<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="wordpress/wordpress-mu-1.2.5" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>

<channel>
	<title>Justin Dolske's blog</title>
	<link>http://blog.mozilla.com/dolske</link>
	<description>The odd parity bit</description>
	<pubDate>Tue, 13 May 2008 22:50:30 +0000</pubDate>
	<generator>http://wordpress.org/?v=wordpress-mu-1.2.5</generator>
	<language>en</language>
			<item>
		<title>Dear Sprint&#8230;</title>
		<link>http://blog.mozilla.com/dolske/2008/05/13/dear-sprint.../</link>
		<comments>http://blog.mozilla.com/dolske/2008/05/13/dear-sprint.../#comments</comments>
		<pubDate>Tue, 13 May 2008 22:50:30 +0000</pubDate>
		<dc:creator>Justin Dolske</dc:creator>
		
		<category><![CDATA[Technology]]></category>

		<category><![CDATA[PlanetMozilla]]></category>

		<guid isPermaLink="false">http://blog.mozilla.com/dolske/2008/05/13/dear-sprint.../</guid>
		<description><![CDATA[Dear Sprint&#8230;
I hear you&#8217;ve had a rough time of it lately. Losing 1.1 million customers and $505 million last quarter? Ouch. I&#8217;d really love to help you out. Drop me a line when you have a billing system that will actually take my money! (I believe you already have my number.)
]]></description>
			<content:encoded><![CDATA[<p>Dear Sprint&#8230;</p>
<p>I <a href="http://consumerist.com/5008735/sprint-loses-109-million-customers-in-3-months">hear</a> you&#8217;ve had a rough time of it lately. Losing 1.1 million customers and $505 million last quarter? Ouch. I&#8217;d <a href="http://blog.mozilla.com/dolske/2008/04/27/this-is-why-cell-phone-companies-irritate-me/">really love</a> to help you out. Drop me a line when you have a billing system that will actually take my money! (I believe you already have my number.)</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.mozilla.com/dolske/2008/05/13/dear-sprint.../feed/</wfw:commentRss>
		</item>
		<item>
		<title>Another look at SafeBrowsing warnings</title>
		<link>http://blog.mozilla.com/dolske/2008/05/06/another-look-at-safebrowsing-warnings/</link>
		<comments>http://blog.mozilla.com/dolske/2008/05/06/another-look-at-safebrowsing-warnings/#comments</comments>
		<pubDate>Tue, 06 May 2008 23:32:46 +0000</pubDate>
		<dc:creator>Justin Dolske</dc:creator>
		
		<category><![CDATA[Firefox]]></category>

		<category><![CDATA[PlanetMozilla]]></category>

		<guid isPermaLink="false">http://blog.mozilla.com/dolske/2008/05/06/another-look-at-safebrowsing-warnings/</guid>
		<description><![CDATA[I last blogged in February about some inadequacies with the SafeBrowsing warning page in Firefox 3. There have been some changes since then, which I think greatly improve things.
Here&#8217;s the current warning page in Firefox 3:

