" value="" /><br />
<select name='shipping_method' id="shipping_method">
<option value="0" selected="selected">Select Shipping Method</option>
<option value='FEDEX_2_DAY' >FedEx 2 Day</option>
<option value='FEDEX_EXPRESS_SAVER' >FedEx 3 Day</option>
<option value='INTERNATIONAL_PRIORITY' >FedEx International</option>
<option value='PRIORITY_OVERNIGHT' >FedEx Priority Overnight</option>
<option value='STANDARD_OVERNIGHT' >FedEx Standard Overnight</option>
</select>
<input id="getrates" type="button" value="Lookup Shipping Rates" /><br />
</form>
</body>
</html>Notice that there are no Javascript functions strewn into the markup as tag attributes (no onclick(), no onmouseover()). That's because jQuery separates code for behavior from code for presentation. All the jQuery code will go in the "head." From high up there, it can hook into the DOM using only its patent pending "selectors."
So now let me show you what to add inside the "head" tag in order to load jQuery on the page, and then jQuery code to write that will do all the work.
First, a tangent: Normally, you would download the jQuery.js libraries from jQuery.com onto your own webserver, and serve them to your visitors from there with a "script src" tag. That's fine if you want to do it that way, but there's another option to direct visitors get those libs from Google instead. There are a lot of good reasons for offloading this job, so I leave it to you to read about it. In this example, that's what we're doing.
So, first, add this inside your head tag (before or after title tag) to get your visitor to load the jQuery libraries:
<script src="http://www.google.com/jsapi"></script>
<script type="text/javascript">
google.load("jquery", "1");
google.load("jqueryui", "1.5.2");
</script>Now the browser understands jQuery. All the rest of your jQuery code can come next, in separate script tags, still in head:
<script type="text/javascript">
// When the DOM is ready to have events hook into it...
$(document).ready(function() {
// when the DOM element with id="getrates" is clicked....
$("#getrates").click(function() {
// make that button you clicked disappear...
$(this).hide(); // opposite of show() // See jQueryUI for more info
// and issue an AJAX request to a PHP script in the same directory
// getJSON is a method that expects a JSON-encoded data structure to be returned
// there are other AJAX methods too. See http://docs.jquery.com/Ajax
$.getJSON("script.php", // 1st arg to getJSON is the URI of the script
{
zipcode: $("#zip").val(),
random: "noise"
},
// 2nd arg to getJSON is an array of key-value pairs to send
// to the script. As many as you want.
// left-side is the GET variable name as seen by the target
// script, right-side is the value that will be sent.
// the above 2 args will cause the AJAX script to be hit with
// the query string: ?zipcode=90019&random=noise
// assuming that the user typed "90019" into the
// element on this page with the id="zip"
// 3rd arg is the callback function for the AJAX response
// The script.php responds in a JSON format so jQuery can
// understand the data structure natively, without you
// writing awful parsing of your own:
function(j) {
// erase all OPTIONs from existing select menu on the page
$('#shipping_method options').remove();
// You will rebuild new options based on the JSON response...
var options = '<option value="">Choose Shipping Method</option>';
// "j" is the json object that was output by your PHP script
// it is the array of key-value pairs to turn
// into option value/labels...
for (var i = 0; i < j.length; i++)
{
options += '<option value="' +
j[i].optionValue + '">' +
j[i].optionDisplay +
'</option>';
}
// stick these new options in the existing select menu
$("#shipping_method").html(options);
// now your select menu is rebuilt with dynamic info
}
); // end getJSON
}); // end clicked button to trigger AJAX
}); // end document ready
</script>That's it. When the user clicks the button, an AJAX request is sent to script.php, and the response is used to rebuild the shipping_method dropdown menu. Prices appear inside the options list before your very eyes. If you want to see a working demo, check here
You may also want to copy this, name it "script.php" and save it on your server in the same directory as the html page above. It outputs a canned JSON answer that the jQuery code will use to make the select options.
<?php
# script.php
$pretend_results = array('PRIORITY_OVERNIGHT' => 39.69,
'STANDARD_OVERNIGHT' => 48.45,
'FEDEX_2_DAY' => 19.75,
'FEDEX_EXPRESS_SAVER' => 15.75);
$haOptions = array();
foreach($pretend_results as $method => $cost)
{
$haOptions[] = array('optionValue' => $method, 'optionDisplay' => "$method $$cost");
}
# make JSON object that will populate select dropdown menu options
if(function_exists('json_encode'))
{
echo json_encode($haOptions); # this puts the php array in the funny javascript array/object
# format so you don't have to know how to translate manually
}
else
{
# some lame web hosts dont have a new version of PHP (5.2+) that includes json functions in core
# so here, I fake it for you so you will have a working demo:
echo '[{"optionValue":"PRIORITY_OVERNIGHT","optionDisplay":"PRIORITY_OVERNIGHT $39.69"},{"optionValue":"STANDARD_OVERNIGHT","optionDisplay":"STANDARD_OVERNIGHT $48.45"},{"optionValue":"FEDEX_2_DAY","optionDisplay":"FEDEX_2_DAY $19.75"},{"optionValue":"FEDEX_EXPRESS_SAVER","optionDisplay":"FEDEX_EXPRESS_SAVER $15.75"}]';
}
# this output is what the jQuery ajax request will receive and parse in its ajax callback function
exit;
?>When pasting the above PHP script into your editor, if your server does not have the json_encode() function (PHP version < 5.2) then be careful to NOT let your editor (like pico) wrap the long line dummy JSON string with hard line breaks. Hard returns in that data structure will break the fragile thing and your AJAX callback function will not execute.
It is still Javascript, after all, what did you expect?
Sunday, March 02, 2008
Reasonable Backups of Filevault
It doesn't take much web searching to come to the conclusion that the new Time Machine in MacOS 10.5 does not work well with Filevault.
The problem is that to Time Machine, a home directory protected with Filevault is just one big "sparse image" encrypted file. Although it will happily backup this file, doing that defeats one of the purposes of TM, which is to give you snapshots of every individual file from different times, so that you can go back through them and preview them easily before restoring.
If TM is backing up this giant disk image each time, then it is spending all your disk space on your backup drive on the whole disk image for every snapshot. This is a total waste of space. Without Filevault, the behavior would be to take a snapshot only of the changed files, so that your backup drive was only using space to store 1 copy of your files, plus the changes for each snapshot. Another problem with the interaction between FV and TM out of the box is that it's not very convenient in the "Cover Flow" interface to browse through the encrypted images, nor to have to provide a passphrase for each and mount each in order to look at the files inside.
Therefore, I decided to use "rsync" (from Terminal) to backup my home directory to an external drive while I am logged in. In order to keep my files secure on the backup drive, I decided to encrypt that whole device with Truecrypt, which just recently added support for MacOSX.
First I downloaded the Truecrypt .dmg file, mounted that by doubleclicking it, then ran the Truecrypt installer inside there. Once Truecrypt was installed on the Mac, I ran it and told it to encrypt the whole external USB backup drive.
After that was finished, I mounted the new volume according to the "Beginner Tutorial" in the TC documentation. At this time, TC could only create the volume as a FAT filesystem. Because I've been burned before by FAT's maximum filesize of 4G (tarring some stuff directly to the backup drive and having my tarball silently truncated at 4g), I wanted a real filesystem for my backups.
To change the filesystem of the mounted Truecrypt volume, I opened Disk Utilities from the Applications, Utilities menu in the Finder and, while Truecrypt volume is still mounted (so you see it without the encryption), told it to partition the new volume 200G HFS+ and 50G FAT. I left a FAT partition on it so that I could still use the drive on other non-Mac computers.
