Saturday, August 18, 2012

Consuming Advertising

As an ordinary person that watches movies, TV, listens to the radio, reads newspapers and hangs out on the Internet, I'm delivered a lot of different advertising. Some of it is effective, a lot of it is not.

When I'm watching advertising on the TV, it is rare for me to actually pay attention to it unless it is actually about an event or something else that I'm interested in but in the age of TiVO and other such devices, advertising is all too often the victim of fast-forwarding, with the exception of the 5 to 10 seconds prior to when the advertising finishes and the TV show begins. Some ads are carefully designed to deliver visuals that convey a readable message even whilst fast-forwarded, some are not. But for the most part, I find TV adverts annoying because they interrupt my consumption of the content being delivered by the television. This has ultimately resulted in "reality" TV shows saying "and the winner is..." - ad break, meaning it is time to get up and exercise or leave the room in disgust at the programming being done by the TV station. Whilst the TV stations may think it is a clever trick, I don't know anyone that looks kindly upon this tactic and I expect that if your ad was the first ad being displayed following that, the chances of the consumer actually being in a receptive state of mind are going to be quite low. Thus it is quite hard for an advertiser to get through to me about general products and in the Internet age, a TV ad alone is not likely to cause me to buy a product.

When I listen to the radio, my goal is generally to listen to music, the football or cricket. Talk-back radio and radio jockeys talking about random topics is not particularly interesting as it is more or less a collection of people with nothing better to do than ring up the radio station and wait to be heard on air. Maybe that's great if you're 75. Not if you're 35. Similarly comedians on the radio can be somewhat boring too and I can't help but wonder if as we grow older as a radio listener, we are able to see through the banter which we once thought was funny and wander off to greener pastures for our ears. When it comes to advertising, It couldn't be more different to TV if it tried. As a person that enjoys listening to music, it is between the hours of roughly 11pm and 5am when radio music content is at its best and adverts are at their fewest. Would that I could TiVO my local FM stations during those 6 hours at night and replay them during the daylight hours. But to drag myself back to the topic at hand, I rarely change radio station because of advertising. I'll change radio station because someone likes the sound of their voice to much or because I've heard that song 5 times today already, but I never walk out of the room when an ad comes on the radio, rather it is more likely that I stay sitting at the desk or table and continue doing whatever it was that I was doing.

Of a morning I read the newspaper headlines over breakfast. This is perhaps the most relaxing way to consume news and current affairs that I know of, save for laying down on the floor/bed and spreading the newspapers out in front of me. In consuming news this way, I can take my time, reread sections that I don't believe at first, ponder what's read and think about it. I don't get 5 seconds to find out about the latest car accident that killed 2 passengers, rather I can take 50 seconds to read and laugh at the Odd Spot on the front page. If there are adverts on the page of a newspaper that look mildly interesting, such as a bank offering a new product for a better return on deposits, there's a good chance that I'll read the fine print and so forth. The ad never gets in the way of the story, even when I have to change page to find the rest of the front page story. Perhaps most importantly, newspapers is the only place I know of where it is common to find out about today's specials or this week's specials, etc. Internet advertising never delivers that. Some newspapers will dedicate the entire back page to advertising for a local store or chain of stores that is running a promotion that day or weekend. On the Internet, the only way to find such information is to directly visit a store's website.

When it comes to Internet advertising, I do my best to block as much of it as I can. The simple reason for this is that ads themselves never have any value to me and are too often distracting and interrupting me. When I access web pages on the Internet, I'm generally looking for content/information. That includes when I use web search engines to search.

I've never deliberately clicked on a facebook ad and never intend to although I occasionally click on one by mistake.  In the first instance, facebook ads are very nicely grouped on the right side of facebook's page, meaning that even if anti-script applications have difficulty in blocking them, I've been able to train my brain to easily exclude paying any attention to that part of the screen. If someone asked me what I thought of facebook ads, I'd probably go "What facebook ads?" Sure, they're there, but they barely get noticed. If anyone is paying to have me see them, they're wasting their money.

