Showing posts with label technology. Show all posts
Showing posts with label technology. Show all posts

Tuesday, July 17, 2012

Don't Look Now, Here Comes Office 2013

As soon as we become comfortable with technology, we are probably behind. For example, many of you at Passaic and Bergen have just received training in the state of the art Office 2010. The biggest feature that will take some retraining is the touch-screen support. Windows 8 and Office 2013 will support touch-screen input, so if you have a touch-screen, you can use that instead of a mouse.

I am interested in seeing the changes they have made, so I will be downloading the free consumer preview and seeing how I like the changes.

Anyone can download and try out the consumer preview for free:
http://www.microsoft.com/office/preview/en

If you already have Office, I would not recommend removing your old version, as preview versions expire eventually. However, if you don't have Office at all and would like to play with it, or if you are a little more tech-savvy, here is your chance to be the first kid on the block to try it out.

That is my plan for Tuesday!


Wednesday, July 04, 2012

Evolution of an Operating System (and my Windows 8 book)

I am finishing up my second book, a Windows 8 book for Pearson/Prentice Hall. Apparently, it will be published on October 12, according to Amazon (Link to my Windows 8 book here).

Delving in to the new operating system has been instructive for a few reasons. First of all, this version of Windows is going to change things. This rivals Windows 95 as the biggest change I've seen to Windows. Short summary: they have removed the Start menu and replaced it with a Start screen.

Wait, no, that is the Partridge family bus. You can see my confusion.


Yep, that's the Start screen!

You can of course add and move tiles. Notice my user name is my Gmail account. You can sign in with a Microsoft account and keep your files and settings "in the cloud". In other words, if I design my Start screen on my desktop, I can log in to my laptop and have the same screen. If I add bookmarks and pictures, they can follow me as well! Microsoft has also added the ability to log in using picture passwords and PINs, much like some cell phones.

The Windows Explorer interface has changed to include the Ribbon, which is the interface you may be used to from Microsoft Office 2007 and 2010.

Other key points: Windows 8 supports touch-screen monitors, so I am guessing in five years or so most people will have touch-screen monitors at home.

They've added new searching functions, gestures (like "pinching" on the screen to zoom), and basically ripped the heart out of the operating system.

There are many changes to be discussed, and a blog entry just won't summarize this. Just prepare to retrain!

Friday, September 23, 2011

Windows 7 and the curse of retraining

As a computer person, I am in the position where I need to constantly retrain myself. Many of the things I learned in college are already obsolete. A career in computers always presents new challenges and new opportunities, and that is part of what I like about it.

I find that many people hate the fact that things change. Computerization of jobs is one thing. I know two doctors with small offices who are pretty computer illiterate. They both plan on retiring if and when they have to submit all medical claims electronically instead of faxing or mailing them. I certainly can understand that. In that situation they feel there is too much added expense (in time and/or money) in retraining themselves, buying equipment, and possibly hiring an assistant to do the computer work.

However, even computer literate users generally dislike retraining. I understand the thought. People who are not in the computer field seem to look at computers as an appliance, much like a stove. If I had to retrain myself on how to use a stove every year I'd dislike that and just order out more.


Since people don't like the idea of retraining, they tend to use a new tool the way they used the old tool. However, newer versions of tools generally include better ways to do things. For example, since Windows 95, I used the same process to take a picture of what is on my screen and save it. I would hit the print screen button on my keyboard (or hit alt+printscreen to only capture the current window). If I wanted to only keep a part of the image instead of the whole thing, I would then open a program like Photoshop, create a new file, paste the screen image, select the part I want, crop it down, and save. This process is clunky, but it works, and this was just how I did things.  Windows 7 (and some versions of Vista) include a tool called the Snipping Tool. This tool would let me take an image of part of my screen in many less steps. Were I not constantly playing around with new features, I would be less efficient. For those of you who haven't started using this cool tool, here is the Microsoft Snipping Tool tutorial.

Rather than learn new versions of a tool, people may even actively seek ways to make the new tool look like the old tool. For example, when Office 2007 came out, people hated the Ribbon interface, which replaced the old menu interface. A number of companies released tools (such as ubitmenu) that allowed users to display the old menus back in Office 2007.

For me, retraining is part of the allure of computers, but if you are among those who view it as a curse, I can understand the thought.

Monday, July 11, 2011

Medicine and IT

If you've ever watched the TV show House, you will know that the main character (a doctor) has a rule that you never believe a patient, because "everybody lies". It's a very dark view of the world.

I can relate.

I've had friends ask me to take a look at computers, and while not everyone lies, I do find that many of them do. I imagine for a full-time tech support professional, it is doubly so. For example, if you spilled coffee on the computer, please don't tell me you dropped it. If you dropped it, don't tell me it just stopped working.

