Saturday, June 30, 2007

Gadget of the Week #12

My latest gadget is my new Dell Latitude D830. This replaces my older Dell Precision M70 and includes all the available bells and whistles. 2.4GHz Intel Core 2 Duo processor, 160GB 7200RPM drive, 4GB memory, 802-11a, g, and *n*, thumbprint reader, TPM, theoretically long battery power, and, of course, Windows Vista Ultimate. It is also thinner and lighter than my former laptop (and the Dell latitude D810's we have here).

The battery life is nowhere near the claimed "up to 9 hours" (which I didn't expect it to be, given how I use the system), but it does last about twice as long as my former laptop with the same relative workload -- about 5 hours now, easily going the entire cross-country flight either direction which I tested last week. With the old laptop I had to bring along a spare battery and used them both up pretty well on the same trips (or I brought a power adaptor).

This is a screamer of a system. About the only thing I can say negative about it is that it only came with the integrated graphics card (they did not offer an option for an enhanced graphics card at the time I ordered -- they do now, but there doesn't seem to be an option to add it to an existing system).

So far Microsoft Vista has been OK. There are some things I like (recent places). There are some things that I miss from Windows XP (hardware profiles being one of them). I'll make a separate report later on Vista as I get more used to it and figure out the tricks.

One other note of interest: While the system does have 4GB of memory installed, the fact that I am running a 32 bit operating system (Vista) which can only address a total of 4GB and has memory reserved for hardware i/o mapping (and some shared memory for the graphics card), the net amount of memory I have is around 3.4GB. Much lower than I thought. I'm thinking about making the jump to a 64 bit OS next time.

I did come like this close (picture me with my thumb and index finger almost touching) to jumping on the Macbook Pro bandwagon this time. I just couldn't give up the 1900x1200 display and the availability of real docking stations. Perhaps next time.

As part of this upgrade, I have done my part for the tech economy, choosing to buy/install upgraded versions of most of my like 5 billion utilities that I use. I guess Microsoft does cut a wide economic swath within the tech industry.

This is the first system upgrade in more than 2 years for me and it was worth it. I've been looking for a while and waited for Intel's Santa Rosa platform to become available.

Tags : / / / / / / / / /

Monday, June 25, 2007

You know you're an addict when....

Back in February, I wrote about getting hooked up with Where's George after finding a dollar bill in my change with some strange markings on it.

I quickly went out and got my stamps and started marking some bills.

Well, 4 months later (today), I am totally hooked on it. So far I have:

  • entered 727 bills worth a total of $5,177 (many of them are $1s).
  • gotten 44 hits on my bills, most of them coming in the last month or so (seems you need to build a certain amount of inertia before the hits start rolling in)
  • achieved a "George Score" of 637.36, placing me above the 85th percentile of Where's George users!!!!!
  • joined Friends of George where I get to pay extra money for the joy of entering my bills and tracking them :-).
  • started paying cash for many transactions that I had been paying with credit cards (so I can mark more bills and cause money to flow).
  • learned that it is better to mark small bills ($10s, $5s, and $1s) as they circulate alot more than $20s, $50s, and $100s which frequently just go to the bank awaiting a future withdrawal.
  • learned that it is better to get a stamp that needs little to no alignment (rather than the nice circular stamp I bought that goes around the treasury seal and must be aligned somewhat carefully -- taking way too much time when trying to stamp a stack of 100 or 200 $1s).

The real signs of my addiction:

  • The anticipation that I have when checking emails looking for hits.
  • The groans that I hear from my "friends" when I pull out my wad of marked bills trying to exchange them for unmarked bills in their pockets.

In any case, I still find it lots of fun and my friends seem to be mostly amused with my addiction. If you're interested, go get a stamp and enjoy marking your bills!

Tags : /

Sunday, June 24, 2007

Perhaps not so much Bashing...

Kim responds to my note about SAML Bashing:

...which is, by the way, absolutely NOT my intent. I’m simply trying to understand how SAML relates to linkability, as I am doing for all the other major identity technologies. I can’t take up all the points he raises, but encourage the reader to look at his piece…

Perhaps I reacted too negatively, but the analogy of some unknown clerk reaching into my pocket really irked me as that clearly isn't what happens and it appears to be written to instill unreasonable fear in an implementation of a browser-based SSO protocol.

I’m not criticizing or discussing the profile for an Enabled Client/Proxy. I was talking about SAML as we know it - in the mode which has been widely deployed in portals all over the world.