To compare with Google, I've disabled the sponsored ads on the right and only click on the sponsored ad for a product if it is the product that I want but in many circumstances, the sponsored ad link from a vendor isn't the one I want as they're usually a general link whereas what I'm seeking is a product specific link

So in summary, for me Internet advertising doesn't work. At all. The Internet is where I go in search of information and I usually have a specific target or focus whilst doing so. Whilst in this state of mind, I'm not going to be receptive to advertising of any sort. My state of mind whilst reading a newspaper is completely different, as it is when watching TV.

I suspect that I'm atypical of the average "heavy Internet user" in various ways but mainly that of sitting down and reading a printed newspaper. When it gets delivered to your door every morning, it is very easy to sit down and read. On a weekend, there's almost nothing better than sitting down on the couch and reading through the paper with a cup of tea and a packet of biscuits.

Monday, April 2, 2012

Logging in with username@google.com to Unix

As part of an April Fools Day prank, Alan Coopersmith wrote about some ideas that were proposed for Solaris 12 but rejected. Amongst those was one where you could use a PAM plugin to login using your Google/facebook account. Whilst at first it seems silly, is it really as silly as it sounds?

Modern, smart, mobile phones are usually running a small operating system not that unlike what you use on your computer. There is a variation of Windows 7 that runs on mobile phones. Android is another example. Apple uses its own proprietary operating system. All of these mean that behind the glassy screen on your phone is a complex set of software that responds to your taps and touchs in a way that allows you to use the device like a phone. A large number of these devices are now able to connect to the Internet via 3G/4G technology.

So how does the Google/facebook account factor into this?

To use our mobile phones, we typically enter in a PIN for either the phone or SIM card and sometimes both. What this amounts to is determining whether or not the person holding the phone is actually authorised to use it. Once we've entered the PIN, all of the phone's capabilities unlocks. Phones are typically used by 1 person, so any customisation is saved locally, along with our contacts, SMS history, etc.

Given that the phone has Internet connectivity via 3G/4G, what if instead of unlocking the SIM card at power on, you logged into your Google account and instead of your contacts being stored locally, on the phone, they're stored on the Google cloud. Now if you lose your phone, you don't lose your contacts list or your SMS history. Similarly, if you needed to call someone, you could use someone else's phone and login as yourself through the very same portal.

For people that use their mobile phone as an Internet access device, logging in using your facebook account and having the phone then dedicate itself to you using facebook could also work.

To protect the privacy of users, the details of every session that get stored locally would need to be encrypted with a session key that is generated anew for each login. This would mean that the phone would have to pull all of my contacts and other bits down every time it was turned on, but the alternative is that guests using the phone would have no privacy from the owner of the phone.

Each session for a given user would run as a distinct user, inside its own virtual screen.

This idea completely shifts the way in which we use a phone from it being the centre piece to being just the access node and the phone itself has little value. To expand this further, you could create a public phone variation of this where anyone can come up to the phone and login using their Google/facebook credentials and have immediate access to all of their contacts.

So to summarise, maybe a PAM plugin to allow a login to be authenticated with a Google/facebook account is really not that silly as it sounds - just different.

Saturday, July 30, 2011

No ads with Mafia Wars on facebook

When I started playing Mafia Wars on facebook, the game was very much centered around input in the top area of the screen. Over time, Zynga have added their own bars and gadgets at the top of the screen, pushing the game content down. In more recent additions to Mafia Wars, you often find yourself spending large amounts of time scrolling down a long way, so much so that the top part of the page is never seen.

And this means that the ads that facebook throws at you are also not seen. Whilst this is a good thing for me (I'm not bothered by ads whilst I play), it also means that those paying for those ads are also not getting what they think they're getting. Why? Although I might be present on a given page for many minutes, as the ads are never seen even though they may be present for many minutes,. Thus a page impression from Mafia Wars results in me seeing the ad for a vastly shorter period of time than I would if it were facebook itself.

