Tuesday, August 11, 2026

27 things Apple will forget to fix in their "System 27"

After a significantly extended hiatus (2010-2025), I have made a decision to switch back to Apple.

With my "fresh eye for UI" I can see some ugly things that should have been fixed long time ago.

For the sake of challenge, I will try and describe 27 "phenomena" that irk my eye every time and make me miss the good old Steve who was a profound, demanding, and family-based user - just like me.

Let's start with the Mac.

1. Fullscreen Mode.

This is some kind of strange and unbelievable (for 2026) experience where the user interface insists that you do not take only one step to do what you intent to do.

For example, when you click on the nice green round button in the upper left of the window, you enter the Full Screen mode. Now there are following issues that I simply do not understand why they exist:

a) you cannot click the yellow button now to collapse the window and expose (free) the screen;


b) you cannot choose "Hide App" action either, by pressing Command+H;

c) you cannot drag any other window onto this "already full" screen, for some reason the whole device is taken so in multi-screen scenarios dragging another open window over a running fullscreen video is impossible (!)

What you MUST do FIRST, is to "gracefully EXIT" this wicked mode in order to continue with repeating your next desired desktop action.

But no, it gets worse. 

d) if while running something fullscreen, you activate another app (say, by switching using Command+Tab), you will see the previously fullscreen'd window take up its normal size, BUT become grey with text "Click to exit FullScreen". The audio will run normally.


Come on, I thought you have already exited the mode, have not you, System 26?

2. Stacks of screenshots.

I don't know about you but I like taking screenshots. With a constantly moving zeitgeist, they can be so much fun - in not so long time. What was weird, becomes normal, and vice versa. It helps to keep the record.

Since by default the screenshots drop onto your desktop I have enabled the feature to collapse them all onto a single stack (Command+Control+0). There is no subfolder.

Now, as time have passed, hundreds of them accumulated in the stack.

When I open the stack, a million of them stares at me. I think they cover the display many times over, forming sort of "sub-stacks" (!) at each position.

Now, how do I hide them back after perusing some? Lord only knows.

I resorted to quick log-outs, log back ins.

3. The window-less apps. (a pointless rant on inconsistency)

On a Mac, historically, and because it is "not Windows", there have been a possibility to have apps without windows. They can have a title bar, and menu, but you may close all windows and the app still runs there, waiting for you to press something like Command+N or Command+O so that it can gain a window (or two). Now, this means you can actually have TWO types of windowless apps - one as per above and the "system bar utilities". The laters do not have a menu and are not in the Switcher carousel on Command+Tab.

With upcoming (or ongoing?) attempts at unifying the various operating systems, it may be seen more harmonious if all devices (at least iPad and Mac) behaved the same way. But on iPadOS, the windowless apps are not there. You close the window, app is closed.

Speaking of iPad..

4. The (almost Microsoft-ey) Recall.

One of the better parts of switching apps on iOS become possible when hp webOS turned up face down ashore. The Andy Rubin's webOS design detail was impeccable - the best I have seen so far. And the app switching element of that OS have found its way (great artists do what?..) onto the myriad of Apple devices in our pockets. I am talking about "switcher carousel" where app "cards" are standing representations of... currently NOT OPEN apps, quite often and sadly.

I do not know definitively, but I can speculate about the reason why the app card remains when the app itself is swapped out of memory and all runtime context is lost. The reason is likely quite small RAM size in iPhones of the time that element was introduced (webOS went kaput in 2013 if I remember my TouchPad / Pre3 era correctly), back then it must have been 1GB.

Not surprisingly, Apple never wanted to give their users "impression" that the memory on the device is quite limited, so they decided to NEVER remove the cards from the carousel, no matter what happened to the apps themselves. Idiotically, those cards even now survive the device restart!

You may have nothing running, but your carousel will be full off cards with screenshots of something you have been doing there last time the app was ran and was swapped up on.

Dare I call this.. Apple Recall ?

There is two issues with that:

a) it breaks WYSIWYG (what you see is what you get) priciple of UI design; you can see "Laura's face" in that message in email, but clicking on the card will only bring up email with Inbox and a list of current emails;

b) it exposes user activity, though to a lesser level than Microsoft Recall - there is only ONE snapshot, and it will be gone once the app is relaunched - still, spooky!

Why not remove the card once the app has been swapped? The RAM memory sizes now are quite generous, and this small mod may even trigger power users into buying more expensive devices to see more apps stay and remain in memory and in context. I am saying we can help Apple sales and UX all at once.

5. The Power Struggles.

Since we've been rekindling wonders of webOS, one thing it did best was notifications. All of them. All non-modal, e.g. not blocking whatever you were doing - typing, dragging bunch on files from a folder into another, painting doodles with your finger - none were ever interrupted. Even.

Not by a phone call. Not by a draining battery. Not by a text message. Not by email... you get the point.

All of those notifications appeared as a sub-banner down at the bottom bar of the screen, along with buttons to accept/reject a call, reply to a message, or switch to powersaving mode (now I'm fantasising - the low power ones simply had a spinner circle with a countdown to self-hide, I think it was 3 seconds).

They all would leave you alone if you ignore them. They would self-hide, you may check them again when you pull-down from the Home Screen.

And none would block your work, or take your focus on themselves.

Now, iPad will block you at 10% battery (and stop your gaming), then will reassert its arrogance at 5% battery. It will also ask you whether you want the Low Power mode on. 

Why is this so hard to remember I always want the low-power mode? My Mac can do that. iPad too stupid?

6. And why my Mac cannot enter Low Power mode automatically at 10%, or 20%? There simply is no setting for that, I am asked every time even though I do not want the stress of this serious decision on my shoulders all the time.