After the TC volume was re-partitioned and reformated, I was ready to run rsync to copy my home directory in there:
While figuring out which rsync command will work for you, add the "--dry-run " option in until you get it right. I will be saving that command in a shell script that I will periodically execute after connecting the USB drive and running Truecrypt to unlock and mount it.
The reason that I am involving Truecrypt at all is just so that I could use the backup drive on other non-Mac machines, since it is cross platform Windows/Linux/Mac encryption. If I didn't care about the cross platform stuff, I would just have used Apple's Disk Utilities to create an encrypted disk image on the USB drive, and stored backups in there. I sort of defeated some of that purpose by using an Apple-only HFS partition, but maybe in the future there will be a better cross platform filesystem to select from the Disk Utility menu that will also support files larger than 4G.
The problem is that to Time Machine, a home directory protected with Filevault is just one big "sparse image" encrypted file. Although it will happily backup this file, doing that defeats one of the purposes of TM, which is to give you snapshots of every individual file from different times, so that you can go back through them and preview them easily before restoring.
If TM is backing up this giant disk image each time, then it is spending all your disk space on your backup drive on the whole disk image for every snapshot. This is a total waste of space. Without Filevault, the behavior would be to take a snapshot only of the changed files, so that your backup drive was only using space to store 1 copy of your files, plus the changes for each snapshot. Another problem with the interaction between FV and TM out of the box is that it's not very convenient in the "Cover Flow" interface to browse through the encrypted images, nor to have to provide a passphrase for each and mount each in order to look at the files inside.
Therefore, I decided to use "rsync" (from Terminal) to backup my home directory to an external drive while I am logged in. In order to keep my files secure on the backup drive, I decided to encrypt that whole device with Truecrypt, which just recently added support for MacOSX.
First I downloaded the Truecrypt .dmg file, mounted that by doubleclicking it, then ran the Truecrypt installer inside there. Once Truecrypt was installed on the Mac, I ran it and told it to encrypt the whole external USB backup drive.
After that was finished, I mounted the new volume according to the "Beginner Tutorial" in the TC documentation. At this time, TC could only create the volume as a FAT filesystem. Because I've been burned before by FAT's maximum filesize of 4G (tarring some stuff directly to the backup drive and having my tarball silently truncated at 4g), I wanted a real filesystem for my backups.
To change the filesystem of the mounted Truecrypt volume, I opened Disk Utilities from the Applications, Utilities menu in the Finder and, while Truecrypt volume is still mounted (so you see it without the encryption), told it to partition the new volume 200G HFS+ and 50G FAT. I left a FAT partition on it so that I could still use the drive on other non-Mac computers.
After the TC volume was re-partitioned and reformated, I was ready to run rsync to copy my home directory in there:
rsync --archive --progress --verbose \Where my username on the Mac is "me" and the HFS partition inside the Truecrypt volume is "MacBackup" and the directory inside there where I want all my backup stuff is "backup." The result of the command is that everything in my home directory, including hidden files that begin with a '.' like .bashrc, will be copied to the backup directory -- except for a few subdirs of the home that I don't care about and have excluded.
--exclude '.Spotlight-V100' --exclude '.fseventsd' \
--exclude 'Desktop ' --exclude 'Library/*' \
--exclude 'Downloads/*' --exclude 'Music/*'
--exclude 'Public/*' --exclude 'Sites/*'
~me /Volumes/MacBackup/backup
While figuring out which rsync command will work for you, add the "--dry-run " option in until you get it right. I will be saving that command in a shell script that I will periodically execute after connecting the USB drive and running Truecrypt to unlock and mount it.
The reason that I am involving Truecrypt at all is just so that I could use the backup drive on other non-Mac machines, since it is cross platform Windows/Linux/Mac encryption. If I didn't care about the cross platform stuff, I would just have used Apple's Disk Utilities to create an encrypted disk image on the USB drive, and stored backups in there. I sort of defeated some of that purpose by using an Apple-only HFS partition, but maybe in the future there will be a better cross platform filesystem to select from the Disk Utility menu that will also support files larger than 4G.
Friday, November 16, 2007
Interested in GPL code for your closed source project?
This post does not really fit the theme of this blog as a "fix" but may may help someone avoid broken-ness in the first place.
Question: If I am writing closed source PHP software intended for distribution (not just for use as a web service, see http://radar.oreilly.com/archives/2007/07/the_gpl_and_sof_1.html), and I incorporate a few GPL components, does my software become "infected" and necessarily GPL as well?
Answer:
The answer to this question would matter to someone who has invested, or is about to invest, significant resources in what he/she may consider an original work, but who may also be tempted to incorporate freely available GPL'd software in the process.
From information you can gather from the Free Software Foundation, the answer seems simple:
or from Richard Stallman:
and even more directly from GNU:
Despite these forceful admonitions that if A, a GPL work, is combined with B, then the resulting A+B then has to be GPL, there are places where even GNU concedes that it is not always the case that when one piece of GPL software is distributed with some other software, that the GPL will always override whatever "some other's" redistribution license might have been.
For example, the Linux kernel is GPL2 only (not "or any later version") and might never be changed by the kernel developers to GPL3 (http://radar.oreilly.com/archives/2007/04/gplv3_linux_and.html), while many other GNU programs in the GNU/Linux may soon be GPL3. If these separate pieces of inter-operable software are distributed together under two incompatible licenses (GPLv2 is incompatible with GPLv3, http://www.gnu.org/licenses/license-list.html#GNUGPL), then that would prove that just because B relies on, and is distributed with GPL'd A, does not mean that B is required to have the same, or even a compatible, license as A.
The possibility that proprietary software may in some circumstances use GPL'd parts is explored a bit on GNU's site:
So, the trick to keeping an original work closed, when part of its function depends upon other GPL'd work, is to maintain separation between the projects. How this is technically achieved is not completely clear.
In the case of PHP or other interpreted languages, the "include" and "require" statements that one might use to bring in some functionality from GPL source (like a template engine or WYSIWYG editor) do not necessarily involve the same level of integration as static or dynamically linked libraries, which GNU advocates have argued clearly results in all parts combining into a single GPL whole.
Whatever technical means used in keeping separation, if you want your source to stay closed, the functions performed by the GPL software should not be the core functions of your proprietary program. For example, if you have some proprietary data manipulation software and would like to add a graph to a report it generates, it might be fine to distribute a GPL graphing script alongside your program without it necessarily "infecting" your closed license and forcing it open. However, if you were producing some closed reporting software whose primary or significant function was generating graphs, then you could not include GPL graphing software to perform that function and expect to keep your source closed.
Another requirement that I've assumed this far in the discussion is that your closed project actually is an original work, and not a "derivative" one. This is because the obligations imposed by the GPL only arise when a work is derived from the GPL work. Derivative is a term defined relatively loosely by US copyright law but involves the same analysis as with books and movies. For example, if I were to write a novel describing the adventures of Harry Potter after his 27th birthday, my work would be derived from the fictional universe created and copyrighted by J.K. Rowling, and since her work is not GPL, my work would be infringing. However, if I were to write a novel about a fictional boy who reads the Potter series and spends the rest of his life trying to learn magic, I am much more likely to have created an original, non-derivative work, deserving of independent copyright.
Whether your software that uses a GPL component is derivative of that component, therefore, depends. Were portions of your work copied from GPL source? Is your version just a wrapper around a GPL core? Or is your work a distinct entity that happens to be able to interact with GPL software?
It is possible to write non-free software that talks back and forth with GPL software, without losing your proprietary license status. The boundary is just fuzzy how close the relationship with GPL software can be, beyond which you will infect your closed project. If it is too close, the risk is that your work will be deemed legally "derivative" of the GPL one, and forced open by the GPL. But if you make sure the two projects keep their distance, talk at arms' length, and keep your project's core purpose distinct from the GPL one, then you will have created a new, non-derivative, copyrighted work and can avoid any sudden GPL "infection."
