Monday, July 30, 2012

Mountain Lion Brings Encrypted Backups to Network Drives

Starting with OSX 10.8 (Mountain Lion), the "encrypt backup" checkbox in the Time Machine preferences is no longer disabled when you're looking at a network volume like a share on a Time Capsule. It's about time.


Before this, only directly attached volumes (like USB, firewire, eSATA) had this option. This bugged me endlessly because all the beauty and ease of Time Machine was dangled in your face then taken away.

Anyone on 10.7 or lower who really wants to use Time Machine but wants it backed up to network shares and encrypted will have 2 choices.  First choice is to follow advice mentioned in the previous post about putting the unencrypted Time Machine backups into an encrypted sparseimage that resides on the network. The down side of this is that you have to mount the disk image before Time Machine will be able to back up to it. Even with Keychain memorizing the password to the encrypted disk, it still takes some manual intervention or custom Applescript automation to get it mounted.

Second choice is to find a NAS that supports iSCSI (just about all of them except the DroboFS) and configure the backup volume as an iSCSI target. This works to because to the operating system, an iSCSI volume looks like direct attached storage, not a network share. So the "encrypt backup" checkbox in Time Machine options is not grayed out, it is enabled just as if you had plugged in a Firewire external drive. The down side of this is that for 10.7, the cheapest iSCSI initiator is about $80, and the other one is $200. For 10.6, there is a free iSCSI initiator. Aside from having to buy software that costs more than OSX itself, iSCSI shares get forcibly ejected when your computer wakes up from sleep or your network connection goes away. This is the same as yanking the cable of an external drive out of your machine without properly "ejecting" it first. It can corrupt data.



So, this fix in 10.8 is welcome, and is the only reason I upgraded from Lion (which I was almost immediately sorry for last year). Now with Mountain Lion I can set and forget Time Machine to make encrypted backups to network attached storage.

As long as you are making backups, you might also think about keeping a copy off-site in case your house burns down or your stuff gets stolen. Crashplan has a nice way of letting you make backups onto your friends' computers. But suppose you have no friends and need to buy storage? Look at these annual prices.

5G 10G 20G 25G 50G 100G 200G 500G 1TB Unlimited
Google Drive free $29.88 $59.88 $119.88 $599.88
Amazon Cloud free $20 $50 $100 $200 $500 $1000
Apple iCloud free $20 $40 $100
Dropbox free $99 $199 $499 $795
Crashplan $24.99 $49.99

Biggest rip-off is from Apple. The best deal for a place to put your backups is Crashplan, who allows unlimited data storage. Its competitors like Carbonite also have unlimited storage for a slightly higher price, but I didn't bother to list them here because their programs have such strange restrictions like not backing up video files or files larger than 4GB unless you specifically ask for them, and not allowing data from external drives unless you pay more. Crashplan, on the other hand backs up everything you have unless you say not to, including all the external disks you can plug into your computer. Plus, Crashplan gives you the option to backup to local storage (your USB drive) and to your friends' computers, not just to the online service they sell. It's clearly the best deal. When digital stuff is so important in our lives, how is it not worth $4 a month to keep it safe?

The unavoidable downside of online backup service is that your hard drive is probably hundreds of gigs, if not terabytes, and so will take a very long time (days or weeks) to upload your first complete backup. Then, if you have an emergency and need your data back, downloading that much data can still take days. (You are also allowed to cherry-pick files to recover, you're not required to download everything.) To alleviate these delays, Crashplan offers a service for $125 in each direction where they ship you an external drive and you send it back when you're done. 

I'm not subscribing right now because I prefer backing up to my own external drive at an off-site place with good internet access, but if that went away, I'd sign. They even have a "family" plan for about twice as much that allows everyone in your house to pile on to make sure their funny-faces from Photo Booth will be safe forever. 

Saturday, July 14, 2012

Still chasing automatic encrypted backups

Apple disables the "encrypt backup" checkbox for any network volume.


The only way to have an easy encrypted Time Machine backup is to use a directly attached storage device (Firewire, USB, Thunderbolt). That works fine for a desktop computer that stays in one place and you can just leave it plugged in all the time. But if I have to plug an external drive in to my laptop before starting Time Machine, it's not going to get done.

Time Machine volumes are supported on my NAS, but I don't want unencrypted backups so that anyone who steals the backup hardware has total access to all my files. That would be an especially ridiculous result for any who has bothered to enable Filevault (full disk encryption) on a machine. To make it clear, Time Machine backups are not encrypted, even when Filevault is enabled, unless you check that little box to make them so, which you can't if they are on a Time Capsule, NAS or any network volume.

The workaround is to create an encrypted disk image with a special filename, mount that, saving the password in your keychain, and use the "tmutil" terminal command to make Lion accept your Time Machine disk. Even this solution is still wanting, because you have to first mount the sparse bundle before Time Machine will do any work, and if the backup plan relies on me to do anything, it's not going to be reliable or regular.

Until I figure out whether something like iSCSI will work, I'll just keep doing intermittent Crashplan offsite backups (things copy only when I connect to a VPN) and the bi-monthly SuperDuper! disk clone, which is really inconvenient on a Macbook Air whose USB ports don't have enough bus power for a 500G external drive, forcing me to also haul out and get tethered to an AC adapter for the duration.


Friday, July 13, 2012

Faster wifi for NAS or bust

The DroboFS has always been so slow that I never use it. It's just a big waste of $600. Now that I have last year's Macbook Air, there are no fast Firewire 800 (800 mbps) ports, so am stuck with USB (480mbps) for any directly attached external drives. I hate having to plug anything into the laptop, and am enamoured with the idea that Time Machine backups can happen automatically without me having to do anything or think about it.
Because I never actually get to use the massive storage in the DroboFS (because it's so slow it is unusable), I got the biggest internal SSD drive available for the Air. Now that space is running low, so I am ready to fight with the Drobo again to try to get some value out of it.