I think such analysis should be based upon the capabilities of the protocol and not about what some deployments have chosen to do within their environment (where they clearly felt that browser-based SSO meets their needs (and in many cases is mandated by the deployment scenario).

I think Conor is misunderstanding my intentions. I agree that with a completely trustworthy Identity Provider following best practices for end user privacy, Conor’s b) and c) above would apply. But we are looking at linkability precisely to judge the threats in the case that parties to identity transactions are NOT completely trustworthy (or are attacked in ways that undermine their trustworthiness.) So arguing that the identity provider will behave properly has nothing to do with what I am exploring: risk. I’ll try to build Conor’s concerns into my ongoing discussion.

I'm sure there's some misunderstanding here. I normally find that I agree with most of what Kim has to say and really respect his opinions.

As far as the trustworthiness is concerned, there's nothing that is completely trustworthy, not even if I make the decisions myself and hand-code the response messages from the keyboard (I'm sure that I will make mistakes of judgment and or typos).

I would ad that the same "attacked in ways that undermine their trustworthiness" applies to client implementations that try to enhance privacy protection. They too are subject to being attacked. Nothing is totally foolproof and I'm not sure which has more likelihood of successful attack, a service maintained under contractual agreements or open software systems in the hands of end user.

I certainly have chosen to put my money in a bank rather than store it under my mattress. Yes, the bank is more likely a target for a robbery, but they are legally obligated to maintain my funds, even if they are robbed. Similar decisions will be made by many people in the identity space (and yes, some out there will always keep their funds in their mattress).

Tags : / / / /

SAML Bashing

Kim writes about SAML's use of redirection protocols.. To start with, he forgets to mention a few important facts as part of his discussion:

  • SAML defines a profile for an Enabled Client/Proxy (ECP) which is an evolution of the Liberty Alliance's LECP protocol. This protocol does *NOT* involve redirection, but instead supports an intelligent client directed by the user driving SSO transactions (a similar model to that adopted by Cardspace).
  • The Browser-Profile that Kim is referring to is one written based upon a use case requirement that the profile work out-of-the-box on unmodified browsers. There is NO other possible solution that will work in this scenario that will protect the users credentials at the IdP.

That said, there are still several statements in Kim's analysis that I feel obligated to respond to. These include:

Note that all of this can occur without the user being aware that anything has happened or having to take any action. For example, the user might have a cookie that identifies her to her identity provider. Then if she is sent through steps 2) to 4), she will likely see nothing but a little flicker in her status bar as different addresses flash by. (This is why I often compare redirection to a world where, when you enter a store to buy something, the sales clerk reaches into your pocket, pulls out your wallet and debits your credit card without you knowing what is going on. (”Trust us.”)

First off, the user only see's nothing if a) they are already authenticated by the IdP, b) they have previously established a federation with the relying party, and c) they have told the IdP that they don't want to be notified when an SSO with this party takes place. I, for one, want things to work this way for me with providers that I trust (and yes, I do trust some providers). The inability to do this type of automatic operation is one of the shortcomings in Cardspace's implementation that I think will eventually be fixed. There is no need to have repeated confirmations of operations that I say may occur without my unnecessary participation.

Secondly, the analogy is way off base, trying to make this seem like I'm bing pick-pocketed by someone I don't know which Kim knows is absolutely not the case. A more proper analogy would be something along the lines of "I give one of my providers permission to reach into my bank account and withdraw money to pay my bill". I do this all the with providers I trust, such as my electric company, my telephone company (both wired and wireless) and may other companies.

So, returning to the axes for linkability that we set up in Evolving Technology for Better Privacy, we see that from an identity point of view, the identity provider “sees all” - without the requirement for any collusion. Knowing each other’s identity, the relying party and the identity provider can, in the absence of appropriate policy and suitable auditing, exchange any information they want, either through the redirection channel, or through a “back channel” that dispenses with the user and her browser altogether.

The IdP does not "see all". The IdP only sees that you have visited a particular relying party. It does not see what you do at the relying party. Knowing that I visited Amazon, is not the same thing as knowing what I looked at and/or purchased at Amazon.

Secondly, my choice of an IdP (as with most others) would be made based upon the appropriate policies and auditing capabilities at that IdP (just like I don't choose to use Johnny down the block as my bank, I choose a reputable firm and just as I would require the exact same policies and auditing in any client that I chose to use to act as my identity selector (yes, I have to *trust* Cardspace's or Credentica's implementation of policies just as I have to trust an IdP's).

