Thursday, October 4, 2012

Unoriginal title for a post about general PC security (Part 1)

First, let me preface this by stating that I am not an expert in online security.  I'm not a hacker, I'm not a cryptologist.  I'm a web programmer who tends to view security from the POV of an end user.

Okay, with that said, here we go....

I've bought this $500+ piece of machinery, but you're asking me to understand how it works?


The sad fact of the matter is that many people who own computers are still largely computer illiterate.  Some are afraid to break/screw things up with their new appliance, and others are simply not interested in learning more than how to send email, visit YouTube, and do some basic office work.  The problem is that seemingly innocuous online activity can lead to a host of problems.  Addressing them isn't difficult, but it requires a bit of effort.  Just like a car needs regular maintenance to keep it on the road, a computer needs regular maintenance to keep it running and your information safe.

It's important to note, at this juncture, that there's no such thing as 100% secure.  Cyber security is always a game of catch up.  The various hackers, malware authors, and other black hat individuals and organizations out there will always have an advantage because, in a lot of cases, threats can't be addressed until an exploit has been abused.  The best we can do is engage in behavior to mitigate risk, and be prepared if an attack does happen.

What do you mean 'P@ssW0rd' isn't a good password?


Let's start with passwords.  If you do anything online, you're all but certain to have one.  A good password is long (the longer the better), contains a bunch of different characters (letters, numbers, punctuation), and isn't based on a dictionary word, or common phrases.  They should also be unique for each account (more on this in a minute).

The problem is that long passwords not based on a memorable pattern and filled with a variety of characters are hard to remember.  They're also a pain to type.  So, what people generally do is create a short, easy to remember password and then use that for just about everything.  If an online account is compromised, who cares?  It's just an account to Fluffy Birds or something unimportant, right?

Wrong.  If login info is compromised (and many times they're compromised without one knowing about it at all), then every account that uses that info is compromised.  That could mean your bank.  Your social media accounts with all the personal information about you and your family.  Your life could be laid bare for those who wish to do you harm.

So, what can be done?  I'm a huge fan of password manager software.  This software is essentially a database of all your passwords.  Even better, most come with a password generator, giving you a high entropy password at the click of a button that you can use for any account.  The password manager itself can be protected with a password, and some even allow you to use a separate key file as a second form of authentication.

The general workflow is:

Sign up for a new online account
 |
V
Open the password manager
 |
V
Generate a new password with the password manager
 |
V
See if the site/system will take it*
 |
V
If yes, you're registered, if not, keep generating new passwords until one sticks

To log into a site that requires a password, simply open the manager, and copy/paste the password into the password field.

*The unfortunate reality is that many sites put ridiculous limits on what they accept for passwords.  Microsoft, for example, limits passwords to just 16 characters, while EA prohibits certain special characters from being used.  These restrictions are completely artificial, and really only serve to negatively affect how secure your login information actually is.

I use and recommend KeePass.  It's free, it's easy to use, and it's available on just about every operating system one would want.  I use it on my iPad, laptop, and desktop, and with it, I can hit all the important attributes of a good password:

Length
Not based on a dictionary word
Character variety
Unique to each account

Okay, cool, now what?


I'll talk about browsing, but in a new post to keep things readable.

Thursday, September 13, 2012

Ghost Hunters; or, That's not how science is done!

As I wait to hear from a client, I figured it was time to finally write my long awaited rant against Ghost Hunters and other shows of its ilk.  Those who know me personally know I have a seething hatred for it, but since my problems with it are many, I've never been able to succinctly express exactly why I hate it.  I figure that it's likely easier to put my thoughts down on 'paper', so here we go.

1. Assumptions


Let's first talk about the assumptions GH makes in order to have the viewer buy into what they're selling:

A. It is assumed that these people are professionals.  After all, they have a TV show.
B. It is assumed that ghosts exist.  This assumption is reiterated every time one of the people attempts to describe what they're scanning for.
C. It is assumed that the show is being truthful.

A:
The two founding members of TAPS (the GH group) are Grant Wilson and Jason Hawes.  Before the show, they were part-time plumbers and co-owned a NH hotel.  They did ghost hunting on the side.  Neither of them, nor any other members of their crew have any formal scientific training.  They are, by all definitions, normal people without formal training.

B:
We are told many times that the paranormal can do any of the following:

Emit an EM field.
Emit cold.
Can speak/make noise.
Manipulate matter (footsteps, things thrown, etc.).
Temporarily become visible.

The Ghost Hunters don't offer any explanation aside from their experience.  That leads into....

C:
Despite the show airing on cable TV, paid for by advertising and merchandise, the crew is being honest in their pursuit of the truth.

2. Faux Science


What the GH crew does is not science.  For one, real science doesn't assume that the thing its testing for is real.  Second, science is testable.  Third, science is repeatable.