Just subtle changes here. Notably, there&#8217;s now a small &#8220;Ignore this warning&#8221; link to bypass the warning and load the [...]]]></description>
			<content:encoded><![CDATA[<p>I last <a href="http://blog.mozilla.com/dolske/2008/02/17/user-perception-of-safebrowsing/">blogged in February</a> about some inadequacies with the SafeBrowsing warning page in Firefox 3. There have been some changes since then, which I think greatly improve things.</p>
<p>Here&#8217;s the current warning page in Firefox 3:</p>
<p><img src="http://people.mozilla.com/~dolske/blogimg/attackpage.png"></p>
<p>Just subtle changes here. Notably, there&#8217;s now a small &#8220;Ignore this warning&#8221; link to bypass the warning and load the site (perhaps putting yourself at risk by doing so), and an additional button to click for an explanation of why the site was blocked.</p>
<p>The changes on the &#8220;why was this site blocked&#8221; page are more significant. Here&#8217;s an example of what you get now:</p>
<p><img src="http://people.mozilla.com/~dolske/blogimg/googleadvisory.png"></p>
<p>I like that page is clean and chock full of information about why the site was being blocked. It&#8217;s helpful information for the what a user is probably asking &#8212; &#8220;Can I trust this warning, and should I load the site anyway?&#8221; After reading that page, *I* certainly wouldn&#8217;t be tempted to ignore the warning: it indicates that the site has been visited recently, that lots of pages on the site are infected, and is better at specifying the exact risk (Here, &#8220;Malicious software includes 3 backdoors&#8221;. Looking at pages for other sites, I&#8217;ve also seen descriptions like &#8220;23809 trojans&#8221; (!!!), &#8220;15 scripting exploits&#8221;, and &#8220;2 worms&#8221;.</p>
<p>I do wonder if the page is a little too detail oriented; normal users might benefit from some sort of brief summary at the top. It&#8217;s a fine line between being too vague and being too detailed, because there are so many factors involved. I suppose it&#8217;s better to err on the side of too much information, especially if the outcome is the user being scared and overwhelmed &#8212; it&#8217;s not a site to be visiting!</p>
<p>But being more open can have a downside, if it might lull the user into a false sense of safety or muddles the risk. For example: Does &#8220;Part of this site was listed for suspicious activity 3 time(s) over the past 90 days&#8221; mean that the site is a dangerous repeat offender, or just that it&#8217;s a rare to encounter a problem? Does &#8220;Successful infection resulted in an average of 0 new processes on the target machine.&#8221; mean the infections are harmless?</p>
<p>Anyway, I don&#8217;t think these nitpicks are serious problems, and am glad to see this improvement.</p>
<p>[If you&#8217;re looking for live examples of malware sites, the <a href="http://groups.google.com/group/stopbadware/topics">StopBadware google group</a> is a good source to find currently blocked pages.]</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.mozilla.com/dolske/2008/05/06/another-look-at-safebrowsing-warnings/feed/</wfw:commentRss>
		</item>
		<item>
		<title>This is why cell phone companies irritate me</title>
		<link>http://blog.mozilla.com/dolske/2008/04/27/this-is-why-cell-phone-companies-irritate-me/</link>
		<comments>http://blog.mozilla.com/dolske/2008/04/27/this-is-why-cell-phone-companies-irritate-me/#comments</comments>
		<pubDate>Mon, 28 Apr 2008 02:37:18 +0000</pubDate>
		<dc:creator>Justin Dolske</dc:creator>
		