A fairly nice mechanical (as opposed to SSD) SATA hard drive may be able to read/write at 100MBs (megabytes per second).  To put that into network throughput terms, which are measured in megabits, multply by 8 because there are 8 bits in a byte. So you need at least 800mbps of network bandwidth to work a decent SATA hard drive to its limit. I'm parenthesizing megabits per second (mbps) and megabytes per second (MBs) throughout this post to relate network speed to hard drive speed (measured in MBs), since the point is answering why Network Attached Storage (NAS) like a DroboFS is slow on a slow wireless network.

Recent computers with a "SATA II" bus are capable of moving data at 3 gigabits per second (3000mbps, about 6 times faster than USB speed). Machines made after 2011 probably are "SATA III," and can drive 6 gigabits per second (6000mbps). A "SATA III" machine like my 2011 Macbook Air can work a hard drive up to 750MBs. The fastest SSD drives available right now go only 500MBs, 5 times faster than a decent mechanical drive. Is it starting to be clear that if your network has only 54mbps (54/8 = 6MBs) of bandwidth, there is no way you can take advantage of what even a crappy hard drive can do? That is my problem. Disk access to the DroboFS is only like 5MBs = unusable.

In the DroboFS are a bunch of 2TB Western Digital WD20EARS energy saving "SATA II" hard drives. The lowest benchmarks on these individual drives are around 80MBs. When added to the Drobo, though, they become part of its disk array, and how fast is that? I need to measure from the DroboFS itself, not from my Mac, because I want an answer that does not include any slowdown caused by accessing the device over a network. I just want to know what the Drobo is capable of, and then try to see how close I can get to that when accessing the device as a NAS.

So I get a root shell on the Drobo (DroboApps Dropbear) and ask how long does it take to write a 2,048 megabyte file ("8" * 1024 byte blocks, written "256" * 1024 times)

# time sh -c "dd if=/dev/zero of=/mnt/DroboFS/output.img bs=8k count=256k && sync"
real 0m 54.97s

Now I flush out any filesystem cache that might exist in the Drobo's memory by writing another file that is at least as large as the amount of Drobo's memory, so that when we read the first file back in, it will be a full read, with no "cheating" from the use of any cache. This Drobo hunk of junk has only 128MB of RAM, so 16000 * 8000 should wipe anything.

# dd if=/dev/zero of=/mnt/DroboFS/flush.img bs=8k count=16k 

After any caches are flushed, how fast can it read the first file we wrote?

# time dd if=/mnt/DroboFS/output.img of=/dev/null bs=8k
real 0m 33.70s

Thanks to this blog for the commands, info about sync time and filesystem caches.

RESULTS:
write: 37MBs (2048/54.97)
read: 60MBs (2048/33.7)

Now I see that the maximum potential disk speed on the DroboFS is only 40-60% of what the bare drives have benchmarked when connected directly to a computer with a SATA cable. Even though I know from internet chatter that the processor and memory components of a DroboFS are cheap and under-powered, this performance loss is still a surprise. RAIDed drives add spindles, which should increase performance. But the Drobo is not RAID, it is a proprietary "Beyond RAID." Whatever.

The true performance that I will see in real world use will actually be even less than the result from the test above because those tests are done with "dd" which doesn't really consider the overhead of filesystem format.  So, real world maximum potential will be worse than those figures, let's say 30MBs, which is what most people who are giving the DroboFS favorable ratings say that it can do.

Botom line: You take a 80MBs drive, put it in a DroboFS, and now it is a 30MBs drive. Boo.

30MB/s should still be usable though for Time Machine and other backups, iTunes and iPhoto Libraries, which are the things that are taking up all the space that pushed me to external storage in the first place. Except that when I access the NAS over wifi, I'm getting only like 5MBs.

In my last post, I said I thought the slowness was due to the network, related to my Airport Extreme Base Station being from 2008 when the 802.11n spec (the fastest wifi) was still in draft. Looking at my wifi connection settings on my Air, I was always seeing slow transmit rates like "30" or "54" (megabits per second), which, divided by 8, works out to those slow MBs disk speeds on the NAS.

So I bought a new Time Capsule (instead of a cheaper diskless Airport Extreme, hedging against getting rid of the stupid Drobo at some future time) to see if that would boost my wifi speed from 50mpbs to something closer to the maximum potential of 802.11n wifi, which is 300mbps (37MBs).

I also bought an Apple USB-to-Ethernet adapter made for the Macbook Air without realizing that it has a maximum throughput of only 100mbps. I thought it was GigE (1000mbps) and just expected it to be capped at USB's maximum of 480mbps. It's not, and I've only been able to get about 80mbps out of it. That's still not fast enough (10MBs) to do anything useful with the Drobo, so it will just be an extra part I have lying around.

With the new Time Capsule, I saw my wifi Transmit Rate jump up to 130, almost triple what I was getting with the old Extreme.


But I'm sitting right next to the Time Capsule, and the maximum "n" speed is 300, so it should be faster. Then I notice that it is connecting to the 2.4Ghz band. A nice thing about the new Airport Extremes and Time Capsules is that they broadcast on both the 5Ghz and 2.4Ghz frequencies (so 2.4Ghz-only "n" devices like iPhones and iPads can still join). I wanted to connect at 5Ghz, expecting it to be faster, but the laptop always ended up on 2.4.

I fixed this with Airport Utility by setting the 5Ghz frequency to get a different SSID under the Wireless tab, then the Wireless Options button.
Then I could force the Macbook Air to connect to the 5Ghz network by clicking the Menubar's wifi fan icon, Join Other Network, and entering the distinct SSID. After that it connected to the 5Ghz network with the full 300mbps Transmit rate.


Now my wifi is 6 times faster than when I started. It's still nowhere near the 1000mbps of a wired GigE network, where a NAS would work fine because there's more than enough bandwidth to get full performance from even a 100MBs (800mbps) hard drive. But accessing the same drive at maximum wireless speed, 300mbps, still cuts off about 60% of the drive's performance (300/8 = 37.5MBs). Even so, 30MBs should at least be usable, not like 5MBs. Or 2.5MBs, as experienced by this person whose DroboFS review I enjoyed.

