• Explore the magic and the mystery!


  • Listen to The Tech Night Owl LIVE

    Last Episode — August 24: Gene presents a regular, tech podcaster and commentator Kirk McElhearn , who comes aboard to talk about the impact of the outbreak of data hacks and ways to protect your stuff with strong passwords. He’ll also provide a common sense if unsuspected tip in setting one up. Also on the agenda, rumors about the next Mac mini from Apple. Will it, as rumored, be a visual clone of the Apple TV, and what are he limitations of such a form factor? As a sci-fi and fantasy fan, Kirk will also talk about some of his favorite stories and more. In is regular life, Kirk is a lapsed New Yorker living in Shakespeare’s home town, Stratford-upon-Avon, in the United Kingdom. He writes about things, records podcasts, makes photos, practices zen, and cohabits with cats. He’s an amateur photographer, and shoots with Leica cameras and iPhones. His writings include regular contributions to The Mac Security Blog , The Literature & Latte Blog, and TidBITS, and he has written for Popular Photography, MusicWeb International, as well as several other web sites and magazines. Kirk has also written more than two dozen books and documentation for dozens of popular Mac apps, as well as press releases, web content, reports, white papers, and more.

    For more episodes, click here to visit the show’s home page.

    The iPhone 3G to the Rescue

    September 23rd, 2008

    So Cox Communications, one of the major cable, Internet and telephone providers in the Phoenix area, is upgrading its network to handle greater capacity, and to offer subscribers more high definition TV channels. Right now, the satellite TV services are ahead in that area, but not for long.

    Well, the other day, Cox customers customers received postcards (yes by snail mail) warning of potential outages over a two-day period, while the work was in progress in their neighborhoods.

    Indeed, a few days ahead of the actual upgrade, I got two voicemail messages advising me of when the actual service interruptions might occur. The maximum duration was supposedly two hours, although it was a mite longer in my particular instance.

    In any case, when Internet connection went down, I quickly felt the downsides to relying so much on online access to manage my life in recent years. Indeed, one of the reasons I got an iPhone was to be able to keep tabs on email, and make last-minute changes to this site should the need arise in the home office and on the road.

    Mrs. Steinberg was grateful not to have me call her constantly, and interrupt her from her chores of the moment, to check my desktop Mac for new messages.

    During the outage, I switched off Wi-Fi, so my iPhone 3G would stick to AT&T’s 3G network instead of my Time Machine. The advantage, I suppose, is that battery life is extended somewhat with reduced network activity.

    Now I could see just how well an iPhone might replace my Macs should the need arise, at least when it came to my online activities, and the answer is mostly a mixed bag. But I don’t think you should be terribly surprised, because the iPhone has obvious limitations. Some can be fixed with a few new features, some can’t be fixed because of the nature of the beast.

    Indeed, packing the guts of a personal computer and a wireless phone in a tiny case is an incredible engineering achievement. It wasn’t so many years ago that the fastest Macs on the planet wouldn’t approach the performance level of your iPhone. As processors get smaller and faster, and consume fewer precious watts, this will only get better.

    When it comes to email, I’d call the iPhone a 90% success, at least for my way of working. No, I can’t edit documents on it, other than a WordPress blog, using their special iPhone app. The lack of cut, copy and paste is telling for longer, more complicated communications, but I haven’t suffered all that much from this particular missing feature, though I wish Apple would hurry up and release it.

    The lone serious problem is the fact that AT&T’s 3G network is relatively new, and as many of you know, performance is not always as consistent as it should be. From time to time, the two or three bar signal strength display would decline to one, or it would revert to the much slower EDGE network. This variation didn’t seem to depend on the time of day, or weather conditions. Even when the bright, hot Arizona sun was shining through the window, there would be moment-to-moment variations.

    Web access is fairly complete, aside from the lack of Flash and Java support. Moreover, navigating through commerce sites with pop-up menus and such isn’t as convenient as I’d like. However, that’s merely meant I could save money and not worry about being unable to complete a transaction.

    As to phone service, our primary number goes through the Vonage VoIP network. When that network is down, whether at the source or because of loss of Internet connectivity, the calls are automatically routed to the iPhone. So I didn’t miss any calls either. With the iPhone 3G, in fact, you’re able to handle a call and consult your email at the same time, though not if it reverts to EDGE. The slower network simply doesn’t have the bandwidth to handle both tasks.

    Unfortunately, Cox lied about the duration of the outage. They claimed in an automatic voicemail that the interruption would last no longer than two hours over a 48-hour period. However, the first inkling that something was happening appeared as a short Internet service interruption, followed by a pair of two-hour cable TV and Internet disruptions. Their service people feigned ignorance about those voicemails, saying they always intended the outages to last up to ten hours.

    While service was unavailable, I felt my Macs were unduly handicapped, but I was actually able to get all of my morning assignments completed on schedule courtesy of the iPhone.

    Except for writing this article, of course. Yes, the WordPress iPhone app is neat, fast, and flexible, but I don’t want to try to type 800 or 900 word manuscripts on a touchscreen. Nor do the tiny buttons on a BlackBerry seem any more inviting.