7. The numbers and the logic of auto-enter-low-power-mode should be same on all Apple devices, and should not distract users from their activities.

8. I am still hurting from them removing Split Screen and Hang Over from iPadOS. Yes I used that, and wanted more in iPhone (split screen vertically).

But no, some twisted parody of window management was added (that's OK, just leave it to the Stage Manager). The simple convenience of two-windows-per-screen, simply arrange is gone. I want it back and in iPhone (vertical stacking in portrait, side-by-side in landscape).

9. Assistive Access.

This is a feature listed in the Accessibility category. However from looking at it, the logic and how it is safeguarded, I can only reach the conclusion this is copycat from the Windows Phone's "Kids Corner" feature. 

Both essentially allow parents to share their devices with kids so that kids would remain in a safeguarded "sandbox" of sanctioned apps only, with pre-selected permissions only, and protected by a separate secret PIN kids won't know - otherwise they escape.

Nice on paper - ugly in reality.

In real life, once kids get Apple devices, it is a case of lost parental control. Because they configure Assistive Access for themselves - and escape the time limits and supervision processes there. In that sandbox, almost nothing runs - by design - this making any type of supervision impossible.

Screen recording stops, phone calls drop, every process is basically killed while you are there - except those sanctioned app they can set up on their own devices.

Apparently nobody thought kids can get their own devices back when this was designed (2012?)

Another issue is MDM - your big brother boss will lose you tracks once you enter Assistive Access. Enjoy.

I have had a case opened and offered Apple three or four ways to fix the issue. My L3 case has been closed and abandoned quietly, which told me quite a bit about internal engineering and product improvement culture.

https://discussions.apple.com/thread/255620405?login=true&sortBy=rank

10. Skin colour tone mapping. There is something really wrong about this, especially apparent when shooting people in sunset light. Everybody looks like an orange. This is not so with Samsung or Pixel devices, please pick up slack here Apple. It used to be worse, many mixed race people used to gain olive-green tones at the are unnatural, but that had been improved now. "Sunset Orange Peel skin faces" remain. And in general, in artificial light sometimes a hue of orange pops in unexpectedly on people's faces. I quite often can see this "shot on iPhone" trademark - even without the authors disclosing. Take a look for yourself.

11. Ads in Paid Apple News+ ? WTF?

No way I am even going to touch that app, not to speak of paying for this. Anything I pay for, must be ad-free.

12. iOS/iPadOS Control Centre annoys.

Apple should arrange the multiple Control Center pages horizontally. 

When arranged vertically, there are two issues:

a) non-reversibility of the swipe action - when you pull down, you expect that pull up will hide the Control Center. Instead, it most irritatingly goes to the next page of the Control Center; one has to "touch wood" somewhere below, which is a ugly and asymmetric solution - imagine using the door knob to open the door, and then having to flick the light switch to close it, the door knob opens another door instead;

b) a long pull-down can bring you somewhere unexpected (next pages).

13. The biometric inconsistency.

Some devices take the fingerprint, others want your face. None require a blood this far (but watch the Apple Watch).

iPad is particularly annoying, with my left palm obscuring the camera when in landscape. They moved the camera now, I guess it is obscured by the right palm when in portrait mode now... 

Not to speak of cases when you simply wanna take a peek without lifting half of your face off the pillow. Mission impossible. Enter your PIN and social security number.

Another case is when riding my motorcycles, wearing a helmet - PIN at the ready. When queue neighbours are watching... You need that wallet activated to pay for petrol now... Or a quick stop to check directions - helmet off or PIN away. 

Come one, I'm used to use my fingers, not my face.

14. Alive after restart? Zombiemac?

When I have installed the last update, macOS 26.6.1, the computer has done a restart. What is weird, is that after restart, without myself logging in, the Mac continued playing a video! 

Now, I do NOT have "restore my apps after logout" checkbox checked. I am not one of those who tend to keep same apps running all the time. I do consider what happened a breach of my preferences.


macOS Updaters, please honour user preferences!

It would have really been problematic if I simply left the Mac once Updater started the log out. It means the Mac would have resumed playing my content without e present, and possibly with others present. The Mac was locked after restart but audio quite audible.

Not only this would have been a breach of preferences, but also unexpected data exposure and battery drain.

15. Self-hiding Notifications please.

So far, Apple have copied Notifications from Growl software, essentially "Sherlocking" it. RIP in 2012.

What they have NOT copied is self-dismissal. This makes Mac screens quite messy - unless you like tidying or do not get any Notifications.How to get render notifications on your iPhone - Blog - Digital Rebellion

A global option to self-dismiss Notifications in, say, 5 seconds would have been perfect. And a meaningful UX progress, since 2012.

16. Vertical Tabs in Safari?

Maybe in System 30. But OK this actually prevents visual confusion with other (alternative) browsers.

17. Is Aperture coming back?

We've heard so, and Adobe is so passé. There is also some vacuum in lightweight photo management a-lá FastStone.

18. Two ports on the left, no ports on the right? 

Please move one port in MacBook Air to the right. This is where my charging cable comes from behind the sofa. This is where some left-handed people want their display cable be. When you mount a sizeable USB stick, there may not be enough space between two close-positioned ports to mount another.

If a Dell XPS from 2019 can do this, so should a 2026 MacBook.

19. Half-size cursor keys.

The up and down curse arrow buttons are half-height, this makes playing something like Crossy Road a nightmare. You want back, you go forth and rise versa. One mistake and score is ruined.

The rest of the buttons are fine, but these you could not fit. They are kind of important, at least for gaming.

20. Insistence on hidden (invisible) controls.

It is quite apparent that slogan "less is more" has been taken as "less visible controls is more fun".