Any of my former IT students run in to this?

Wednesday, June 15, 2011

Google Image Stalking

So, Google is introducing a few new features, and as always, the applications can be used for evil.

One of the features aims to allow users to ask questions through their microphone, and have Google search for the words you speak rather than requiring you to type them in. It will recognize your voice and send the words to the search engine.

Another new search is the Google Search By Image. This feature claims that it will let you upload a picture and find information about that picture. For example, if I have a picture of me in front of a building, Google Search By Image would attempt to identify that building. That seems really interesting.

I decided to test it out with some pictures of a trip I took. I went to the Google image search, and downloaded the Firefox extension which allows you to right click on any image in your Web browser and search the Google Search By Image tool for it. However, it doesn't work with Firefox 4.0 yet, so I decided to try it in Google Chrome. I then dragged a few images in to the browser.

I had some pictures of a cruise I took last summer, so I decided to try those.

First, I tried a picture of a lighthouse I saw in Canada. It came up with some pictures that were very similar, but they were the lighthouse in Cape May, NJ.

I decided to try something easier, and I dragged a photo of the Statue of Liberty there. Google Search by Image correctly identified it and returned other images of it and a link to the Wikipedia article.

I tried a picture of a random chunk of the NYC skyline, taken from sea, and that also did not return anything useful.

I tried a picture of a pretty distinctive tour bus from St. John's, Canada, and it wasn't able to match that either.

Verdict on the image locator: weak so far.

Google also claimed it could locate an image that is on the Web. I dragged an image of something I am selling on Craigslist, and it was able to immediately find and display that for me. I dragged another image of something I am selling on eBay, and it was able to find that. Finally, I tried an image I downloaded randomly, and it was able to show me where that image came from. I would say this is a success.

Verdict: This could also be pretty powerful if you are checking to find where an image came from, in case you want to use legally it in a publication, but isn't going to be able to determine where a vacation photo was taken unless it has a pretty obvious or distinctive monument in it.

Google does claim there is no facial recognition that will be available. Color me suspicious.

For a number of years, Google had a free 411 service called Google 411. Many people felt like the reason Google was doing this was to allow testing of their voice-recognition algorithm. All of a sudden, they have Google voice search. I would assume they tested and improved their algorithms in part with their free 411 service.

Now, Google is going to claim there is no facial recognition that is available. However, they will be amassing a powerful database of photographs. The Google privacy statement seems to allow them to keep Web requests, and my interpretation of an image is that it is a Web request.  Given what they did with Google 411, I would suspect that they will save the images you upload for their own testing purposes. Could facial recognition be something they are testing?  Who knows.

I tend to trust Google more than some of the other big name companies, but just because they aren't making facial recognition available to the public, doesn't mean they aren't gathering our uploaded photos to test their software.

I also have some concerns about how, if this technology develops, people might use this to stalk or harass other people. For example, let's say someone uploads a few pictures to their Facebook, or hacks their phone, or steals their digital camera. If someone is trying to hide from someone, those pictures may be searchable and usable. In addition, let's say a criminal finds a digital camera and notices people wearing nice jewelry in it. Could the pictures possibly lead them to a person's residence? As I said before, this does not seem to be at that point yet, but always something to think about.

Wednesday, April 27, 2011

Cool Tools: Tunatic

I found a bunch of old CDs the other day, with hundreds of songs on them. These were CDs I had burned in 2000, 2001, and 2002. There were a number of songs I remembered, but I could not remember the name for them. I figured there had to be a tool out there to help me find the names (because iTunes imported all the files with the names Track1, Track2, etc).

I did a quick search and found a tool called Tunatic. This is a pretty nice tool that works much like the iPhone tools Shazam and Midomi. You let the computer hear the song, and the tool will identify it. It's a free tool, so I downloaded it and gave it a shot.

This worked extremely well for me. It had a little problem with some of my more obscure songs, especially anything without vocals. Since I have a computer headset with a microphone, it was extremely easy to set this up.

I'd recommend this, as long as you have some sort of microphone input.

Link to Download

Tuesday, April 19, 2011

The Day eBay Changed

Today is the day eBay changed to a new business model. For years, eBay has had a fee structure based on a few things (for small sellers, anyway):
  1. Listing Fees (a cost for posting an item)
  2. Listing Upgrade Fees (want your listings to appear in bold? go for 10 days? etc.)
  3. Final Value Fees (they take a percentage of the final sale value)
In addition, eBay bought Paypal a number of years ago, so they also take a percentage of each payment processed.