    However, this does little episode does seem to reveal the need for some sort of Apple eMate-style device, a diminutive network computer with a larger screen and more conventional style keyboard. Internet access would limited to the cell phone network and Wi-Fi. If it was something that weighed no more than a pound or two, and easily carried in a case far smaller than that required for a conventional note-book computer, you might find the perfect marriage of convenience and miniaturization. And bundling cell phone capability into such a device wouldn’t be a bad idea. Call it a Super iPhone.


    A Warning About Mac Security Fear Merchants

    September 22nd, 2008

    You’ve heard the same sad tale over and over again: Now that Macs are finally becoming really popular, it’s inevitable that malware will soon infect this platform in a significant way. Just you wait, and all this crying wolf will soon become up close and personal. No tilting at windmills, but real, honest to goodness virus threats and other dangers are imminent.

    Certainly the fact that Apple releases security updates that address a slew of potential sources for exploits every few months must surely demonstrate that these fears have a basis in fact. After all, why would Apple fix something that doesn’t need fixing?

    Before you batten down the hatches and hide your head in the sand, consider the word “potential” in the previous paragraph, because that’s pretty much the story right now.

    Now I remember that silly Consumer Reports survey some time ago, saying that over 20% of Mac users had been infected by computer viruses. You take those figures and then look at the known fact that few Mac OS X viruses have spread into the wild, and only small numbers have been impacted, and you have to wonder just what’s going on.

    Well, I didn’t read that Consumer Reports survey question, so I don’t know what they were getting at. It may well be, as I’ve seen from time to time, that people who encounter crashes or other untoward behavior on their Macs might blame them on a virus. In fact, a local photographer and long-time client will often write me and express her fears about a potential virus whenever something goes wrong with her computer.

    So why won’t the fear merchants just give up and go away?

    Well, if you just take a gander at the list of exploits in any recent Apple security fixer-upper, you have a right to feel concerned. Every nook and cranny of the Mac OS, including the Finder and QuickTime, has been impacted at one time or another. It seems as soon as one security leak is closed, another one seems to appear in its place. It’s almost as frustrating as stomping out a colony of insects. Rest assured, many more will replace them soon enough.

    The biggest issue here is that fact that no computer operating system is 100% secure, however hard you try. Apple also builds its operating system with lots of open source components that, themselves, may suffer from potential security lapses. Even though some of those components, such as the Apache Web server, have been tested and proven for years, something new will almost always appear. So developers around the world are busy writing patches to address those problems.

    Apple will take these fixes, bundle them into the operating system and release the updates. Sometimes they come in a matter of weeks, and sometimes Apple assembles a bunch over a longer period before committing to a release.

    At the same time, whenever a serious serious hole is found that may be exploited in a test lab, or anywhere on the planet, security software companies will produce their own fixes. Those fixes will be accompanied by press releases that are no doubt meant to inform, but they may seem lurid enough to induce you to buy their products.

    This is not to say that the Mac OS X landscape is perfectly safe. Beyond malware, there are those phishing scams, where people send you letters asking you to update your personal information at your bank or other financial institution. If you click on the link, you’ll be taken to a bogus site made up to look like the genuine article. You enter your login information, social security number or other personal data, and your bank accounts may be quickly depleted before you discover what’s really going on.

    You can easily avoid phishing scams simply by not clicking on links of this sort in your email. Go to the company’s site directly and if you have further doubts, call their customer service people for verification. That will help combat schemes that depend on social engineering. And, no, no fallen Nigerian dictator’s heirs are ready to deposit ten million dollars in your bank account because your name was picked at random. I wonder how people fall for that silliness, but they do.

    Even before the scourge arrives, though, you may still want to install security software on your Mac, if only to keep from sending infected email to your friends who are still saddled with Windows. Maybe it does serve them right for choosing an inferior platform, but why give them more misery than they already have?

    In addition, some companies might just have proactive protection policies in place where both the Mac and PC users on their corporate networks must have security software installed and kept up to date.

    Even if the effect is placebo so far, the latest group of Mac security products don’t seem to seriously impact speed or reliability. That’s quite different from the old days, where certain virus protection apps would exact a stiff penalty on startup and application launch speeds, and cause lots and lots of crashes. As near as I can tell from doing a little random research, the products you buy today from such companies as Intego and Symantec seem to be pretty robust. So the only downside in protecting yourself in advance of any real threat is perhaps the loss of a small amount of money, including the original purchase price and the annual update contracts.

    More to the point, when and if a true virus threat appears that might impact lots of Mac users, having software already installed may not be a bad idea. That way, you don’t have to download a copy, or get a copy from a local dealer after it’s already too late!

    Then again, I still haven’t seen any compelling reason to install security software on any of my Macs, although I do keep the system’s built-in firewall active.


    Newsletter #460 Preview: Microsoft Tries Again and Again to Find Itself

    September 21st, 2008

    You’d think a company that owns more than 90% of its primary market would understand how to sell its products and services. After all, isn’t that how they made it to the top?