The way GH works is that they find an interesting/spooky place whose owner is already predisposed to believing in ghosts.  They interview the owner, paying close attention to particular details of the supposed hauntings.  They then spend the night in the location while filming/recording.  At dawn they stop, go over the hours of media they produced, and then present their findings.

One night's worth of observations is NOT scientific.  It's the very definition of small sample size.  A real scientific endeavor would take far longer (weeks, if not months or even years) in order to weed out all the variables (seasonal changes, atmospheric conditions, etc.).  The data itself would be analyzed by professionals.  Secondary (or even tertiary) observations may be required if the initial data sets were inconclusive or raised questions.

But, what of the data itself?  Unsurprisingly, everything TAPS records is digital.  That means it can easily be altered.  Add to that the abilities of an on-site production crew, and the fact that, again, this is being done for profit, and the data has to be considered suspect at best.

"Wait!  The GH crew itself debunks things all the time!"  Ah, well that plays into....

3. The Trick's the Thing


Ghost Hunters is one of the only shows where the majority of the action takes place off camera.  Think about that for a moment.  9 times out of 10, the camera is focused on one of the member's faces when the inevitable (and there's always at least two per case for advertising breaks) surprise happens.  And, really, that's the key.  The focus on the show isn't about the place they are or even ghosts at all.  It's about the crew.  They're the stars.

Now, there are shots of EMF meters blinking their lights, and various FLIR images, and even the occasional stationary camera shot.  I go through them individually.

The EMF meter shots are always filmed the same way: a tight zoom on the device itself as its lights blink in accordance to the off-screen instructions of a team member imploring a ghost to make the device light up.  EMF meters do exist (http://en.wikipedia.org/wiki/EMF_meter), but they don't generally look like what the GH crew uses.  So, it's questionable as to whether the GH prop is legit in and of itself.  Being charitable and assuming it is, why is the camera zoomed in so closely?  There's no need for the device itself to take up the majority of the frame, especially given how often things 'happen' off camera.  I have the suspicion that since the lights ALWAYS behave on cue, someone to the side is manipulating them.

The FLIR images, being digital, can easily be manipulated in post-production.  Some, like the far-off humanoid images, likely ARE people (producers, assistants, etc.).

The stationary camera shots usually pick up some physical movement that's off to the side, in the distance, or with a small object (desk clock).  Usually something moves, slides, rolls, or opens/closes suddenly.  This kind of thing has been used to great effect in movies like Paranormal Activity.

The same sort of thing can be said about the sounds obtained from EVP sessions (Electronic Voice Phenomenon) when one of the crew sits alone in a room and attempts to talk to a potential ghost while recording audio.  Since the recording is digital, it can be easily manipulated.  More on EVP: http://en.wikipedia.org/wiki/Electronic_voice_phenomenon

What about the GH crew debunking things?  That all adds to the air of authority and truthfulness.  It's simply a way to get people to trust them.  It's really no different than a snake oil salesman plucking a 'random' member from the audience.

4. Conclusion


In the end, Ghost Hunters is not scientific.  It's not even remotely believable.  It's merely a combination of likeable everymen visiting spooky places at night while using camera tricks and post-production editing to sell a story.  There's no truth here.  Rather, it's just the continuation of a brand that's more interested in DVD sales than knowledge.

Friday, July 27, 2012

Adventures in repository land

My original Entity Framework repositories sucked.  No, they really did.  They were bloated, ugly things, each tied to a particular type, and filled with repetitious code that was far too application specific.  I mean, look at this crap:



To be fair, the code above was one of my first iterations of a repository, written before I was comfortable with C# and EF.  That said, the recent iterations of my standalone repos weren't much better.  A whole bunch of inflexible, type-specific code.

I knew that the ideal solution would be to make my repositories as generic as I could (code to an interface, not an implementation, right?), but the existing Game repo had specific functionality not shared with the others, and, more importantly, it required the eager loading of related data, and I wasn't sure how I'd tackle that, or if it was even possible.

IObjectSet does not have the Include() method, and I thought I was sunk until I found this old blog post from Julie Lerman.  IObjectSet implements IObjectQuery, which meant that I could write my own extension method that (for all intents and purposes) overloaded Include().  Problem solved in a decidedly C# way.

So, behold my generic repository, and my Game specific subclass:


Now, what about my Game-specific code?  Simple:


When I need to do the extra Game-related things, I simply cast (canned example):


I'm not sure if this is the most elegant way to go about it.  The cast strikes me as a bit of a code smell, but since those methods are used sparingly in my project, it seems like it's good enough.  Most importantly, my code footprint has been significantly reduced, and my backend is far simpler than it was originally.