For years in my CIS 152 course at PCCC and more recently my INF 163 class at Bergen, I've discussed how having an item go for 99 cents is not a good thing for eBay, in my opinion. It would be better for them to let people set a starting price and give them a free listing fee, because they would make more money off a final value fee. For example, if I list an item for $1.00 and it sells for $1.00 cents, eBay would get about 19 cents (10 cents to list the item and 9 cents for a final value fee). I might list an item so cheaply to avoid paying a large listing fee, which I am responsible for even if the item doesn't sell. Many sellers avoid risk, so they start items cheap in case the item doesn't sell, minimizing cost for listing fees.

My personal opinion was that if eBay cut out listing fees and simply raised final value fees, they would reap two benefits:
  1. Sellers would list items for higher prices, therefore leading to higher final value fees.
  2. Sellers would be more likely to sell items that might not sell, due to reduced risk of wasted fees.
eBay has seemingly decided to go with this, and will now allow sellers to sell 50 items a month with no listing fee, regardless of starting value. In addition, these auctions will be eligible for a free "Buy It Now", which allows an anxious buyer to purchase an item for a set price and preempt the auction.

Link to new fee information

Listing upgrade fees still exist, as do final value fees.

Of course, there are always catches. First of all, eBay will no longer just be taking a percentage of the final sale. They are also taking a percentage of the shipping cost. There still seem to be some workarounds, but eBay has done this because a seller could list a $200 item for $0.01 with $199.99 shipping and pay no fees on an item (and sellers did try to exploit this).

It seems like eBay's idea here is to keep small sellers around, while motivating medium sellers to move to eBay stores. The eBay stores are a system which has monthly subscription fees ranging from $15.95 to $299.95.

The loser in all this is the buyer who is looking for bargains, because in my opinion, they are going to be harder to find.

Friday, March 25, 2011

Adventures in Laptop Repair

My friend had an old laptop he brought to me today. It was pretty old. It has 64 MB of RAM, a 233 Mhz processor, a 4 GB hard drive, a dead battery...a real winner! In addition, whoever set it up installed Windows XP on it, so it takes FOREVER to start up.

He asked me if I could put it in Spanish so he could send it to his niece in Puerto Rico.

I decided to take a look and see what I could do. After all, it keeps my tech skills fresh!

As I have never done a Spanish install before, I first started by going to the Windows control panel. I took a look around, and went in to the language settings. Ah ha, I thought, this should fix it. I switched everything to Spanish, restarted the machine, and waited for it to work.

Sadly, this did not work. The Windows XP system files were installed in Spanish, and this did not even change the Start Menu to Spanish. It made sense when I thought about it. All the programs were already installed in English. A little Internet research showed that in order to do what we wanted, I would need a special installation of Windows with a new license key. License keys are generally tied to a specific version of Windows, so even if I got the Spanish version, I doubted the existing license key would work.

I was also sure that my friend did not want to pay for a new XP license for this machine.

At this point, I had a few options. I could have considered pirating the key, but my personal ethics ruled this out. Even if they didn't, the risk of downloading stuff from torrents/file sharing networks (0-day viruses, getting caught) would deter me.

Besides, when I thought about what my friend wanted for his niece, it was a computer that allowed her to do Internet research and type papers. At this point I decided to investigate Linux. I figured there should be a Spanish distribution of Linux, and it would certainly run better than Windows on this machine.

I am familiar with Ubuntu Linux, but it did not look like there was a complete version, so I did some searching and found Asturix, a Spanish Linux distribution based on Ubuntu. I downloaded the CD image and burned it on to a CD.

I brought my new CD back to the old laptop, and tried to open the CD-ROM drive. No response. Luckily, I know about the trick to open a stuck CD-ROM drive with a paperclip (that's why that tiny little hole is on the front of the drive!).

I opened the drive, inserted the CD, and started the machine. I walked away and came back, and it booted directly in to Windows. I restarted, and went in to the BIOS (the computer's basic input/output system). It was correctly set up to try the CD-ROM drive before it booted off the hard drive.

I restarted again, and paid attention this time. When the computer restarted, the CD-ROM drive made a very odd sound and then stopped spinning, and then the computer booted in to Windows. To verify, I went to My Computer, and the CD-ROM drive wasn't even listed, which means it was malfunctioning.

Normally at this point, I would consider creating a USB boot drive, but this machine was so old, the BIOS did not support it.

At this point, I considered partitioning the hard drive, but it just wasn't worth the effort for me.

Saturday, February 19, 2011

I am the number 6 Google result for "cat-proof software"

Statcounter (the site I mentioned which showed what browsers people were using to visit my site) provides a lot of cool features. If I had my own Web server, I could get this same information by perusing my Web server logs, but since I am running a site through Google's Blogger service, I don't have access to those.

Statcounter logs all sorts of information, for example, computer IP address, operating system, browser information, screen resolution, and more. One of the other things that is cool is that it can tell you how people found your Web site, assuming they didn't just type it in to their address bar.

