Monday, June 23, 2008

The Mac I want

I want a Mac.

Not for any particular reason, I just want one, because I want one.

Of course I do have other reasons:
  • I want one, because I pride myself in being proficient and current in most common operating systems, and I have barely used OSX at all.

  • I want one because I want to play with various other Apple technologies (like the iPhone SDK, which might actually get me interested in writing code again for the first time in years), and in many ways a Mac is the best way to do that (or in some cases, the only way).

  • I want one, because they are very well designed, and have excellent support.

  • I want one, so I can teach the kids Mac, Linux, and Windows; so they know all the major computing platforms (if you learn Linux, the other UNIXen are an easy pickup).

  • I want one so that if I have Mac people over to the house, they'll have a comfortable environment to work and play on.

  • I want one for photo, video, and sound editing.

    Although Windows and Linux do a good job with it (now), Macs are still the standard platform for most professionals, and it's always useful to be able to do work on the same platform as the guy sending you files to review.

    Oh and I'd really like to be able to do BluRay authoring on it.

  • I want to be able to do recovery, analysis, forensics, and security work on Macs.

    Though I have Windows, Linux, BSD, and Solaris to do it with (and I do, mostly on Linux), I don't have any Macs to do that sort of work with. There's a lot you can (and should) do on a platform other than the one where the drive came from; but for some things, you really need to do the work on the native platform.
But mostly, I want one just because I want one.

The problem is though, Apple doesn't make the Mac I want; and I think there's a LOT of folks out there who could say the same.

For years, Apple followed the strategy of having three desktop Mac model lines; a low end home/kid/housewife/grandma model, a midrange model, and a high end model for power users and professionals.

When the iMac came out, Steve Jobs switched them over to a "Four Corners" model, where they had a low and high end lines for desktops and laptops. These positions were covered by the iMac and the PowerMac (now MacPro) on the desktop side; and the iBook (now MacBook), and PowerBook (now MacBook pro) on the laptop side.

At the same time, Apple experimented with bridging the gap with various products; but they did it kind of half heartedly.

First they put out the PowerMac cube, which although gorgeous, was mis-marketed and had heat problems. Those issues were solvable however, if Apple had been serious about it; or is Steve Jobs could ever once accept that he screwed up in product conception.

They weren't, and he wasn't.

The real problem with the cube, was that it was neither fish, nor fowl, nor good red meat. It mid-range computing power, but almost no expansion; and yet it was priced as an upper midrange machine (where people expect higher power, and expansion capabilities).

Yes, style sells computers, but it doesn't sell mid-range computers unless there is a fair bit of substance behind them. Basically, the people who wanted midrange machines, also wanted expansion. They wanted to be able to tinker, and they wanted to be able to extend the life of their machines with upgrades.

After the cube, Apple decided they'd figured out where they went wrong. Unfortunately, they were wrong there again.

By this time, iMac sales had slowed dramatically. In fact, with the "sunflower" iMacs (the iMac with the LCD on an upside down flowerpot base), they had started moving the features out of the low end, and the price had climbed to match. This basically took the bottom out of iMac sales entirely; because once again, you were buying a mid range priced machine, with just barely midrange specs, and no expandability.

Given this market situation, Apple did something which puzzles me to this day. Rather than refocus the iMac back to its low end roots, they they moved the iMac upmarket, turning it into a true midrange machine (at mid range prices) and a "lifestyle accessory".

To make up for the low end, they introduced the eMac (supposedly for educational sales, but they mostly went to former iMac buyers), which was basically an updated version of the 1998 iMac. This left Apple without a REAL system for the low end market position; because the eMac was never really a serious product, more of a placeholder.

Finally, in '06 Apple introduced the MacMini, with roughly similar specs to where the iMac would have been before the change to mid-range had it been release that year; except of course without a display, keyboard, mouse, or speakers. Most importantly though, they did it at the lowest price ever for a mac, at $499.

The only problem with that is, they went TOO low end. Not that the price wasn't great, but they shot very low on the specs; and they had spent the previous two years marketing Macs as midrange lifestyle accessories, and high end "supercomputers".

Honestly though Apple wasn't really interested in selling the MacMini. They barely marketed it at all, and when they did, they didn't know how to sell it. They didn't want to compete with the supercheap walmart PCs, though with their pricing and support and upsell opportunities, this would be ideal position to be in; "Look, you can buy that cheap piece of crap, or you can spend $100 more and get this beautiful tiny little box that's better, and has real support". They didn't want to try and sell it upmarket any either though, because that might hurt iMac sales.

The reason for targeting the mini this way puzzles me, because they don't want to sell to the super-low end; but yet they STILL don't have a real midrange machine, that has any expansion or tinkering capabilities.

