Tuesday, March 23, 2010

In search for ... a better keyboard

Have you noticed how keyboards get smaller and worse, over the years?

My Apple Pro keyboard (1999-2001) from the PowerMac G4 Cube died on me, and suddenly I was in the market for a decent keyboard.

And I did not like what I saw.

Apple have shifted production to a simple piece of aluminum, which fits my kitchen more than my desk (not to say my fingers). Later on, they cut down on this piece of aluminum, getting rid of the numeric pad. These keyboards, being shipped with Mac Pro, it's a pitiful sight now...

Then I found old bookmark to Matias Pro keyboard, but online research told me that they're loud, and have their own quirks.

Knowing Logitech and Microsoft usually make good peripherals, I am looking at their offerings.

What do you use and prefer, guys?

Monday, March 22, 2010

E-mail encryption with FREE certificate

Hi, I've just discovered this interesting offering from DOCOMO:

The only caveat, compared to Thawte's WoT which came way of Dodo:

It does not verify persona.

So, what it's good for, and what - not?
It's still attractive for those who want to play without pay. I believe this case covers 90% or more, however sad that may sound.
It's also good for personal authentication as long as you know that:
(1) e-mail address belongs to an identified person (say, your friend whose e-mail you can positively identify from your previous transactions)
AND
(2) that it's really your friend who's gotten that free DOCOMO offer first.

Because even though your friend still may have access to his e-mail box, so may the bad guy have. And it's not hard for that bad guy to jump first and get that certificate, and peruse it for his deceptive purposes.
There is no persona verification, nobody goes to WoT notary with his passport and another photo Id, so whoever gets that certificate, and has access to the e-mail box (with no SSL used and abundance of free open WiFi it's not hard to do) - can positively forge his identity and make you believe that you are communicating over encrypted channel to your trusted partner.

In other words, "better than nothing", but "nothing for some".
Try it, use it, message me...

Note: did not work in Opera 10.10 (PC), had to use IE

Thursday, February 25, 2010

Apple IS going towards video calling, after all!

Exactly as I envisioned 8 months ago, Apple seems to be moving towards a new and worthy accomplishment - getting bloody unfortunate heretofore Video Calling to the masses.

There are news spread around, and for me - that's rigid proof enough.

It would be nice if they expand some 3GPP standards, in part of video codecs - and open those for everybody else.
Such move would give more installed base of "new" video callers, and more chances to "connect people", bringing benefits to CSP.

Knowing Apple's business tactics, though, I find it highly unlikely that they release such feature to non-Apple users.
Most likely only iPad/iPhone users will be able to visually connect with those new features.
Selling more Apple devices is of course more important than "unduly taxing" CSP network.
Apple's got to know by now - they don't like it!

We're about to watch enrollment of a "new" killer app for 3G, folks!
I told you there were only two major ones, and this one was woefully amiss from the great platform.

Saturday, January 30, 2010

AOL fixes Sent Items

There's hope to AOL.

They have finally fixed the long-standing, pesky issue with sent e-mails, which they "managed" even for IMAP accounts, by placing them into "Sent" folder.
While that was quite OK for web clients, this functionality posed a problem for signed/encrypted mail, as well as duplication of saved sent e-mails.

I wrote to AOL earlier last year and later in October and 3 months later (today) they do the fix. Hurray!

Hello,
there are some issues in your e-mail service.
More specifically, digitally-signed e-mails become "tampered with" in status, as they are automatically moved BY YOUR SYSTEM (not my e-mail client) into Sent Folder.
I am including one of many such e-mails in attachments.

It is also of note that I previously contacted you about this "auto copy" functionality - this feature is completely unneded on IMAP interface, as most IMAP e-mail client programs are able to perform this on their own.
It is exactly this feature that causes also troubles with signed and encrypted e-mails as I described in first paragraph.

In case you need more info/descriptions, please connect me to developers/admins.
I am a system engineering architect myself, in telecom.

Thank you
.


And the response team strikes back:

Dear cubeover,

If you access your email using third party software, such as Outlook or Thunderbird, please read this important message.

We want to inform you of a change to our email infrastructure that will result in copies of sent emails no longer being automatically placed in your Sent folder when sent via third party email software, as of Tuesday, February 2, 2010.

In order for you to continue having your sent emails automatically placed in your Sent folder on February 2, 2010 or later, you will need to make a change in your email software settings no later than February 1, 2010. Please note that you will not be required to enter your AOL login and password as part of this process.

Below are links to help articles on how to update the settings for the most common email software

Outlook 2007

Outlook 2002/2003

Outlook Express

Thunderbird for Windows and Mac

Mail on Mac OS X

Please make the necessary updates as soon as possible.