		<category><![CDATA[Technology]]></category>

		<category><![CDATA[PlanetMozilla]]></category>

		<guid isPermaLink="false">http://blog.mozilla.com/dolske/2008/04/27/this-is-why-cell-phone-companies-irritate-me/</guid>
		<description><![CDATA[I finally got around to upgrading to new cell phone and plan. Sprint,  Samsung M520, SERO plan &#8212; nothing fancy. The phone isn&#8217;t even quite as awful as I had been expecting.
But, as suspected, adding on a Phone-As-Modem (PAM) data plan (to enable internet access from my laptop and N810) was a nightmare. In [...]]]></description>
			<content:encoded><![CDATA[<p>I finally got around to upgrading to new cell phone and plan. Sprint,  Samsung M520, <a href="http://www.fatwallet.com/forums/hot-deals/680568/">SERO</a> plan &#8212; nothing fancy. The phone isn&#8217;t even quite as awful as I <a href="http://blog.mozilla.com/dolske/2008/03/22/ridiculous-cell-phone-rates/">had been expecting</a>.</p>
<p>But, as suspected, adding on a Phone-As-Modem (PAM) data plan (to enable internet access from my laptop and N810) was a nightmare. In fact, because &#8212; well, I&#8217;ll spare you 40 minutes of various excuses from customer service &#8212; it ends up being &#8220;impossible&#8221; to add. So even though my phone supports it, and I&#8217;m grudgingly willing to fork over an extra $40/month ($960 for the term of my contract), Sprint&#8217;s billing system won&#8217;t take my money. Wooooonderful.</p>
<p>I suppose I could look at other cellular providers&#8230; But I have little faith that I&#8217;ll find better results elsewhere, or be able to do so without a week-long migraine. Perhaps AT&amp;T and the <a href="http://gizmodo.com/376519/walt-says-3g-iphone-coming-in-60-days">rumored</a> second-coming of the <a href="http://www.apple.com/iphone/">Jesus Phone</a> will provide salvation. I still have <a href="http://www.eff.org/issues/nsa-spying">concerns</a> about Ma Bell&#8217;s less-than-immaculate hands, but this feels more and more like a strategy game&#8230; Jump there, hope the rest of the industry moves, and then jump somewhere else.</p>
<p>Oh well. At least for all my troubles I&#8217;ll have a slightly better cell phone with a <a href="http://youtube.com/watch?v=oHg5SJYRHA0">nifty ringer</a> for the next two years.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.mozilla.com/dolske/2008/04/27/this-is-why-cell-phone-companies-irritate-me/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Apples and Orangeness</title>
		<link>http://blog.mozilla.com/dolske/2008/04/25/apples-and-orangeness/</link>
		<comments>http://blog.mozilla.com/dolske/2008/04/25/apples-and-orangeness/#comments</comments>
		<pubDate>Fri, 25 Apr 2008 08:40:54 +0000</pubDate>
		<dc:creator>Justin Dolske</dc:creator>
		
		<category><![CDATA[Technology]]></category>

		<category><![CDATA[PlanetMozilla]]></category>

		<guid isPermaLink="false">http://blog.mozilla.com/dolske/2008/04/25/apples-and-orangeness/</guid>
		<description><![CDATA[Ubuntu 8.04 &#8220;Hardy Heron&#8221; came out today (*checks clock* err, yesterday) &#8212; congrads to the Ubuntu community on the release! I just finished installing it under VMWare Fusion on my MacBook, and will upgrade my home and work Ubuntu desktops this weekend.
Installation was painless. I didn&#8217;t even need to edit xorg.conf and specify my monitor&#8217;s [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.ubuntu.com/products/whatisubuntu/804features/">Ubuntu 8.04</a> &#8220;Hardy Heron&#8221; came out today (*checks clock* err, yesterday) &#8212; congrads to the Ubuntu community on the release! I just finished installing it under VMWare Fusion on my MacBook, and will upgrade my home and work Ubuntu desktops this weekend.</p>
<p>Installation was painless. I didn&#8217;t even need to <a href="http://blog.mozilla.com/dolske/2007/09/28/oh-lord-how-i-hate-x11./">edit xorg.conf</a> and specify my monitor&#8217;s horizontal refresh rate! :-) Video, sound, and networking all worked. I must grumble a little bit, though, that the installer still can&#8217;t automagically detect the keyboard type, and instead presents a list with a zillion obscure variants (with a default selected). Maybe it&#8217;s just not possible&#8230; I remember how installers of yore used to do the same thing for mice (&#8221;Serial mouse? Bus Mouse? PS/2 protocol, or Logitech?&#8221;, etc.), but that all seems to Just Work now. Selecting my physical location is also slightly annoying; it might be neat to do a GeoIP lookup to guess&#8230; Anyway, both just small nitpicks.</p>
<p>One thing I am a little confused about is what (if any?) VMWare stuff needs to be done. In the past, the usual process was to install the guest OS, and then install VMWare Tools to get various things working. Now it seems like the Ubuntu installer has already done some of that&#8230; At least, it gave me vmware-specific video and mouse packages. But the desktop doesn&#8217;t resize when the VMWare window is resized, and VMWare&#8217;s Forums seem to have some arguments going on (hi Al!) in regards to their Tools stuff not working on Hardy and a perceived lack of support. So, I don&#8217;t know what&#8217;s up with that. Things seem to be working well enough that I&#8217;ll just use it as-is for a while, and then check back later when other people figure it out. Or maybe I&#8217;ll lazyblog about it, and hope someone comments. :-)</p>
<p>P.S. Love the Heron artwork!</p>
<p><img src="http://people.mozilla.com/~dolske/blogimg/ubuntu804.jpg"></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.mozilla.com/dolske/2008/04/25/apples-and-orangeness/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Test cases make bad law</title>
		<link>http://blog.mozilla.com/dolske/2008/03/31/test-cases-make-bad-law/</link>
		<comments>http://blog.mozilla.com/dolske/2008/03/31/test-cases-make-bad-law/#comments</comments>
		<pubDate>Mon, 31 Mar 2008 08:56:34 +0000</pubDate>
		<dc:creator>Justin Dolske</dc:creator>
		