I'll tell you whether any of this saves my DroboFS from the garbage can as soon as my Time Machine backup to the Time Capsule finishes.


* * * *

After my new Synology DS412+ arrived, I took 4 WD20EARS 2TB drives out of the DroboFS and put them in the new NAS configured in a RAID10 set.

RESULTS from "dd" tests at DS412 shell:
write: 273MBs (2048/7.49)
read: 218MBs (2048/9.36)     <-- wow, is that crazy fast for "green" disks?

RESULTS from "dd" tests at Mac shell writing to DS412's AFP share over Wifi
read: 24MBs (2048/85.76)
write: 27MBs (2048/74.68)

RESULTS from "dd" tests at Mac shell writing to Time Capsule (4th gen) share over Wifi
read: 19MBs (2048/108.82)
write: 12MBs (2048/175.14)

Summary: Time Capsule passes (it's just backups and doesn't need to be very fast). DS412+ fileshare over 802.11n wifi is in the usable range. Numbers directly on the DS412 made me recheck my math 3 times.

This tells me that, yes, the DroboFS was about the worst network attached storage device available on the market when I bought it in 2010. They still sell them today. Garbage.

Sunday, July 08, 2012

DroboFS, so slow. NFS Slower.

Two years ago I got a DroboFS because I wanted extra storage accessible to the whole family, a place to keep Time Machine backups, easy hotswap maintenance, and no hassle with plugging in any directly attached storage devices. The Drobo FS can do all this, but it is so slow, I hardly ever use it. Whenever I do try to use it, it is such a slug, I almost always get sidetracked starting to research something to replace it so I can get rid of it. Like this guy.

Using the DroboFS over 802.11n (2.4Ghz, n-only) wireless, it reads and writes at about 5MB/s (megabytes per second). This is under OSX 10.7.4 Lion, the most recent Drobo firmware 1.2.4, and all Western Digital 2TB EARS "green" drives. It's about the same speed when the base station is set to n plus b/g compatibility. In my house, the n-only 5Ghz was worse.

I have read that the best DroboFS will ever do is about 30MB/s (megabytes per second, or 240 megabits per sec), which is 6 times faster than what I am getting out of it over wifi. Sometimes I would be willing to plug in to ethernet to get things moving faster, but that's not very convenient on a Macbook Air with no ethernet.

The Apple Airport Extreme Base Station that I have is from 2008 and can do "802.11n" according to the draft specification that there was at the time. That should mean wireless speeds of up to 160mbps (20 megabytes per second). However, I have never seen it go faster than "g," which is a maximum of 54megabits/sec (6.75MegaBytes/sec). I know this because iStat Menus gives me nice little speedometers in the menubar that I am always checking. If my base station is too old to get real world "n" speed, then I am within 1MB/s of what the hardware can push and it's not Drobo's fault that it's  practically unusable over wifi. But, assuming that I can get "n" wifi speed, there are 15 more megabytes/second (3 times faster) that I should be able to read from/write to it.

While trying to find out whether there was any way to make it faster, I read that some people found some performance gain using NFS, as opposed to the built-in AFP protocol. In order to try it, you have to enable DroboApps, and install the unfsd. I did that and found NFS is even worse than AFP, losing about 1MB/s in both read and write speed.

In order to get NFS to even work at all, I had to read a lot of blog posts. The default exports file that comes with the unfsd app offers to share every share created in the Drobo Dashboard:

/mnt/DroboFS/Shares 10.0.0.0/8(rw,no_root_squash)

and uses the "no_root_squash" option, which means that files created over NFS get done on the Drobo system as the root user. That is usually not good, and usually the opposite of how any software would generally come by default.

In order to connect to this NFS export you can either get to the Finder and choose "Go, Connect to Server" from the top menu (Command + K) and type:

nfs://[IP address of DroboFS box]/mnt/DroboFS/Shares/

(Notice that the path on the end of that connection string is the entire full path to the share from the perspective of the Drobo box. It won't work if you put the share name alone after the IP address.)

Or you can manually mount the export from a shell prompt. Before mounting this way, you have to make an empty directory as the spot that you will mount it on top of. So, first:

mkdir ~/myDroboshare


sudo mount -w -t nfs 10.0.1.2:/mnt/DroboFS/Shares/Public /Users/[your username on your Mac]/myDroboshare

all the above has to be typed on 1 line.

If you do one of the above, then you'll find the share accessible to OSX and can see it in Finder windows, and from a shell prompt you will be able to write in there. But from the GUI, everything will appear as a read-only filesystem. GUI apps will think they cannot write in there and give you error messages.




In order to fix this problem, you need to get back to the Drobo box and edit the services.sh file that is in the same directory as the exports file (/mnt/DroboFS/Shares/DroboApps/unfsd/) and add in a "-s" for "single user mode" to this line:

${prog_dir}/unfsd -s -e ${exportsfile} -i ${pidfile} >> ${logfile} 2>&1

After editting the file, you want to restart the nfs service on the Drobo box. The best way to do that is by running that script from a shell prompt on the DroboFS box:

/mnt/DroboFS/Shares/DroboApps/unfsd/service.sh restart

In order to do it that way, you will have to have installed the Dropbear SSH app, and ssh into the box as root. Otherwise, the only way to restart any of these DroboApps is to restart the whole DroboFS box, by turning it off and on, or using the "restart" button in Drobo Dashboard under the "Tools" menu.


Wednesday, November 09, 2011

Fun with Applescript, VPN and Proxy

I have a lot of digital pictures and home movies, and I'm supposed to be smart enough not to lose them by mistake or hardware failure. So part of my backup process is to backup files off-site across the internet using Crashplan.