The infrastructure change we are making will only affect email sent through third party email software. Email sent using AOL software (AOL 9.0, 9.1, 9.5, Desktop), AOL webmail, or a mobile device such as a Blackberry or iPhone will continue to have copies of sent email placed in the Sent folder.

Thank you for using AOL Mail.

Regards,
The AOL Mail Team

I can only add that of all times I tried to ask Yahoo! Mail team for similar fixes (mostly related to handling of international char encodings), none succeeded.
I got usual third-world support banter instead, and promptly decided to close my Y! account, few years ago.

Friday, December 18, 2009

Donate to Wikipedia.org

Everybody's using it. It's free. No ads displayed.
Not everybody knows it's run by a non-profit.
And to help it develop and cover their costs, now they need YOUR donation.
Attention is the only limiting factor in a human.
One can make unlimited piles of money, or design a fiendishly complex system.
But it's ability of a human to concentrate (attention) which governs ability to achieve all that.
Jimmy's appeal
And that would be a waste when YOUR attention will start being bogged down by ads and your brain starts accomplishing less and less because of loss of focus (*attention*) - all due to "free" sites surging with ads!
Wikipedia Affiliate Button
DONATE

Friday, October 23, 2009

Kaspersky vs proxies

Trying to find best antivirus, I have tried Kaspersky and here's what I have to say.

While it may be OK for home usage, it's a no-go for many corporate environments (like mine) which use script-driven proxy setup.




It just does not support .PAC script-based proxy setup, and so did not work for me.
And by the way, my previous companies also used such proxy setup.






Too bad for Kaspersky.
Not to speak of the higher pressure it puts onto system...
I tend to incline more and more along the way of thinking that it's software popularity is based more on marketing gimmicks like "personal touch" a-la Peter Norton, that quality merits.

And by the way, have you tried the free Microsoft Security Essentials?

It's got great usability! I can't speak of it's protective abilities (I'm sure Kaspersky will) but it's so easy to use and puts very light load on system, and nothing beats free. Recommended!

Wednesday, October 14, 2009

Thawte Web of Trust to kiss goodbye soon

In my email today was a sad announcement - Thawte, a well-renowned company providing security solutions to the Internet (mostly SSL certificates for web sites) is canning the free "Web of Trust" service on Nov 16th.

Web of Trust was a way to give people some electronic privacy in form of e-mail cryptography via freely-issued certificate.
That's the kind of stuff you'd configure in Tools-Options-Security menu (Outlook Express or Outlook).
I say "some" because the company might still keep your private key in some storage, and whoever has proper laws on their side, may get to that part of your e-privacy.
Any way, it's better to trust ONE government that trust EVERY intermediary provider, hacker, sniffer, rogue admin or the like.
That's called "reduction of attack surface".

"Why would we need Thawte, there are free tools for generating certificates" you'd ask.
Because a certificate has to be trusted, by default, each OS comes with an ample set of "root" certificates, those to whom every computer on the net has absolute (but not everlasting) trust.
Personal WoT certificates are signed by Thawte's CA (which are trusted via pre-installed root certs coming with most OSes) so your wot-secured e-mail would not cause a verification problem.

Anything singed by an untrusted root CA (certificate authority) is NOT trusted by most computers out there and will cause a problem that I briefly explained here.

What is Web-Of-Trust and how it helped keep constitutional right for personal privacy?

WoT is based on Notaries. A WoT Notary is a voluntary (unpaid) person with certain level of trust (not less than 100 points) who can certify that he has seen enrolling persons and verified their national ID (passport, driver license etc) and have recognized that they provided enough proof as of their name. The only piece of info that goes into WoT certificate is person's name and e-mail address, so that addressees (and e-mail client software) could positively identify the authenticity of e-mail correspondence.
"WoT Trust spreads thru the grapevine" one could say.

Basically speaking, you can get free "noname" certificate right now, but you can have your name on it only when you get some points from WoT notaries (by visiting them in person and showing your IDs).
As soon as you get your cert, you could SIGN your e-mail. Any change of your e-mail in transit (except for headers) would be detected by the addressee. In fact, that is like having your written signature on it.

As soon as your addressee has own digital ID, and because he has your public key from your signature on first e-mail, she could ENCRYPT their replies back to you, so that the content of e-mail could not be seen.
That's how privacy works. Both parties must have IDs and there must be a transfer of public key (for ex. via first signed e-mail or offline).

There are alternatives, of course, and I welcome you to discuss them in comments.

I am Sergey Zak and I'm a Thawte Web of Trust notary.