Of course, there is still much uncertainty in this area. For example, some companies refuse to write drivers for Linux because they believe (whether because of FUD or otherwise) doing so would cause the GPL to spread through their intellectual property like a disease, opening source to competitors for free, and harming themselves financially. After this analysis, I don't think that would actually be the legal outcome, but there's not a black and white answer. Perhaps with more research, there would be.
References:
http://blog.lab49.com/archives/659
http://drupal.org/node/25768
http://www.linuxjournal.com/article/6366
http://www.linuxjournal.com/article/5935
http://www.redhat.com/magazine/007may05/features/compliance/
http://tech.amikelive.com/node-14/the-gpl-myth-opensource-is-free-of-charge/
http://www.techdirt.com/article.php?sid=20070921/145609
http://radar.oreilly.com/archives/2007/07/the_gpl_and_sof_1.html
http://www.gnu.org/licenses/gpl-faq.html
http://www.gnu.org/philosophy/pragmatic.html
http://en.wikipedia.org/wiki/Open_source_vs._closed_source
Question: If I am writing closed source PHP software intended for distribution (not just for use as a web service, see http://radar.oreilly.com/archives/2007/07/the_gpl_and_sof_1.html), and I incorporate a few GPL components, does my software become "infected" and necessarily GPL as well?
Answer:
The answer to this question would matter to someone who has invested, or is about to invest, significant resources in what he/she may consider an original work, but who may also be tempted to incorporate freely available GPL'd software in the process.
From information you can gather from the Free Software Foundation, the answer seems simple:
"[P]eople have been wondering what the rules are when you link to some GPLv3-covered code. They're the same as they were under GPLv2: the combined work you create needs to be GPLed as well."(from http://www.fsf.org/blogs/licensing/2007-10-18-gplv3-fud)
or from Richard Stallman:
"I once found out about a non-free program which was designed to use Readline [a library covered by GPL], and told the developer this was not allowed. He could have taken command-line editing out of the program, but what he actually did was rerelease it under the GPL."(from http://www.gnu.org/philosophy/pragmatic.html)
and even more directly from GNU:
"You cannot incorporate GPL-covered software in a proprietary system.... A system incorporating a GPL-covered program is an extended version of that program.... [and] must be released under the GPL."(from http://www.gnu.org/licenses/gpl-faq.html#GPLInProprietarySystem)
Despite these forceful admonitions that if A, a GPL work, is combined with B, then the resulting A+B then has to be GPL, there are places where even GNU concedes that it is not always the case that when one piece of GPL software is distributed with some other software, that the GPL will always override whatever "some other's" redistribution license might have been.
For example, the Linux kernel is GPL2 only (not "or any later version") and might never be changed by the kernel developers to GPL3 (http://radar.oreilly.com/archives/2007/04/gplv3_linux_and.html), while many other GNU programs in the GNU/Linux may soon be GPL3. If these separate pieces of inter-operable software are distributed together under two incompatible licenses (GPLv2 is incompatible with GPLv3, http://www.gnu.org/licenses/license-list.html#GNUGPL), then that would prove that just because B relies on, and is distributed with GPL'd A, does not mean that B is required to have the same, or even a compatible, license as A.
The possibility that proprietary software may in some circumstances use GPL'd parts is explored a bit on GNU's site:
"in many cases you can distribute the GPL-covered software alongside your proprietary system. To do this validly, you must make sure that the free and non-free programs communicate at arms length, that they are not combined in a way that would make them effectively a single program."(from http://www.gnu.org/licenses/gpl-faq.html#GPLInProprietarySystem)
So, the trick to keeping an original work closed, when part of its function depends upon other GPL'd work, is to maintain separation between the projects. How this is technically achieved is not completely clear.
In the case of PHP or other interpreted languages, the "include" and "require" statements that one might use to bring in some functionality from GPL source (like a template engine or WYSIWYG editor) do not necessarily involve the same level of integration as static or dynamically linked libraries, which GNU advocates have argued clearly results in all parts combining into a single GPL whole.
Whatever technical means used in keeping separation, if you want your source to stay closed, the functions performed by the GPL software should not be the core functions of your proprietary program. For example, if you have some proprietary data manipulation software and would like to add a graph to a report it generates, it might be fine to distribute a GPL graphing script alongside your program without it necessarily "infecting" your closed license and forcing it open. However, if you were producing some closed reporting software whose primary or significant function was generating graphs, then you could not include GPL graphing software to perform that function and expect to keep your source closed.
Another requirement that I've assumed this far in the discussion is that your closed project actually is an original work, and not a "derivative" one. This is because the obligations imposed by the GPL only arise when a work is derived from the GPL work. Derivative is a term defined relatively loosely by US copyright law but involves the same analysis as with books and movies. For example, if I were to write a novel describing the adventures of Harry Potter after his 27th birthday, my work would be derived from the fictional universe created and copyrighted by J.K. Rowling, and since her work is not GPL, my work would be infringing. However, if I were to write a novel about a fictional boy who reads the Potter series and spends the rest of his life trying to learn magic, I am much more likely to have created an original, non-derivative work, deserving of independent copyright.
Whether your software that uses a GPL component is derivative of that component, therefore, depends. Were portions of your work copied from GPL source? Is your version just a wrapper around a GPL core? Or is your work a distinct entity that happens to be able to interact with GPL software?
It is possible to write non-free software that talks back and forth with GPL software, without losing your proprietary license status. The boundary is just fuzzy how close the relationship with GPL software can be, beyond which you will infect your closed project. If it is too close, the risk is that your work will be deemed legally "derivative" of the GPL one, and forced open by the GPL. But if you make sure the two projects keep their distance, talk at arms' length, and keep your project's core purpose distinct from the GPL one, then you will have created a new, non-derivative, copyrighted work and can avoid any sudden GPL "infection."
Of course, there is still much uncertainty in this area. For example, some companies refuse to write drivers for Linux because they believe (whether because of FUD or otherwise) doing so would cause the GPL to spread through their intellectual property like a disease, opening source to competitors for free, and harming themselves financially. After this analysis, I don't think that would actually be the legal outcome, but there's not a black and white answer. Perhaps with more research, there would be.
References:
http://blog.lab49.com/archives/659
http://drupal.org/node/25768
http://www.linuxjournal.com/article/6366
http://www.linuxjournal.com/article/5935
http://www.redhat.com/magazine/007may05/features/compliance/
http://tech.amikelive.com/node-14/the-gpl-myth-opensource-is-free-of-charge/
http://www.techdirt.com/article.php?sid=20070921/145609
http://radar.oreilly.com/archives/2007/07/the_gpl_and_sof_1.html
http://www.gnu.org/licenses/gpl-faq.html
http://www.gnu.org/philosophy/pragmatic.html
http://en.wikipedia.org/wiki/Open_source_vs._closed_source
Thursday, August 30, 2007
Dog Boots don't exist for a 80lb. steel spring
Review of Bark'n Boots Grip Trex
These boots display great quality materials (Vibram sole, neoprene/cordura uppers), smooth stitching and great craftsmanship. They are far better than anything else available such as Walkaboot, Ultra-Paws, Neopaws, etc). This whole shoe looks as good as any made for human children. HOWEVER, they did not fit or stay on, at least for my dog, who is like a tightly wound spring and creates a lot of traction forces when he runs and darts about.
The general design of these boots is still the same as the old version (which you may see on the clearance rack at some shops) in that the shoes only come up to the wrist, and unlike a human wrist or ankle, the width of the dog's wrist is about the same as the paw's width. That means this boot's single wrist strap holds about as well as a handcuff would on a cigar. My dog lost the first boot in less than 5 minutes after we started walking a wooded trail and continued to lose more at regular intervals.