This worked fine at first, but over time something happened and my computers just couldn't see each other unless I connected over a VPN. Bringing up the VPN is a manual step (enough of them and you won't have backups anymore), and so is restarting it when it drops, which happens at least once an hour.

If I don't have too much data, then I can start the VPN, nudge Crashplan to notice it right away, and get my files sent off-site. But if there is a lot, home broadband upload speed is slow, and not much will be done before the VPN gets knocked down. Then the backup will stop until I come back and fix it, which probably won't happen. Usually when I see that I have hundreds of megs or more of stuff not finishing, I will just bring my computer to the other site, plug it into gigabit ethernet LAN where it can finish pretty quickly.

After staying up too late on the internet the other night, I found out how to automatically restart the VPN when it falls down. So now I can just leave the computer on at home and bigger backups get farther without babysitting.

It's just an Applescript, created with "Applescript Editor" that comes with every Mac, "Saved As" format "Application," with the checkbox for "Stay Open" checked. I saved it under my Home directory in ~/Applications/restartVPN.app

on idle
    tell application "System Events"
        tell current location of network preferences
            set myConnection to the service "WHATEVER THE SERVICENAME IS"
            if current configuration of myConnection is not connected then
                connect myConnection
            end if
        end tell
        return 60
    end tell
end idle

The "WHATEVER THE SERVICENAME IS" is whatever the VPN service is called in the list of services under System Preferences, Network. If it's a long name, it might be shortened in the list with an ellipsis but you can see the full name by either hitting the "Advanced" button and looking at the top of the next pane, or by checking the "Show VPN status in menubar," then clicking that menubar icon.

Under Lion, if you need to add routes for the VPN, you put them in /etc/ppp/ip-up


#!/bin/sh
if [[ "$5" == "123.456.789.253" ]]; then
/sbin/route add -net 10.10.10.0/24 123.456.789.253
fi

Now whenever I start the VPN connection, I also invoke Spotlight (Command+Spacebar), start typing "restartVPN.app" and after a couple of letters, when that result jumps to the top of the list, hit the Enter key and the will app run until I quit it. With VPN disconnections of less than 60 seconds, Crashplan can keep uploading to the other side for as long as the machine is on.

Hungry for more Applescript, I thought about how many manual steps there are to setup system wide proxying through an ssh tunnel. First, open Terminal, run "ssh -D 9999 me@somewhereelse" to connect to the other host (using ssh keys) where I want my tunneled traffic to come out. Then System Preferences, Network, click my current servicename (typically Wi-Fi), Advanced, Proxies, then enable checkbox for "SOCKS proxy" ("SOCKS proxy server" on that pane should have "localhost:9999"), then "OK" and then finally "Apply."

What a hassle, but then, SOCKS aware apps like Firefox will automatically send their traffic through the tunnel, so my IP address while browsing will be the IP of the place I ssh'd to, not the IP assigned by my Internet Service Provider at home. However, not all programs are SOCKS aware. Transmission, uTorrent and wget are not. When they connect to places on the net, they do it with your real, not proxied, IP. Safari, Vuze and Xtorrent are: TCP only reveals your proxy IP to those you connect to. Curl can do SOCKS, but you have to ask it special, and even when the tunnel is down, it still acts like it is there, which was confusing to me and I didn't spend much time trying to figure it out. 

So, to automate setting and unsetting the system wide SOCKS proxy,  here's a bash shell script. It scans to see if it's already on or not. If it's on, it turns it off. If it's off, it turns it on, kills any ssh process that looks like a leftover from an old tunnel, creates a new ssh tunnel, and prints the current status and my IP address as seen from the other side of any tunnel in a Growl notification.

The script uses "osacript" in order to run some Applescript to launch Safari and read a webpage to figure out the IP address I look like on the internet. The Applescript is because Safari will use the tunnel if it is there -- wget cannot (and curl was just weird).

#!/bin/bash

device="Wi-Fi"
#device="Ethernet"

function myip {
osascript <<
EOF

property myURL : "http://automation.whatismyip.com/n09230945.asp"

tell application "Safari"
 

    if (count documents) = 0 then
        make new document with properties {URL:myURL}
    else
        set URL of document 1 to myURL
    end if 



    launch
    repeat until exists (window 1)
    end repeat

    repeat with w in (get every window)
    set miniaturized of w to true
    end repeat

    tell window 1
        delay 1
        set mySrc to source of the current tab
        return mySrc
    end tell

end tell
EOF
}

if [[ `scutil --proxy | grep SOCKSEnable | awk '{ print $3 }'` == "1" ]]; then
    networksetup -setsocksfirewallproxystate "$device" off
    proxyState="disabled"
else
    networksetup -setsocksfirewallproxy "$device" 127.0.0.1 9999 off
    kill `lsof -i 4TCP@localhost:9999 -P -sTCP:LISTEN -a -c /^ssh$/ | awk '{ print $2 }' | tail -1`; 2> /dev/null
    ssh -N -D 9999 me@somewhereelse &
    proxyState="enabled"
    sleep 5
fi

if [[ -e /usr/local/bin/growlnotify ]]; then
       /usr/local/bin/growlnotify -m "IP: `myip`." "SOCKS Proxy: $proxyState"
else
    echo "SOCKS Proxy $proxyState. IP: `myip`."
fi


This shell script could just be run from a Terminal window, but I decided to turn it into an "application" with Automator.app so that I could invoke it with a Quicksilver keyboard shortcut. That is Command+Spacebar, type "automator" (click it or hit Enter when "Automator" jumps to the top), then Command+N, click "Application" and "Choose" from the "Choose a type" dialogue, then drag the "Run Shell Script" action into the big empty workflow area, erase the default "cat" text from the input box and replace it with the full path to where you saved the shell script, like /Users/whoeveryouare/togglesox.sh then "File", "Save" as format "application." I saved mine as  togglesox.app under the Applications directory below my home directory.