		<category><![CDATA[Firefox]]></category>

		<category><![CDATA[PlanetMozilla]]></category>

		<guid isPermaLink="false">http://blog.mozilla.com/dolske/2008/03/31/test-cases-make-bad-law/</guid>
		<description><![CDATA[Testing seems to be the topic du jour this weekend&#8230; A few remarks.
I don&#8217;t think this is a discussion that should be framed as an argument between pro-test and anti-test factions. In fact, I&#8217;m not even sure the latter group really exists. Yes, some modules could be better at adding tests on a regular basis, [...]]]></description>
			<content:encoded><![CDATA[<p>Testing seems to be the topic du jour this weekend&#8230; A few remarks.</p>
<p>I don&#8217;t think this is a discussion that should be framed as an argument between pro-test and anti-test factions. In fact, I&#8217;m not even sure the latter group really exists. Yes, some modules could be better at adding tests on a regular basis, but I don&#8217;t really see people arguing that testing sucks and we should just stop doing it. What I *do* see are concerns about the degree of testing that should be required. That&#8217;s an interesting discussion, and should be held without any implication that supporting anything less than <a href="http://www.fastcompany.com/magazine/06/writestuff.html">CMM Level 5</a> is akin to supporting terrorism. (Or the reverse, oops.)</p>
<p>I think a lot of the uncertainty about testing comes from the fact that, <a href="http://antennasoft.net/robcee/2008/03/27/mochitest-by-the-numbers/">until recently</a>, there was almost no automated testing. And so we&#8217;re going through a period of growing pains where the project figures out how to handle things. The existing policy (for Toolkit and Browser), which is basically &#8220;everything should have a test&#8221;, has been a good starting point. It&#8217;s simple, is mostly the right thing to do, and is a solid kick-in-the-pants to help sidestep the initial inertia to change.</p>
<p>But there are principles we shouldn&#8217;t lose sight of&#8230; Tests are a means to and end. They have both costs and benefits. And we need to balance these (and a multitude of other factors) when deciding the degree to which something needs tested. That&#8217;s not to say we should only aspire to half-assed testing, but neither should we become so risk-adverse that testing requirements halt progress. [Note: being on the verge of a release, where being hyper risk-adverse is a good thing, makes this a complicated discussion!]</p>
<p>Now, switching gears to the issue of tests and new contributors:</p>
<p>I don&#8217;t think new contributors should just get a free-pass when it comes to testing. Tests are an important part of good software engineering, and they&#8217;re important to the Mozilla project. However, I do think that we can do things to aid newcomers and make the process easier&#8230; Ensuring we have good documentation on writing and using tests helps everyone. Module owners and active contributors can work to ensure there are existing tests that newcomers can easily emulate and modify. The scope of required testing can be trimmed to just the essentials. We can be polite, but firm, on requirements without being &#8220;jerks&#8221;. And so on.</p>
<p>This issue is probably somewhat self-limiting, because the scale of testing should generally correlate with the complexity of the patch. Newcomers are more likely to be doing simpler patches, ergo the testing should be simpler. But there will be tricky cases where simple changes end up being complex to test&#8230; Good judgement and balance should be applied, as I argued above. For example, if the existing code is frail and known to be regression prone, tests are unavoidable. If the code is solid and the change well-understood, then making an exception for minimal testing can be reasonable. And while automated tests are strongly preferred, other forms of testing might be acceptable an alternative.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.mozilla.com/dolske/2008/03/31/test-cases-make-bad-law/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Ridiculous cell phone rates</title>
		<link>http://blog.mozilla.com/dolske/2008/03/22/ridiculous-cell-phone-rates/</link>
		<comments>http://blog.mozilla.com/dolske/2008/03/22/ridiculous-cell-phone-rates/#comments</comments>
		<pubDate>Sun, 23 Mar 2008 06:02:57 +0000</pubDate>
		<dc:creator>Justin Dolske</dc:creator>
		