In fact all versions of SAML include an “artifact” binding intended to facilitate this. The intention of this mechanism is that only a “handle” need be exchanged through the browser redirection channel, with the assumption that the IP and RP can then hook up and use the handle to “collaborate” about the user without her participation.

That isn't the intention at all. The intention, as Kim surely knows, is to pass a message by reference rather than by value. For the non-programmers in the audience, this means that I have a message that I need to send to the relying party (in this case that message contains an assertion, which can be big and complex and which has additional security requirements if passed through someone else's hands -- yes, the user can count as someone else). Instead off sending the token to the client to have the client then send it up to the relying party, I can send a small artifact that the relying party then presents to the IdP to get the token. The protocols explicitly define what the artifact is exchanged for -- it was never intended as, nor can it be used within the protocol definitions, as a general collaboration handle.

In many enterprise implementations, the artifact is used to allow the IdP to issue assertions to the Relying Party that don't need to be signed by the IdP. Clearly that isn't something I could do if the assertion was sent to the client (otherwise we'd be talking about how I took the token and edited it say I was Bill Gates when I sent it to his bank).

In considering the use cases for which SAML was designed, it is important to remember that redirection was not originally designed to put the “user at the center”, but rather was “intended for cases in which the SAML requester and responder need to communicate using an HTTP user agent… for example, if the communicating parties do not share a direct path of communication.” In other words, an IP/RP collaboration use case.

All SSO use cases (where one party authenticates a user and asserts an identity for that user at a relying party), redirection or not, would then be, by Kim's definition, an IdP/RP collaboration since the RP (Relying Party) is relying on the identity presented by the IdP. This has nothing to do with redirection or user involvement, or SAML in particular.

As Paul Masden reminded us in a recent comment, SAML 2.0 introduced a new element called RelayState that provides another means for synchronizing or exchanging information between the identity provider and the relying party; again, this demonstrates the great amount of trust a user must place in a SAML identity provider.

No. RelayState is designed for the RP to send information to itself, not the IdP, so that it can remember what the user was trying to access when the user is returned to the RP following a successful SSO operation. This is primarily used in the case where the RP is unable to set a cookie in the user's browser to remember that information. SAML even points out that as little as possible data should be included in the RelayState.

Paul's point in his comment was that if an RP used this incorrectly, they could leak information. The SAML specs contain exactly this caution.

I don't claim to say that SAML is the end-all for every use case. I do believe that we need to support multiple methods, some of which have different privacy implications. I also don't want some privacy weenies making life intolerable by the need for a confirmation of every thing that I already said it was OK to do. I do trust some of the parties that I interact with and want to be able to automate as much as I feel comfortable doing. I have no problem with the privacy weenie that wants to turn on the "let me approve everything" -- just don't force me to live that way as well.

Tags : / / / /

Saturday, June 23, 2007

You know you're late when...

Earlier this week, a computer glitch in United's sysytem caused hundreds of flights to be delayed or canceled. As my luck would have it, I was caught up in the delays. My flight was one of the last flights from San Francisco to Portland and was supposed to arrive at 11:59 that night. The arrival was delayed until around 2:15 AM and I didn't arrive at my hotel until after 3AM.

This was made worse by the fact that the previous night, my flight from Dulles to San Francisco was delayed by close to 3 1/2 hours by thunderstorms in the Dulles area (causing that 5 hour flight to be 8 1/2 hours as they didn't start the ground hold until we were already loaded onto the plane). Luckily, it was an internationally configured 777 and I had upgraded into business class, so at least it was comfortable.

I really knew I was late getting to my room at the hotel when I found that my USA Today for the next day was already delivered to the room.

Tags : / / / / / /

Wednesday, June 20, 2007

Updated Liberty Open Source

I've updated my Liberty ID-WSF Open Source implementation for both the server side and client side to include support for much of the the Advanced Client Provisioning Service specification.

The Advanced Client Technologies Overview is a good starting point for understanding what we're trying to do with the advanced client specs.

This release also includes some updates/fixes in the basis ID-WSF support.

Have fun!

Tags : / / / / / /

Tuesday, June 19, 2007

Concordia Schmordia

Next week, I will sit on a panel with Mike Jones of Microsoft and David Recordon of VeriSign. This panel will be a part of day spent on the subject of the Concordia Project.