Then go get really frustrated trying to remember how to set a Trigger for a keystroke combination in Quicksilver while Lion acts buggy and freezes Quicksilver or makes it disappear. The keystroke should "open" /Users/whoeveryouare/togglesox.app or wherever you saved it. Alfred or regular OSX Keyboard Shortcuts could also launch it.

So now I can do Command+Shift+p and a little Growl notice will popup on my screen telling me "Proxy Enabled; IP address [other side of my tunnel]." Do it again and Growl shows "Proxy Disabled; IP address [given by my ISP ]."

I also found http://checkmytorrentip.com/ to be helpful in telling you whether your torrent client is going through your tunnel or not, since I just found out that a checkbox setting I enabled months ago in Transmission preferences for something about "SOCKS proxy" only referred to trackers, not to peers, and that setting is now gone and feature removed in the current version.

All this took way more time to get working than could possibly be justified, so please make some use of it.

Monday, April 04, 2011

Stop form input from capturing/ignoring certain keypresses

Too many web forms have some stupid javascript that tries to limit what keys you can press while you are focused in a certain input element. For example, in my bank billpay system, they have javascript that makes it so you can only type numbers while you are in the "Zip Code" field. When they do that, it disables me from using the CMD+v to paste a zip code in the field, because "CMD+v" is not a number.

Here is a sample of the javascript they use:

function numbersonly(myfield, e)
{
    var key, keychar;
    if (e) key = e.which;
    else return true;
   
    // allow control keys
    if ((key==null) || (key==0) || (key==8) ||
         (key==9) || (key==13) || (key==27) )
        return true;

    // numbers
    else if ((("0123456789").indexOf(keychar) > -1))  return true;
    else return false;
}

Then they have HTML like this:

<input onKeyPress="return numbersonly(this, event)" type="text" />

So, if you are a Windows user, you probably are allowed to CONTROL+v to paste a zip code. But Mac users just see the "Edit" menu flicker for a moment and their paste command (keycode 118) is dropped on the floor. Neither can you "CMD+," (keycode 44) to get Application Preferences, or use the metakey to do any other Firefox action while in that form field. It should validate only when the user is ready to submit, not while typing.

Install Greasemonkey and rip that crap out with this script:

// ==UserScript==
// @name           Get Off My Keypress
// @namespace      http://gomk.amulder.modwest.com/gomk.user.js
// @description    stop websites from setting event handlers to capture your keypresses
// @include        https://sitethatbothersyou.com/*
// @require  http://ajax.googleapis.com/ajax/libs/jquery/1.5.1/jquery.min.js
// ==/UserScript==

$(document).ready(function() {
    // unsafeWindow.console.log("testing firebug after jq");     
    $("input").each(function(i, elem) {
        // unsafeWindow.console.log(i + $(elem).attr("name"));
        var h = elem.getAttribute("onKeyPress");
        // might return "return numbersonly(this, event)"
        if(h) elem.setAttribute("onKeyPress", "return true");
    });     
}); 

Having to use Greasemonkey is really more complicated than it should be. We should be able to use the new CAPS (capabilities) security policy settings built into Firefox 4 to grant noAccess to specific websites to set onkeypress events or read what keys you are pushing on. I tried several iterations using the "Control de Scripts" extension to block these:

HTMLInputElement.onKeyPress
Window.numbersonly
Window.onKeyPress
Window.onkeypress
event.preventDefault 

but none worked. I think this is because I don't really grasp what an event handler is or where it is in the DOM. Maybe someone else can comment to get a solution that is native to the browser, without needing a whole extension just to do this one simple thing.

Saturday, March 26, 2011

Review of OWC 480G SSD laptop drive

After waiting for SSD notebook drives to get big enough that I could fit everything on it that I carry around on my Hitachi 500G 7200 rpm mechanical drive, OWC finally came out with a 480G SSD last summer that was over a thousand dollars. Just recently, they lowered the price a lot and I got mine for a total of $908, including Fedex 2 Day shipping and a $25 rebate for using Amazon Checkout when I bought it through their website.

I think the price change is related to recent Sandforce chip changes and maybe also that the next rev Sandforce 2000, reportedly twice as fast as these, may be only 8 weeks away.

I got the drive on time from OWC and, unlike the Seagate that just came in an antistatic bag like a McDonald hamburger, this one came in nice retail packaging. Since I mention the Seagate, I should also say that this Hitachi that I eventually replaced it with was slightly slower, but without the confidence eroding clicking, and maybe less pinwheels until recently.

Before installing the new SSD drive, I ran some crude benchmark tests, then used SuperDuper! to clone my old internal drive to my external backup, a firewire 800 G-Drive Mini, which are the nicest bus-powered enclosures I have seen. After making a bootable backup, I opened the laptop to install the new SSD drive, then booted from the firewire backup.

Upon logging in, OSX offered to "initialize" the unrecognized/unformatted internal SSD drive. When I said yes, it opened Disk Utility, where I clicked the disk, named it, and erased/formated it as MacOS Extended (Journaled). Then I launched SuperDuper! and told it to restore everything from the external backup drive that I had booted from onto the empty internal SSD. That process read data off the 5400rpm backup drive and over the firewire at about 50MB/s (according to the "Disk Activity" graph in Activity Monitor). While 300 gigs went from here to there I did laundry and played with my baby.

Once my backup was restored to the internal SSD, I rebooted and here is the comparison:

Boot time comparison
7200rpm OWC SSD
Apple logo 38 sec (but probably with unset startup drive system preference setting) 4 sec (after setting startup drive in system preferences)
Login Window +30 sec +13 sec
Boot Total 68 sec 17 sec
Login and launch all startup items, including Firefox +80 sec +9 sec
Usable Total 148 sec (2.5 minutes) 26 seconds

I was pretty impressed with how fast it launched all my stuff after I logged in. The OWC website linked above has a graph showing powerup to desktop in 19 seconds. Mine's not doing that, but I am still happy with it.  Correction on March 28,2011: Thanks to the article on macperformanceblog that tells you to set your startup disk after upgrading a hard drive, my machine really does go from off to login window in < 20 seconds! If I can type my password fast enough, my machine is totally ready to use in a total of < 35 seconds!

