The Daily Parker

Politics, Weather, Photography, and the Dog

Anals (?) of bad URLs

Crain's reported this morning that a company I used to work for has laid off 180 workers, about 10% of its workforce. I hope none of the people I'm still friends with was affected.

Also unfortunate is the URL that Crain's content server generated, which makes the story seem much more complicated than the news would otherwise suggest:

https://www.chicagobusiness.com/technology/west-monroe-lays-180-workers

really hope that (a) none of my friends had that happen to them, and (b) some prankster gamed the system to produce that URL. Because in a way, yes, some employees definitely got screwed.

Finally turning in

We've got a big demo at 8am that we've just put to bed, which means I get to go to bed. While the pipelines ran I came across Cory Doctorow's latest post on how DRM ruins everything:

[In 2002,] we warned that giving manufacturers the power to restrict how you configured your own digital products would lead them to abuse that power – not to prevent copyright infringement, but to shift value from you to them. The temptation would be too great to resist, especially if the companies knew they could use the law to destroy any company that fixed the anti-features in their products.

For brain-wormed market trufans, the digital media dream was our nightmare. It was something I called "the urinary tract infection business model." With non-DRM media, all the value flowed in a healthy gush: you could buy a CD, rip it to your computer, use it as a ringtone or as an alarmtone, play it in any country on any day forever.

Everywhere we find DRM, we find fuckery. Even if your cable box could be redesigned to stop spying on you, you'd still have to root out spyware on your TV. Companies like Vizio have crammed so much spyware into your "smart" TV that they now make more money spying on you than they do selling you the set.

Remember that the next time someone spouts the lazy maxim that "If you're not paying for the product, you're the product." The problem with Vizio's TVs isn't that they're "smart." The problem isn't that you're not paying enough for them.

The problem is that it's illegal to unfuck them, because Vizio includes the mandatory DRM that rightsholders insist on, and then hide surveillance behind its legal minefield.

This all starts with the idea that the problem with "content" is that Congress gave us, the public, too many rights under copyright, and that nickel-and-diming us to buy those rights a la carte would fix this problem. 20 years later, the benefits of this system are thin gruel indeed, and the costs keep mounting.

At least you can still read The Daily Parker for free.

And now, I'm off until the demo.

How is it 6:30?

With tomorrow night having the earliest sunset of the year, it got dark at 4:20 pm—two hours ago. One loses time, you see. Especially with a demo tomorrow. So I'll just read these while devops pipelines run:

Finally, John Seabrook takes a few pages to explain how to become a TikTok star. Hint: do it before you turn 22.

Uncomfortable, possibly exciting deployment this afternoon

We didn't deploy code to production at the end of last sprint because we had a seriously large epic that took 3 weeks to complete. It involved re-architecting an entire feature so that it can support multiple data types rather than the single type we originally planned for.

We knew this would happen, and we expected it right around the three-year point in development. So here it is, right on time. But despite all the testing and care that we put into the Dev/Test branch, and despite the multiple safeguards we have to prevent stupid code from getting into production, I worry we will not have a boring deployment in two hours.

Ah, well. We can roll back if needed, and I haven't got anything on my schedule tonight.

I still need a new drivers license, though

My drivers license expired in 2020, when all the Secretary of State's offices (what we in Illinois call the DMV) were closed, so I just renewed it online. I had hoped to upgrade to a Real ID, but it turned out the 2021 deadline for getting one got pushed back to 2023.

Since I moved in October, I actually have to go to the SOS office as they won't accept address changes online. But I still don't need a Real ID, it turns out:

Americans will have two more years to obtain a Real ID driver’s license or identification card, the Department of Homeland Security announced Monday.

U.S. air travelers will be required to present the Real ID credential to board a domestic flight beginning May 7, 2025. Before Monday’s announcement, implementation had been scheduled to take effect in May next year.

Postponing enforcement of the last phase of the Real ID Act will give motor vehicle departments across the country more time to process the new credentials, but will come 17 years after the changes initially were to be in place. States have reported that progress on the Real ID program was hindered by the coronavirus pandemic.

In any event I already have both a passport book and a passport card. But still, how has it taken 17 years to get this done?

Making progress at work, slacking on the blog

Clearly, I have to get my priorities in order. I've spent the afternoon in the zone with my real job, so I have neglected to real all of this:

Finally, because only one guy writes about half of the songs on top-40 radio, modulations have all but disappeared from popular songs.

Winter is here

Meteorological winter begins in the Northern Hemisphere today. In Chicago right now we have sunny skies and a normal-for-December 2°C. And any day above freezing between December 1st and March 1st works for me.

Meanwhile:

Finally, on a whim I looked back at my posts from 10 years ago, and I came across this painful memory of debugging an Azure 1.8 deployment. And 15 years ago we got our first snowfall of the season. Ah, memories.

If I have your computer, I own your computer

Via Bruce SchneierArs Technica describes in painful detail how computer repair people snoop and steal people's data all the time:

If you’ve ever worried about the privacy of your sensitive data when seeking a computer or phone repair, a new study suggests you have good reason. It found that privacy violations occurred at least 50 percent of the time, not surprisingly with female customers bearing the brunt.

Researchers at University of Guelph in Ontario, Canada, recovered logs from laptops after receiving overnight repairs from 12 commercial shops. The logs showed that technicians from six of the locations had accessed personal data and that two of those shops also copied data onto a personal device. Devices belonging to females were more likely to be snooped on, and that snooping tended to seek more sensitive data, including both sexually revealing and non-sexual pictures, documents, and financial information.

The amount of snooping may actually have been higher than recorded in the study, which was conducted from October to December 2021. In all, the researchers took the laptops to 16 shops in the greater Ontario region. Logs on devices from two of those visits weren’t recoverable. Two of the repairs were performed on the spot and in the customer's presence, so the technician had no opportunity to surreptitiously view personal data.

In three cases, Windows Quick Access or Recently Accessed Files had been deleted in what the researchers suspect was an attempt by the snooping technician to cover their tracks. As noted earlier, two of the visits resulted in the logs the researchers relied on being unrecoverable. In one, the researcher explained they had installed antivirus software and performed a disk cleanup to “remove multiple viruses on the device.” The researchers received no explanation in the other case.

In all, the findings from the study were:

 Privacy policies and the practice of communicating protocols and controls to protect customers’ data do not exist across service providers of all sizes.
 Service providers largely (10/11) require “all access” to the device, even when it is unnecessary.
 Technicians often snoop on customers’ data (6/16) and sometimes copy those to external devices (2/16).
 Technicians who violate privacy often do so carefully to not generate evidence (1/6) or remove such evidence (3/6).
 A significant proportion of broken devices (26/79, 33 percent) are not repaired due to privacy concerns. For the devices that get repaired, device owners are concerned about threats to their privacy but do not use the proper controls to protect their data.

The results likely confirm what many more experienced computer users already know: that their data is vulnerable to snooping or copying any time they surrender their device to an untrusted or unknown individual, particularly when the individual has their login password. But for a much larger percentage of people wanting to recover crucial data on a broken device, the findings are likely a wake-up call with few, if any, good solutions.

Another way to look at it: do you trust your locksmith?