With other games such as FarmVille, the action is very much centered on the main playing screen, such that you don't have to scroll away from the ads.

If facebook and Zynga are in bed together to keep customers around, then it would seem that it's the third party in this menage a trois - the advertisers - that are getting screwed by both of their bed mates when it comes to Mafia Wars.

Monday, June 27, 2011

In search of hidden waterfalls

With this year being a very wet year in California, it seemed like a good idea to go in search of waterfalls. Not just the well known ones such as Yosemite, but others. This is something of a mixed blessing as quite often waterfalls look better in photographs when there is not as much water flowing.

This quest led me to a website called Waterfalls of the West. Note: only very easy/popular water falls have their full information available. Others require you to register. Registering requires submitting your email, after which you get a short period (24 hours?) of "free access" to information about the waterfall. This includes its height (estimated), GPS co-ordinations, etc.

A few weekends ago, I tried it out. For the waterfalls that are easily reached by a recognised and dedicated trail, the website provides good information. For others, the directions are somewhat lacking. The problem with the directions is that the person providing them is a GPS navigator and does not understand what is necessary to describe for others hiking using the directions rather than following GPS co-ordinates. For example, in one description it recommends that you "park at the turnout and walk down the road." However road is a misleading word - unused, overgrown track is more appropriate. Thus my first attempt to find that waterfall failed as I was looking for something resembling a road. After this, I made another go and discovered that there is something there that may have once been a track - not a road.0 Even USGS maps prior to the expedition being described it is clear that what's being described was never a road. When confronted with details like this, the website author complained that I was being "too picky". I'm flabberghasted. Details are extremely important when you're describing where and how to get somewhere but maybe this is a result of dealing with the Internet generation that use a GPS instead of a map.

Perhaps the most galling part of my interactions with the web site owner was that he still expressed hope that I'd pay him money. For what? Writing inaccurate directions that lead to people going astray with a caveat "you may want to use a GPS."?

Nevertheless, I found the waterfalls that I wanted - such as Mossbrae - and others that I didn't want - Little Roaring Creek. The latter is a story in itself.

Sunday, January 30, 2011

Online Persona

Every website asks us for the same information: date of birth, zipcode, phone#, etc, so that it can later verify that we are who we say we are by answering a question or two based on this information. The catch is that those who are close to us probably also know all of that information, including what our friends look like. So long as everything is calm, this poses no risk. But what happens if you have a rather acrimonious break up with your partner? Suddenly all those secret questions that offer you privacy do not seem so strong..

Enter the Online Persona.

If we carefully construct our online persona to be fictitious by choosing a different date of birth, where we were born, etc, then we're adding layers of security (although only by obscurity.) Each extra piece of incorrect information acts as another password that only we know. Whilst this means that features like facebook's birthday announcements become meaningless, does it really matter? Those who need to know when your birthday is will know, one way or another. The real catch with this is you need to be able to remember all of the false answers or you may find yourself locked out of your own accounts!

Wednesday, September 8, 2010

IPFilter: Designing for security

In the last 15 years, IPFilter has been popular enough that it has inspired at least one other firewall to imitate its configuration syntax (pf) and seemingly the basis of another in progress (npf). The examples that I've seen used for each indicate to me that neither of them is intended to be used in a manner that focuses on security as the prime goal of the design. That is distinct from saying that they can't be used to implement or achieve security.

One of the central themes in security is the ability to audit. For IPFilter, my interpretation of this requirement is that it is absolutely necessary to be able to audit the running configuration of the machine against what is found in its configuration file otherwise how else do have any assurance of what security policy is actively being applied to packets? In this instance, rule expansion where one rule with 5 ports becomes 5 rules or when you're using a text expression that is compiled into opcode makes it significantly harder to verify what's loaded into the kernel with what's in your configuration file.

To successfully audit an IPFilter configuration, three steps are required:
(1) collect the sorted rules from the kernel
(2) generate a list of sorted rules from the configuration file
(3) compare the results of (1) and (2)

Why do I mention "sorted rules"? The order in which rules are retrieved from the kernel and their grouping (all input rules and/or or output rules) is not likely to match the order in which they appear in the configuration file.

