Wednesday, September 7, 2011

Digi Notice all those updates?

You may or may not have noticed, but over the last 96 hours your computer has probably been going completely nuts with automatic updating. Windows Update, Microsoft Update, Firefox Update, Mac OS X Software update, Chrome Update, Thunderbird Update; pretty much every piece of software that you have that connects to the Internet as part of its daily business, has been frantically updating.

If you didn't notice, that's fine; it means that the automatic updates are working as intended, and that's good. Maybe you just clicked "OK" a few times, or tolerated an extra reboot or a sluggish startup in the morning when you got to the office. Cool if that's so, because unobtrusive background updating is one of the Great Good Joys of these times, and I'm pleased when it turns out as it should.

But if you did notice all that updating, and wondered what it was all about, here is (I think) the scoop: it all had to do with a tiny little company in Holland that nobody had ever heard of named Diginotar.

Diginotar was (yes, I am using the past tense intentionally) one of the global Certificate Authorities: a commercial organization charged with the right, and responsibility, of issuing signed SSL certificates. These certificates are the foundation of server identity verification on the Internet; they are what makes that little "lock" icon appear in your browser when you access an "https" URL; they are what provides the software on your computer with the vital assurances that, when it ventures out into the cruel and heartless jungle of the Public Internet, that your software is talking to the partners that you think it is.

Concretely, when you sit down at your computer and enter https://mail.google.com, a web page appears in your browser. But how do you know that you are actually talking to the real GMail server? That is what SSL certificates do: your browser does a bunch of cryptography and ascertains that the server that it got connected to, presented a bit of data, that can be independently verified as being data that only an authentic GMail server could provide.

Unless, that is, some tiny Certificate Authority in someplace that you've never heard of, gets hacked. By a powerful government agency. And is comprised for many months, possibly even years, allowing the Bad Guys to issue more than five hundred forged certificates for, essentially, every important web site on the planet.

At this point, my rambling isn't making things much clearer, though, so you need to get the facts. Read this, and then read this, and then read this.

I'd like to tell you there's a simple answer, but there isn't. SSL and its Certificate Authority trust chain are widely felt to be flawed beyond repair, but it isn't clear what could replace them. A number of people are working hard on a new basic security mechanism called DNSSEC, but it has both technical and political obstacles to overcome.

It may be a rocky road over the next few years. Hang on tight.

UPDATE: The technical team over at the Electronic Frontier Foundation have a new detailed discussion of the attack

Faint Praise

StackOverflow's algorithms have decided to award me the Tenacious badge:
Zero score accepted answers: more than 5 and 20% of total.
I'm not exactly sure how to read that, but I think it means: "you keep answering questions on StackOverflow, even though nobody up-votes or accepts your answers."

I think that part of what's going on is that I've been participating in the Derby sub-community on StackOverflow, which is a particularly small and quiet community.

I've found that even the smallest of participations that I've made into the Perforce sub-community on StackOverflow have resulted in much larger voting and commenting activity, as that group of StackOverflow users seem much more active.

Hmm...

Tuesday, September 6, 2011

Perforce 2011.1 has entered beta testing!

The latest Perforce release, 2011.1, is now online and available for beta testing: here are more details. The two main features of this release are the new "Streams" functionality and the re-written integration engine. I didn't directly work on either of those features, but was pleased to be a part of some of the other, smaller, aspects of the new release. Give it a try! Let us know what you think!

Presence in Endeavor

The board game Endeavor is one of my wife's favorites, and a favorite of mine as well. It is a very well-balanced game with a moderate playtime and a nice initial random-ness in the setup that leads each game to be pleasantly different.

Recently, we've been exploring the 2 player variant rules published by Jarratt Gray (the author of the game) himself. Although Gray issues several disclaimers for these rules, we've found them to be simple and very playable, and it's renewed our interest in the game.

One thing we've discovered as we play the game some more, however, is that in our initial games we had completely overlooked the crucial concept of presence in Endeavor. We simply weren't using this concept, and so we were playing the game entirely wrong (this is not uncommon with me; in my haste to start playing a game I often read the rules very fast, and miss some fundamental concept until I re-read the rules some time later).

When the game initially starts, the only open region is Europe, and all players automatically have presence (of '0') in that region. Subsequently, as other regions open, a player only has presence in that region if they have placed a player marker there. Presence is a numerically-measured concept: if you have 3 player markers in a region, you have a presence of 3.

Presence affects the game in a number of ways:

  • You cannot occupy a city, nor attack a city, unless you already have presence in that region
  • You cannot draw a card from an open region unless you have a equal or greater presence in that region (for example, to draw a value 2 card from a region, you must first establish 2 or more player markers in that region).