The stark tendency to de-visualize onscreen elements that allow users to control applications and system has become apparent during "3D Touch" era. But then, this required a special hardware (screen) and because this was hidden, e.g. invisible, very few users realised it is there, or remembered to use it. As an effect, Apple have given up and deprecated the feature.

But the tendency stuck and grew.

For example, visible Home Button has been replaced with a super-slim small "inverted line" that is hardly visible. You have to know it is there, and "swipe up". Someone who picks up iPhone the first time will have no idea. And will deride Apple for being counter-intuitive and non-apparent. Sometimes even interferes with app functionality (being so small, to save diminishing screen verticals?)

That would be understood if there was an ever-decreasing screen space available that would force to remove visual elements, but hey - it is quite the contrary, iPhone screens are getting stupid tall and that height often goes unused. It is only good for sticking out your bum pocket.

21. I still don't know why there's no 9:16 phone screens anymore.

There must be a conspiracy to force you onto narrow screens so less webpage text fits. They are doing whatever they can not to give you 1440 pixels wide. Perhaps the "big screen" TV manufacturers give those narrow cutouts away at deep discounts? This is really silly when they want a larger folding screen. "Whatever you do, do not go 9:16 wide!" must be a commandment somewhere.

But you can try prying my Razer Phone 2 off my dead fingers.

22. Non-flicker screens.

Try asking an Apple Genius for a health-focused non-flicker iPhone and see them scramble.

The newest iPhone 17 have made some steps towards that, still hybrid dimming is not the full answer. Thousands suffer headaches and nausea from the 240Hz OLED flicker. iPhone 11 or SE are your only bets.

23. Filesystem Support.

Please bake in NTFS read-write and EXT4 read-write. The three big worlds - Linux, Windows and Apple should be able to read and write each other's storage. This is not hard to do given a UNIX_based OS.

24. Apt-X bluetooth as paid option.

I know Apple hates to pay royalties to 3rd parties. They prefer it the other way instead. But this really gets kinda ridiculous - there is no high-quality bluetooth codecs on Apple, only AAC. There is only so far you can go on a 2003 codec.

Please allow 3-rd party paid extensions so users pay. You get your 30%.

25. Lower App Store fees.

Yes I think 30% is ridiculous. It should be 10%, the same amount Church charged for ages without revolts.

Correction - they only charge 15% for the first million dollar revenue. Then you get slogged quite a bit.

26. A pencil for each iPad.

It looks like each generation of iPads designed to be unable to work with previous generation of Apple Pencil and Smart Keyboard. Given the non-trivial price of those accessories (reaching the cost of mid-way Android phone) this makes iPad ownership even more expensive than it should have been. 

We're getting petty, so I shall leave you with this last one.

27. Battery Level of Bluetooth Devices.

For connected 3rd party Bluetooth devices, on iPadOS/iOS there is no indication of how much battery they have left. Going to Settings - Bluetooth and choosing the device only gives you option to Disconnet or Forget it. No battery level. Duh?

One must install the 3rd-party accessory utility and launch it to enjoy seeing the battery level. On the good side, this decreases "battery anxiety".

After all, somehow Apple must nudge you towards their own accessories. The headphone roaming across all devices is really good... I wonder when EU will force them to open this up for all...

Tuesday, October 28, 2025

How subscription changed software business

While the world in general seems to converge on believing and trusting that software subscription is the best way of business in software, let me express my considerations.

The thing is, there are false premise and perception on what software is and what it's worth.

If not for that perception by users, that "there's nobody there just my device, and I have paid for device already, why would not that device 'grow' and become more and more capable, because you know, 'progress'...", then consumers and users would recognise that all software development is done by very clever people who deserve to be paid not less but maybe more than "that nice butcher guy who I go to each week".

Most of casual users have no idea nor interest to understand how much skill and training it takes to build neat useable software. They expect "things just to work".

Moreover, many modern application also require backend servers and associated hosting / hardware renewal and maintenance costs. These are even less visible to the unlearned and untrained eye of the "poi polloi", and building a viable business model has proven to be a choice - or, sometimes, bait-n-switch - between three possibilities: 
  1. Delver for free in order to grow, then sell the company later to an internet whale
  2. Charge users for usage or for a version of software
  3. Monetize users (run ads, sell or share user activity data) 
Each of choices has its opponents and proponents, reality showed that (3) is the most viable, given the psychological and fiscal barriers for (2) and the temporary nature of (1). 

At the same time, there's a number of companies still successfully pursuing business model (2), namely Software Subscription.

In this article I would like to offer a novel variant of (2) that might improve its uptake by removing usability barriers and converting the model into a zero-click default with an optional user opt-out.

This can be done with help of fiscal intermediaries; enter Internet Service Providers.

Similarly to how Ebay and Amazon have "gamified" and "1-clicked" the purchase process on their sites, with the "zero-click attention payment" scheme it could be theoretically possible to charge users for usage, even before they have subscribed - provided that all prerequisites of the Architecture are met.

With payments, VISA and MasterCard act as fiscal intermediaries for Ebay.

With the "zero-click attention pay" (ZCAP) scheme I propose, ISP can act in the same way for any service that's compliant and is recognised by the ISP.

What are prerequisites for ZCAP to work?
  • ISP keeps an extraneous pool of client's funds in order to be used with ZCAP every month; this can be pre-allocated and limited for client's surety, or post-payment
  • Each ZCAP service uses a recognised network protocol that allows network-side observation of Time Spent by the user
  • ISP performs network-side observation and real-time charging for used ZCAP services from pre-allocated pool
  • Upon the pool exhaustion, ISP may raise a request to allocate another or upgrade the plan
  • ISP may charge a percentage of ZCAP for the charging infrastructure support and maintenance
  • Users do not need to subscribe to services as long as they have funds in the pool and service is ZCAP-compatible
  • ISP may pass relevant user data to ZCAP service in order to identify and authorise the user
  • ZCAP services may use standardised _SRV text DNS records to indicate ZCAP support and relevant API locations
What's in it for ISPs?
  • higher ARPU
  • increased stickiness
  • bundling opportunities
What's in it for Subscription-based Services?
  • higher usability
  • zero-click opt-in
What's in it for the Users?
  • potential to avoid user data compromise
  • no passwords to remember
  • unified billing
  • capped billing
  • pooled billing (if ZCAP agrees to share the same monthly pool with others)
The diagram for such a scheme follows.