    Well, it appears Microsoft hasn’t found the going terribly easy when it comes to convincing individuals and companies that Windows Vista is impressive enough to make them upgrade. As it stands, many still prefer XP, which has been tested and proven for seven years and has, after service packs and other fixes, proven to be fairly secure (with proper malware protection installed) and reliable.

    In contrast, Vista has been shown to be a bloated, rather buggy beast, with lots and lots of driver conflicts. While the bugs and driver issues are supposedly largely resolved, most older PCs will have difficulty meeting its extraordinary resource requirements without costly upgrades — or replacement. Worse, some of the interface changes, which seem arbitrary rather than logical, will likely require retraining.

    So businesses are showing an understandable reluctance to migrate until absolutely necessary, and that might be years away, since it’s still easy to roll back the operating system on new PCs to XP.

    As far as Vista’s successor is concerned, well Windows 7 will still be largely based on the same code base, so it’ll be just as bloated, if not more so, assuming Microsoft wants to pour lots more features into it. That will probably be a given, since they want to entice people to upgrade. That is, after all, their way of doing business.

    That takes us to Microsoft’s questionable efforts to boost the image, and, of course, the adoption rate for Vista.

    Story continued in this week’s Tech Night Owl Newsletter.


    Don’t Let Them Post Your Email on the Net!

    September 18th, 2008

    Most of you have heard the news that Governor Sarah Palin’s Yahoo-based email account has been hacked, and the contents of her messages, including some family photos, are now being posted all over the Internet, and even being quoted in the mainstream media.

    Now I suspect this dirty trick was perpetrated more as a publicity stunt than by people actually trying to find out some secret information about the Republican vice presidential candidate, though it might be a combination of both. Regardless, the question is how it might have happened, and whether it could happen to you too!

    I’m not about to tell you about the tricks hackers might use to gain control of your email box, because I’m sure they use techniques that I could only begin to understand. But there are two simple things you can do to protect yourself, and they don’t require buying extra software.

    First and foremost, don’t publish your email address online. That only gives ammunition for spammers and other Internet criminals to fill your mailbox with junk. Worse, it creates the climate for someone to hack in, particularly if the account belongs to a high-profile personage.

    In the case of Governor Palin, part of the blame for that disclosure rests squarely on the shoulders of the Washington Post reporters who released her Yahoo addresses. While they have a perfect right to examine various matters concerning a candidate for high office, posting personal information of this sort represents a serious lack of ethics, and it may be why this entire episode occurred.

    Now some people actually create temporarily addresses (or aliases) to use for online commerce and other transactions where the information is given out to third parties. That way, if the account is compromised, it can be quickly deleted without harming your important mail.

    In this case, Governor Palin has also been accused of allegedly doing business for the state of Alaska via her personal email account. I don’t know if that’s true or not, but the ease of cracking her account does demonstrate a lack of knowledge on her part when it comes to Internet questions.

    Once you have established your address, temporary or otherwise, you should always use a strong password. That way, if a third party does acquire the address, it will make it doubly difficult to hack. A typical strong password is generally a random combination of upper and lower case letters and numbers. If that proves to be difficult to remember, you might use a normal word, interspersed with numbers and a random capital letters. That would still make it more difficult for password sniffers to figure it out.

    One example might be teN3nIs4bU8m. The three numbers might have personal significance to you, so they are easily remembered. Regardless, it’s not a bad idea to write it down, and put it in a safe, secure location, such as a bank vault along with your most important documents.

    I suppose if you’re not a supporter of Governor Palin, you might just as well suggest that she got what she deserved, but that’s not the point. She deserves her privacy as much as anyone, and this particular prank happens to be a serious offense. The perpetrators, if they’re ever caught — and I doubt that they will be — can face an extended vacation in a federal prison.

    However, I rather suspect that Alaska’s most famous “hockey mom” might have been the victim of a rather pathetic system devised by Yahoo for retrieving a lost password. In such an instance, the account holder is asked some basic questions that, the service provider presumes, could only be answered by that person and nobody else. In Governor Palin’s case, such information as her zip code, date of birth, and even where she met her husband, are in the public record. So it was simple for a hacker to trick the system and gain access to her account.

    Aside from this lapse, and Yahoo is no less guilty than other email services, they do appear to be working towards making sure they provide a safe environment for their users. However, Yahoo! Mail is also a den of spam. I know I had our sites hosted by them some years back, and I used their email hosting facilities for my regular business mail.

    Alas, I got thousands of bogus messages. So many, in fact, that I once lost a serious sale to a client because her message with a routine inquiry got caught in the morass of junk. As a result, I never saw it until it was too late.

    At present, most email addresses on this site are encrypted by special software, so few of them can be detected by spam robots. Most of the time, we simply redirect you to a special contact page, where your information goes through a background antispam detector, which also helps reduce the amount of junk that ends up in our mailboxes.

    Now I realize very few of you, even if your accounts are hacked, will find the contents of your email exposed all over the Internet. But you should take the above precautions anyway. It won’t stop all spam or totally protect your accounts from being compromised, but at least you’ll have an extra couple of ounces of protection, and that’s always worth it.