To give a brief example..

An extract of my configuration file looks like this:


pass in quick on lo0 all
pass out quick on lo0 all
pass out quick on nfe0 proto tcp all flags F/F
pass out quick on nfe0 proto tcp all flags R/R
#
block in log all
block in log quick from any to pool/666
block out quick log from any to pool/666
block in quick log from pool/666 to any
block out quick log from pool/666 to any


If I parse that configuration file and sort it using ipf, I get:

$ ipf -nvf /tmp/foo | sed -e 's/(!)//' | sort

block in log all
block in log quick from any to pool/666
block in log quick from pool/666 to any
block out log quick from any to pool/666
block out log quick from pool/666 to any
pass in quick on lo0 all
pass out quick on lo0 all
pass out quick on nfe0 proto tcp from any to any flags F/F
pass out quick on nfe0 proto tcp from any to any flags R/R


If I dump the kernel configuration and process it like above:


# ipfstat -io | sort
block in log all
block in log quick from any to pool/666
block in log quick from pool/666 to any
block out log quick from any to pool/666
block out log quick from pool/666 to any
pass in quick on lo0 all
pass out quick on lo0 all
pass out quick on nfe0 proto tcp from any to any flags F/F
pass out quick on nfe0 proto tcp from any to any flags R/R


Thus it is immediately possible to compare both. If I were to audit what is in the file itself rather than what the parser interprets it,
then the text I would be comparing with what is output from the kernel would be:


block in log all
block in log quick from any to pool/666
block in quick log from pool/666 to any
block out quick log from any to pool/666
block out quick log from pool/666 to any
pass in quick on lo0 all
pass out quick on lo0 all
pass out quick on nfe0 proto tcp all flags F/F
pass out quick on nfe0 proto tcp all flags R/R


Whilst that isn't the same as what ipfstat reports, it is very close and allows for a simple audit with diff to determine what the differences are and if they're proper. In this example, the only difference is "all" vs "from any to any". "all" becomes "from any to any" whenever there is a packet attribute that is required for matching that is not an address or port number.

This is a very simple requirement that actually delivers a very strong foundation.

For those familiar with IPFilter, you may be wondering why didn't I apply the same rationale to ipnat. Indeed when I review it, it is most definitely lacking a mechanism to display only the loaded NAT rules or only the active sessions. Currently doing "ipnat -l" lists both at once. Whilst the NAT functionality isn't directly responsible for enforcing security and thus exposed to the requirement of being able to be audited, it does play a part and should be more friendly in this area.

An additional benefit of this design is that removing a rules from the kernel's configuration is rather easy. For example, to remove all of the current rules you can perform a flush (ipf -Fa) or remove rules individually (ipfstat -io | ipf -rf -). The former is more common because it is both simpler and there are fewer complications when using rule groups. As it is, the design allows for tools to interrogate the kernel and the result of that interrogation is valid input that can then be reused.

Saturday, February 7, 2009


With a new record temperature in Melbourne (Australia) set this month, there will be, without doubt, cries that global warming is to blame. But is it?


On the other side of the world, England has been hit by a severe cold front, disrupting life for millions. But nobody there is blaming global warming. But they've had worse winters, for snow, than this year. How do we know that there hasn't been similarly hot (or hotter) weather in the "Melbourne" part of the world before?


A big problem that Melbourne faces is that it is one great big Urban Heat Island - especially in areas of new development. Footpaths with trees that can grow up and provide a canopy to the road in later years is essential. A good way to grasp the problem here is to take a walk in a wooded area on a hot day and compare that with walking by a road. Compare the temperature of the ground, not just during the day, but after night fall, when black ashphalt can still be releasing significant amounts of heat. The contention here being, to what extent would the construction of cities made from steel, concrete and ashphalt make on the environment even if there were no people or fossil fuel burning?