Wednesday, July 12, 2017

5 things that are really wrong with iTunes

Just a summary of my thoughts on iTunes, compared to other similar products.
I am not fussed my the "bloated UI" or any "too complicated" comment that seems to be floating around on forums.
I must confess though that I have used iTunes since v1.0 back in 2001.

So here it goes - I do not love iTunes anymore BECAUSE of:

1. The way it does not scan for its library content updates automatically
2. The way it (re)imports library content, ignoring XML files already there and only looking for media
3. The way it re-downloads TV Shows after re-import, even though the media files are already present there in the folder
4. The way it fails to import or even play CDs on my LiteOn BDROM drive - it just skips them
5. Apple made it really difficult for me to put Album Art into every mp3 song I add to iTunes library - they removed drag-n-drop frame with the cover art.

Others may have their own gripes but these are mine. Yes, I still use iTunes to play SOMA FM, and access my Purchased and otherwise acquired library of many years. I won't buy standard music anymore though, but hi-rez tracks are a separate topic where Apple is not pioneering either.

Tuesday, July 11, 2017

STOP hurting our eyes indeed

It is high time that ALL manufacturers paid attention to screen ergonomics.

Wednesday, October 26, 2016

Glaring issues with iPhone UI remain

Apple's mobile operating system, iOS, has almost turned 10. Incidentally, it is at version 10 now as well.
One might as well call it "iOS X" now that there is no confusion with the macOS name.
(boy am I happy it is back to "macOS" name like the old times!)
But despite abundance of options and settings I am still missing a couple of simple things:

- Low battery indicator pops up in the middle, distracting me from whatever I am doing, and covering the centre of screen

I really wish it was a disappearing status bar alert at the top of screen. The pesky thing also repeats the flash act at 10 and 5% now, only to make it more annoying.
An option to go to Battery Saver mode automatically without asking my confirmation when it is lower than 20% would also be an improvement.

- Changing volume while watching a movie poses a similar issue with the central spot overtaken by the volume banner that takes few seconds to dissolve itself. When I am missing some phrases because of a low sound volume (or increased noise around me), turn the volume up and then get a "double whammy" by missing some visual action because of that pesky banner.

Apple, please make that banner pop up on top of screen.
It might also be nice to have a system-wide setting for all such banners.
The only banners that I want shown in the center are those that require my action - not confirmations of my actions.
"Dismiss" is not really a valid action - especially not when navigating in the car's hands-free holder.

Do you guys support my suggestions? Anything else you would like to improve in iOS User Interface?

Tuesday, June 24, 2014

Disparate identities? No thanks.

We all are used (or at least adapted) to keep and reenter a multitude of passwords.

They follow us everywhere - at work, when home, even when we're calling the bank on the go.

Security is a complex concept. Sometimes things that feel "intuitively right" are not in the best interest of securing your access.
Quite often, we are secured FROM accessing the services we so desire...then we resort to the oldest and least secure SMTP protocol that is long overdue for Rev.3 or Rev.4.

Many have adapted the use of "password manager" tools / addons.

Let's consider if there is a better alternative to existing solutions.

In few example cases, I will show how "feel-good" solutions, that are often "specifically designed" to improve your security, will actually decrease security of your access or even open ill-considered backdoors into your systems.

Case 1. ID Federation vs Multiple ID

Imagine controlling several separate security domains.
This happens most often at work, where you use one ID to logon to your PC, then another one to connect to your (Development Environemt/Model Environment/External VPN/Internal Applications etc).

You may have another username (a).
You may have to use slightly different usernames (b).
Sometimes you use exactly same username (c).

What IS important is you do not care to use different passwords in each domain. You would go crazy if you did, especially in case (c).
"Domain Name" is often not considered by the Application developers, and users are not always aware to which domain they are logging into.
Sometimes domain name is not even shown, especially in cases where applications are not designed for, and hence would not allow cross-domain logins.
What IS ALSO important is that there is no easy way to make sure users use different passwords in every domain.
Your SAP solution would not check Active Directory and make sure you use a different password.
Where are we ending with this non-SSO enviroment?

Users like to use same passwords everywhere.
It is enough to hack one enviroment and then reuse same password in other environments.
The thinking that non-SSO environment would "protect" against a password compromise is not often substantiated in practice; it is "false intiution".

How easy it is to protect against potential compromise?
We'd have to make users change passwords in every domain.
They may not even remember all passwords, when some were left behind and unused!
When disaster strikes, many doors will be open even though the storm is already gone.
When people leave the company, several non-integrated systems may still contain active credentials.
This is especially bad for VPN or other internet-exposed systems that are not AD-integrated.

What's the best architecture for multiple domains controlled by same people?
Use full SSO, one login connects users to all services at work.
Through IT Policies, make sure that every app deployed supports a form of integration with your most important credential data, Active Directory.
Prefer Kerberos integration over LDAP. LDAP would not support multi-domain environment easily.
Let application developers, modelling and vendors build a one-way external trusts towards your single forest root domain.
This is often safer, and is always cheaper that external "integrations".