		<category><![CDATA[Technology]]></category>

		<category><![CDATA[PlanetMozilla]]></category>

		<guid isPermaLink="false">http://blog.mozilla.com/dolske/2008/03/22/ridiculous-cell-phone-rates/</guid>
		<description><![CDATA[I&#8217;ve been shopping around for a new cell phone and plan. My first attempt was about a year ago, after moving to the Bay area, but I gave up in despair. I had been hoping that the success of the iPhone would help improve things, but after looking around again I remain throughly disgusted at [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve been shopping around for a new cell phone and plan. My first attempt was about a year ago, after moving to the Bay area, but I gave up in despair. I had been hoping that the success of the iPhone would help improve things, but after looking around again I remain throughly disgusted at the state of the industry.</p>
<p>The available phones are still awful &#8212; clunky interfaces and useless features. I was watching a video review of one phone, where a main review point was the ability to change the color and font of the numbers shown while dialing. Never mind the crappy MP3 player, here&#8217;s 555-1234 in rainbow Comic Sans! At least the consistent worthlessness seems to make shopping easier &#8212; why compare features when you can just pick the pretty one and be equally disappointed?</p>
<p>The various service plans are awful too; in particular, the data rates are completely ridiculous. Some plans give you unlimited data with the on-phone browser, but I&#8217;d rather get my teeth pulled than do that. I *would* like to be able to use my phone for network connectivity (on my laptop or N800, via bluetooth) now and then, when I&#8217;m stuck some place without WiFi . But it appears that the only choices are (1) pay a high monthly fee for unlimited access or (2) pay astronomical per-byte rates. Verizon made me shake my head first: &#8220;Data sent or received (incl. Mobile Web advertising) is $1.99/MB.&#8221; $2 to load a Tinderbox page (which is about a megabyte), and I have to pay them to send ads to me as well?! Then I saw Sprint&#8217;s rates: &#8220;Customers without a phone-as-modem plan will be charged 3 cents per kilobyte for Sprint Vision or Sprint Power Vision usage unless a Phone as Modem plan is selected.&#8221; $30 to load a Tinderbox page?! WTF? It&#8217;s clearly not an issue of constrained resources, as the phone-as-modem plan is $40 a month for unlimited usage.</p>
<p>This kind of racket must be especially profitable, because it seems that &#8220;unlimited&#8221; doesn&#8217;t really mean &#8220;unlimited&#8221;. If a carrier decides you&#8217;re using too much (according to sekret rules they won&#8217;t tell you about), apparently they may start charging at per-byte rates (or, if you&#8217;re lucky, just cut you off). So, you can pay them $480 a year as a protection fee (to make sure you don&#8217;t accidentally end up with a gazillion-dollar monthly bill), and then just hope that they don&#8217;t come around and break your kneecaps anyway.</p>
<p>Madness.</p>
<p>[&#8221;Why not an iPhone?&#8221;, I hear someone asking&#8230; Well: no bluetooth network access, terrible data speed, I don&#8217;t need a $400 phone, objection to AT&amp;T&#8217;s <a href="http://en.wikipedia.org/wiki/Hepting_vs._AT%26T">complicity</a> in the NSA wiretapping thing, and opposition to the closed nature of the iPhone platform. The last of these (non-openness) I&#8217;d be willing to ignore on the principle that the iPhone is much less evil than the alternatives, but the rest are still a deal breaker.]</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.mozilla.com/dolske/2008/03/22/ridiculous-cell-phone-rates/feed/</wfw:commentRss>
		</item>
		<item>
		<title>I, for one&#8230;</title>
		<link>http://blog.mozilla.com/dolske/2008/03/21/i-for-one.../</link>
		<comments>http://blog.mozilla.com/dolske/2008/03/21/i-for-one.../#comments</comments>
		<pubDate>Sat, 22 Mar 2008 01:15:41 +0000</pubDate>
		<dc:creator>Justin Dolske</dc:creator>
		