For example, if you Google:
Professor Cameron blog

I am the first result for this. This makes sense. If you were to then click on that Google link, I would be able to see that someone Googled that and found me using those search terms. I can also see which search engines people used to find me. Of my recent visitors, 55 found me using Google, 7 using Bing, 4 using Yahoo!, and 1 using Ask. (Note: Statcounter only logs the most recent 500 visits for free users, and many of them didn't find me using a search engine, hence the small numbers).

I sometimes will pop on the system and see how people for finding me, and there are always some interesting results.

For example, I have a number of searches I would expect. The following searches led people to me (again, some Google, some not):
interesting computer stuff (name of the blog, that makes sense)
professor cameron (makes sense, that's me)
fun stuff with professor cameron (I assume someone just forgot the name of my blog here)
eric cameron pccc us (that's me!)

In addition, there are searches that turned up specific blog posts of mine. I have a number of searches related to computer hardware disposal (due to a recent post), PCCC Panther Alert (something I've discussed a few times - PCCC's emergency alert system), Zune disaster (an older post), an assortment of things related to Microsoft Office hotkeys, and other such searches. As a matter of fact, I am the number 6 result on Google for cat proofing computer due to a post from last year.

Then, there are the bizarre ones. These serve to show me that search engines, though amazing, still have a ways to go. Here are some of the bizarre searches that have led people to my site:
  • simple one touch notification pagers from chef to servers 163-001
  • i get taken advantage of a lot
  • AVERAGE TIME WASTED WAITING FOR OLD COMPUTER
  • Bergen Community College, "flight simulator"
  • Professor Cameron porn
  • wife playing world of warcraft when supposed to take children +subpoena
Some of those are bizarre! I wonder what was going on in that last search...

Anyway, you can see searches like Professor Cameron porn would lead you to this site because somewhere in a page is each of those words. I posted about pornography a few times, and of course Professor Cameron is on every page, so yeah, that works.

I am pretty sure whoever was searching for that was disappointed when they found my blog.

Wednesday, February 16, 2011

Web browser usage

Sites like Statcounter can track happenings on your Web site. For example, I can tell you of my last 500 visitors, 49% used Firefox, 27% used Internet Explorer, 6% used Google Chrome, 2% used Safari, 0.4% used Nutch, and 0.2% (one user) used Konqueror.

We see a lot of statistics regarding Web browser usage. It does vary by region. Firefox and Chrome seem to be more popular in Europe. According to Statowl, the latest numbers for the US, around 60% of users are running Internet Explorer, and only 20% running Firefox. World numbers are somewhere around 47% for Internet Explorer and 31% for Firefox, according to Statcounter.

None of these will be 100% accurate, but they do paint a picture for us. Why are my users more likely to use Firefox than the average world user? I would assume that, as I maintain a technology-related blog, my users are more likely than the average user to use a browser like Firefox.

If I were doing Web design and I had these numbers, I would need to make sure the browsers my users use were the browsers I was testing my site in. Though it really should not happen, there are times a page looks different in Internet Explorer and Firefox (for example).

It is interesting for me, as someone who is not running a for profit site, to look at these statistics. For someone who IS running a for-profit site, this information can be critical.

Tuesday, January 18, 2011

Metadata and You

I first encountered the word metadata back when I started creating Web pages in the mid 1990's. Programs called "search engines", like Webcrawler and Altavista, would automatically find your page and make it available for the world to find. They did have issues adequately describing your page, so as a Web developer adding "meta tags" was critical. It was a way of adding text that did not show up in the Web browser, but allowed search engines to find information about your site.

Metadata is something that is used today in many areas, from computer forensics to corporate espionage. I will give you a regular example first. As a professor, there are times when I think something might be an exact copy of someone else's file. The first thing I will do is take a look at the file properties. In Office 2010, I would go to the File tab and select "Info". On the right side are properties. I can see very easily the name of the person who created the file. In a computer lab, most people probably have the same user name, so that may not tell me anything. However, if you created it at home and gave it to a friend, there is pretty damning evidence since your friend has handed in a file with your name in it. Other ways include "date created" - this tells me the day and time the file was created. I am of course not opening up my whole bag of tricks here, but these are two ways to investigate a file further.

In terms of corporate espionage and hacking...many times, the metadata in programs such as Word (and most of the rest of Office) includes data like username, company name and a file path. If this file was created on a network drive, I now know the name of one of your company's internal servers and possibly your username. This information is valuable for hackers!

If you are distributing a file from Office, also be aware if your company uses tracking changes, revisions, comments, or hidden text, that information can be included in a file you distribute. If a member of a company's staff left a comment in the file, there is a good chance it could be found. You can use the Office 2010 Prepare for Sharing options to minimize this risk, though once again, most people do not realize this.