Additional advice - use AD as your master DB. If you use external ID providers (Oracle, IBM) then those must have admin service accounts into your Production AD. This is bad...
External vendors (or their subbies) may be able to reset passwords of your CxO and read their email / access documents. Again, those service passwords most likely will be moved around the world over unsecured SMTP emails, often on "Cloud" providers and multiple governments looking over the shoulder.
Instead: Let your forest root domain controllers keep all IDs safe and ready to be reused in your forest child domains. Let DC talk to DC to automatically reset computer account passwords at predetermined intervals. No humans mucking around.

Case 2. Policing the passwords.
In password credential management, there's a number of parameters that often make even "experienced" people make stupid mistakes.
Every time, the whole password lifecycle process must be considered in an end-to-end manner.

The basic password policy parameters include:
- minimum password length
- maximum password age
- minimum password age
- password history
- password complexity checks
- password change warning period

Many of those parameters require consideration of how your passwords are: set initially; distributed to users; reset by users; reset by service personnel; aged and requested change; accounts disabled etc.
Let's take a quick example of CONTOSO company.
They have set password history to 24, and password minimum age to 1 day.
When passwords are reset by the helpdesk personnel, they are dictated over the phone to users calling in for a password reset.

Issues? Oh yes!
Firstly, when dictated over the phone, several users in the call centres (sometimes abroad) get to hear them out, spelled clearly and nicely.
Secondly, the two parameters they set, were designed to prevent the same specific unsecure situation - users recycling same passwords indefinitely.
But because these parameters designed to reach the goal via different means, only one or the other of them should have been used.
Using both, while seeming to "improve security", simply by tweaking all the knobs we see there, in fact cause a very insecure situation.
Password History is a barrier for users to always select a new password when changing it. The depth of password history log defines how many passwords user have to invent, before reusing the old and loved one.
Set it to 1 and users only have to change it twice - first time to invent a new password (the current one goes into the history log) and then back to the second password. Two passwords can be recycled indefinitely.
Set it to 12 however, and I doubt the users will go through the pain of changing passwords 13 times (inventing new ones) in order to reuse their favourite mot-de-passe.

In case of CONTOSO, however, the minimum password age was set to 1. This parameter was designed for cases with no password history.
Users would have to WAIT AND USE the new password they just set or got assigned BEFORE they could ever change it again.
This means that all newly assigned passwords, that were probably overheard on both sides of the phone calls, cannot be changed immediately by the user.
It also means that if someone overlooked your password as you were changing it, you'd not be able to change it once more when that person leaves the room.
They would have to use the passwords as assigned at least for one day. Compromised new passwords stay compromised for at least 24h. Not good...

What this means in practice is that passwords reset by the service desk are never changed by the users. Not on the next day.
Never - until the next expiration cycle.
There is no way to force users doing that.
The only way out is to change the policy and set minimum age to 0 and check "Must change password at next logon".
The password history will take care of "inventive" users trying to revert back to old and loved passwords.
As of now, users tend to stick with very simple and possibly compromised passwords well beyond the first day.

As for the password expiration period, it should not be left at default 14 days. In 14 days, many users are reluctant to change passwords so far ahead of time.
At the same time, 3 days is a bit too short - users may be compelled to change it on Friday and they won't remember the password Monday.
Five days seems the best choice. Users who receive the warning on Monday will have full week to think about doing it. They'd know they need to do it "this week".
It the pesky dialog pops up Friday for the first time, 5 days is good time to postpone it "till next week".

Password complexity? Of course.
If you serious about complexity, you should write your own PASSFILT.DLL.
Include dictionary lookups, as well as proper non-generic error messages towards users, so they know why the new password they tried to choose was a poor choice.


Case 3. External domains
Consider your "work" environment is fine-tuned and well-considered, time-tested and pen-analyzed.
How can you be sure your users are not using same password on their Facebook?

Well, this is where our discussion will lead us to the next gen of ID management, the frontiers of developments ongoing in various bodies and corporations.

Remember Microsoft CardSpace?
This was Microsoft's first attempt at "embracing and extending" credential management on the websites, "out there".
By design, web developers would have to include CardSpace support in their websites.
Then, once users connected to the website, it would send a signal to Internet Explorer to indicated that it accepts CardSpace.
Come on, fire up your XP machine and check in Control Panel.
It was basically same as Windows Credentials Manager (still present in Windows 7 and 8) - only for websites.
You could fill up, save and one-click-reuse so called "cards", one per site. Each card could contain your names, email, as well as "salted association ID" that would be used in place of password on the particular site that generated and saved the card.

Now consider the SmartCard standards.
Many computers still have the readers. But it has been a long time since I saw someone use a smartcard. OK CBA folks I know you do :)

The real reason why smartcards aren't popular is because the current standard sucks.
It does - because it hosts only one certificate. It seems designed only for "work use".
One certificate, same thumbprint - very easy to track the user.
This is definitely not a good architecture - for privacy reasons.
There's also no controls designed around what sites can access which certificates.

A better architecture would see the SmartCard standard extended and merged with some concepts of the Microsoft CardSpace component.

1. From a hardware perspective, each SmartCard would need to be able to keep up to 1024 user certificates (or other credentials), one in each separate isolated cell.
2. Each cell would be signed by a special website certificate, and verified via full DNS name. Other sites would not be able to send requests for that particular card.
3. One per-card PIN would unlock all cells, but each individual user card request would be screened by OS UI and approved/denied by the user.
4. OS would support new card creation by suggesting values from the user profile (name, nickname, email etc) but the user would have the right to override all values to establish a new account with a new service.
5. Some government sites would only accept "verified" cards that were issued by specific government sites/bodies.
6. Cards would not be "locked" to specific countries, they would be open for any new web services globally.
7. It would be possible to combine multiple "government verified IDs" on one card.
8. During new account creation, a uniquely-generated credentials would be stored on the card, only accessible by the site that generated it.
9. Some websites would offer to reuse government IDs, while allowing to create a new "local" account to anyone.
10. Optionally, a plain-text password can be displayed on the screen, to be taken by the user and used on computers without the new smart card readers.

