Thursday, September 04, 2008

The 3 HSDPA Dongle Review

I've just dropped the HSDPA dongle I've had on loan into a prepaid envelope to return the hardware to 3, so I thought I'd better write up my experiences with it now while it's still on my mind...

After some initial teething troubles I got the dongle working under OSX on my Intel Macbook, and gave it a fairly thorough work out over the course of the last couple of months.

As can be seen from their rollout map, 3 doesn't yet have any HSDPA coverage down here in the South West. Locally then, I'm suffering under the same sorts of problems I had with 3's Skypephone. The places where there isn't any 3 coverage is rather long; my house, my office, the cities and towns I visit regularly. The list of places where there is coverage is considerably shorter, and that's bad. What this also implies is that the problems seen with HSDPA when on the fringes of coverage are perhaps more significant than you might think.

However, whether a wireless modem works when you're in your own living room isn't, perhaps, as relevant as how well it works when it isn't. I used it extensively when I was out in Italy for the Trieste meeting roaming onto the 3 network there, and if I hadn't had the dongle on loan, I'd have only have been paying UK rates to do so...

I've also made use of it on various trips up and down the country, while stuck in hotel rooms, on trains and in coffee shops. I found it to be a good backup if wireless wasn't available. That said, performance was noticeably more sluggish than wireless, and if wireless access was available I generally still ended up paying for that rather than using the dongle.

Because somewhat unfortunately I found the process of using the dongle klunky and inconvenient. Coverage wasn't always there, and when it was there it wasn't there automatically. If I wanted to make use of it I had to dig the dongle out of my bag, plug it in, wait for it to find the 3 network, then wait for it to connect, wait for authorization. A lot of waiting...

I think I would have found the process a lot less inconvenient if HSPDA was built-in to my laptop, and like WiFi, automatically connected to a network when one was present. I'd like my data connection to seamlessly switching between wired, Wi-Fi and HSDPA when needed, without having to do do any fiddling around. Which I why I found the Dell and Vodafone announcement earlier today so interesting. You have to wonder how well integrated Vodafone's HSDPA card and Dell's mini 9 are going to be?

Three blew the roof off the mobile data market late last year when then started offering flat rate mobile broadband. Except of course it's not unlimited, their biggest plan has a data allowance of 15GB a month for £30. Which by mobile network standards is pretty good going. But despite the fact I wasn't paying for the bandwidth I found myself obsessively checking how much of the data allowance I was using, and the days where that's acceptable to me are long gone...

So the question I'm asking myself is "what's it for"? With a 15GB per month allowance this would never replace my home ADSL connection, I'd blow through that within the first week. So this is strictly for when you're out of the house, and the office, traveling. Perhaps this isn't normal, but most of the traveling I do is to the US. I don't spend much time in Europe, and less time than that traveling around the UK. Which means that I'd be paying £3 per MB when roaming, which clearly is just totally unacceptable.

So perhaps what I'm really saying here is that for me, this isn't the solution. Even when in Europe, and paying 10 pence per MB rather than £3 per MB, it isn't really good enough. However if you do most of your traveling in the UK, or within the coverage of a 3 sister network, perhaps you should take a look. It could be well worth your while.

As always then, your mileage may vary...

The Mini 9 with built-in HSDPA?

Hot on the heels of the official release of Dell's new netbook, the Inspiron mini 9, is the news that Dell has shaken hands with Vodafone on a co-marketing deal.


However the rumour is that, unlike similar deals, the Dell netbook will ship (at least here in the UK) with built-in HSDPA broadband. Which will certainly set the cat amoungt the pigeons...


If true, and initial reviews of the netbook certainly suggest that there could be more than a grain of truth here, this is exciting stuff.

Update: Okay, that's official. Although there isn't any news as to cost as yet, Vodafone would be mad not to significantly subsidise the already fairly moderate cost of the mini 9. Free with a contract data plan sounds like a decent price point to me...

Now I have to decide whether I should pick one up now, or wait? If I buy now, can I get an HSDPA board for it later, or will I be stuck without WWAN access? Decisions, decisions...

Update: The Vodafone press release...

Update: If true, the news that the stock version of the mini 9 "...doesn't have the internal antenna infrastructure needed to support mobile broadband", isn't good...

The Dell Inspiron Mini 9

The much rumoured and long awaited Dell Insipron mini 9 was released officially today, both in the US and in the UK. Although from the looks of things the US rollout isn't going that smoothly, with XML errors and unreachable web pages that are appearing and disappearing at random...


The bad news is that while there are three models in the US, priced at US$349, US$399 and US$449, only the top end model has seen the light of day here on the other side of the pond, priced at £299. The UK version is also only shipping with Windows XP, there isn't an option for an Ubuntu installation, as there is in the US...

However, taking the exchange rate into account, and the fact that the US prices aren't quoted with sales tax included, the UK price is actually (for once) fairly comparable with the US price for the same hardware. Well done Dell. But unfortunately there is more bad news...


There isn't any sign of the red version of the new notebook, either here or in the US. While in the US you can have the mini 9 in either white or black, shades of the Apple Macbook there? On the UK side of the pond you can have any colour you like, so long as it's black. Unfortunately for Dell, the red version was the reason I wanted one in the first place, it's certainly the reason my wife wants (wanted?) one.

The good news? Apparently additional colours and a version shipping with Ubuntu are "coming soon"...