Even programs like Photoshop can cause metadata issues. Let's say you have an image, and you choose to blur out bits of it. Photoshop will save a thumbnail as part of the file, to make it quicker for the operating system to give users a preview. Therefore, a smart hacker may be able to see your original image using some advanced techniques. Programs such as jStrip will help minimize this risk, but many people don't realize it is a risk.

Like many other technology issues, the only way people know about this generally seems to be if they are burned by it.

Saturday, December 11, 2010

There's an option for that

One thing many computer users don't seem to intuitively understand is the idea of customization for the programs and apps they are using.

My approach to using software is to try to use the software, and when I find something I don't like, to try to find some way to change it. For example, inside of Microsoft Internet Explorer, you can change the start page. Most computer savvy users know this, but one of my friends just called this morning saying he changed his somehow and couldn't figure out how to switch it back.

This applies to Web sites as well. For example, Facebook allows you to turn off certain notification emails, change privacy settings, and change many other options. Most free email providers allow you to set up "filters", which would basically let you screen your mail (for example, you could have all email from people at a certain college go in to a special folder so it does not fill up your Inbox, but does not get deleted). If you use a site such as Yahoo! Calendar, you can set it up so it will send email reminders for events to a certain email address or phone number by default, instead of having to set that up every time you create a new event. Even games like World of Warcraft are customizable. You can switch things on or off using some of the menus in a game.

Chances are, if you are annoyed by something, there is an option to change it. Don't like Excel starting every file with three worksheets? You can change that. Do you hate it when you open a bunch of windows, and things compress on your taskbar? That can be changed. Would you prefer your Word to always space in one inch when you hit tab instead of a half inch? That can be done. Does your Blackberry give you annoying little "message sent successfully" messages every time you send an email? That can be removed.

The key is knowing that things can probably be changed, and finding the answer on the Internet.

Tuesday, November 30, 2010

Proper Hardware Disposal

In one of my classes last week, we discussed the proper way to get rid of old computer hardware, to avoid privacy issues.

I've gotten rid of old computers, but I generally either keep the hard drives (to destroy) or use software to do a thorough wipe of the drive's data When I say "thorough wipe", I am not talking about deleting files, because data can easily be recovered from a hard drive, EVEN AFTER YOU DELETE IT. Really. As a matter of fact, Microsoft's pre-Windows operating system, DOS, used to include an undelete tool which could recover deleted files easily.

eBay is one place people can purchase used hard drives, and they even provide information on why you need to thoroughly wipe a hard drive before you sell it. You can see that the site shows that social security numbers, credit card numbers, and all sorts of stuff can be found on these hard drives. This means your identity can be stolen even if you do nothing wrong, if a company you have purchased from does not follow good procedures for hard drive disposal. Aside from eBay, there are sites like Craigslist where people get rid of old hardware, and there are always garage sales. In the corporate environment, many colleges and companies pay companies to dispose of old hardware (such as eRevival locally). If you go with a cut-rate company, you may find that though they promise to clean hard drives, they may not do so thoroughly. Any of these are ways that data can be leaked if the hard drives are not wiped.

One way you can provide a level of security is to physically destroy the hard drive, though someone could pick it out of the trash and recover something. The best way is to do a full wipe of the hard drive, or what we used to call a "zeroize" at the company I used to work for. We were putting defense systems in military crafts, and one of the requirements was that the pilot needed to have a button to wipe all the data in the system, to prevent classified data from falling in to the enemy's hands. (Yes, that information is public.)

The Department of Defense has pretty high standards for data wiping, and there are a number of tools that meet their standards. The problem is most of these tools cost money. The one that I recommend is a free tool called Darik's Boot and Nuke (available for download at www.dban.org). Despite the informal name, it is a legitimate program (referenced by CNN and the BBC). There are commercial tools that do this sort of thing as well, but the major difference is not function, it is speed (DBAN has a reputation for being slow - the BBC article says it took two hours for an 80GB drive). DBAN is cool because it gives you a CD to boot off of, and you select the depth of the wipe you want. The more depth you want, the longer it will take to run. If you are going to do this, I would recommend choosing the most in-depth wipe, doing it before you go to bed (as a home user) or before you leave work in the evening (at work), and just letting it run overnight. That way, there is no time wasted waiting for wipe to be completed. In a professional environment, having a DBAN CD around is not a bad thing, especially so your company does not end up in violation with the standards that govern your industry (Sarbanes-Oxley, HIPAA, FACTA, etc.).

A larger company may want to invest in faster, packaged software for this, or a hard drive sanitizer (such as this one - though I am certain their claim of 7 minutes per drive is for the simple wipe and not the seven-pass version).