With inception of such universal standard, all woes about passwords would be solved and the internet would become a more secure space.

It is time to move away from insecurities of keyboard keystrokes into the area of specialized chips and certificates controlled by the openly reviewed and secured hardware/OS standard.

Instead of building ID around Facebook, it's time to ask for universal standards for the new generation.

Ask your local Member of Parliament to support this.

Share and repost in social media!

Help to propel the cause to get rid of password headache and insecurities.

Chime in the comments as well - do you develop something like this?
Can you help developing this?

Desktop Peek guffaw

Dear Reader
just a little tip for those who are annoyed by the “hide all windows” feature automatically activated when you [accidentally] move your mouse into the lower right corner.

It is easy to disable this, just by right-clicking the small empty bar in your lower right corner
and un-ticking the “Peek at Desktop” option:


Left-clicking the bar will still show Desktop.
At least it’s not activated accidentally.

Wednesday, April 23, 2014

NSLOOKUP prank

If you name your server "EXIT", people won't be able to troubleshoot its name resolution using NSLOOKUP.

Tuesday, April 8, 2014

Microsoft and Vendors

PC hardware vendors should only hate Microsoft for removing "Computer" icon from Desktop by default in Windows 7.
"Less-hardware-minded users aren't keen to upgrade often..."
NB. The Recycle Bin is holding on.

Life is Good

That's it, folks.
I now only have time to write quick tweets here, not full articles.
I hope you will like more frequent but shorter messages.
They will still contain same kind of insight, just packed more densely.
Life is Good.

Thursday, August 8, 2013

Built-in tracking protection in IE10+

A simple trick to help you thwart attempts to track you on the web.

It's a little-known built-in feature that applies to Internet Explorer 10 and later users; yes, you should update any prior versions you may still have, even if you do not use IE - many system components are using its frames.

While in Internet Explorer, press Alt-X or click the Tools button on the toolbar (most right), select "Manage Add-Ons".

Click "Tracking Protection" on the left - you will see a pre-defined "Your Personalized List" on the right.

Click the list and then click "Enable" button below.

Click "Settings" button below and select "Automatically Block" on the dialog that opens.

"OK", "Close"


Now what happens is IE will detect tracking frames on all websites that you visit.
If there are more than 10 occurences (different sites) having embedded the same tracking scripts, it will be considered a tracking network and will be blocked from placing an identifying cookies on you.

Hopefully this helps stopping the trackers "profiling" you, i.e. gathering info on types of sites you visit, and placing you into certain categories.

Possible uses of tracking involve targeted advertisement, market research for correlated traffic, audience statistics etc.

Not bad for an un-advertised feature that is given for free to all.

Tuesday, August 6, 2013

Lost in phone, or another opportunity for iOS 7

Let me confess, I have been using Apple iPhone since 2008.
Back in 2010, my phone was stolen. A month later, we were moving to Australia and I did not buy a new one.

I have been using a Nokia phone for a year, it was a Symbian one.
Interestingly, I did not miss the iPhone. I was on the lookout for something new, something better.
It happened to be an hp pre3 powered by [ex Palm's] webOS operating system. But that's another story.

I tried to understand why I did not miss the iPhone, after all, I was a Mac user since 2001.
And I think I can explain why, at least to myself.

There are things in iPhone experience that simply make you bored.
The same old grid of same old icons, mostly static. Onerous App Switching functionality.

But now I also see things that actually enrage me, even if they used to do it subconsciously.

Let us talk about one.

Phones are many things to us now, but for me, they still must serve well as PHONES.

It seems that iPhone fell short on this, even compared to my first smartphone that I bought in 2004, the absolute flagman of the years and everything before the iPhone - Sony Ericsson P910i.

Consider unlocking your iPhone, you will see Phone and Contacts icons.
Inside the Phone icon, you will see Contacts tab.
Along the Phone app tabs, you will see "Favorites", "Recents", "Contacts".
As well as "Contacts" outside of the phone app, on the dock.
"Recents" tab is split in "All" and "Missed" categories.
Can you still follow me? :)

Guess what? THERE IS NO PEOPLE PHOTOS, NO USERPICS not in any of these multiple tabs. Huh?
All four tabs I have listed, have no people faces on them. Not even in Favorites!
To see a picture, you need to drill down to a particular contact! This is in 2013.

Many times we are trying to catch up with people on the go, while walking, some [unwise folks] even when driving.
No pictures does not help at all!
What is even worse, is getting stuck in "Recents"-"Missed" and trying to dial a number who you just talked to and said "I'll call you in a minute".

This is because Phone app remembers where you were last time, making navigation to where you want to be this time a process that takes more brain cells to coordinate their work, distracting from other things you're trying to do (unless you're sitting on a sofa playing the phone).

I took out my old SonyEricsson and checked the Phone application.

Always takes you to Favorites that have faces on them. Two-touch calls to Favorites are possible from wherever I am.


On the iPhone, if your favorite people are calling you then your Recents will look much like Favorites, but sometimes sans the guy you want to talk to now. Same-looking text in both tabs, no pictures. Frustration. No wonder they need Siri to help.

Finding yourself switching to less-often used tabs like Dialpad is OK.
Having to switch out of that rarely used functionality is not.

Another source of confusion is the double Contacts functionality.
Since there are two of the Contacts tab, and each remembers its own position, you will have to re-find (find again) the user that you have focused on, should you go to the "wrong" Contacts tab.