One might ask, "What's Concordia?" and I, of course, would respond that that's a good question. My recollection (questionable, I know) of the sequence of how we got to where we are is as follows: The name originated in an earlier internal project at the Liberty Alliance where a number of us were examining potential paths towards convergence with the other technologies/protocols in the identity and web services space. Eve Maler can be blamed for the name as she brought it up given that Concordia was the Roman goddess of agreement, understanding, and marital harmony (not that any of us were getting married to each other) -- which, theoretically, is what convergence is about.

Anyway, as we moved forward on the project we eventually figured out that doing this ourselves would likely be a waste of time (why would anyone else listen to us). If we really wanted to talk about convergence we needed to bring the other players to the table. That led to more deep thinking (and perhaps a few visits to the neighborhood psychologist) and the eventual realization that many of the differences in the current approaches had to do with different use cases and with looking at the problem from different points of view.

So, here we are. Trying to organize an effort to bring together people interested in this space so that we can discuss our respective use cases and understand the problems that need to be solved. Liberty has tried to be very careful and very clear that this isn't a Liberty effort, but an industry effort (which Liberty supports). My hope is that we can use this common understanding to drive towards common protocols, features and capabilities so that those trying to use our stuff will have an easier time integrating with the rest of the world.

So come join us for the Concordia day at the Burton Catalyst Conference. At the minimum, it should be fun (though without Dick Hardt on the panel, I won't have someone to pick on :-)). The Concordia sessions are free, you just need to register here.

I look forward to seeing you all there!

Tags : / / / / / /

Monday, June 18, 2007

Business traveler Magazine

Partly from some of my writings here about my frequent trips on United, I was interviewed for this article in Business Traveler Magazine. Of course, the picture in the article was not a picture of me -- I think it might be Britta, there's some resemblance or, perhaps, that's just wishful thinking :-).

I should also point out that I wasn't the one to find the article. My sister, Theresa, was looking for our family web page (where I put up family photos) on google and she found the article and told me about it. Yes, I knew it might be coming at some point, but wasn't aware it was published. Now if I could only get a print copy to hang onto :-).

Tags : / / /

Annual Credit Reports

Not sure what brought this up now, but for some reason I thought to go get the "free" annual credit reports that we are entitled to here in the US at least once every year. I started with AnnualCreditReport.com (the central clearing house setup by the 3 major credit reporting agencies) which asked me for the standard credit information (name, ssan, address, dob, etc.).

Once I entered that information they prompted me to select which of the 3 agencies I would like to review the report at (yes, you can select multiple). I selected all 3, but now, after thinking about it, perhaps I should have selected one only and rotated around the 3 agences throughout the year -- that way I can get a new checkup every 4 months rather than only one per year -- Oh well).

The web site then forwards you to each of the agencies where you will go through a different process at each of them to further verify your identity and get access to your credit report. My experience at each of them:

  • The first agency I was sent to was TransUnion where I had to create an account in order to get my report. I was then prompted for 2 account numbers (which I had to go find) and then the tried to upsell me a copy of my credit score for $7.95 before they would let me see my credit report. When I was done, the process had taken so $#@%ing long that my session at AnnualCreditReport.com had expired and I had to start all over for the remaining two agencies.
  • On to Equifax, where they wanted to know which provider I opened an account with in 2005 and what was the payment (much easier to deal with), then they too wanted to upsell me my credit score for $7.95. No need to create an account. Got my report and printed it.
  • And, finally, Experian ((the last of the 3). This time, I went back to AnnualCreditReport.com fairly quickly, so no need to re-enter all of my information. Experian started with verification of my ssan (last 4 digits), then they asked for verification of 2 accounts (who gave me a mortgage at a particular time and who gave me an auto loan at a different particular time) as well as the name of the county in which I live. Poof. I got to see my credit report. No need to create an account, no attempt to upsell me with the credit score (at least not as an intrusive click-through step -- it may have been there somewhere else on the page that I just ignored).

Moral of the story.... be tenacious and make them give you a copy of your report -- it IS free (as long as you don't fall for the upsell). Unless you think you have been a victim of identity theft, I would stagger the reports from each agency as many of them carry the same information as the others and this kind of gives you better coverage over the year (there's a lot someone can do in the 12 months between your annual reviews if you do all 3 at the same time).

Tags : / / / / / /

Monday, June 04, 2007

The Combo

Paul must be getting a little hard up for cash nowadays as he seems to be out moonlighting.

Tuesday, May 08, 2007

Dick and Conor

Today, at the European Identity Conference, Dick Hardt and I (as well as several others) participated in a panel on user centric identity in the enterprise. As I had suspected it was a fun session with lots of back and forth and a very interested audience.