If you're going to do a desktop Mac, why not just make the Mini 3 or 4 times the height (it would still be smaller and prettier than anything that sold with Windows on it), use cheaper but faster desktop components rather than the slower and more expensive laptop components, leave room for a PCIe slot or two, and an extra hard drive bay. It would actually cost LESS to make than the mini does currently, and you cuold sell it for more.

Or hell, if you're really committed to the mini, sell both; and rename them the Mini (for the medium sized one), and the Nano (for the current mini).

Even better, if you're REALLY committed to the Mini, put a faster processor and a bit more RAM in there, the biggest laptop hard drive they make, make the onboard sound decent (with an optical output), replace the cheezy integrated video with something that will do on board video compression and decompression, and add HDMI video input and output. You'd sell one to every home theater enthusiast in the world, and to half the videographers, SFX people, multimedia show presneters etc... (as a portable video workstation).

...Oh wait a sec, they already did half that with the Apple TV; why not just go all the way with the Mini and sell it as the natural big brother?

Seriously, once they've captured all the "lifestyle accessory" sales they're going to get for the iMac; they're still selling a midrange priced and powered machine, without the features that a midrange buyer wants (unless they specifically want an all in one machine). For the MacMini, they've pretty much marketed themselves out of the supposedly intended market position by making people think of the Mac as either a lifestyle thing, or a supercomputer.

So who bought the mini? Mostly PC users who wanted to mess around with Macs, and Mac laptop owners who wanted a desktop too.

So as far as I'm concerned, right now Apple is aiming too low with the Mini, too high with the iMac, and WAY too high with the MacPro.

As of right now, there are three basic Mac models in the product line:
  • The Mac Mini, with up to a 2ghz dual core processor (1.8 base), a max of 2 gb RAM (1gb base), integrated video, integrated DVD burner, and a max of 120gb hard drive. The only upgradeable or changeable component (in theory) is the memory; though people not concerned with Apple warranties have put in larger hard drives, and faster processors. Base price is $599, fully optioned up, it's about $950.

  • The iMac, with up to a 3ghz dual core processor (2.4 base), up to 4gb ram (1gb base), up to a 1tb hard drive, integrated DVD burner, decent discrete video; and of course a 20" or 24" LCD. Again, theoretically the only thing upgradeable is the ram, but actually you can upgrade everything but the video card pretty easily. Base price is $1199, fully optioned up, it's about $2700.

  • The Mac Pro, with up to 2, 3.2ghz quad core processors (yes, 8 cores. A single quad core 2.8 is base), up to 32gb of ram (2gb is base), up to 4, 1tb hard drives (a single 320gb is base), and a decent industry standard PCIe video card (or as many as 4). Expansion is virtually unlimited. Base price is $2299, up to about $20,000 fully optioned up ($9,100 of that is ram, and $2100 of that is to go to dual 3.2ghz processors).
The MacPro is a tremendous beast of a machine. With a 64 bit (mostly) UNIX based operating system behind it, the serious horsepower of the hardware, and the excellent expansion capabilities; it's a spectacular machine for any purpose you would want to put a Mac to... Of course it's also spectacularly expensive. The base price is $1000 more than the base price of the iMac (and that's without a display. Add one, and you're talking about another $600) and we won't even talk about the optioned up price.

Frankly, the MacPro is overkill. It's far more than anyone but the most hardcore users would need; and costs far more than anyone but a complete mac fanatic, or a professional working in sound, video, or graphics production could justify. They don't call it the "Mac Pro" for nothing.

The MacMini has been a market failure; but I think it's a good little box, and for an Apple, it's at a good price. It is a reasonably capable machine for what it is, which is basically a low-midrange laptop, crammed into a very tiny little case. It's gorgeous, and tiny; but it's only got a small hard drive, limited RAM capacity (the motherboard and processor could support 4gb but Apple deliberately limts it to 2), integrated video, and nothing can be upgraded. Your sum total expansion possibilites consist of 4 usb and a single firewire port.

At $499 and $599 for the two models, the Mini would still be a great deal actually, but at $599 base, and $950 optioned up, with no expansion or upgrade capability... and like the cube, it's neither fish, nor fowl, nor good red meat.

Clearly, the iMac is a midrange machine in terms of equipment specification; and it is an excellent system (though I think overpriced), but it's all integrated everything, including the display. No expansion, no upgrade, you get what you get.

This is a machine for people who want a sleek, and compact form factor (it's essentially a flat panel LCD with a thick case); and don't care about expansion. That makes it great for moms, and office workers, and students in non science/engineering fields etc... but once again, where's the true midrange offering.