Here are 2 more before/after comparisons.

Xbench

dd test
Writing to /test on the 7200 rpm drive:
#sudo time dd if=/dev/zero of=/Volumes/Macintosh\ HD/test bs=1024k
[waited a while, then CNTRL+c]
97679048704 bytes transferred in 1565.832047 secs (62381562 bytes/sec)

Reading /test on the 7200 rpm drive:
#sudo time dd of=/dev/null if=/Volumes/Macintosh\ HD/test bs=1024k
[waited a while, then CNTRL+C]
39557529600 bytes transferred in 543.910842 secs (72727967 bytes/sec)
#sudo rm /test

Writing to /test on the SSD:
#sudo time dd if=/dev/zero of=/Volumes/Macintosh\ SSD/test bs=1024k count=16384;
17179869184 bytes transferred in 66.070450 secs (260023493 bytes/sec)

Reading /test on the SSD:
#sudo time dd of=/dev/null if=/Volumes/Macintosh\ SSD/test bs=1024k
17179869184 bytes transferred in 61.126414 secs (281054753 bytes/sec)
#sudo rm /test

So that tells me compared to the 7200rpm Hitachi writing 59MB/s and reading 69MB/s, the SSD's 248MB/s writes and 268MB/s reads are about 4 times faster. Plus, the battery runtime that the battery monitor is reporting now looks about an hour longer than it would have been with the mechanical drive.

This and the cheap 8 Gig RAM upgrade also from OWC put an end to any other hardware upgrades for this computer.

Wednesday, January 20, 2010

BoA Nickname Payees Greasemonkey Script

Bank of America does not let you create "nicknames" for your payees on its Quickpay online billpay webpage. This means that if you have more than 1 account with the same entity, or different individuals with the same bank, it is very hard to tell your payees apart when you go to make a payment. This can result you sending a payment to the wrong payee.

You may end up with identical looking payees if you pay utility bills to the same company for more than 1 address, or if you frequently send money to family members who use the same bank as each other. In these cases, the way BoA's Quickpay page is now, you would have to memorize which account number goes with which payee in order to tell them apart and make a payment to the right person. See the screenshot below for how confusing it is:



In the screenshot above, the first "BANK OF AMERICA CHECKING" in the payee list is for one person, and the second one is for someone else, who also happens to bank at BoA. I wrote this Greasemonkey User Script in order to let people who use the BoA billpay create useful nicknames for these payees, since the BoA system doesn't allow it.

After you install the Greasemonkey script, you'll be able to create and edit nicknames for your payees by clicking the link to "create nickname" or by clicking the nickname to edit if you already created one. All other items display on the QuickPay page as usual. After you've made some nicknames, the billpay screen will look like this:



Now you can tell your payees apart without having to remember which account number is which.

Here is the script:


You can also download it from https://gist.github.com/3272964

Sunday, January 03, 2010

Thinking about using itshidden.com

I was thinking of using the anonymous VPN service from itshidden.com. I was even thinking of paying for it, despite not knowing the reliability or trustworthiness of those on the other end. So I signed up and got this:



So, just nevermind.

Tuesday, May 19, 2009

Review of new Seagate 500g 7200rpm laptop hard drive

When my 1 year old Hitachi laptop hard drive died in March, I started shopping for a bigger one. That's when I found the new Seagate Momentus 7200.4 model ST9500420AS with 500 gigs of space at 7200rpm.

At that time though, the drive was out of stock everywhere as Seagate seemed to have stopped production to fix some engineering problems. Since even now (May 2009) this is the biggest and fastest consumer 2.5 inch drive available, I decided to wait for it.

In the mean time, I read reviews on it, which were mixed. Some people who got their hands on one of the first run models reported them slow, noisy, buggy and hot. Other owners reported back that the drives were fine. Two more good reviews issued from barefeats and hardwarelogic.

After about 2 months of waiting, these drives were for sale once again, this time with updated firmware 2SDM1. This is the one I bought online from WiredZone for $133 with free shipping. It's just a brown box, egg foam and anti-static bag. No glossy fanfare, manuals or any of that. I don't know if that's typical.



Before evicting the old (warranty replacement) Hitachi 200g 7200rpm, I decided to take some crude benchmarks of it so I'd know whether the new Seagate was any better. Say goodbye to HTS722020K9SA00 Made in Thailand:



Hello Seagate Hecho in China:

Seagate ST9500420AS 7200rpm 500gig, firmware: 2SDM1

After copying a bootable backup onto an external firewire drive with the excellent SuperDuper! cloning software, I was ready to swap drives. Disassembly instructions for the model 3,1 MacBook Pro are at iFixit. If you have a Bugs Bunny video, then you won't have to unhook the delicate ribbon cable that connects the keyboard to the motherboard.



After the swap, I booted from the external firewire drive and used SuperDuper! to clone back onto the new empty internal hard drive. Then a reboot and everything is running on the new Seagate.

Now, for the comparisons, which may not be quite fair because the Hitachi was almost full for the benchmarks, while the Seagate was mostly empty.