What amazed most people who know us was that we actually agreed on several issues and Dick was quoted at least twice as saying something along the lines of "As amazing as it seems, I agree with Conor on this" and we even shook hands once (luckily no one in the audience had their camera ready for the historic moment).

The kinds of things we agreed on included:

  • Users should be able to control the use and dissemination of their data.
  • Users should be able to allow an agent (local or perhaps in the cloud) that can interact on their behalf in between authoritative issuers of attributes and relying parties.
  • Users should be able to allow direct access from some relying parties to some issuing authorities (specific example discussed was around someone accessing my calendar service to add an appointment).
  • Strong authentication is separate and distinct from strong identification.

We only had an hour on the panel and could have easily gone on for another hour or two with a very participatory audience.

Tags : / / / /

Thursday, May 03, 2007

April... an unusually quiet month...

I just noticed that last month, I only wrote 6 blog entries (Paul frequently hits that number in a day)... My slowest month in a long time.

This wasn't about a lack of things to write about -- there's more than enough stuff going on out there that is clearly calling out for my essential input :-). My lack of posting has been because my free time (what little there is) has been taken up by the updating of my Open Source Liberty ID-WSF implementation to have some of the functionality documented in the new Advanced Client specifications.

No, it isn't done yet, but I just had to take a breather and do something fun like post a blog article about not blogging. I'm sure Paul will find some higher meaning in my doing so :-).

But, no worries, the interoperability event is scheduled for the first week of June in Dulles, Virginia (yeah, that's a real place, not just an airport -- although the airport was first). I should have my head above water by then.

In the meantime, I'm off to Munich to participate in the European Identity Conference hosted by Kuppinger Cole. I'll be in 3 sessions there:

It should be a fun week! I hope to see many friends there.

Tags : / / / / / / / / / / /

Anonymous identity

Paul writes in "Identity as Relationship Precursor":

This is interesting because it seems the exact opposite of most use cases in which identity attributes are shared (and those that Liberty ID-WSF has historically focused on). In these use cases, interaction comes first. The user shows up at a service provider and, in order to provide some enhanced level of customization, the service provider seeks to obtain identity. The model is

Interaction --------------> Identity Sharing

I'll argue that current identity systems (OpenID to a lesser extent, albeit not spec'd out) are geared to the latter model, what are the implications of the former?

Au contraire Monsieur Madsoooooon, we considered the both use cases and specifically designed the anonymous release of attributes around the case where the user gave away some bits of information in order to get a better experience at a target entity without giving away their identity nor creating a federation to their identity (which they could, of course, do later if desired).

The common discussion around anonymous identity was, for example, releasing your zip code out of your personal profile to anybody so that when you showed up at a movie web site, they could automatically display the movies that are showing in theaters in your area.

Tags : / / /

Monday, April 23, 2007

A knife... a real knife... like the metal kind

Last night, on my United flight from Dulles to Portland, with the 1st class dinner, I was given the typical cloth napkin with the cutlery rolled up inside. When I unrolled it, I found the normal 2 metal forks and a metal spool as usual. However, instead of getting the little silver plastic knife that I've gotten since 9/11, I was given a real, metal knife (pictured, quite badly, to the left).

I looked to the left and right to see if the other passengers were also getting a metal knife -- they were, so it wasn't some accidental fluke.

I presume the FAA has removed the restriction on metal knives -- something long past due as they airlines have had bulletproof (not just knife-proof) doors on the cockpit.

Tags : / /

Saturday, April 21, 2007

When is a rebate not a rebate?

When I purchased my cool Samsung Blackjack phone, Cingular had a rebate program in place offering a $100 rebate if you bought the phone and signed up for the data package.

I took them up on the offer, followed all the directions and sent in my rebate form the next day. This is the step that the cynical Conor (me) believes they hope you won't do (so they get the benefit of offering the rebate without having to give you the cash -- and it's your fault since you didn't follow through). Of course, being the pedantic person that I am, I *always* fill in the form and send it in just to make sure they pay up.

Well, today -- approx 6 weeks later, I receive the "the rebate". I was expecting to receive a check like any other rebate program that I've ever participated in. A check that I could exchange for cash at my local bank, or just deposit into my account.

However, that wasn't to be. Cingular sent me a "Rewards Card". This is a Visa debit card that supposedly carries the value of my rebate.