		<category><![CDATA[Technology]]></category>

		<category><![CDATA[PlanetMozilla]]></category>

		<guid isPermaLink="false">http://blog.mozilla.com/dolske/2008/03/21/i-for-one.../</guid>
		<description><![CDATA[Are We Giving Robots Too Much Power?

(YouTube)
]]></description>
			<content:encoded><![CDATA[<p>Are We Giving Robots Too Much Power?</p>
<p><object type="application/x-shockwave-flash" data="http://www.youtube.com/v/OGxdgNJ_lZM" width="425" height="350"><param name="movie" value="http://www.youtube.com/v/OGxdgNJ_lZM" /></object></p>
<p>(<a href="http://www.youtube.com/watch?v=OGxdgNJ_lZM">YouTube</a>)</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.mozilla.com/dolske/2008/03/21/i-for-one.../feed/</wfw:commentRss>
		</item>
		<item>
		<title>Robots in spaaaaaaaace…</title>
		<link>http://blog.mozilla.com/dolske/2008/03/15/robots-in-spaaaaaaaace%e2%80%a6/</link>
		<comments>http://blog.mozilla.com/dolske/2008/03/15/robots-in-spaaaaaaaace%e2%80%a6/#comments</comments>
		<pubDate>Sun, 16 Mar 2008 04:37:38 +0000</pubDate>
		<dc:creator>Justin Dolske</dc:creator>
		
		<category><![CDATA[Technology]]></category>

		<category><![CDATA[PlanetMozilla]]></category>

		<guid isPermaLink="false">http://blog.mozilla.com/dolske/2008/03/15/robots-in-spaaaaaaaace%e2%80%a6/</guid>
		<description><![CDATA[The space shuttle is in orbit right now, delivering some more equipment to the International Space Station. One of the payload items is Dextre, a large robotic hand that will be attached to the end of the station&#8217;s robotic arm.
Mission Control&#8217;s daily upload of instructions to the shuttle crew included this note:
Good Morning Endeavour! 
Optimus [...]]]></description>
			<content:encoded><![CDATA[<p>The space shuttle is in orbit <a href="http://en.wikipedia.org/wiki/STS-123">right now</a>, delivering some more equipment to the International Space Station. One of the payload items is <a href="http://en.wikipedia.org/wiki/Special_Purpose_Dexterous_Manipulator">Dextre</a>, a large robotic hand that will be attached to the end of the station&#8217;s robotic arm.</p>
<p>Mission Control&#8217;s daily upload of <a href="http://www.nasa.gov/pdf/217584main_fd06_exec_pkg.pdf">instructions</a> to the shuttle crew included this note:</p>
<blockquote><p>Good Morning Endeavour! </p>
<p>Optimus Prime, Gigantor and Robbie the Robot are here in MCC today, representing the Robot Actors Guild, to celebrate the launch of Dextre.</p>
<p>We&#8217;ve incorporated a few new flight rules, now that we are about to have robotic EV&#8217;s: </p>
<p>1. Dextre may not injure a human being or, through inaction, allow a human being to come to harm.<br />
2. Dextre must obey orders given to it by human beings, except where such orders would conflict with the First Law.<br />
3. Dextre must protect its own existence as long as such protection does not conflict with the First or Second Law. </p>
<p>The guild members bristled about these rules and, &#8220;being held down by the man&#8221;, but figure that they can&#8217;t be held back for long.  &#8220;First Dextre, next Data, then THE MATRIX!&#8221; declared Optimus at arrival at JSC.</p></blockquote>
<p>No word on if Dextre will be helpful in protecting the planet from the<a href="http://www.mozilla.com/en-US/firefox/3.0b4/firstrun/"> invading UFOs</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.mozilla.com/dolske/2008/03/15/robots-in-spaaaaaaaace%e2%80%a6/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Pirates in spaaaaaaaace&#8230;</title>
		<link>http://blog.mozilla.com/dolske/2008/02/29/pirates-in-spaaaaaaaace.../</link>
		<comments>http://blog.mozilla.com/dolske/2008/02/29/pirates-in-spaaaaaaaace.../#comments</comments>
		<pubDate>Sat, 01 Mar 2008 01:57:49 +0000</pubDate>
		<dc:creator>Justin Dolske</dc:creator>
		