Boot Time
HitachiSeagate
Apple Logo: 51 sec
Login Window: +33 sec
Total: 84 secs
Apple Logo: 16 sec
Login Window: +40 sec
Total: 56 secs


Xbench
HitachiSeagate
Results 43.50
System Info
Xbench Version 1.3
System Version 10.5.6 (9G55)
Physical RAM 4096 MB
Model MacBookPro3,1
Drive Type Hitachi HTS722020K9SA00
Disk Test 43.50
Sequential 79.03
Uncached Write 108.92 66.88 MB/sec [4K blocks]
Uncached Write 110.86 62.73 MB/sec [256K blocks]
Uncached Read 40.92 11.98 MB/sec [4K blocks]
Uncached Read 125.34 62.99 MB/sec [256K blocks]
Random 30.01
Uncached Write 9.76 1.03 MB/sec [4K blocks]
Uncached Write 97.19 31.11 MB/sec [256K blocks]
Uncached Read 77.83 0.55 MB/sec [4K blocks]
Uncached Read 130.73 24.26 MB/sec [256K blocks]
Results 52.73
System Info
Xbench Version 1.3
System Version 10.5.6 (9G55)
Physical RAM 4096 MB
Model MacBookPro3,1
Drive Type ST9500420AS
Disk Test 52.73
Sequential 119.09
Uncached Write 164.42 100.95 MB/sec [4K blocks]
Uncached Write 146.68 82.99 MB/sec [256K blocks]
Uncached Read 65.58 19.19 MB/sec [4K blocks]
Uncached Read 183.84 92.39 MB/sec [256K blocks]
Random 33.86
Uncached Write 10.73 1.14 MB/sec [4K blocks]
Uncached Write 171.66 54.96 MB/sec [256K blocks]
Uncached Read 80.56 0.57 MB/sec [4K blocks]
Uncached Read 148.96 27.64 MB/sec [256K blocks]


Bonnie++
Hitachi:
Version 1.93c       ------Sequential Output------ --Sequential Input- --Random-
Concurrency 1 -Per Chr- --Block-- -Rewrite- -Per Chr- --Block-- --Seeks--
Machine Size K/sec %CP K/sec %CP K/sec %CP K/sec %CP K/sec %CP /sec %CP
arf.local 16G 297 97 52023 18 24538 9 332 95 55015 11 105.9 10
Latency 80374us 687ms 610ms 121ms 213ms 4029ms
Version 1.93c ------Sequential Create------ --------Random Create--------
arf.local -Create-- --Read--- -Delete-- -Create-- --Read--- -Delete--
files /sec %CP /sec %CP /sec %CP /sec %CP /sec %CP /sec %CP
16 6111 55 +++++ +++ 9257 61 367 8 +++++ +++ 151 4
Latency 76653us 920us 79744us 333ms 1399us 414ms

Seagate:
Version 1.93c       ------Sequential Output------ --Sequential Input- --Random-
Concurrency 1 -Per Chr- --Block-- -Rewrite- -Per Chr- --Block-- --Seeks--
Machine Size K/sec %CP K/sec %CP K/sec %CP K/sec %CP K/sec %CP /sec %CP
arf.local 16G 293 96 90295 32 36049 14 343 98 91548 20 164.4 13
Latency 134ms 388ms 217ms 85474us 132ms 1942ms
Version 1.93c ------Sequential Create------ --------Random Create--------
arf.local -Create-- --Read--- -Delete-- -Create-- --Read--- -Delete--
files /sec %CP /sec %CP /sec %CP /sec %CP /sec %CP /sec %CP
16 5313 56 +++++ +++ 5567 41 320 8 +++++ +++ 149 5
Latency 106ms 200us 151ms 497ms 380us 322ms


dd
I ran the write in root "/" directory (and therefore had to use sudo) to avoid writing in my home directory, which is Filevault and would probably skew performance downward. The 1st dd in each section below is writing, the 2nd is reading.

HitachiSeagate
$ sudo time dd if=/dev/zero of=/Volumes/Macintosh\ HD/test bs=1024k count=16384;
17179869184 bytes transferred in 319.400409 secs (53787875 bytes/sec)

$ time dd of=/dev/null if=/Volumes/Macintosh\ HD/test bs=1024k
17179869184 bytes transferred in 305.974147 secs (56148107 bytes/sec)
$ sudo time dd if=/dev/zero of=/Volumes/Macintosh\ HD/test bs=1024k
17179869184 bytes transferred in 188.208635 secs (91280983 bytes/sec)

$ time dd of=/dev/null if=/Volumes/Macintosh\ HD/test bs=1024k
17179869184 bytes transferred in 180.531769 secs (95162581 bytes/sec)


The result of the tests showed that in addition to more than doubling my disk space with the new drive, it is also objectively faster than the old one, even at the same spindle speeds. However, this is probably just because the new one is mostly empty and the old one was mostly full. Performance will always be a lot better when data is on the beginning instead of the end of a mechanical drive.

The last bit of info to share is from SMART, accessed with smartctl from smartmontools. The Hitachi was in pretty good shape, aside from the strange value for Power-Off_Retract_Count. Don;t have a clue what that one means:

Hitachi SMART
Model Family:     Hitachi Travelstar 7K200
Device Model: Hitachi HTS722020K9SA00
Serial Number: 080830DP0470DTGP3MMC
Firmware Version: DC4AC77A
User Capacity: 200,049,647,616 bytes
Device is: In smartctl database [for details use: -P show]
ATA Version is: 8
ATA Standard is: ATA-8-ACS revision 3f
Local Time is: Sun May 17 23:31:07 2009 PDT
SMART support is: Available - device has SMART capability.
SMART support is: Enabled


SMART Attributes Data Structure revision number: 16
Vendor Specific SMART Attributes with Thresholds:
ID# ATTRIBUTE_NAME FLAG VALUE WORST THRESH TYPE UPDATED WHEN_FAILED RAW_VALUE
1 Raw_Read_Error_Rate 0x000b 100 100 062 Pre-fail Always - 0
2 Throughput_Performance 0x0005 100 100 040 Pre-fail Offline - 0
3 Spin_Up_Time 0x0007 176 176 033 Pre-fail Always - 1
4 Start_Stop_Count 0x0012 100 100 000 Old_age Always - 200
5 Reallocated_Sector_Ct 0x0033 100 100 005 Pre-fail Always - 0
7 Seek_Error_Rate 0x000b 100 100 067 Pre-fail Always - 0
8 Seek_Time_Performance 0x0005 100 100 040 Pre-fail Offline - 0
9 Power_On_Hours 0x0012 100 100 000 Old_age Always - 342
10 Spin_Retry_Count 0x0013 100 100 060 Pre-fail Always - 0
12 Power_Cycle_Count 0x0032 100 100 000 Old_age Always - 192
191 G-Sense_Error_Rate 0x000a 100 100 000 Old_age Always - 0
192 Power-Off_Retract_Count 0x0032 100 100 000 Old_age Always - 42954326020
193 Load_Cycle_Count 0x0012 100 100 000 Old_age Always - 8991
194 Temperature_Celsius 0x0002 130 130 000 Old_age Always - 42 (Lifetime Min/Max 14/47)
195 Hardware_ECC_Recovered 0x000a 100 100 000 Old_age Always - 0
196 Reallocated_Event_Count 0x0032 100 100 000 Old_age Always - 0
197 Current_Pending_Sector 0x0022 100 100 000 Old_age Always - 0
198 Offline_Uncorrectable 0x0008 100 100 000 Old_age Offline - 0
199 UDMA_CRC_Error_Count 0x000a 200 200 000 Old_age Always - 0
223 Load_Retry_Count 0x000a 100 100 000 Old_age Always - 0