Perhaps I'm over-reacting, but I'm not at all happy with this. In fact, I'm downright pissed. This is some form of bait-and-switch that should be illegal. When you offer a rebate to your customer, you should provide them with a CASH rebate, not a debit account that they somehow have to figure out how to use.

For the smart ones out there who were thinking, just use the card to get cash -- no dice. I thought the same thing, but alas the rules include:

Your card is valid only in the U.S. and may not be used for cash withdrawals or at any cash dispensing machine.

It's even invalid at the gas pump. If you want to use it to pay for gas, you have to go inside the station and wait in line.

And, of course, it expires in a relatively short period of time.

What are the problems with this debit card model?

  • Cingular hopes that this is another deterrent for the user getting the full value of the rebate. At the minimum, it will slow down the transfer to cash to the user as the user finds ways to make use of the debit card until it is used up.
  • Most facilities are not setup to allow you to mix multiple payment methods, especially online merchants. This means that to get the full value, you have to find a collection of things that add up to the exact amount of $$ on the card (the card even prohibits you from adding $$ to increase it's value up to a value you would want to spend.
  • Cingular hopes that nobody will be able to use up the exact amount ($100 in my case) and so they will profit from the remaining cents left on the card. The only way to totally use it up is to find a friendly merchant who will let you use multiple cards on the same purchase).
  • I'm sure there's some slice of the transaction fee paid by the merchant that somehow makes it into Cingular's pocket (yes, cynical Conor strikes again).

In fact, as I was writing this blog entry, I went to Amazon to try to use up the entire value of the card right away. However, I ran into that "single card" problem for a purchase (so my $100.75 purchase wouldn't work as it was 75 cents over the value of the card). I ended up spending $92.86 of it (just couldn't find something worthwhile to purchase for $7.14 and so I have to remember the card and the amount so that if I do end up making a purchase again, I can use up the rest of it... Perhaps some candy at the local grocery store).

Can you tell that I really hate the idea of this bait-and-switch reward card vs getting the rebate check? Cingular you should listen up -- this is the kind of thing that Elliot Spitzer likes to go after.

Tags : / / / / / /

Thursday, April 19, 2007

Gadget of the week #11

I've finally upgraded my "old" Motorola Razr (which I had been pretty happy with) and found the first Windows Mobile based phone that I actually like. I've tried several other WM phones including the Motorola MPx200 and MPx220, as well as an iPAQ H6315, but my new phone puts them to shame.

So, what did I buy? The Samsung Blackjack.

It took me a while to decide on which phone... I've looked at a number of them over the past few months and decided on the Blackjack for several reasons including:

  • It's on my provider (Cingular) so I don't have to pay the premium for an unlocked phone without subsidy.
  • Its small and light, but still has a full qwerty keyboard (though my big fat thumbs are still getting used to it).
  • It has data push available for email so I can set it up to get email from work (haven't done so yet, but one of my compatriots at Intel has gotten this done).
  • It felt nice in my hands.
  • I got it for a good price!

I've been very happy with it since I bought it. It's worked pretty much anywhere I've tried even internationally (though there's an update for it that I've yet to load that is supposed to fix problems with some international access).

Of course, once I bought it I had to go and get the typical set of accessories. I started with a belt clip leather case. I bought the one from Cingular since I wanted one right away (though since it had a plastic clip, I knew it wouldn't last long) -- then when I got home ordered a good one. My case of choice for any device is the case made by Nutshell. They claim their cases are "tough as nuts" and they are. I've had several for different devices and they have never broken in any way -- meanwhile the Motorola case from Cingular broke within 4 days (the clip broke off). See the pics below for the case.

Of course, I had to get my Gadget-of-the-Week-#5 Gomadic power/sync tip:

Which works like a charm, of course.

My other modifications include:

  • A replacement home screen. I didn't like the options that I had built in, nor was I able to find any that I liked that I could download, so I bought a copy of Home Screen Designer 2.0 and made my own. You can see it pictured above (although pictures of the phone screen just don't seem to come out very well). If you like it and want to use it yourself, you can download it from here. I will not support it, I will not provide you with any form of help installing it, and I will not provide any form of renumeration if, when you install it, it causes your phone to go up in flames (in other words, you're on your own).
  • I installed a good Irish ringtone -- a midi rendition of "The Sally Gardens" (an Irish Reel).
  • I figured out (with the help of the web, but I can't find the link anymore) how to configure it to work as a data modem for my PC (and so far Cingular does not charge me for the data minutes). The one sad thing there is that I was unable to get it to work via bluetooth. I was only able to get it to work via the USB cable and I guess I can live with that. I've used it a few times with decent success.
  • I figured out (again with the help of the web) how to substantially lengthen the battery life at the cost of slower connectivity. I'm not sure if I'll keep it that way once I get email push enabled (if I do), but for now, my battery can last several days without a problem -- before this fix, even the extended battery was wearing down by the end of a day.