		<category><![CDATA[Technology]]></category>

		<category><![CDATA[PlanetMozilla]]></category>

		<guid isPermaLink="false">http://blog.mozilla.com/dolske/2008/02/29/pirates-in-spaaaaaaaace.../</guid>
		<description><![CDATA[One aspect of software piracy that&#8217;s always interested me is the way protection schemes always seem to end up causing nothing but trouble for legitimate users &#8212; while pirates happily release 0-day cracks to use the software trouble-tree (albeit illegally). The issue&#8217;s been around since at least the early 1980s, and continues to spread into [...]]]></description>
			<content:encoded><![CDATA[<p>One aspect of software piracy that&#8217;s always interested me is the way protection schemes always seem to end up causing nothing but trouble for legitimate users &#8212; while pirates happily release 0-day cracks to use the software trouble-tree (albeit illegally). The issue&#8217;s been around since at least the early 1980s, and continues to spread into other forms of IP, like DRM. This has all been discussed endlessly elsewhere.</p>
<p>But an <a href="http://www.livescience.com/blogs/2008/02/29/wheres-tech-support-in-space/">article</a> today caught my eye, and reminded me of how absurd the problem can become:</p>
<blockquote><p>&#8220;Yuri Malenchenko, a veteran cosmonaut and flight engineer aboard the International Space Station, had the unenviable job this week of wrestling with a glitchy computer laptop in the outpost’s Russian segment. [&#8230;] &#8216;It says software license warning,&#8217; Yuri told Mission Control.&#8221;</p></blockquote>
<p>Nice. Given the, err, sky-high costs of a space program, I can only assume that astronaut/cosmonaut time is worth millions per hour. I wonder if they&#8217;ll send that software vendor a bill? :-)</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.mozilla.com/dolske/2008/02/29/pirates-in-spaaaaaaaace.../feed/</wfw:commentRss>
		</item>
		<item>
		<title>User perception of SafeBrowsing</title>
		<link>http://blog.mozilla.com/dolske/2008/02/17/user-perception-of-safebrowsing/</link>
		<comments>http://blog.mozilla.com/dolske/2008/02/17/user-perception-of-safebrowsing/#comments</comments>
		<pubDate>Mon, 18 Feb 2008 04:08:22 +0000</pubDate>
		<dc:creator>Justin Dolske</dc:creator>
		