Another problem with the fit was that the boots would flip upside down on the dog's feet so that he was standing on the uppers instead of the sole. For the boots that were not totally lost, I had to keep resetting them on his feet every 5-10 minutes. What allows the boot to twist around like this is that the inside of the boot is shaped like a cone, which allows the boot to rotate around on the foot. If the upper material was cut flatter and had more of a wetsuit stretch, it might resist that spinning better.
Relating to the boots' ability to stay on is its "side-loading" design like a slipper, as opposed to "top loading" like a human boot. Because of this and the poor holding power of just the single Velcro strap, the boot just comes off the way a tube sock would if it were pulled down to just the ball of your foot and given a few shakes. If the boot were top loading, though, the L-shape angle of ankle to foot seam would help hold the boot on, plus there could be additional lacing up the ankle as there is on a human hi-top shoe.
Another problem with the low cut is that at the back of the boot, where ankle becomes paw, the shoe suffers from "plumber butt." That is, at the L bend between ankle and foot, the shoe material hangs open in the same way that the back of your own pants opens along your rear belt loop when you bend over. This gap at the back of the shoe allows debris such as weed seeds, foxtails, pebbles, sand and other itchy poky things to fall inside the shoe where they will irritate the dogs feet worse than having no shoes at all. This could be alleviated if the upper were cut to angle up the leg a bit more before being wrapped with a second strap. A second strap could prevent things from falling inside the shoe and assist in securing the boot on the foot.
I contacted Ruff Wear about the problems of this low-top design and they said they would be coming out with another model boot that will secure higher on the ankle in Spring or Summer 2008.
After observing the performance of the Velcro in the field, I found that with a dog that runs through all kinds of grass and brush, the "sticky" side of the Velcro quickly becomes clogged with debris, reducing its effectiveness at staying fastened. I think that the straps on these boots got clogged enough to weaken the connection enough that just brushing against things on the trail and the dog's flexing caused them to release, and make the boot just suddenly open and fall off. Perhaps old-fashioned laces would be better, or else quick-adjust buckles like are used on backpack straps. Velcro in this application seems to only be good for securing dangling slack strap.
I feel part of the reason the boots stayed on so poorly was because they were not fitting properly. If you intend to buy these boots, you need to have a look at the "alternate size chart" that is buried in the FAQ on Ruff Wear's website. It is slightly different than the more common size chart that you typically see displayed near these products and it may help you pick the right size.
Also buried in their FAQ is notice that most dogs' rear feet are smaller than their front feet. Because of this, their rear feet may take a smaller size than their front feet. So, if you want to get the right fit, try on some boots at an REI store first, or order boots 2 at a time from ruffwear.com (they sell individual boots now for $15 each). Otherwise, if you just buy a set of 4 boots all the same size, as they are sold at retail, you may end up with half being too big.
Because of all these problems, I had to be dealing with boots every 5-10 minutes on the hike, instead of enjoying ourselves on it. These boots are so expensive to replace, the fact that they do not stay on as designed currently is a big problem. That said, I still would much rather have a set of boots that worked than $60 or even $100.
These did not work for me. If your dog just prances gently along, or is old and moves slowly, they might work for you.
These boots display great quality materials (Vibram sole, neoprene/cordura uppers), smooth stitching and great craftsmanship. They are far better than anything else available such as Walkaboot, Ultra-Paws, Neopaws, etc). This whole shoe looks as good as any made for human children. HOWEVER, they did not fit or stay on, at least for my dog, who is like a tightly wound spring and creates a lot of traction forces when he runs and darts about.
The general design of these boots is still the same as the old version (which you may see on the clearance rack at some shops) in that the shoes only come up to the wrist, and unlike a human wrist or ankle, the width of the dog's wrist is about the same as the paw's width. That means this boot's single wrist strap holds about as well as a handcuff would on a cigar. My dog lost the first boot in less than 5 minutes after we started walking a wooded trail and continued to lose more at regular intervals.
Another problem with the fit was that the boots would flip upside down on the dog's feet so that he was standing on the uppers instead of the sole. For the boots that were not totally lost, I had to keep resetting them on his feet every 5-10 minutes. What allows the boot to twist around like this is that the inside of the boot is shaped like a cone, which allows the boot to rotate around on the foot. If the upper material was cut flatter and had more of a wetsuit stretch, it might resist that spinning better.
Relating to the boots' ability to stay on is its "side-loading" design like a slipper, as opposed to "top loading" like a human boot. Because of this and the poor holding power of just the single Velcro strap, the boot just comes off the way a tube sock would if it were pulled down to just the ball of your foot and given a few shakes. If the boot were top loading, though, the L-shape angle of ankle to foot seam would help hold the boot on, plus there could be additional lacing up the ankle as there is on a human hi-top shoe.
Another problem with the low cut is that at the back of the boot, where ankle becomes paw, the shoe suffers from "plumber butt." That is, at the L bend between ankle and foot, the shoe material hangs open in the same way that the back of your own pants opens along your rear belt loop when you bend over. This gap at the back of the shoe allows debris such as weed seeds, foxtails, pebbles, sand and other itchy poky things to fall inside the shoe where they will irritate the dogs feet worse than having no shoes at all. This could be alleviated if the upper were cut to angle up the leg a bit more before being wrapped with a second strap. A second strap could prevent things from falling inside the shoe and assist in securing the boot on the foot.
I contacted Ruff Wear about the problems of this low-top design and they said they would be coming out with another model boot that will secure higher on the ankle in Spring or Summer 2008.
After observing the performance of the Velcro in the field, I found that with a dog that runs through all kinds of grass and brush, the "sticky" side of the Velcro quickly becomes clogged with debris, reducing its effectiveness at staying fastened. I think that the straps on these boots got clogged enough to weaken the connection enough that just brushing against things on the trail and the dog's flexing caused them to release, and make the boot just suddenly open and fall off. Perhaps old-fashioned laces would be better, or else quick-adjust buckles like are used on backpack straps. Velcro in this application seems to only be good for securing dangling slack strap.
I feel part of the reason the boots stayed on so poorly was because they were not fitting properly. If you intend to buy these boots, you need to have a look at the "alternate size chart" that is buried in the FAQ on Ruff Wear's website. It is slightly different than the more common size chart that you typically see displayed near these products and it may help you pick the right size.
Also buried in their FAQ is notice that most dogs' rear feet are smaller than their front feet. Because of this, their rear feet may take a smaller size than their front feet. So, if you want to get the right fit, try on some boots at an REI store first, or order boots 2 at a time from ruffwear.com (they sell individual boots now for $15 each). Otherwise, if you just buy a set of 4 boots all the same size, as they are sold at retail, you may end up with half being too big.
Because of all these problems, I had to be dealing with boots every 5-10 minutes on the hike, instead of enjoying ourselves on it. These boots are so expensive to replace, the fact that they do not stay on as designed currently is a big problem. That said, I still would much rather have a set of boots that worked than $60 or even $100.
These did not work for me. If your dog just prances gently along, or is old and moves slowly, they might work for you.
Monday, July 30, 2007
Toyota Tacoma Seats
I came across this scanned document (click for full size view) describing the available seat types for 2005-present Toyota Tacoma while ordering waterproof neoprene seat covers from Wetokole.com.In case Tacoma owners didn't know, the passenger seat folds flat into a table with a plastic tray for tabletop, and in between the seat back and seat bottom of the passenger seat, some models have 2 metal brackets intended for holding a baby seat.
This diagram is probably hard to find and may be useful for other modifications or accessories.
Now does anyone know whether the stock stereo has an aux audio input behind the dash somewhere for my mp3 player so I don't have to take the whole dash apart to find out?