I'm very happy with the phone -- been using it for a month or so at this point and it's held up great. I'll probably try to install the upgrade at some point soon as I have a trip to Brussels scheduled for next week.

Tags : / / / / / / / / / / /

Wednesday, April 18, 2007

Bizarre Circumstances

Clearly the boy has missed his calling (or at least he can give up his day job anytime).

Tags : /

Tuesday, April 17, 2007

A useless process

A few weeks ago, Microsoft, IBM and a number of their closest friends started the Technical Committee (TC) creation process within OASIS for the WS-Federation specification. As has been typical with the submission of the various WS-* specs to OASIS and the W3C, they proposed a charter that was an extremely ratcheted down requirement to publish the input document as close as possible to its current state (and they've gotten better with the ratcheting with each subsequent submission).

So much for the cooperative standardization process

This time, what was somewhat different than many of the previous WS-* submissions is that the functionality proposed in WS-Federation has substantial overlap with an existing standard specification which was approved as a standard more than two years ago -- SAML 2.0.

OASIS's TC creation includes a comment period which, in this case, was used by a number of OASIS participants including the likes of Nokia, France Telecom, Sun, Fujitsu, Oracle, and Neustar.

Many of the comments questioned the overlap in functionality between the 2-years-ago-standardized SAML 2.0 and the proposal.

The response to this input is recorded here. If you want the cliff notes version all you need is:

No changes to the proposed WSFED TC charter are required.

The only winning comment was Frederick Hirsch's comment about spurious characters in the charter -- this resulted in an agreement to remove them from the final charter document.

So, while there is a comment period, the proposers for the TC don't have any obligation to accept, listen to, or even pay attention to any such comments. In the session in which the comments are discussed, only the proposers can provide input, the commenters can't argue their case, nor can they do anything to impact the outcome of the treatment of their comments, even if they are being totally ignored.

OASIS and its members would be better served by a process that has some useful purpose. Asking people to provide comments and input that can be out-of-hand totally ignored is wasting their time in putting the input together, wasting the proposers time in having to organize and participate in the review meeting where they can simply ignore all input, and wasting the rest of our time in un-beleivably reading the out-of-hand dismissal 31 separate times.

So the official call for participation has been released now. The WS-Federation TC is forming under what many view as a flawed charter and a flawed standards process. Perhaps the not-so-nice response to this not-so-nice process would be to join the TC and to simply vote to block forward movement of the spec until these issues are resolved. Yeah, that's the nuclear option, but perhaps it's time to throw down the gauntlet and somehow drive some convergence in this market rather than continuing to drive separation.

Clearly I'm speaking, even more so than normal, from my non-PC personal point of view.

Tags : / / / / / / /

Tuesday, April 10, 2007

Making an MP3 CD...

I was on a long trip this past weekend through the mountains of Pennsylvania where there was little to no radio station coverage and it kept changing as I drove through one location to another. I had made a similar trip a week ago with a rental car from Hertz which was configured with a Sirius satellite radio receiver and it was one of the first times I really appreciated the benefit of such a device. However, I don't make this trip all that often to justify the cost of subscribing to the service.

My car, a Chevy Colorado pick-up truck, has a 6 disc CD player so I could, and did, use some audio CDs to fill in with some music, but the number of tracks is quite limited even with 6 potential discs (although I only had one disc with me).

I tried using my FM transmitter for my iRiver Clix, but depending upon where I was, the chosen frequency kept getting overridden by an outside transmitter and I had to keep moving the frequency around -- not a good thing to do driving along at 70-75MPH.

My car's CD player does support the ability to play MP3 data CDs, giving me a 10x improvement in audio quantity, so I set out to create a disc that I could use in the car with my best music. Of course, it can only play MP3 formatted files, not WMA formatted files.

My media player of choice in my computer is Windows Media Player (WMP) and I rip my CDs in 160kbps Windows Media Audio (WMA) format. I have taken great pains to go through my entire collection of music and rate each song and wanted to use some automatic playlists to select the best of the best music for my new CDs (e.g. all 4 or 5 star rated songs). That's where the problem started.

