Thursday, September 04, 2008

The Dell Inspiron Mini 9

The much rumoured and long awaited Dell Insipron mini 9 was released officially today, both in the US and in the UK. Although from the looks of things the US rollout isn't going that smoothly, with XML errors and unreachable web pages that are appearing and disappearing at random...


The bad news is that while there are three models in the US, priced at US$349, US$399 and US$449, only the top end model has seen the light of day here on the other side of the pond, priced at £299. The UK version is also only shipping with Windows XP, there isn't an option for an Ubuntu installation, as there is in the US...

However, taking the exchange rate into account, and the fact that the US prices aren't quoted with sales tax included, the UK price is actually (for once) fairly comparable with the US price for the same hardware. Well done Dell. But unfortunately there is more bad news...


There isn't any sign of the red version of the new notebook, either here or in the US. While in the US you can have the mini 9 in either white or black, shades of the Apple Macbook there? On the UK side of the pond you can have any colour you like, so long as it's black. Unfortunately for Dell, the red version was the reason I wanted one in the first place, it's certainly the reason my wife wants (wanted?) one.

The good news? Apparently additional colours and a version shipping with Ubuntu are "coming soon"...

Update: Also coming soon is a version of the mini 9 shipping with built-in HSDPA broadband from Vodafone...

Tuesday, September 02, 2008

This is not the Earth you are looking for...

After spending more time than I should hacking Sky support into Maps.app on my iPod touch I'm somewhat ambivalent about the arrival of Earthscape on the App Store (via the Google Earth Blog).


This is not the Earth I was looking for...

Earthscape has poor imagery outside of the continental United States, and the current version has no KML or accelerometer support and no search capability. Right now at least it's a cool toy. I've bought a copy because I quite like cool toys and I'm sure a bunch of other people will buy it for the same reason, and as a technical demonstrator it's impressive. But as a useful tool? Not at the moment.

At which point I guess I'm still waiting for Google Earth, and Google Sky, for my iPod touch. Of course I can't yet get Google Earth in a browser on my Mac, so I might be waiting a while...

Wednesday, August 27, 2008

The iPhone NDA

So last night I pre-ordered a copy of Erica Sadun's "iPhone Developer's Cokbook" from Amazon. The expected ship date is sometime late in October, but I'll be surprised if that's even vaguely accurate considering the ongoing problems with the NDA. Developers are now resorting to paying each other US$1 so they can be a sub-contractor, and presumably have some sort of legal protection against Apple's legal team and the NDA, before sharing information about developing against the official iPhone SDK.

So I doubt Erica's publisher will let her release the book until the NDA is lifted, and she isn't alone in having that problem, there are no doubt a bunch of books, tutorials and other such things waiting in the wings, waiting for Apple to lift the NDA.

However it currently seems to be a case that it's not when the NDA is lifted, but if it's going to be lifted at all. In what is now being called the fourth age of software distribution, might yet more companies adopt this bullying approach? That's a faintly scary prospect for independent developers like me...

Border Gateway Protocol

Close on the heels of the publicity surrounding cookie hijacking there is now another potentially much more serious problem, this time with the Border Gateway Protocol the core routing protocol underlying the Internet...

Wednesday, August 20, 2008

Cookie Hijacking

Things are looking a bit grim on the security side. Close on the heels of the DNS cache poisoning flaw discovered by Dan Kaminsky last month, there is now a new bogie man, automated HTTPS cookie hijacking...


Time progression showing vulnerable DNS servers: Red dots represent unpatched servers, yellow dots patched servers with NAT problems, green dots are patched servers.

The problem has gotten a lot of attention with respect to unencrypted GMail sessions, in fact there is now a widely available automated tool which allows you to steal session cookies on HTTP and HTTPS sites that do not set the cookie secure flag.


Surf Jacking Gmail demonstration from Sandro Gauci on Vimeo

However the problems is more widespread than just GMail, although there are still problems even there, and potentially affects a much broader range of sites.