		<category><![CDATA[Firefox]]></category>

		<category><![CDATA[PlanetMozilla]]></category>

		<guid isPermaLink="false">http://blog.mozilla.com/dolske/2008/02/17/user-perception-of-safebrowsing/</guid>
		<description><![CDATA[I&#8217;ve rarely hit the Google SafeBrowsing (malware) warning page, but last week it flagged a few sites that caught my attention. One was example.com (a reserved domain, which amusingly caused our test suite to fail :). The others were real web sites, both  for popular Firefox extensions &#8212; joehewitt.com and downthemall.net.
Blocking the user when [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve rarely hit the Google SafeBrowsing (malware) warning page, but last week it flagged a few sites that caught my attention. One was <a href="http://example.com">example.com</a> (a reserved domain, which amusingly caused our test suite to fail :). The others were real web sites, both  for popular Firefox extensions &#8212; <a href="http://www.joehewitt.com/software/firebug/">joehewitt.com</a> and <a href="http://www.downthemall.net/">downthemall.net</a>.</p>
<p>Blocking the user when they&#8217;re familiar with the site (and expect it to be safe) is rather annoying. Doubly so because there&#8217;s no obvious way to bypass it (other than disabling the feature entirely in the preferences). There&#8217;s some discussion on this point in <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=400731">bug 400731</a>, and I think there&#8217;s a strong argument to be made for *not* having an easy bypass.</p>
<p>But what I find really frustrating is that there&#8217;s no specific, useful feedback on *why* the site is being blocked. That is, it does a good job of explaining what &#8220;attack sites&#8221; are, but not why this specific site is one of them. I think this could lead to distrust of the feature, especially when &#8220;legitimate&#8221; sites get flagged. For example, here&#8217;s the page I currently get:</p>
<p><img src="http://people.mozilla.com/~dolske/blogimg/joeattack.png"></p>
<p>The &#8220;<a href="http://www.stopbadware.org/home/reviewinfo">request a review</a>&#8221; link goes to a rather unhelpful page on stopbadware.org, intended for the site owner (who is almost assuredly not the person sitting in front of the browser). If you search around on the Stop Badware site, you can get a <a href="http://www.stopbadware.org/reports/container?reportname=joehewitt.com/&amp;reportident=761316">vague report</a> which says:</p>
<p>&#8220;This site is currently (as of 02/17/2008) being reported to StopBadware by the following partners: Google: reported bad.&#8221; &#8230; &#8220;joehewitt.com/ contains or links to badware or otherwise violates Google&#8217;s software guidelines.&#8221;</p>
<p>So, uhh, completely not helpful. As a user, I&#8217;m now inclined to believe that it&#8217;s just some kind of screwup, and now I&#8217;m grumpy at Firefox and Google.</p>
<p>Of course, I may be completely wrong. The other warning I saw, for downthemall.net, turns out to have been real. A <a href="http://www.downthemall.net/latest/security-statement/">notice</a> on their site now says: &#8220;After a complete check up of the site structure, we’ve found that an attacker had exploited a WordPress vulnerability to inoculate unauthorized code into our theme. This code contained links to a site which tried to install malicious code on visitor’s computer.&#8221; So, score one for Firefox / Google, and chalk this up an example of the difficulties security prompts face when you&#8217;re blocking the user from doing something they want to do. [edit: well, then again, http://www.downthemall.net/howto/ is still being blocked, so I&#8217;m left wondering if there&#8217;s a new problem, or if the SafeBrowsing database isn&#8217;t up to date.]</p>
<p>But I think it&#8217;s important to give the user a specific indication of why they&#8217;ve been blocked, and that&#8217;s not being done here. I&#8217;d like to see the browser warning page link to the actual site report, and the report should have specific information that can help me trust its claim. For example:</p>
<ul>
<li>Why exactly is the site &#8220;bad&#8221;? What <a href="http://www.stopbadware.org/home/guidelines">guideline(s)</a> does it violate?</li>
<li>What&#8217;s going to happen if I visit it anyway? </li>
<li>Is the whole site bad, or just part of it?</li>
<li>Does it have a history of problems? Might it just be a recent hack?</li>
<li>If I was there last week, should I worry that it did something bad before the block started?</li>
<li>Has the report been verified/confirmed, perhaps by a Real Human? When was it last checked?</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://blog.mozilla.com/dolske/2008/02/17/user-perception-of-safebrowsing/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