You may have noticed that my type parameters implement IHGEntity.  That's just a utility interface that allows me to access to my types' ID property, which in turn allows me to save my entities.  It is an epic one-line interface:


So, there it all it is.  I hope this will be of help to those just starting out with EF.

NOTE: Apologies for the inconsistent capitalization of type parameters in the code blocks above.  The synax highlighter is automatically making anything within angle brackets lowercase.

Tuesday, June 5, 2012

E3 Musings

Maybe it's because I'm an old fart, but heavily scripted 3rd person action games like Uncharted, the upcoming Lara Croft, the upcoming Star Wars 1313, etc. just don't appeal much to me any more.  They're all essentially the same game - Prince of Persia platforming + Gears of War cover/gun play.  And linear.  Suffocatingly linear.

The only reason why I still go after Rockstar's games are because they're usually pretty well written, and the open world aspect where I can at least cause some of my own mayhem.  Getting chased by cops in, say, Vice City is a game in itself.

But, yeah, I was struck by how many games simply didn't speak to me while watching the E3 presentations.  All the 'realistic' FPS games look the same.  All the 3rd person action games look the same.  Sports titles are the same every year anyway.  It's just startling to see such little innovation among the AAA titles. 

Like I asked yesterday/last night on my Twitter/Facebook, can anyone tell me the difference between the upcoming Call of Duty, Metal of Honor, and Battlefield games, aside from their titles?

---

That said, the two titles I'm most interested in are Dishonored and Watch Dogs.  Likely because they offer several ways to tackle a particular situation.

Thursday, May 24, 2012

E3 potpourri

Just some random, stream of consciousness thoughts on the coming E3:

Like someone else said on the Penny Arcade forums, isn't it funny/sad that the things most people are looking forward to from Square-Enix are its Eidos offerings?

Prediction: Microsoft's keynote will be barren.  Kinect + media apps + already announced exclusives = yawn.  I'm hoping that they're lying and will do something regarding the NextBox/Xbox 720, but I'm not counting on it.

I hope that Ubisoft unveils a new Splinter Cell.  And, I hope it refocuses on stealth.  Playing Sam Fisher as Jason Bourne is fun, but I wanted more stealth capability in Conviction.  Not being able to move bodies was a grievous oversight.

Apparently there's a rumor that Sony will have a megaton announcement during their keynote, and that it has something to do with the cloud.  Some people are wondering if it's tied with Valve/Steam.  I'm wondering if it has something to do with rumors of Sony and Microsoft talking over the last few months.  Maybe some Azure?

I can't help but wonder what Bioware will show.  Likely the Mass Effect 3 apology DLC, but what else?  Their new post-ME IP?  Something Dragon Age related?

I'm curious on the JRPG front.  I haven't played a JRPG I liked in ages.  Will Final Fantasy XIII Versus finally materialize?  Anything actually worth playing in the genre?

The Wii U both intrigues and frightens me.  I can't help but wonder about the tablet controller's accessibility.  The Wiimote is already a barrier.  The tablet looks orders of magnitude ("Pop pop!") worse.

I got 38 problems but a game ain't one

Holy crap, a blog post!  First, the usual professional update:

Paying work has slowed, I've had issues receiving payment from one client, and I'm busy cleaning up code/finishing writing code on the first of my personal projects.  Naturally, I want to change its look, because I suck at design, so, yeah, more delays there.  Good times.

Now, to the meat of this post:

We're entering silly season for video games.  There's a whole bunch of corporate things going on, and E3 is a week+ away.  I figured that with everything going on, a couple posts would be apropos.

---

38 Studios.  The company that's taken 6 years to make a mediocre adventure game and a still-in-development MMO, both of which look like they have Azeroth envy.  Is it a shock that they're going under?  That they wrote a bad check for the $1.1m loan payment they missed?  That what employees are left haven't been payed since May 1, and that their health insurance ends tonight at midnight?

Nope, not really.

For a time, it seemed like every studio wanted to take the MMO crown from World of Warcraft.  The problem is that they didn't take the time to see what made WoW special. 

For one, pedigree.  WoW was the continuation of a very popular brand.  What's more is that the original developers were vets from Everquest and Dark Age of Camelot.  They had working experience in the genre. 

Second, a massive, public beta.  WoW became a part of the gaming culture even before it was released.  Popular entities like Penny Arcade were salivating over it at the time, which made it more than just another game.

Third, a good deal of luck and timing.

I've said it before, and I'll say it again.  Trying to become the "Next X" is a fool's errand.  How many game companies have tried making the next WoW?  Remember Warhammer Online?  Age of Conan?  Anarchy Online?  SWTOR is hemorrhaging subscribers as I write this, and that's a Star Wars game from Bioware!  Even WoW itself lost a significant number of subscribers after its Wrath of the Lich King expansion. 