Any of these options are better than the ol' sledgehammer method, because who wants to clean up that mess?

Saturday, November 13, 2010

Keeping up with the Jobses

There's a saying "Keeping up with the Joneses" which goes back to the early 1900's (thanks Wikipedia). It basically has to do with people needing to keep up with the neighbors (in this case, the generic Joneses). I feel like Microsoft has this same symptom at points.

According to recent numbers, Microsoft Windows Mobile was only on 2.8% of cell phones, according to Gartner Research. Compare this with 36.6% for the open-source Symbian OS, 25.5% for the Android OS, 16.7% for iPhone OS, and 14.8% for the Blackberry OS. In other words, Microsoft Windows Mobile just is not cutting it.

Since Microsoft needs to keep up with the Jobses (Steve Jobs is often considered the Face of Apple), Microsoft released Windows Phone 7 last month. Microsoft basically redesigned the operating system, because as we see it wasn't working. According to USA Today, the first phone to run this OS is the Samsung Focus through AT&T, which was released on November 8.

According to cNet reviews, Microsoft does seem to have done a nice job on the operating system, but as they point out, it is an uphill battle to overtake some of the companies above them on the list. One interesting feature that jumped out from the review (since I haven't used it myself yet) was the integration with Xbox Live. That could be something that sets this phone apart, if it gives people access to their games and accounts in a mobile fashion.

We'll see how it shakes out, but Microsoft does have a long way to go.

Thanks to Kevin for the heads-up!

Wednesday, September 29, 2010

Census and computing

The US census brings to mind one of the reasons computers advanced.

The 1880 census took 8 years to tabulate. Of course, the census is done every 10 years, so a long wait for results makes this data almost useless. The fear was that the 1890 census would take more than 10 years to tabulate, which of course makes no sense.

Enter Herman Hollerith and his fabulous mustache. He invented a tabulating machine that helped with this purpose. This tabulating machine allowed them to count survey results in one year. Of course, many early computers used punch cards, so this was one of the forefathers of those computers. I did not know (until I read a little bit of the Wikipedia article) that his company was one of the companies that would merge to form IBM in 1924. Thanks, Wikipedia!

Anyway, the 2010 census results are being tabulated, and you can already see the response rates posted for all towns. Making things more interesting is the use of data mining. We can now use the computers to not only count results, but to do projections, spot trends, and all sorts of stuff that would have been impossible 100 years ago. It looks like President Obama will get the first report by December 31, 2010. Considering surveys were sent out in March and data collection ended in July, that's really amazing turn around time. Now, if everyone just did the data entry on the computer, imagine how quickly it would go!

Anyway, here's the site with the response rates:
http://2010.census.gov/2010census/take10map/

Tuesday, September 21, 2010

Using Google Earth to make $75,000

Just another case of learning from my students...

In class today, we were discussing Google services, including the advanced Google search options, image search, and Google Maps. It came out during class that the town of Riverhead, NY used Google Earth in a very interesting way. People started getting summonses for having illegal pools, and it came out that they were using Google Earth to find this out. Really! Turns out they wrote about $75,000 worth of summonses before people caught on and complained.

NPR did an interview with the chief building inspector of the town, and he said they did it for the protection of the neighborhoods, saying "I use it strictly for safety." Of course, there is some validity there, because as he states, there are requirements to make sure children don't drown, and I agree with that. I also think that, well $75,000 had something to do with it. I'm a little cynical when someone won't admit to that. Of course money making is part of it. It's not just about safety.

In the "DUH" statement of the year, he stated "Most of the people that complained were the ones that didn't have the permits." Of course those are the people that complained, because they were the ones who were directly affected and may or may not have had their right to privacy violated.

The town is no longer doing this, so I think that tells us how they feel about whether it was a good decision. If they thought it was, they would have kept on doing it. My opinion? As someone who worked for a company doing government contracting, we were told that the government could not spy on its own citizens. The government tried to implement domestic spy-satellite imaging through the innocuous-sounding National Applications Office, but this idea was withdrawn over privacy concerns. If the government can't do it using our own satellites, why can they do it using Google's? Again, my opinion, they shouldn't be doing that, but that's me.

The other interesting part is Google. This sort of use of Google Earth is not prohibited, either in the main terms of service or the government agency terms of service addendum. Yes, I checked. In theory, this is fine per Google's viewpoint. Then again, they haven't updated the terms of service in a while.