The Seagate, on the otherhand, looked alarming when I first checked it out. I thought the drive was defective and was ready to send it back for RMA:

Seagate SMART
$ sudo smartctl -s on /dev/disk0
SMART Enabled.

$ sudo smartctl -a /dev/disk0
Device Model: ST9500420AS
Serial Number: 5VJ079ZE
Firmware Version: 0002SDM1
User Capacity: 500,107,862,016 bytes
Device is: Not in smartctl database [for details use: -P showall]
ATA Version is: 8
ATA Standard is: ATA-8-ACS revision 4
Local Time is: Wed May 20 00:42:19 2009 PDT
SMART support is: Available - device has SMART capability.
SMART support is: Enabled
...
SMART Attributes Data Structure revision number: 10
Vendor Specific SMART Attributes with Thresholds:
ID# ATTRIBUTE_NAME FLAG VALUE WORST THRESH TYPE UPDATED WHEN_FAILED RAW_VALUE
1 Raw_Read_Error_Rate 0x000f 118 100 006 Pre-fail Always - 184273167
3 Spin_Up_Time 0x0003 100 100 085 Pre-fail Always - 0
4 Start_Stop_Count 0x0032 100 100 020 Old_age Always - 2
5 Reallocated_Sector_Ct 0x0033 100 100 036 Pre-fail Always - 0
7 Seek_Error_Rate 0x000f 100 253 030 Pre-fail Always - 139058
9 Power_On_Hours 0x0032 100 100 000 Old_age Always - 24
10 Spin_Retry_Count 0x0013 100 100 097 Pre-fail Always - 0
12 Power_Cycle_Count 0x0032 100 037 020 Old_age Always - 5
184 Unknown_Attribute 0x0032 100 100 099 Old_age Always - 0
187 Reported_Uncorrect 0x0032 100 100 000 Old_age Always - 0
188 Unknown_Attribute 0x0032 100 100 000 Old_age Always - 0
189 High_Fly_Writes 0x003a 100 100 000 Old_age Always - 0
190 Airflow_Temperature_Cel 0x0022 062 052 045 Old_age Always - 38 (Lifetime Min/Max 28/41)
191 G-Sense_Error_Rate 0x0032 100 100 000 Old_age Always - 0
192 Power-Off_Retract_Count 0x0032 100 100 000 Old_age Always - 0
193 Load_Cycle_Count 0x0032 099 099 000 Old_age Always - 3798
194 Temperature_Celsius 0x0022 038 048 000 Old_age Always - 38 (0 22 0 0)
195 Hardware_ECC_Recovered 0x001a 045 045 000 Old_age Always - 184273167
197 Current_Pending_Sector 0x0012 100 100 000 Old_age Always - 0
198 Offline_Uncorrectable 0x0010 100 100 000 Old_age Offline - 0
199 UDMA_CRC_Error_Count 0x003e 200 200 000 Old_age Always - 0
240 Head_Flying_Hours 0x0000 100 253 000 Old_age Offline - 70690866724884
241 Unknown_Attribute 0x0000 100 253 000 Old_age Offline - 2076453070
242 Unknown_Attribute 0x0000 100 253 000 Old_age Offline - 2307582568
254 Unknown_Attribute 0x0032 100 100 000 Old_age Always - 0

SMART Error Log Version: 1
No Errors Logged

SMART Self-test log structure revision number 1
Num Test_Description Status Remaining LifeTime(hours) LBA_of_first_error
# 1 Short offline Completed without error 00% 21 -
# 2 Extended offline Aborted by host 90% 21 -
# 3 Extended offline Aborted by host 60% 9 -
# 4 Extended offline Aborted by host 50% 2 -


Raw_Read_Error_Rate, Seek_Error_Rate and Hardware_ECC_Recovered make it look like the disk is dying. Attributes 240, 241, 242 are nonsensical. After investigating though, it seems that these type of values on those attributes are just normal for a Seagate.

A few searches on these attributes will find many discussions where people are concluding that these odd values don't indicate a problem. Seagate also has a KB article basically warning users not to pay attention to those SMART values. Apparently they stuff their own proprietary values into the SMART circuits which only becomes meaningful when pulled through their "Seatools" disk analyzer software. Regular SMART software tools that follow the published SMART protocols won't be able to make any use of Seagate's stored raw values for those attributes. Incidentally, there is no Mac version of Seatools.

I've had my new Momentus drive running now for about 24 hours. Over the last 4 hours while I've been using the machine, I have heard a pretty loud "CLUNK" twice. Probably the heads parking or unparking for powersaving mode. The Hitachi never did that, but it's only happened twice and other than that, I can't tell the difference between this drive and the old one by noise, vibration or temperature. Tests indicate that there are no errors that other owners were complaining about this past winter with the older firmware rev, and it is a bit faster than Hecho in Thailand.

I guess it's a good one but I'll still keep up the SuperDuper! onsite and Crashplan offsite regimen.