What's worse in 38 Studios' case is that, like I said above, their world of Amalur looks very similar to Warcraft's Azeroth.  The architecture, the environments, the people, the creatures - it all looks like WoW 2.0.  Don't take my word for it.  Check it out below:


Off the top of my head, I can see Orgrimmar, Teldrassil, Loch Modan, Gilneas, and Stormwind analogues.  This could be a drinking game.

So, let's recap:

38 Studios decided to put almost all their eggs in the MMO basket.  A genre which, over time, has proven over and over to be a bad investment.  Despite seeing the multitude of failures from other companies - both with original and existing IPs - they refused to change course.  Their one game to date, after 6 years of being in business, is Kingdoms of Amalur: Reckoning, an admitted side project which sold 400,000 copies, and is, by all accounts, decent but not memorable.  In order to differentiate themselves from other IPs, they make theirs look like an updated WoW.

... who was in charge here, again?

I feel for the employees, but man, the people at the head of the company were idiots.  I'm sure the Rhode Island taxpayers must be thrilled.

Thursday, April 5, 2012

PSA

You're a young, plucky go-getter with an interest in tech and nothing but time on your hands.  What to do?  Why learn web development, of course!  So, here are some random tips for those just starting out:

1.  Learn HTML and CSS.

Seems kinda like a no-brainer, right?  You'd be amazed at how many people feel uncomfortable with the basic building blocks of the web.  Some developers learned HTML in the late 90's and never took the time to keep up-to-date on it.  They get all Unfrozen Caveman Lawyer when confronted with the modern web ("Your world of Cascading Style Sheets confuses and frightens me").  Don't be that person.

Other would-be devs feel that HTML/CSS is somehow beneath them.  That, somehow, they'll be forever isolated from the unwashed masses that have to write markup because they're a programmer, not a coder.  Don't be that person, either.

Here's the thing: at some point, the stuff you'll program will be rendered in a browser.  Even if you're a programmer, chances are you'll need to tweak templates in order to have the yummy, yummy data you massaged earlier in the process display on screen in the right place/format.  Knowing how to debug these templates when things go wrong (and they will) is essential.

Besides, both are fairly easy to learn.  HTML can be learned in a couple hours.  CSS takes a bit more time, mostly due to CSS positioning and the Box Model, but is still doable.  No one will expect you to be an awesome designer.  They will expect you to be familiar with the basics.

2. Server side language choice

In the long run, this doesn't matter too much as you'll likely learn a variety of languages if you stick with it.  But, short term, it's an important decision that must balance ease of use, availability of quality resources, and success/failure/positive reinforcement.

For me, there are only two viable choices: PHP and C#

PHP has some nice benefits - Ubiquity, easy syntax, it's dynamically typed, so you don't have to worry about type initially, and it rewards the developer with fast results.

PHP also has some drawbacks - A lot of horrible, out-of-date resources and tutorials floating around online, when done wrong PHP can teach some very bad habits, it's dynamically typed, so you may not even learn about type, and a lot of little technical things that a newbie likely wouldn't notice, but are there anyway.

C#'s benefits are - Statically typed, so one learns about type right off the bat, clean syntax, object oriented, more options in terms of more complex data structures.

C#'s drawbacks are - A much higher learning curve from the get-go, possible reliance on the .NET framework as a crutch, the MSDN (although it's getting easier to navigate).

For web development, I started with PHP.  I feel it's the best at efficiently teaching a prospective developer how forms work, how a server side language interacts with a database, and how processes on the back end eventually become things an end user experiences.  YMMV.  That said, I prefer C# now.

3. It's a database, not a spreadsheet

One of the classic mistakes a newbie can make is treating a database like a spreadsheet.  Most of the databases used with the web are relational databases.  Database tables model the relation between different sets of data.  To get the tables into the right form, developers 'normalize' them.  Here's a good primer on normalization: http://mikehillyer.com/articles/an-introduction-to-database-normalization/

Simply put, if you use your database as a spreadsheet, you're doing it wrong.

4. It's 2012.  Time to learn JavaScript

JavaScript is probably the most important language employed on the web today.  It's a vital component of many sites (Google Apps, Facebook, Twitter, to name a few), and with the upcoming improvements in HTML5, it will only become more widely used.

Despite that, JavaScript still carries a stigma.  Older end users remember a time of constant JavaScript errors, and older developers remember the browser wars.  It doesn't help that the language itself is a bit odd, and has some hidden gotchas baked right in.

That said, the emergence of JavaScript frameworks (including the ubiquitous jQuery) has all but made the pain go away.  There's no reason not to learn the basics.  With the way things are progressing, saying, "Nah, I don't do JavaScript," will be akin to saying, "Nah, I don't do email."  Get on board.

---

So, there you go.  Random thoughts on a Thursday morning.