Since so many sites are likely vulnerable, the actual reporting process is probably going to fall on the shoulders of users. To check your sites under Firefox, go to the Privacy tab in the Preferences window, and click on "Show Cookies". For a given site, inspect the individual cookies, and if any have "Send For: Encrypted connections only", delete them. Then try to visit your site again. If it still allows you in, the site is insecure and your session can be stolen. You should report this to the site maintainer. - Mike Perry

Of course we can't all go hide in a darkened room and realistically, unless you're a high profile target, your chance of getting caught by this vulnerability is fairly low. However potentially at least, this is serious. You email, merchant account, banking and other personal information are potentially at risk. Right now it's not clear how widespread this problem actually is, so be careful out there...

Tuesday, August 12, 2008

Poor indexing?

Nick Carr passes on James Evan's argument in a recent issue of Science that the chief advantage of print media is "poor indexing". How bizarre...

Ironically, my research suggests that one of the chief values of print library research is its poor indexing. Poor indexing—indexing by titles and authors, primarily within journals—likely had the unintended consequence of actually helping the integration of science and scholarship. - James Evans in the Britannica Blog

Friday, August 08, 2008

Paper Phishing

So we're all used to identifying and avoiding phishing attempts via email, but what about when it happens on paper? Today I received an actual paper letter, purporting to be from one of my banks, advising me that they had contacted me some time ago and hadn't had a reply, and that the due to a change in the law they needed to update the information about my extra card holder.

The letter looked genuine and included a 'Extra Cardholder Information Form' and a prepaid envelope to provide the details, and a freephone number that I could alternatively call to provide them. It went on to advise me that if I still needed my extra cardholder I must provide the information within 28 days or they would remove the extra card from my account.

So it looked genuine, except it sort of didn't. My finely tuned spider sense was tingling, if this was an email it wouldn't have even made it past my spam filter.

Despite the fact the letter had my account number on it, and was sent to my address, I was suspicious. So I called the fraud division of the bank in question, they had no record on my account of sending out such a letter, and the freephone number didn't, as far as they knew, belong to them. I'd just been the (almost) victim of a paper-based phishing attack.

Both of us were surprised, this is the first example of a paper-based phishing attack that I, and perhaps more worryingly the bank, had come across. If you get a letter that doesn't look quite right from your bank and is asking for personal information that, as far as you know, they should already have, call your bank on a number you know is genuine to confirm that it was actually from them.

It looks like the bad guys just raised the stakes, and we're now playing a new game entirely. It also looks likely that there has been some sort of major compromise with this specific bank, there were too many details in the letter to have come from a retail source. So this is your warning, keep your guard up...

Thursday, July 31, 2008

Interrupted Journeys

For those of you puzzled by my early departure from OSCON a week ago, and my non-appearance at HTN IV this week, I'd like to announce the very unexpected early arrival of my son, Alexander Michael. Born late yesterday evening, just under two months premature, and weighing just over 4 lbs.


Both mother and baby are doing well...

Wednesday, July 23, 2008

OSCON: Wednesday Morning Keynote

My jet lag caught up with me last night and I ended not making it to the Tuesday Night Extravaganza, although other people did and cruelly didn't blog Damian's talk for the rest of us that didn't. So I don't get to find anything more about "Temporally Quaquaversal Virtual Nanomachine Programming In Multiple Topologically Connected Quantum-Relativistic Parallel Timespaces", which is a pity...


The keynote kicked off with Allison Randall and Edd Dumbill, talking about the history of Open Source and OSCON. This is the first OSCON without Nat at the helm, and while I've seen him around, it's pretty weird not to have the keynote kick off with "...and here's your conference chair, Nat Torkington".

Update: Looks like I'll see you all next year. While I was in the keynote I got a phone call and I'm now heading back into the UK somewhat earlier than planned.

Update: More than one interrupted journey...