Thursday, September 09, 2010

Zero-Day exploits

I have pretty tight security on my home system. I have my anti-virus, my anti-spyware, and router with built in firewall. I keep my operating system and anti-virus up-to-date. I feel pretty safe on a day-to-day basis. I sometimes forget that this is not true. We are all vulnerable to "zero-day exploits". These are basically newly discovered ways for you to get a virus (or get hacked, etc) even if your virus scanner and operating system are 100% up-to-date. This is the part of computer security that people don't always understand. Anti-virus programs, anti-spyware programs, the operating system, and things like that all get updated AFTER problems happen, so someone needs to be the first group of people to get this virus. Unfortunately, fixes are often reactive (oh, no, we didn't think of that!) rather than proactive (hmm, how would I exploit this system if I were a hacker?).

Yesterday, Adobe (the company that makes Acrobat and Flash, among other tools) released a statement saying there was a vulnerability in even the latest version of Adobe Reader. This is a free tool most people have installed that reads read-only versions of documents. Sounds pretty innocuous, right? Well, there is an exploit that allows this to beat security. If I were to download a file, my firewall, anti-virus, anti-spyware, and operating system would all be beaten by this exploit.

What helps is avoiding high-risk activities online. File sharing networks and torrents obviously present advantages in the form of free stuff, but even if you have all the protection I mentioned before, you are subject to zero-day exploits. This one is an exploit with Adobe Reader, but it could happen in iTunes, or in Windows Media Player, or Internet Explorer, or Firefox, or any other software package. It can also happen when people download software through these networks and actually run a program on their machine. Just remember that despite the updated anti-virus, you are vulnerable. This doesn't even take in to account the folks who have anti-virus software that they don't subscribe to and don't receive updates to.

(For those of you who understand digital signatures, this is a very clever exploit that seems to take advantage of stolen certificates. Who knows, maybe the hackers used a zero-day exploit to steal the certificates!)

Wednesday, July 28, 2010

Workshops, and the role of computer training

I just finished a series of workshops with the group I work with at Montclair (PRISM) in conjunction with PCCC. It was very interesting to be working on a joint effort with these groups. I have been working for the PRISM project (and it's previous incarnation, CETERMS) since the summer after my sophomore year. They are a grant funded project that provides teachers with training in the math/science areas. It is actually the place I got my start teaching. Someone was scheduled to do a technology workshop and called out sick. I had been assisting the workshop coordinator, so I knew the workshop, and I gave the workshop that day. I've been doing technology training for them ever since. I've done Internet concepts (and for 1999, that was pretty forward thinking!), PowerPoint, data analysis with Excel...and a few more workshops. I also used to do their Web site (coding the Web pages by hand, instead of with a tool like Dreamweaver). Who knew I would turn out to be good at teaching and would turn it in to my career? I certainly did not, and I don't think the woman who runs the program foresaw this either.

Anyway, this summer presented a very interesting challenge. The theme that was chosen for PCCC and PRISM to work together was Forensic Science. I didn't really see any way I fit in to this, but eventually as I worked to liaise between the two groups, I noticed they had fingerprinting database software. Basically, it would be able to look up people's fingerprints and match them to a local criminal database that you create. It's not FBI, but it's good enough for training and small police forces. When I suggested including that, I was told that they did not have anyone qualified to teach it, and that people were waiting to go to training for the software.

The beauty of studying computers is that once you have a feel for computer interfaces, new technologies are easier to learn. I sat down in front of this program (by a company named Sirchie called ComparaPrint- though oddly enough, I can't find it on their Web site so I can link) and picked it up very quickly, and I have never seen a program quite like this one. I managed to learn how to use the software very quickly because I understand the concepts of databases. This software is basically a big database package, and since I understand databases, all the natural operations (adding a record, performing a query, generating a report) came pretty naturally. Likewise, back in my undergraduate days, I remember teaching myself a programming language called Perl by doing what we called "hacking around". I just sat down, played with the language, and learned the key things in one night. That was easy for me since I learned programming concepts at Montclair (as opposed to receiving training in a specific programming language). Montclair did an excellent job of using the programming language as a vehicle to teach programming concepts.

In most college programs, there is a mix of theoretical concepts and facts, and the general feeling I get is that if you teach students how to learn about their field, it will treat them well going forward. It reminds me of the old saying "give a man a fish, and you will satisfy his hunger...but teach a man to fish, they will eat for a lifetime". Most careers require evolution, and computers perhaps more so, so this is why I do not think it is critical if my students remember what tab the spell check button is on. My personal opinion is that Information Technology should not be a degree where you simply learn where to click around, but a career where you learn how to learn new technologies. This is why, even though I teach software in my application software training classes, I do tend to ask some short answer questions about how the tool can be used.

I had a lot of fun, and I do not think that many people (some of whom may be reading this now, since I did give out this blog address) realized exactly how short of a time I was using that tool.