First off, WMP seems to only want to create discs that are either an audio CD (with the standard audio format and thus about 80 minutes of music on a 700MB disc) or it can create a WMA format data disc which has good compression (close to 800 minutes) but unfortunately can't play in my car. I was unable to find a way to get WMP to burn a CD in MP3 format, nor a way to get WMP to generate a directory of MP3s from one of my playlists. Some research on the web indicated that I may have gotten this capability if I purchased the Windows XP Plus! Superpack, but I didn't have that nor did I want to purchase that.

I have Roxio Easy Media Creator 7.5 (yeah, I probably should upgrade to version 9, but they ticked me off when I bought version 7 less than a month before 7.5 came out and they didn't want to give me a free upgrade to 7.5) installed and tried to use that (which does have the ability to create an "MP3 disc" -- which I'm pretty sure is exactly what I'm looking for. However, it was unable to take WMA formated files as input nor was it able to use one of the WMP playlists.

I also have iTunes installed which is able to import WMAs and is able to store files within it's library in MP3 format, but it too appeared to be unable to use a WMP playlist as input to specify the files to copy/convert, nor was I able to find a way to get it to generate an MP3 disc (audio disc yes, backup disc -- whatever that is -- yes, but MP3 disc apparently no).

However, this motley collection of tools, along with some shell scripting, was able to accomplish the task at hand. The steps are shown below:

  1. Create a directory containing the WMA files that I want to have on the MP3 disc. This was necessary so that I didn't have to manually select each song that I wanted to import into iTunes, nor re-generate my ratings/playlists within iTunes because I imported the entire WMA collection. I saved a WMP playlist containing the files of interest and ran the following script within cygwin:
     grep "\.wma" "$OLDPWD/mylist4.wpl" \
             | sed -e 's;.*"M:.My Music.;;' \
                   -e 's;"/>;;' -e 's;\\;/;g' \
                   -e "s-'-'-g"          \
                   -e "s-&-\\&-g"         \
             | cpio -pdm /cygdrive/d/data/tmp/music
    

    This reads the specified WMP playlist (mylist4.wpl in this case), uses SED to convert the XML into a list of files (XSLT is probably the right way to do this as the file was XML, but a) I don't have XSLT installed and b) the XML was simple enough to do this all with the SED script), and uses CPIO to copy the WMA files to a temporary directory.

  2. Import the files in the temp directory into iTunes. Be sure to change the preferences setting within iTunes to tell it to import the files in 128Kbps MP3 rather than the default AAC format.
  3. Use Roxio's Creator Classic utility to burn an MP3 disc, selecting the iTunes collection as the source (I had no other music in my iTunes installation so this made it pretty easy -- I didn't have to go poking around selecting files to include on the disc.) The default iTunes music directory in my install was "My Documents\My Music\iTunes\iTunes Music".

I presume that someone, somewhere has an easier way to do this and I would love to hear about it as I presume I will need to do this again. It's a shame that WMP didn't offer this capability directly as it certainly has the necessary codecs and could have done so -- but I presume they are more interested in spending time on their hateful DRM stuff.

UPDATE - after all this, I find out that it is only the single-disc player for my car that includes the ability to play MP3s. The 6 disc changer does not have this capability. So it was all a waste!!!

Tags : / / / / / / /

Friday, March 30, 2007

Ad Blocking

I've known about the Firefox adblock plug-in for a long time, but have resisted installing it. For the most part, I think that sites I visit have a reasonable case for showing advertisements (to pay for the thing that I'm going to view or use). I don't mind that they make money. And, I don't mind getting ads that are related to what I'm doing, so it was sort of a win-win for everyone.

However that changed today... Over the past few weeks I've been poking around on my system when it would go slow. Of course, Outlook was frequently to blame. But there were times when I could not attribute the problem to Outlook and looking in my task manager, I found that it was Firefox that was using up the CPU -- 15 to 20% of it, even when I was doing nothing.

Some experimentation found that there were several adds running on different sites that were flash based and were eating away at my CPU.

So, I installed the plug in, restarted Firefox, and went to the pages that had the ads in question and easily blocked them. I'll continue to allow ads that aren't hungry consumers of my CPU (for the reasons I gave earlier), but nobody has the right to put an ad on my system that has a measurable impact on the performance. Ad writers, take this to note... Stop with the flashy, high load ads lest we block them all.

Anyway, thanks a bunch to the Adblock Crew and Michael McDonald for making this great plug-in available.

Tags : / / / /