da: A smiling human with short hair, head tilted a bit to the right. It's black and white with a neutral background. You can't tell if the white in the hair is due to lighting, or maybe it's white hair! (robot)
da ([personal profile] da) wrote2005-01-13 07:16 am
Entry tags:

On obsolescence

Life is Change, and woe to those who can't deal with that.

I ran across this philosophy stated in stronger terms, that God is Change, but I won't go so far as to suggest that right now. Maybe later when I'm in an Octavia Butler mood. That post will probably have a lot to do with Internal versus External Locus of Control. But this entry is instead about obsolescence.

Three signs of change that prolly ought to piss me off but don't this morning, in order of increasing amusement value:

On a personal level, the Internet just got more complicated for both me and my brother Zack. Our mother started reading my journal. Long story short, I talked with her and we worked out that it was awkward enough that I didn't want her reading it, but I'd email her more instead. Then, she found [livejournal.com profile] cyanpill my brother and the results weren't pretty. Objectively, I think, there are some mom-alarm-worthy moments in his journal, but hell, the guy's 22, of course there will be (if they're going to be posted in a public journal). So he's gone friends-only posts. Mom hasn't told him she won't read his. So it's rather messy. It's leading to all kinds of interesting talks in my family at least, but it's definitely an off-kilter way to have them. So far, neither of us in my household are switching to friends-only posts, but I now have reason to consider it.

On a more interpersonal level, in the last 12 hours, my personal email address got 111 spam messages that got through spamassassin (version 2.64). I'm a patient guy, but ~175 a day aren't worth wading through. I considered killing the address completely, but I like the domain, and I was there first. So I'm going to lower my spam threshold and consider killing the address completely if that and similar fixes don't work. It's surprising to me, since taking a "regular job", the number of previously unquestionable assumptions I can now question, since I don't have to put so much work energy into finding and keeping clients myself. (Can I move my server in-house and save $100US/month? Do I need to answer email at so many addresses? Do I need a cell-phone? Do I need a PO box in Ithaca for business mail? and so on.) Every change I've made has felt freeing, and simplification is good.

On a not-at-all connected to me level, seems to me that Microsoft's security model has got to be in trouble. It appears that any windows program that uses MSHTML is an attack vector, according to those who report such things.
So, if you run Windows (up through XP/Server 2003 including SP 2) better patch or unplug from the network. I think I no longer trust any argument that security works better in a closed company than in an open-source project. How many thousands of engineers, how many levels of security audits did their latest OSes go through? This looks like a pretty wide hole, at least to a relatively naive non-windows-programmer like me.

[identity profile] ng-nighthawk.livejournal.com 2005-01-13 04:29 pm (UTC)(link)
[Is it bad blog ettiquette to post to a friend of a friend you don't know? I'm not sure. . . new to this. . . ]

I've thought a lot about the security problems in windows vs. open source projects. (I'm a software quality assurance engineer.) I wonder if open source projects have as many or more security holes than windows, but windows is such a bigger target. This is because
a) Microsoft is the devil, and therefore must ba attacked
b) Most low-level users who don't know anything about how to keep their systems secure are on windows, making it an easier target than the higher-level users who are on open source
c) There are more windows machines out there than open-source machines
d) Did I mention MS is the devil?

Mind you, I pretty much work exclusively with Windows/.NET/Office/etc. in my work, so maybe I'm just biased.

[identity profile] da-lj.livejournal.com 2005-01-13 06:11 pm (UTC)(link)
Is it bad blog ettiquette to post to a friend of a friend you don't know? I'm not sure. . . new to this. . .

Welcome. I always like meeting friends-of-friends. :)

Gotta run now, but I'll respond to the other half later.

On Security, Microsoft and Open Source

[identity profile] da-lj.livejournal.com 2005-01-14 02:31 am (UTC)(link)
I would love to see non-partisan studies which compared security failures in open-source and closed-source. The only studies I have seen were deeply partisan (one way or another).

It is my suspicion, not borne out by hard data, that Microsoft's security holes are more serious and the security model they choose for ActiveX and assorted web prototocols (in part to make it easier for naive users?) makes it easier for exploits to result in serious harm.

I'm mostly concerned about the number of successful exploits made on machines run by security-concious admins. That is a better test of whether the operating system is insecure, as far as I'd think.

I'm on security mailing lists that cover Windows and Unix; and the size of the holes in windows (anacdotally, as I remember) are greater; things like "if you don't disable activex now, you're machine's wide open." As opposed to local exploits, which seem more prevalant on Unix.

*shrug*

[identity profile] thomb.livejournal.com 2005-01-13 05:14 pm (UTC)(link)
The philosophy in question is called "Process Theology", and was developed first by Alfred Whitehead (the same one who collaborated with Bertrand Russell on Principia Mathematica).

[identity profile] da-lj.livejournal.com 2005-01-13 05:51 pm (UTC)(link)
thanks, I'll have to look that up.

[identity profile] mynatt.livejournal.com 2005-01-13 07:32 pm (UTC)(link)
Before my computer melted down I was receiving something like 100 to 200 spam messages a day, of which between 1 and 2 would slip through spamassassin 3.x. I've lost my bayes dbs now and will have to spend some time teaching the filter what my mail looks like again, but it was working very well for a long time. (I also kept track of which sorts of messages tended to be flagged as false negatives and tweaked their spam scores accordingly.) You have to perform a few extra steps when upgrading to 3.x to save your dbs but they're well worth it.

And good luck with simplifying your life, at least a little. I always feel like a large weight has been taken off my shoulders when I get to do things like that, like when I got rid of my car years ago.

[identity profile] da-lj.livejournal.com 2005-01-13 08:29 pm (UTC)(link)
Ah, so 3.x is ready for prime-time? The last I heard (I think partly from you) it had problems.

Heh. I think we went through a similar "simplification" when we traded in our 14-year-old car for a 5-year-old car and all of the repair problems went away. :)

[identity profile] mynatt.livejournal.com 2005-01-13 08:37 pm (UTC)(link)
I think I said that before I read the migration documentation (http://svn.apache.org/repos/asf/spamassassin/branches/3.0/UPGRADE). I like it fine now. Hope it works for you too...

[identity profile] da-lj.livejournal.com 2005-01-13 09:09 pm (UTC)(link)
spiff. thanks.

[identity profile] melted-snowball.livejournal.com 2005-01-13 09:17 pm (UTC)(link)
An ironic fact of D.'s and my life is that for a while, I've simplified my life by throwing parts of it that I just can't deal with (money, for example, or many involving using the telephone) at D. The irony comes that now that he's got a full-time job, we're going to have to re-assess much of this thinking. Maybe we can have much simpler lives as a consequence...

(Unfortunately, I can't see us getting rid of Harold the Toyota. Too much of our lives are unplanned, and we travel by car to the US too often. It's frustrating, because it does carry a lot of the weight you mention.)

[identity profile] mynatt.livejournal.com 2005-01-14 06:55 pm (UTC)(link)
Yeah, I feel fortunate to know enough people with cars that I don't need to own one myself.

Anyways, good luck.

[identity profile] cyanpill.livejournal.com 2005-01-14 07:13 pm (UTC)(link)
I didn't knowthe thought to get rid of your car had even crossed your mind- if it does again in the next year or so, I will most likely be in the market. Not sure it that will make things any simpler or not.