Update: Also coming soon is a version of the mini 9 shipping with built-in HSDPA broadband from Vodafone...

Tuesday, September 02, 2008

This is not the Earth you are looking for...

After spending more time than I should hacking Sky support into Maps.app on my iPod touch I'm somewhat ambivalent about the arrival of Earthscape on the App Store (via the Google Earth Blog).


This is not the Earth I was looking for...

Earthscape has poor imagery outside of the continental United States, and the current version has no KML or accelerometer support and no search capability. Right now at least it's a cool toy. I've bought a copy because I quite like cool toys and I'm sure a bunch of other people will buy it for the same reason, and as a technical demonstrator it's impressive. But as a useful tool? Not at the moment.

At which point I guess I'm still waiting for Google Earth, and Google Sky, for my iPod touch. Of course I can't yet get Google Earth in a browser on my Mac, so I might be waiting a while...

Wednesday, August 27, 2008

The iPhone NDA

So last night I pre-ordered a copy of Erica Sadun's "iPhone Developer's Cokbook" from Amazon. The expected ship date is sometime late in October, but I'll be surprised if that's even vaguely accurate considering the ongoing problems with the NDA. Developers are now resorting to paying each other US$1 so they can be a sub-contractor, and presumably have some sort of legal protection against Apple's legal team and the NDA, before sharing information about developing against the official iPhone SDK.

So I doubt Erica's publisher will let her release the book until the NDA is lifted, and she isn't alone in having that problem, there are no doubt a bunch of books, tutorials and other such things waiting in the wings, waiting for Apple to lift the NDA.

However it currently seems to be a case that it's not when the NDA is lifted, but if it's going to be lifted at all. In what is now being called the fourth age of software distribution, might yet more companies adopt this bullying approach? That's a faintly scary prospect for independent developers like me...

Border Gateway Protocol

Close on the heels of the publicity surrounding cookie hijacking there is now another potentially much more serious problem, this time with the Border Gateway Protocol the core routing protocol underlying the Internet...

Wednesday, August 20, 2008

Cookie Hijacking

Things are looking a bit grim on the security side. Close on the heels of the DNS cache poisoning flaw discovered by Dan Kaminsky last month, there is now a new bogie man, automated HTTPS cookie hijacking...


Time progression showing vulnerable DNS servers: Red dots represent unpatched servers, yellow dots patched servers with NAT problems, green dots are patched servers.

The problem has gotten a lot of attention with respect to unencrypted GMail sessions, in fact there is now a widely available automated tool which allows you to steal session cookies on HTTP and HTTPS sites that do not set the cookie secure flag.


Surf Jacking Gmail demonstration from Sandro Gauci on Vimeo

However the problems is more widespread than just GMail, although there are still problems even there, and potentially affects a much broader range of sites.

Since so many sites are likely vulnerable, the actual reporting process is probably going to fall on the shoulders of users. To check your sites under Firefox, go to the Privacy tab in the Preferences window, and click on "Show Cookies". For a given site, inspect the individual cookies, and if any have "Send For: Encrypted connections only", delete them. Then try to visit your site again. If it still allows you in, the site is insecure and your session can be stolen. You should report this to the site maintainer. - Mike Perry

Of course we can't all go hide in a darkened room and realistically, unless you're a high profile target, your chance of getting caught by this vulnerability is fairly low. However potentially at least, this is serious. You email, merchant account, banking and other personal information are potentially at risk. Right now it's not clear how widespread this problem actually is, so be careful out there...

Tuesday, August 12, 2008

Poor indexing?

Nick Carr passes on James Evan's argument in a recent issue of Science that the chief advantage of print media is "poor indexing". How bizarre...

Ironically, my research suggests that one of the chief values of print library research is its poor indexing. Poor indexing—indexing by titles and authors, primarily within journals—likely had the unintended consequence of actually helping the integration of science and scholarship. - James Evans in the Britannica Blog

Friday, August 08, 2008

Paper Phishing

So we're all used to identifying and avoiding phishing attempts via email, but what about when it happens on paper? Today I received an actual paper letter, purporting to be from one of my banks, advising me that they had contacted me some time ago and hadn't had a reply, and that the due to a change in the law they needed to update the information about my extra card holder.

The letter looked genuine and included a 'Extra Cardholder Information Form' and a prepaid envelope to provide the details, and a freephone number that I could alternatively call to provide them. It went on to advise me that if I still needed my extra cardholder I must provide the information within 28 days or they would remove the extra card from my account.

So it looked genuine, except it sort of didn't. My finely tuned spider sense was tingling, if this was an email it wouldn't have even made it past my spam filter.

Despite the fact the letter had my account number on it, and was sent to my address, I was suspicious. So I called the fraud division of the bank in question, they had no record on my account of sending out such a letter, and the freephone number didn't, as far as they knew, belong to them. I'd just been the (almost) victim of a paper-based phishing attack.

Both of us were surprised, this is the first example of a paper-based phishing attack that I, and perhaps more worryingly the bank, had come across. If you get a letter that doesn't look quite right from your bank and is asking for personal information that, as far as you know, they should already have, call your bank on a number you know is genuine to confirm that it was actually from them.

It looks like the bad guys just raised the stakes, and we're now playing a new game entirely. It also looks likely that there has been some sort of major compromise with this specific bank, there were too many details in the letter to have come from a retail source. So this is your warning, keep your guard up...