UPDATE on aux input: No, your non-premium stock stereo does not have an aux input. But it does have a plug on the back for connecting a CD changer. The USA Spec PA12TOY adapter can plug in there, and then provide you with analog RCA stereo inputs and a native iPod dock connector so you can play your music through your car stereo.
Thursday, February 22, 2007
Recovering (or stealing) a domain registration
Most organizations don't think much about their domain registration until it either expires -- disabling their website and email -- or until the day before they intend to launch a new website at a new webhosting provider.
Often the internal employee who originally purchased a domain registration for a company no longer works there, or the web host that handled the registration as a middleman becomes defunct, and the owner is left with no record of how to access the registration. The result is that the registration is frozen, nameservers and WHOIS contacts cannot be changed and the poor mope who's been assigned the wild goose chase of regaining control of the domain name has no idea where to begin.
Where to begin is first identifying the registrar for a particular domain name. This information is in the publicly available WHOIS database. If you've never queried WHOIS, take a look at http://geektools.com/whois.php and enter any domain name. In the output, the identity of the registrar is contained in the bits of data labeled "Referral URL," "Sponsoring Registrar," or "Registrar."
Because everything these days is web-based self-service, most registrars have a self-help way to recover a password. This generally consists of going to a public page on the registrar's website (that you identified through WHOIS), entering the domain name in a form, and the registrar sending an automated message to the email address in the registrar's records that offers a way to recover or reset the password used to access the registration. Whoever can read that email will be the de facto new owner of the registration.
As a practical matter, whoever controls a domain registration controls all email and the website for that domain. Gone are the days when you needed to pay a special "registrant transfer" fee and sign papers in order to sell your registration to another party. Today, any legitimate registrar has a web interface that lets the domain owner login and change whatever data they please, including "registrant." If you want to sell your domain name, all you do now is give the username and password to the new owner, and they can login to change WHOIS info, nameservers, or even approve a registration transfer to a new registrar.
Network Solutions, the oldest registrar with the worst service and highest prices, has automated tools on their website that allow anyone on the internet to take control of a domain registration registered there, so long as that person has access to read the email of the Administrative Contact listed in the publicly visible WHOIS database. You can find Network Solutions automated login recovery page here: https://www.networksolutions.com/manage-it/forget-login.jsp
[Unlike most other registrars, at Network Solutions, total login recovery is a 2 phase project. First you have to recover the "Account ID" that NetSol arbitrarily assigns to owners, and that no one can remember. This is done by putting either the domain name or the Admin Contact's email address in NetSol's web form. Then they automatically email the Admin Contact the Account ID associated with the registration. Once you have that Account ID, you paste it into the "lost password" form, and they email the same Admin Contact a link to click that will reset the password. Whoever receives those emails can reset the password to the account, login, and do whatever they please with the registration.]
If the Administrative Contact's email address is "@" the same domain as the registration, then the organization should have an easy time reading those machine-generated emails (ask your system administrator or web host for help). However, using the same domain name as an email contact point on the registration is usually a bad idea, since if anything goes wrong with the registration (like expiration), then email at that domain name is likely to be broken and you will not be able to receive email sent to that address at the same domain name. For that reason, it's a good idea to use a permanent email address at a different domain name as a contact point on your registration, such as one from Yahoo, Gmail, or your local ISP.
In some cases, the email address for the Admin Contact that the registrar has on record may also be defunct, and if it's your job to recover that registration, you might be ready to give up at that point and start faxing blurry paperwork to Network Solutions (which, by the way, anyone, even Nigerians, can also do) to prove you're entitled to access, then waiting helplessly four days for them to get around to considering it.
An alternative is to look closely at the Admin Contact email address listed in WHOIS. If you can take over the email address marked as Administrative Contact, you can take over the entire registration of any Network Solutions registration. Seizing a registration that way means you will have control over email to the entire organization, can redirect their website traffic and more.
Because many organizations never think about their domain registration until it's expired and their entire domain is down, the contact information in WHOIS associated with those registrations is consequently not maintained accurately by registrants, either. This provides any registration recovery agent, or thief, a foothold. If the email address of the Admin Contact is one "@" a public internet service provider, you can check to see if that email address is valid anymore. If it's not, it's yours.
One can check by sending an email to that address and waiting for a bounce message or reply. Or, you can lookup the MX record of the domain name, then connect to the SMTP port on that server, and initiate a manual SMTP conversation with that server to test whether the listed Admin Contact email address is still "occupied."
For example, the Admin Contact for a particular domain name registered at Network Solutions is "swall@bigsky.net." Bigsky.net was a company bought out by bigger ISP, Amerion. Amerion continues to let subscribers (like S. Wall) have email at the original local ISP's "bigsky.net" namespace.
The organization for which S. Wall was an Admin Contact has lost its registration login info, has kept no records, and now wants to change web hosts, which requires gaining access to and modifying their domain registration.
The easiest thing we might do to resolve this is email that Admin Contact's address and see if we can get the user to cooperate and either forward or read to us whatever emails from the registrar they receive. But what if that user canceled her email service a long time ago and there's no one to answer? What if, when we email that address, we just get a bounce message with an error like "Code 550, no such user?"
If were interested in learning on a more massive scale how prevalent this condition is (Admin Contact email addresses that are abandoned), we might write a script to harvest all the Admin Contact email addresses from a list of domain names, programatically testing each Admin Contact's email address, searching for "no such user" type errors, and saving all the ones that we find in a pile labeled "vulnerable."
In our example, we're looking at the Admin Contact address "swall@bigsky.net," and after extracting the MX record of the bigsky.net domain using nslookup, host, or dig (http://geektools.com/digtool.php), we find the following MX records:
All of the above could be encapsulated into a fairly simple script capable of being fed a long list of domain names (or dictionary words ending in ".com") that an attacker would like to steal, extracting the email address of the Admin Contact using a little WHOIS and regular expression action, then another regex to parse out the domain name of that email address, then a lookup to pull the MX for that email address' domain, and then a little socket programming to test that MX to see if that email address is still valid. An attacker who has written the above program could have a list of 1000 popular domain names that are ripe for hijacking, overnight.
For any email addresses at public internet service providers that are invalid, all one need do to own that address is go to that ISP's website and sign up for an account. In our example, I signed up with Amerion over the phone for a $9.95/month account. Five minutes later I was receiving mail addressed to "swall@bigsky.net" through Amerion's handy webmail system. Two minutes after that (and after changing the email address listed as Admin Contact on the registration), I was canceling the account over the phone with a nice Amerion rep who did not inquire further into why I needed the service for less than 10 minutes.
Anyone could do the same with any unoccupied email address at any public internet service provider.
Being able to receive that email meant that I could receive Network Solutions' automated password recovery messages, and as soon as that happened, I had control over this domain. Lucky for this organization, they asked me to provide them with this service.
However, for all the thousands of other organizations out there with stale contact information on their domain registrations, and the chunk of those unlucky enough to have the Admin address be unoccupied space at a public provider, anyone with a stolen credit card number can deface your website, intercept your company's email, or even sell your domain name for a tidy sum to an innocent third party.
For those readers feeling uneasy about my publishing such exploits, I recommend reading the rationale of "full disclosure" and how publication actually improves security: http://www.schneier.com/crypto-gram-0702.html#4
Admittedly, though, this really is not a case of Network Solutions or any other registrar leaving a security hole in the domain registration system. Rather, this vulnerability of some registrations is really a product of the convenience demanded by consumers who are just not very well-versed in maintaining integrity or security of sensitive data.
Often the internal employee who originally purchased a domain registration for a company no longer works there, or the web host that handled the registration as a middleman becomes defunct, and the owner is left with no record of how to access the registration. The result is that the registration is frozen, nameservers and WHOIS contacts cannot be changed and the poor mope who's been assigned the wild goose chase of regaining control of the domain name has no idea where to begin.