Sunday, June 13, 2010

Times Square Bomber and Computer Forensics

Most people think just because it is a free email address with no billing address, they are safe, but there are many ways they can be tracked.  Take for example the suspect in the Times Square bombing.  Technology helped lead to his arrest.   The car that was used was apparently purchased in cash after an ad on Craigslist. The guy was apparently somewhat clever in covering his tracks, according to reports. He switched license plates at a place where it was unlikely to be noticed (a garage - when was the last time you checked to see if your license plates are really yours anyway?).  He also attempted to remove the vehicle identification number.  Unfortunately, it is found in a number of places in most vehicles, and the suspect missed a few locations.

So, how did Craigslist play a role? The seller apparently got an email from the buyer, who paid in cash. With that email, authorities can determine what IP address that email was sent from.  With that IP address, it's an easy matter to determine who the Internet Service Provider of the sender was, and you can subpoena that ISP to get the name of the customer.

If that was a dead end, they could also trace the email address.  Let's say the guy signed up for a free Hotmail account.  He signed up from some computer somewhere, so law enforcement could subpoena Hotmail to find out what computers accessed that email account, and follow the trail as mentioned above.

Now, this guy was either sloppy or just did not think they would catch up to him quick enough for things to matter, because there were a number of ways he could have obscured his identity better.

First of all, he should have created this email address from a public computer, and only accessed it from a public computer.  Either that, or he should have "borrowed" someone's wireless Internet connection, because then the trail would lead back to them.  He could have driven around and found one easily (and this is part of the reason not setting up security on your wireless Internet can be a very bad thing).

Secondly, he should have made sure there were no cameras that could help aid in his identification, regardless of the method.  A nice, unsecured location could be helpful, and scouting is important.

Thirdly, he should have made sure to pay in cash (if this were a cybercafe), use a fake ID (in a library), or used a program to try to hide his computer's network card address (if he used someone else's Internet connection).  Each network card manufactured has a unique identifier, so if he connected to my router, I could browse my logs and find out the network card address (known as a MAC address).  Law enforcement could subpoena the manufacturer to get the name of the buyer.  If he was smart, he would have paid cash for a cheap network card (and bypassed the built-in wireless found in most laptops) and used a throwaway one.  Again, if it was purchased recently, store cameras could be used to track suspects.

Finally, he should have used some program to anonymize his Internet usage and/or mask his IP address.

I do not know the specifics of what he did or did not do right, but electronic communication is not difficult to track with a little technical knowledge and the power of a court order.

Link to Story

Thursday, May 27, 2010

Your lawmakers and technology laws

In my CIS 152 (Internet/E-Commerce Technologies) course, we discuss some of the reasons technology is ahead of the laws.  I usually then bring up a picture of Frank Lautenberg (an 86 year old Senator from Paterson) and half jokingly asking if the class thinks this guy even knows how to check his email, let alone write laws on technology.  (And yes, I am sure he has a staffer who does the work for him)

I do know there are many committees and subcommittees who specialize in certain areas, but part of the problem is the representation we have.  A government should really represent the people they represent - in demographics, education, race, occupation, etc.  However, if you look at the numbers (scroll down to "Education" or "Occupations"), you will see that over 50% of the Senate have law degrees (57/100), while only 1 of 100 has nothing beyond a high school diploma.  None have associate's degrees.  Yes, this means 99/100 Senators have at least a bachelor's degree.  Now, I understand that you do need a level of savvy to do things politically, but it is one thing to study groups you don't know, and another thing to actually be one of those people and try to be an advocate for them.

In addition, if you look under the occupations, you will see there are (as far as I can tell) no Senators and only one Representative with a degree in Computer Science (Steve Scalise from Louisiana).  Meanwhile, there are 24 members of Congress who are medical professionals.  Of course, one does not need a degree in Computer Science to understand technology, but if you are not using the technology on a daily basis as an everyday person is, you can't truly understand the challenges the way the everyday user does. 

If I needed any more proof in my mind, the article below confirmed what I thought.  In this Washington Post article, it says that a number of Congresspersons do not even know how to use an ATM, or do not use them frequently.  This is information culled from public statements, and I am sure there are many more who, if they answered honestly, would say they also do not use ATMs.  Therefore, when reform comes across the Congressional floor regarding ATM fee reform, they do not truly understand the problem (in this case, large ATM fees) as someone who pays large ATM fees does.

So, if Congresspersons do not have a deep understanding of ATMs (which I take for granted as a pretty simple technology), imagine when someone tries to explain phishing to them...or the challenges of wardriving....or why spyware should be restricted.

I am sure they have some staff members who can inform them about these things, but it is very different when a Congressperson has first hand understanding of an issue and a passion to fix it...and another thing when a staffer gives them information on a topic.

And this, ladies and gentlemen, is part of the reason why technology laws are so far behind the technology.