But is it fair to blame a temperature of 46.4C on global warming? Hardly. The earth is 100s of millions of years old. We have accurate weather data for maybe 100 years. What we can say is that putting more carbon dioxide in the air is bad (because it must mean that there is less oxygen) and we can say that on average, there has been a small rise in average temperature over that time.


But consider the Earth's history. It has descended into ice ages and come out of them without man to either help or instigate them. So there must be clearly something else going on. Our problem is that we do not have any accurate data to know what happened before these events that brought them on.


While global warming is something we need to face up to, what are we (the human race), going to do when the next ice age comes around? I say when and not if because they do occur on a regular basis. How will we deal with North America being under half a mile of snow and ice? Where will 300+ million people go? Will they just die? And what of Europe and Asia? And what if global warming is the only way to avoid another ice age? I suspect that may be a foolish statement and that either the progression to ice age is cyclical (and we will end up in another one, regardless of what we do or do't do, just as the tide always goes in and out) or we'll manage to change the cycle to be something else. Whilst some dooomsday folk would like to pretend that we'll cook the planet, I don't believe that will happen. What will happen is that we'll change the points between which the planet's weather oscillates. For example, last year, many places on Earth recorded much lower temperatures than average: Temperature Monitors Report Widescale Global Cooling.


While we can say that there has been a gradual rise in the average temperature over the last n years, how do we know that has not happened before in the history of the planet? And how do we know it will continue? In short, we don't. And perhaps our greatest folly is pretending that the world will always be as it is now. That it won't change. That the weather won't change. That another big chunk of rock from space won't land on our back door step. In our ascendency here on Earth, we've become masters of many aspects of this planet but we aren't (yet!) masters of its weather or tectonics (and will likely never be.)


If the Earth has swung into being very cold as recent as 15,000 years ago, how do we know it hasn't swung to being much warmer, before, than the average we've calculated over the last 100 years?


But consider this: in our continued burning of fossil fuels, each year we release into the Earth's environment extra energy. That energy doesn't all just evaporate out into space, it hangs around, warming the planet. Thus to solve global warming, we need to find a way to take that energy out of the atmosphere and return it to the ground. The only option we have here might be to just start planting more trees. In the mean time, using energy sources such as the wind and sunshine will help move our energy use away from tapping the bank of stored potential energy. The green reader might notice that I left out geothermal from that. I've also left out microwaving energy to Earth from orbit for the same reason: while both are "green", both introduce more energy into the biosphere than what brought us to our position of content - the continual bombardment of our planet with energy from the Sun.


All of this isn't to say that we shouldn't stop polluting the atmosphere: we should! In our thirst for money and power, we're stripping forests away at an alarming rate, largely in impoverished areas like the Amazon jungles of Brazil where it is hard to make a living otherwise. In doing so, we're reducing the capacity of the planet to make oxygen (which we need to live) and increasing the amount of carbon dioxide (which is not so healthy for us.) A similar problem exists for cars: they consume oxygen and produce carbon dioxide, not to forget using up our finite supply of fossil fuel. We're cutting off our noses to spite our faces.


The problem we face is two fold: (1) the current level of pollution is higher than we believe it has ever been for the planet and (2) there is no sign yet of the human race's activity abating. So while some might be tempted to say that even at current levels we're all surviving on this planet, so things can't be that bad and therefore we don't need to do anything to change, where we're we at is not the end game and the real problem is, we don't know what the end game will be or what it will look like.



p.s. If you're wondering what the point of this all is, it is to consider that we really have a paucity of data available on the environment (when you consider its age) with which to make predictions for the future. In places on Earth that have dynamic weather patterns (such as Melbourne), the Bureau of Meterology considers a successful forecast to be if their forecast for the day from 5am is close to accurate. That's a forecast for the next 18 hours. 5 day forecasts are notoriously unreliable. But yet people are trying to claim that models for the climate (due to global warming) can predict what the world will be like n years from now. Who's to say that the macro weather patterns aren't just as dynamic as the micro weather patterns?