It took me some time to realize that in order to send an email, I have to touch the actual email address instead of reading all the button labels below in vain search for "Email" button, then trying to figure out whether "Send Message" button meant "email message".

There's simply not enough visual cues. Have a look at how it was done in the SonyEricsson.

One more thing about my ancient but greatly usable phone.
It seems to be the only 3rd party phone that Apple has written software for.


No kidding, Apple programmed for Symbian UIQ 2.1. Steve must have cared enough.
Here's a proof.

The iSync agent worked hand-in-hand with iSync Apple app for MacOS, making sure that bluetooth synchronization of Calendar, Contacts and such was impeccable. And it was, unlike my Nokia PC Suite experience.





Overall, with a couple of tweaks I hope that Apple will resolve these issues in upcoming iOS 7 - they just need more of that "attention to detail".
But maybe not - it does not seem to be about phone calls anymore...at least, this is not Apple's business.
Or is it?

Friday, July 12, 2013

WhoIs Microsoft

I have just downloaded WHOIS for Windows from Microsoft.
I have no idea why I have not done this before.
Microsoft were right when they bought SysInternals.

Friday, May 24, 2013

SHAZAM 6

Shazam will now listen to your music in background. How convenient.

Thursday, March 28, 2013

Error Codes

"Hey Computer! Why don't YOU run that command?!?"

Tuesday, March 5, 2013

Product Creation

Why companies exist? To make money or to improve humanity?
...
The product creation process in some companies is broken.
Instead of creating the best possible product and letting others enjoy it, they deliver the absolute minimum and then only fix gaps where absolutely required by customers.

Friday, June 8, 2012

What's coming in Apple TV?

The word is out: "Apple have 'figured' TV".

What does it mean, what can it be?

Here's my idea. (Any likeness to the real Apple idea is coincidental, of course)

There are things that make TV what it is now - an industry on the wane.
While it is still relevant, the big question is for how long.

It won't be long, if Apple can make it.
If they can change another industry, that is.

And here's how.

What's wrong with current TV?
-----------------------------
Let's have a look at the current business model of a typical television channel.
They show news, to be relevant.
They run shows, to amuse and show you ads.
They run movies, again to amuse and show you ads.
They just show you ads ("sofa shops").
They do not get money from viewers.
They depend on advertisers.
Some get funding, and then pay off by running agendas.
It's a B2B enterprise, us consumers are bystanders.
They don't know individual tastes.
They have trouble fitting one to all tastes.
They don't know who, or how many are watching them at a given moment
(yes, there are aggregation methods but they are not precise because people just switch channels intead of switching off TV sets)
Viewers have a limited choice of dozens (sometimes hundreds) channels, have to wait for a content they want if it's not running.
Worst of all, TV channels have no way of taking money directly from customers.
Sure, you can "subscribe" to a block of channels but it 'happens so' that one block never contains everything you like, so you have to overpay. PLUS watch ads again!

There's lots of things historically wrong about TV, due to limitations of past technology.

What could be improved?
-----------------------
Let's not talk about boxes - everyone has them.
A better TV ecosystem would allow each channel for a fairer revenue collection and accounting.

Just Think:
Nowadays it's possible to have individual billing records for every second of the time you spent watching every IP-based TV channel.
Hence, it is possible to "vote" with your channel selection towards the program you're watching.
Your monthly subscription fee can be "split" per every channel, by time you spend watching IP TV.

If you watch a particular channel less often, they would get less revenue from you.

How would this change the business model?

"No Ads" - becomes possible! If channels can get enough watchers, by providing a higher quality entertainment, people come in droves and increase direct revenue.

Those channels that stay "free" or not popular enough, will still run ads and will be viewed as a lower-quality experience.
This will drive the quality up, and price - down, very similar to what happened in the applications business.

Is it an easy change to accomplish? By all means, not.

We have not been waiting for Apple to "finalize" their TV box, but more to make contact with parties who are ready for a significant and arguably the best change to TV since it became color.

Competing with the Internet is possible - if an industry follows the principle - "user first".
If it "listens" to each user. Not each 1M users. Here, money is the tool, not the goal.
A tool for users to have their say.

Driving up the experience quality and engagement with TV is possible by improving content and eliminating distractions. But only in the new model of business (channels get paid for their content, not their advertisers').

Once the new model becomes the norm, ads may become a rare and unexpected interventions into people's minds.
While advertisement is a necessary tool for some, it may as well become obsolete soon.

Crazy as the idea may seem, Apple might try...

[not really being a TV person] Is there anything fundametal I have missed?

What would you guys like in the new Apple TV solution?

Thursday, April 19, 2012

So why webOS failed?

I have just had a fresh look into webOS, and why it failed.



It is too open, too neutral.

Why would providers "forget" about their preferenced partners?

In webOS, twitter is just a "Service", and to twit is to perform a "webOS Action".

There's no point to put your brand out, it will still become a subdued "part of" webOS.

webOS will de-brand your service, aggregate it into it's common way of doing things.

Now if you're Google, Twitter or Facebook major internet (web) brand, would you want to step forward, and put your own "app" out, or would you be resenting to an almost empty corner of hp Catalog, the "Services & Actions" corner?

User also felt that something was amiss - the UI is so good that most of the usual parts were simply removed, not needed. In some minds, this was 'not rich enough'. People like to play with things, not necessarily focus on content.

It was mostly the same thing that killed the Atom blogging protocol - nobody likes to be de-branded for being inter-compatible.

Tuesday, March 6, 2012

NOKIA will stop "sharing"


Just in the e-mails -
on May 30th, NOKIA will shut it's Ovi Share service and will delete any data you may have accumulated within.

Anybody surprised?

Despite being conveniently integrated into Symbian, the service did not get traction, mostly because it was available exclusively on Symbian mobile paltform.
Or your choice of a PC...There was nothing for iOS or Android.