Where to begin is first identifying the registrar for a particular domain name. This information is in the publicly available WHOIS database. If you've never queried WHOIS, take a look at http://geektools.com/whois.php and enter any domain name. In the output, the identity of the registrar is contained in the bits of data labeled "Referral URL," "Sponsoring Registrar," or "Registrar."
Because everything these days is web-based self-service, most registrars have a self-help way to recover a password. This generally consists of going to a public page on the registrar's website (that you identified through WHOIS), entering the domain name in a form, and the registrar sending an automated message to the email address in the registrar's records that offers a way to recover or reset the password used to access the registration. Whoever can read that email will be the de facto new owner of the registration.
As a practical matter, whoever controls a domain registration controls all email and the website for that domain. Gone are the days when you needed to pay a special "registrant transfer" fee and sign papers in order to sell your registration to another party. Today, any legitimate registrar has a web interface that lets the domain owner login and change whatever data they please, including "registrant." If you want to sell your domain name, all you do now is give the username and password to the new owner, and they can login to change WHOIS info, nameservers, or even approve a registration transfer to a new registrar.
Network Solutions, the oldest registrar with the worst service and highest prices, has automated tools on their website that allow anyone on the internet to take control of a domain registration registered there, so long as that person has access to read the email of the Administrative Contact listed in the publicly visible WHOIS database. You can find Network Solutions automated login recovery page here: https://www.networksolutions.com/manage-it/forget-login.jsp
[Unlike most other registrars, at Network Solutions, total login recovery is a 2 phase project. First you have to recover the "Account ID" that NetSol arbitrarily assigns to owners, and that no one can remember. This is done by putting either the domain name or the Admin Contact's email address in NetSol's web form. Then they automatically email the Admin Contact the Account ID associated with the registration. Once you have that Account ID, you paste it into the "lost password" form, and they email the same Admin Contact a link to click that will reset the password. Whoever receives those emails can reset the password to the account, login, and do whatever they please with the registration.]
If the Administrative Contact's email address is "@" the same domain as the registration, then the organization should have an easy time reading those machine-generated emails (ask your system administrator or web host for help). However, using the same domain name as an email contact point on the registration is usually a bad idea, since if anything goes wrong with the registration (like expiration), then email at that domain name is likely to be broken and you will not be able to receive email sent to that address at the same domain name. For that reason, it's a good idea to use a permanent email address at a different domain name as a contact point on your registration, such as one from Yahoo, Gmail, or your local ISP.
In some cases, the email address for the Admin Contact that the registrar has on record may also be defunct, and if it's your job to recover that registration, you might be ready to give up at that point and start faxing blurry paperwork to Network Solutions (which, by the way, anyone, even Nigerians, can also do) to prove you're entitled to access, then waiting helplessly four days for them to get around to considering it.
An alternative is to look closely at the Admin Contact email address listed in WHOIS. If you can take over the email address marked as Administrative Contact, you can take over the entire registration of any Network Solutions registration. Seizing a registration that way means you will have control over email to the entire organization, can redirect their website traffic and more.
Because many organizations never think about their domain registration until it's expired and their entire domain is down, the contact information in WHOIS associated with those registrations is consequently not maintained accurately by registrants, either. This provides any registration recovery agent, or thief, a foothold. If the email address of the Admin Contact is one "@" a public internet service provider, you can check to see if that email address is valid anymore. If it's not, it's yours.
One can check by sending an email to that address and waiting for a bounce message or reply. Or, you can lookup the MX record of the domain name, then connect to the SMTP port on that server, and initiate a manual SMTP conversation with that server to test whether the listed Admin Contact email address is still "occupied."
For example, the Admin Contact for a particular domain name registered at Network Solutions is "swall@bigsky.net." Bigsky.net was a company bought out by bigger ISP, Amerion. Amerion continues to let subscribers (like S. Wall) have email at the original local ISP's "bigsky.net" namespace.
The organization for which S. Wall was an Admin Contact has lost its registration login info, has kept no records, and now wants to change web hosts, which requires gaining access to and modifying their domain registration.
The easiest thing we might do to resolve this is email that Admin Contact's address and see if we can get the user to cooperate and either forward or read to us whatever emails from the registrar they receive. But what if that user canceled her email service a long time ago and there's no one to answer? What if, when we email that address, we just get a bounce message with an error like "Code 550, no such user?"
If were interested in learning on a more massive scale how prevalent this condition is (Admin Contact email addresses that are abandoned), we might write a script to harvest all the Admin Contact email addresses from a list of domain names, programatically testing each Admin Contact's email address, searching for "no such user" type errors, and saving all the ones that we find in a pile labeled "vulnerable."
In our example, we're looking at the Admin Contact address "swall@bigsky.net," and after extracting the MX record of the bigsky.net domain using nslookup, host, or dig (http://geektools.com/digtool.php), we find the following MX records:
bigsky.net mail exchanger = 20 bigsky.net.amerion.mail6.psmtp.com.We can test any of those mailservers (they all should behave the same) in the following way:
bigsky.net mail exchanger = 30 bigsky.net.amerion.mail7.psmtp.com.
bigsky.net mail exchanger = 10 bigsky.net.amerion.mail5.psmtp.com.
telnet bigsky.net.amerion.mail5.psmtp.com 25The last response tells us that the Admin Contact's email address is up for grabs.
Trying 64.18.5.10...
Connected to bigsky.net.amerion.mail5.psmtp.com.
Escape character is '^]'.
220 Postini ESMTP 157 y6_8_11c0 ready. CA Business and Professions
Code Section 17538.45 forbids use of this system for unsolicited
electronic mail advertisements.
helo whatever.com
250 Postini says hello back
mail from: someone@whatever.com
250 Ok
rcpt to: swall@bigsky.net
550 unknown user
All of the above could be encapsulated into a fairly simple script capable of being fed a long list of domain names (or dictionary words ending in ".com") that an attacker would like to steal, extracting the email address of the Admin Contact using a little WHOIS and regular expression action, then another regex to parse out the domain name of that email address, then a lookup to pull the MX for that email address' domain, and then a little socket programming to test that MX to see if that email address is still valid. An attacker who has written the above program could have a list of 1000 popular domain names that are ripe for hijacking, overnight.
For any email addresses at public internet service providers that are invalid, all one need do to own that address is go to that ISP's website and sign up for an account. In our example, I signed up with Amerion over the phone for a $9.95/month account. Five minutes later I was receiving mail addressed to "swall@bigsky.net" through Amerion's handy webmail system. Two minutes after that (and after changing the email address listed as Admin Contact on the registration), I was canceling the account over the phone with a nice Amerion rep who did not inquire further into why I needed the service for less than 10 minutes.
Anyone could do the same with any unoccupied email address at any public internet service provider.
Being able to receive that email meant that I could receive Network Solutions' automated password recovery messages, and as soon as that happened, I had control over this domain. Lucky for this organization, they asked me to provide them with this service.
However, for all the thousands of other organizations out there with stale contact information on their domain registrations, and the chunk of those unlucky enough to have the Admin address be unoccupied space at a public provider, anyone with a stolen credit card number can deface your website, intercept your company's email, or even sell your domain name for a tidy sum to an innocent third party.
For those readers feeling uneasy about my publishing such exploits, I recommend reading the rationale of "full disclosure" and how publication actually improves security: http://www.schneier.com/crypto-gram-0702.html#4
Admittedly, though, this really is not a case of Network Solutions or any other registrar leaving a security hole in the domain registration system. Rather, this vulnerability of some registrations is really a product of the convenience demanded by consumers who are just not very well-versed in maintaining integrity or security of sensitive data.
Sunday, December 24, 2006
Could Santa Exist?