Except for the initial region of Europe, where no shipping occurs, presence must be initially established by shipping to a region, since that is the only action you are allowed to take in a region where you have no presence. In Europe, your presence is established solely by the number of cities you occupy, but in the other regions (once open), your presence counts the number of shipments you have made and the number of cities you have occupied.

The concept of presence explains a number of aspects of Endeavor that are somewhat puzzling without it:

  • The Docks building, which allows you to ship and occupy in the same turn, allows a player who is "late to the party" to establish presence in an already-open region by shipping to it (even though the shipping lane is already complete, you just "over-ship" and place your marker alongside the full shipping lane) and then occupying a city in that region, in a single turn.
  • The more valuable cards in the game are much harder to acquire, since in order to legally draw a value 5 card from a region you must first have established (at least) 5 population markers in that region.
  • The otherwise "poisoned" Slavery cards are much more attractive. Firstly, it will take a while for slavery to be abolished (if at all), because for that to occur, a single player must accumulate (at least) 5 cities in Europe, which is a challenging feat since there are only 10 total cities in Europe, and in most games they will end up split rather evenly. Secondly, since drawing cards requires a superior presence, the low-valued Slavery cards are compelling to players with a lesser presence in Europe.
  • The limit on population markers per player (though we rarely reach it) means that a player will find that they cannot establish presence throughout the board, but will end up having a greater presence in some regions, and a lesser presence in others. This subtle imbalance is crucial to gameplay.

Another rule which we often forget to play in Endeavor involves the re-filing of discarded over-capacity cards, although now that we aren't drawing cards so willy-nilly, it is less common that we end up discarding cards. When a player chooses to discard a card (to get down to their required limit according to the number of Politics tokens they have scored), the player returns the discarded card to the stack where it came, and refiles it in numeric order, unless it is a Slavery card which are always retained, upside down, for negative points at the end of the game.

This means, importantly, that a low-value card may return to the game in an open region late in the game, so if you weren't able to draw that card initially, and are locked out of drawing the higher value card due to insufficient presence, you may find that the lower value card's return provides you that opportunity. Similarly, the return of that lower-valued card may block some other player, who has high presence, from drawing a higher-valued card that they have their eye on (thus the point of the Trade Office, which lets you draw twice from an open region in a single turn.

Monday, September 5, 2011

Backups remain non-trivial

Here's a nice post from Scott Hanselman about his recent re-work of his home computer backup strategy.

Backups remain the poor step-child of computing. Nobody does them, and so every day countless valuable data is lost to computer crashes or accidental fumble-fingering on the keyboard. Reading Scott's essay, you can see why nobody does their backups properly: it's a lot of work!

My parents are more dedicated to their backup strategy than most people I know; they have decades of digital photography, genealogy, writing, and other treasures on their computers. But still, even though they know the importance of backups and do the best they can, it's hard work. It requires constant attention and discipline to ensure that you have complete, verified, and reliable backups.

Like Scott, we've switched to using multiple spare external hard drives as the basic backup technique; online cloud backup tools seem nice, but just aren't up to the task of backing up hundreds of gigabytes. We let one run on our somewhat sizable machine, and after days it was still reporting less than 5% complete. The far simpler technique is to periodically hook up an external drive, copy everything to it (overnight), and then label that drive with an index card and store it someplace far away for safekeeping.

One problem is that those spare external drives age, too, and there's no guarantee that you'll be able to fire one up in case of emergency. Not so very long ago we did a restore from backup, and sadly had to go through three space external drives before we found one we could restore from (and we thanked our stars, since the third one was the last one we had!).

So here's a Labor Day though for those of you sitting around relaxing on this fine morning: take a few minutes and think about your backup strategy. If you haven't got one, make one. And if you've got one: I bet it's time for you to make a new backup!

Saturday, September 3, 2011

Stuff I'm reading

It's been a busy few weeks, so this is one of those "link dump" sort of posts. Hope you find something interesting in here:

Thursday, September 1, 2011

Google Summer of Code 2011 nearly complete

The 2011 edition of the Google Summer of Code is winding down. This year, I worked with Houx Zhang on internationalization issues in the Derby test harness. I think it was a successful year, and we had a chance to dig into some problems with the Derby testing techniques that had languished for years. It isn't enough to internationalize the software that you distribute; you must also internationalize your documentation, your tools and infrastructure, and your tests. Derby has a rich and mature test suite, and making it possible to run the Derby test suite in non-English locales makes the test suite even stronger. I haven't had much time to work with Derby recently, but I still enjoy the team and the community tremendously, and I'm glad to stay involved as time permits.