Since NOKIA is walking hand-in-hand with Microsoft, they will probably be incorporating Microsoft's "sharing" services into future products.

As for Symbian, I guess the best choice is get a facebook plug-in from furtiv. Or use flickr.

Does anyone care? Chime in - what shall you use next?

Friday, March 2, 2012

"Windows" 8? Wait a minute


Microsoft Windows 8 is a very brave endeavor on Microsoft's part.
It essentially aims to replace, revolutionize the user interface that people use to "compute".

Wait a minute... "Compute"? Well, it seems that this term is obsolete, too.

Most of the times people don't crunch numbers, they are mostly after consuming numbers.
Modern PCs performance depends heavily not only on the pure computational power, but on storage transfer speed, network speed and memory size (even if that's video memory).

Did you notice Microsoft's stubbornness applying the "Windows" moniker to all their Operating Systems?
Is not it time for a product name change, as opposed to just the number?

Effectively, on a mobile device, we would not have the Desktop metaphor as invented by bright minds of Xerox PARC, and later implemeted by Apple Computer Inc.
Hence, we won't have overlapping "windows" (think "paper sheets"), representing different applications.
The "fourth screen" is too small, to have many different windows. We would have one window (possibly with many panes, as in highly acclaimed alas mismanaged webOS). Or multiple "tiles", replacing iOS's boredom of icon grids.

So they are not windows anymore, but "tiles". So why not "Tiles 1.0"?
Certainly, Microsoft thinks about itself in a very serious tone. They know they have to be brave, but consistent naming gives users false impressions, that the next OS is the same old, but better.

Ask many, and they will opinion - it's the new world, but not necessarily "better" in all senses. It's "different", and time will tell how quickly it will improve and be accepted.

Microsoft has learned to "think different" after all. Kudos.

Now, to the essense of what's going on.

Intrinsically, laziness wins, even when there are other grave considerations against it.
Did you notice, there's no ideology anymore, that would foster utmost strive for self-improvement and creativity in masses? The world is driven around money, not high ideals to achieve. Money is a carrot, it is also a stick.
With Information Superhighway (Bill Gates, 1995) being built on scale, and penetrating every house, one important thing has happened.

Digital Communism.
It has arrived. There is a mechanism, a technology invented and machinery built that makes [some parts] of former social regime obsolete. DMCA, ACTA, PIPA, SOPA, ring a bell? They are trying to reing it in, still wrap it under Capitalism, but "times they are a'changing".

When a major technological breakthrough happens, the social regime has to change.
Remember feudalism? Once a certaing advances have been made in producing mechanical machinery and steam engines, electricity were invented, these allowed material goods to be produced in quantities (sic!) that led to major changes in quality of life. This became Capitalism in most parts of the world, some have tried to build Communism, and very few have built a Socialistic-like societies (thank you, Sweden). There's no more feudalism - at least globally.

With Internet giving people "near-free" access to information, another social change is happening.
We have recently seen a wave of resistance from "undemocratically chosen" lobbyists pushing laws while the general public was asleep.
One big thing not solved yet - how to make new things "near-free" for everybody, in a decentralized manner.
But hold on, nanotech is coming.
Once the fundamental problem of easily "copying" material things verbatim is solved, "goodbye, Capitalism".

When it comes to gadgets and widgets we use, I observe a worrying trend.
A Personal Computer used to be thought of as a "bicycle for a mind", an open-ended thing that you would have full liberty to program, assign to any task you'd wish.

Nowadays, PCs are being replaced by a "shopping cart for a mind", a TV with many channels.

Most people who use computers now (as opposed to 70s and 80s) have no capacity to program them, they are formed by the Capitalistic regime to absorb what's being fed via "channels". Those who are not lazy, are building their own "channels", and take part in existing social mode, but on a different side.
Ironically, it's a bicycle which is preset to so many roads; you could always buy more "routes" for it, but all routes have to be approved, no riding around Whtie House anymore.

The conceptual idea of SmallTalk OOP language - to make PC programming so easy as to let anyone build programs for it - has been betrayed, privatized and forgotten.

The big mainstream capitalistic companies will have very strong control over all developers, very soon.
They will enforce digital signatures, Trusted Computing, and will revoke access of developers, following only their own internal company policies, not the government laws that cannot interfere with go-to-market strategies of private companies.

When Microsoft's transition to Tiles complete, we will only install what Microsoft likes, or allows us to install. Everybody in Metro development will have to be on good terms with Microsoft.
Microsoft may take a policy of accepting only "prudent" developers.
Doesn't it remind of something?

Customization options will be limited.
Did you notice it's not possible to use own color schemes in UI of major OSes?
Back in XP/2000/98/95 era you could paint windows your own colors.
Soon, even Wallpaper will go way of Dodo. Your only consolation would be to go buy more new tiles.
Reminiscent of Zamyatin's "We".

But most importantly, TV is back with vengeance. Just pick your channel.
Oh and what a TV is it.
It's a TV that watches you, knows your moves, your Contacts and Calendar.
The vendors only have to offer free "convenience" of backup for all of these.
Maybe it won't be offered, but built-in, mandated.

A lifetime account, anyone? The government would create it for you as you're born.
When you grow up to buy your device, just apply your RFID tag in your forehead and logon. A new ritual.
You will be able to apply to transfer it from MS to Apple or Google, but this will only increase number of parties who know a lot about you.
The irony is that Macintosh was started with the ad denouncing exactly the system they have been so instrumental in building.

I know you must be thinking I'm over-dramatizing it now.
Yes, I am. Some of it may not happen. Only good things will happen if every user's aware and informed, and uses own judgement.

Just remember, Gods live in the Clouds :)