Spending Christmas with girlfriend's kids ages 4 and 6 who ask questions about how Santa delivers all these presents to good boys and girls while they sleep on Christmas eve. I say I don't know the answer, but let's figure it out together using some basic math and a few conservative assumptions.
We assume that Santa only delivers presents during the night while you're sleeping. That's why children never see him. So, in order to accomplish that before you (or another child in the same time zone) wake up, Santa must finish all his work in that time zone within about 10 hours.
Tonight, for this Christmas Eve, we're in north Idaho, and luckily for the kids, I happen to have a McNally Road Atlas showing the other places in the same time zone, along with their populations. Other places like Washington (5.8 million), Oregon (3.4 million), Idaho (half of 1.2 million), California (33.8 million), and Nevada (1.9 million). British Columbia, half of Alberta, Canada and a bit of Mexico are also in the same time zone, but we don't need to consider them for this exercise.
If we add them all up, the total number of people living in our time zone is about 46 million. Since it takes 2 adults to create one child, but one adult can create more than one child, and also that some adults have no children, let's make a conservative estimate that only 1/4th of the total population are children. That comes to about 11.5 million children (46,000,000 / 4).
Let's assume that half those children are rotten little goblins and that Santa doesn't stop at their houses. That reduces it down to 5.75 million children (11,500,000 / 2). Lets also assume that on average, there are 2 children to a household, so Santa would only need to make 2.875 million stops (5,750,000 / 2) during that 10 hour overnight span.
All this means that Santa would need to make 287,500 stops every hour (2.875 million / 10 hours). That's equivalent to 71,875 stops every 15 minutes (287,500 / 4). Or 4,791 stops every minute (71,875 /15). If Santa worked at this pace, he would have to slide down the chimney, drop off presents, eat the cookies that you leave out for him, and fly off away again at a rate of (4,791/60) 79 houses per second!
If all these reasonable assumptions are true, and with the distances of thousands of miles, then that would mean Santa moves faster than the speed of light, which Einstein said was impossible. Theory of Relativity aside, how could a man so fat move that fast?
And if he could, on a sleigh built by elves, wouldn't the U.S. military shoot him down and haul all the wreckage back to Area 51? Why wouldn't they? After all, Santa delivers presents to children around the world, including to terrorist states like Iran, North Korea, and Syria. And anyone who provides aid or comfort to our enemies is also our enemy. Even if it's Santa Claus.
So if you still think there's a Santa Claus, then go to sleep!
We assume that Santa only delivers presents during the night while you're sleeping. That's why children never see him. So, in order to accomplish that before you (or another child in the same time zone) wake up, Santa must finish all his work in that time zone within about 10 hours.
Tonight, for this Christmas Eve, we're in north Idaho, and luckily for the kids, I happen to have a McNally Road Atlas showing the other places in the same time zone, along with their populations. Other places like Washington (5.8 million), Oregon (3.4 million), Idaho (half of 1.2 million), California (33.8 million), and Nevada (1.9 million). British Columbia, half of Alberta, Canada and a bit of Mexico are also in the same time zone, but we don't need to consider them for this exercise.
If we add them all up, the total number of people living in our time zone is about 46 million. Since it takes 2 adults to create one child, but one adult can create more than one child, and also that some adults have no children, let's make a conservative estimate that only 1/4th of the total population are children. That comes to about 11.5 million children (46,000,000 / 4).
Let's assume that half those children are rotten little goblins and that Santa doesn't stop at their houses. That reduces it down to 5.75 million children (11,500,000 / 2). Lets also assume that on average, there are 2 children to a household, so Santa would only need to make 2.875 million stops (5,750,000 / 2) during that 10 hour overnight span.
All this means that Santa would need to make 287,500 stops every hour (2.875 million / 10 hours). That's equivalent to 71,875 stops every 15 minutes (287,500 / 4). Or 4,791 stops every minute (71,875 /15). If Santa worked at this pace, he would have to slide down the chimney, drop off presents, eat the cookies that you leave out for him, and fly off away again at a rate of (4,791/60) 79 houses per second!
If all these reasonable assumptions are true, and with the distances of thousands of miles, then that would mean Santa moves faster than the speed of light, which Einstein said was impossible. Theory of Relativity aside, how could a man so fat move that fast?
And if he could, on a sleigh built by elves, wouldn't the U.S. military shoot him down and haul all the wreckage back to Area 51? Why wouldn't they? After all, Santa delivers presents to children around the world, including to terrorist states like Iran, North Korea, and Syria. And anyone who provides aid or comfort to our enemies is also our enemy. Even if it's Santa Claus.
So if you still think there's a Santa Claus, then go to sleep!
Wednesday, November 22, 2006
Itiva, quanta, venture capital, snakeoil
Recently came across a startup called Itiva, claiming to have technology to bring high quality media to PC's without bandwidth worries. It involves a lot of long noun chains, new paradigms, and revolutionary but proprietary Quanta™. Sounds like snake oil to me.
My point is that ISPs cant sell broadband internet connections and then expect to prevent people from using those connections in order to reduce the ISP's own bandwidth costs. Itva is not really solving a problem, the content I want is most likely not on my ISP's network, and therefore I have to get it from the internet. Breaking bits into "Quanta™" and reassembling them on my computer does not use less bandwidth. If I need a 4gig file, 4 gigs worth of bandwidth ultimately needs to be used, if there is no compression (and Itva is not a compression tool).
Those stated reasons are part of the story, but can be overcome with current technology platforms if one is intent on overcoming them. The primary reason digital content doesn't compare with traditional content is because the RIAA and MPAA will not allow high quality digital copies to be put in the stream of commerce because they are afraid of copying.
Itva seems to be mostly some kind of proxy caching thing that ISPs are supposed to employ on their own network so that they can serve their users without having to use internet bandwidth. This means also that ISPs are supposed to pay Itva for this product, but I don't see why they would. It's going to be a long time before a good number of internet users reach even T-1 speeds (relatively low speed broadband), and that's only 1.54megabits per second.
1,540,000 bits = 192,500 bytes
1 megabyte ~= 1,000,000 bytes
at T-1 speed:
5 seconds to get 1 megabyte
500 secs (8m) to get 100 megabytes
5000 secs (1.2h) to get 1 gig.
A full screen DVD quality movie will be at least 3 gigs, and therefore take about 3.5 hours to download, even over a relatively fast T-1 or DSL rated at 1.54mbp/s. Even if my ISP has the movie proxy-cached or running special Itva software so they don't have to deliver over the internet, it still takes this long just to get it the last mile from my ISP to me. And most people have connections slower than that and that condition will be a fact of life for most ISP customers for a long time. People don't want huge files, they want small ones. And with the increasing popularity of networked mobile phones with small memory capacity, I think there will be more demad for smaller, not bigger files. See also the Freedom to Tinker article on Last Mile.
I can't see any advantage that Itva would bring. It seems like a middle man adding very little value, and worse, contributing to the proposition that ISPs need not act with "net neutrality," which is a bad thing for all consumers/internet users. Breaking large files into small peices and reassembling? So what?
One of the principals of Itiva has recently started a blog (how can you convince venture capitalists without one?) at http://www.robertarn.com/ that doesnt illuminate much about the product, but a lot about his anti-consumer position regarding "net neutrality."
The blog offers a couple of "widespread beliefs" that I don't agree in the first place are widespread, and then spends several paragraphs debunking those beliefs. Then it talks about broadcast video usage on dumb devices like TVs (and even DVRs, where your recorded content is trapped and you cannot access it except to play it back just on that DVR) and implies that the amount of usage on user-controlled computing devices will soon approach it.
Of course, it wont, because copyright holders won't put the content out there, for fear of copying, piracy, and the total inadequacy of any DRM scheme (if your machine can read the data, and you control the machine, then you can always make the machine record the data). He also spends a lot of time bashing P2P, probably because it accomplishes for free what his product will charge for. He also wrongly characterizes as "theft of services" when a paying ISP customer uses P2P. I don't like his attitude, needlessly referring to the Bittorrent creator as autistic, and for being on the wrong side of the net neutrality debate. Maybe because his product is of no use in a net-neutral environment. There's way too much hype, FUD and self-promotion. Compare it to blogs of legitimate companies, where there is no preaching, fact twisting, or arguing. This guy is after the venture capital and that's all.
Granted, I may just be demonstrating my own ignorance. When the first web browser "Mosaic" came out in 1994, I installed it on my 486, looked at it for a few minutes and said "this is stupid," and deleted it.
"Itiva provides the first scalable, reliable and economic Internet video delivery platform"False. There are plenty of scalable, reliable video platforms, the latest of which is bittorrent. Apple.com/trailer serves video content all day long and has for years. Google just bought YouTube that serves tons of video.
"patent-pending technology delivers fast, full screen, high quality (DVD or HD quality) video over the Internet without performance compromise"This is not a compression technology, merely a transport technology. Therefore, I can't see how full-screen DVD quality data can ever be "fast." A movie that fits on a regular DVD is about 4 gigabytes worth of data. That will never be fast no matter how many "quanta" you break it up into.
"highest quality home theatre video experience for millions of simultaneous viewers"Think about Apple's iTunes and how long it took to struggle for a deal with record companies in order to provide the music content. And all that music content is encoded in a "lossy" format not because Apple doesn't have the bandwidth to serve larger, better quality music files, it's really because the record companies will not allow high quality digital content to be sold like that on the internet. They are too worried about flagging CD sales and digital piracy. That's why every single bit of music for sale in iTunes is of worse quality than the CD you can buy at the store. The videos for sale there are also only about VHS quality and smaller than the resolution of a regular TV, and not because Apple can't handle the traffic. Also, look at the fact that Netflix, the internet movie pioneer, still does not offer movie downloads. It's not because of a technical problem, it's because of a legal problem. The MPAA does not want high quality video floating around the internet. So why will these media companies that own the rights to this content suddenly begin releasing it just because a technology appears that makes mass consumption more feasible? If anything, easy mass consumption will make media companies less likely to release high quality digital material.
"while popular in the illegal file sharing community, [P2P] is not suited for large-scale commercial deployment"False. torrents are not just a way to steal copyrighted material. Torrents are used to easily distrubute large (800+meg) files such as Linux CD images by big-name vendors like Debian. Many other open source projects that take up a lot of space are being distributed by torrents/P2P. P2P has lots of purposes. And, if one of your peers happens to be on your same network, their traffic does not have to be routed over the internet to you, permitting the ISP to reap the same benefits that Itva says its own product provides (and that I'm guessing an ISP would have to pay for).
"P2P is also very costly to ISPs because it uses tunneling protocols that have a direct impact on bandwidth cost to the ISPs"Anything that actually uses any bandwidth is going to be costly to ISPs who pay for bandwidth. Unless the data is sourced from within the ISP's network, in which case they are not generating internet traffic in order to serve it. This Itva product seems to involve a little of that but I can't see why I'd be interested in it as an ISP unless I was AOL or MSN. An ISP generally is just a conduit, not a content provider. If they are selecting and providing content, they become legally responsible for it, and why would I be interested in that mess (and losing my DMCA safe harbor) if I make a living selling connections?
"In order to keep these costs under control, ISPs have throttled the P2P protocol by using packet shapers"And in response, people defeat that by training their P2P programs to travel over port 80 to look like other web traffic. Also, if I pay my local ISP for a 1mb/s connection, I am going to complain if they are shaping my torrent traffic down to 256k just because of the type of traffic it is. They sold me a pipe that was advertised to do a certain speed, and it's wrong for them to discriminate against certain kinds of traffic. This concerns the whole "net neutrality" debate that is going on right now. See Freedom to Tinker articles on the subject.
My point is that ISPs cant sell broadband internet connections and then expect to prevent people from using those connections in order to reduce the ISP's own bandwidth costs. Itva is not really solving a problem, the content I want is most likely not on my ISP's network, and therefore I have to get it from the internet. Breaking bits into "Quanta™" and reassembling them on my computer does not use less bandwidth. If I need a 4gig file, 4 gigs worth of bandwidth ultimately needs to be used, if there is no compression (and Itva is not a compression tool).
"designed to support the volume of rich media and streaming video available. Consequently, the video viewing experience is poor and has not yet reached a point that is comparable with traditional TV,"and then claims 4 reasons for why that is.
Those stated reasons are part of the story, but can be overcome with current technology platforms if one is intent on overcoming them. The primary reason digital content doesn't compare with traditional content is because the RIAA and MPAA will not allow high quality digital copies to be put in the stream of commerce because they are afraid of copying.
Itva seems to be mostly some kind of proxy caching thing that ISPs are supposed to employ on their own network so that they can serve their users without having to use internet bandwidth. This means also that ISPs are supposed to pay Itva for this product, but I don't see why they would. It's going to be a long time before a good number of internet users reach even T-1 speeds (relatively low speed broadband), and that's only 1.54megabits per second.
1,540,000 bits = 192,500 bytes
1 megabyte ~= 1,000,000 bytes
at T-1 speed:
5 seconds to get 1 megabyte
500 secs (8m) to get 100 megabytes
5000 secs (1.2h) to get 1 gig.
A full screen DVD quality movie will be at least 3 gigs, and therefore take about 3.5 hours to download, even over a relatively fast T-1 or DSL rated at 1.54mbp/s. Even if my ISP has the movie proxy-cached or running special Itva software so they don't have to deliver over the internet, it still takes this long just to get it the last mile from my ISP to me. And most people have connections slower than that and that condition will be a fact of life for most ISP customers for a long time. People don't want huge files, they want small ones. And with the increasing popularity of networked mobile phones with small memory capacity, I think there will be more demad for smaller, not bigger files. See also the Freedom to Tinker article on Last Mile.
I can't see any advantage that Itva would bring. It seems like a middle man adding very little value, and worse, contributing to the proposition that ISPs need not act with "net neutrality," which is a bad thing for all consumers/internet users. Breaking large files into small peices and reassembling? So what?
One of the principals of Itiva has recently started a blog (how can you convince venture capitalists without one?) at http://www.robertarn.com/ that doesnt illuminate much about the product, but a lot about his anti-consumer position regarding "net neutrality."
The blog offers a couple of "widespread beliefs" that I don't agree in the first place are widespread, and then spends several paragraphs debunking those beliefs. Then it talks about broadcast video usage on dumb devices like TVs (and even DVRs, where your recorded content is trapped and you cannot access it except to play it back just on that DVR) and implies that the amount of usage on user-controlled computing devices will soon approach it.
Of course, it wont, because copyright holders won't put the content out there, for fear of copying, piracy, and the total inadequacy of any DRM scheme (if your machine can read the data, and you control the machine, then you can always make the machine record the data). He also spends a lot of time bashing P2P, probably because it accomplishes for free what his product will charge for. He also wrongly characterizes as "theft of services" when a paying ISP customer uses P2P. I don't like his attitude, needlessly referring to the Bittorrent creator as autistic, and for being on the wrong side of the net neutrality debate. Maybe because his product is of no use in a net-neutral environment. There's way too much hype, FUD and self-promotion. Compare it to blogs of legitimate companies, where there is no preaching, fact twisting, or arguing. This guy is after the venture capital and that's all.
Granted, I may just be demonstrating my own ignorance. When the first web browser "Mosaic" came out in 1994, I installed it on my 486, looked at it for a few minutes and said "this is stupid," and deleted it.
Subscribe to:
Posts (Atom)