Do you see the holes in market position?

Why can't Apple?

I go back to my previous statement; the people who want and need midrange machine also need expansion and upgrade capabilities; and they want to tinker.

Look back to what I want to use my Mac for and think about what I want and need.
  • A fast processor, but not high end server class, that I can upgrade
  • A fair bit of memory, that I can upgrade
  • A lot of storage, thats reasonable fast
  • Great video
  • Great audio
  • The ability to add and change hard drives
  • The ability to add and change optical drives
  • The ability to add and change primary video cards
  • The ability to add and change other PCI cards, like video capture cards, and HDTV tuners
Now, I can do all of that in the MacPro, but at a base price of $2300, it's just not worth it; especially given that all but the lowest end Wintel PCs let me do all of that.

Very specifically, here's what I want in my Mac:
  • 1x processor socket, with support for up to Core 2 Quad, and several processor options
  • 4x RAM slots, with support for 2gb dimms, and maximum of 8gb ram
  • 2x PCIe x16 slots, for hardcore video if I want it
  • 1x PCIe x8 or x4 slot for other PCIe cards
  • 2x PCI slots (because most IO cards are still PCI)
  • 2x 3.5" hard drive bays
  • 2x 5" external bays for optical drives
  • A good looking (or concealed) media card reader,; and front panel audio, USB, and firewire
  • Either the cheapest possible PCIe card, or cheap onboard video
  • Onboard surround sound, with analog and digital inputs and outputs
  • I'd love a BluRay option, but a DVD burner standard is a minimum
  • I'd love an HDTV tuner and video in/DVR option; and an HDMI output
  • Integrated bluetooth
  • Integrated 802.11n wireless
  • Integrated Gigabit ethernet
  • A really nice toolless case, with good cooling, and excellent sound insulation
You might note something with those specs... They're exactly what every other mid/high end PC on the market has. In fact, they're basically the same specs as my main desktop, and my wifes main desktop (we both have BluRay, but neither has wireless N, or Bluetooth built in)

Why isn't Apple doing this? It wouldn't cost them anything, except maybe a bit of pride.

Given the marketing position it wouldn't hurt MacMini sales, and I doubt it would cannibalize the bottom end of MacPro sales. You could sell them for $1000 to $2000, capture a huge market segment, and not lose a dime off the iMac or MacPro

Seriously, if Apple offered something like that, I'd buy it up in a heartbeat. In fact, as of today, I can buy a generic PC configured as above; and presuming I choose the right components (for driver support) put OSX Leopard on it with the help of the hackintosh community. I can even pay a company called Psystar to do it for me at a base price of $1000, and fully optioned up price with a quad core, and 8 gigs of RAM, at about $1500 (they also offer low end models starting at $399).

The only reason I don't do this, is because at any moment, Apple could decide to change their software to completely break all of these unsupported hacks, and then I'd be up the creek (of course I could still use the hardware for windows or Linux, I'd only be out the cash I ponied up for Mac software).

... Well, not quite the only reason. I also want a REAL MAC. I want the excellent support, and I want the well designed case, and I want the "EVERYTHING JUST WORKS" factor going for me.

Until Steve sees the light and gives me what I need though, at best I'm going to use a hackintosh to play with, or maybe ebay a cheap MacMini.

Thursday, June 19, 2008

Why I buy HP

Hewlett Packard is the number one vendor of printers and scanners in the world; the number two vendor of desktops (behind Dell), the number two vendor of servers (also behind Dell)...

They're big stuff so to speak.

They also do a lot of trading on their name, and reputation; and as such, they charge a bit more than say Dell... which is why they are number two, to be honest.

Now, in terms of desktops and laptops; and sadly to an extent servers (since Carly Fiorina took over, HP service went WAY down hill); I don't think the superior reputation is entirely deserved, at least not anymore; but if there is one area of business where HP is still the top, is printers.

Honestly, I just won't bother buying a printer other than an HP, and here's why.

I've got this $499 super duper HP top of the line all-in-one printer, fax, scanner, and copier...

It's a great printer
... and it's a great copier
... and its a great scanner

Thing is though, I already have a great HP printer and a great HP scanner; and between the two, I have a half decent copier.

Unfortunately, what I don't have, is a working fax machine; because there's some kind of firmware problem on this particular printer; and you CAN'T FLASH THE FIRMWARE IN ANY WAY.

Seriously, it's a $500 network printer with its own Linux based print, fax, and web server(which is why I bought the thing by the way, so I could use network faxing) but you can't flash the firmware.

That makes absolutely no sense to me. It's insane; and with most vendors this is where I'd be telling you that it's the reason I won't be buying from them again.

From HP though, it leads directly to the reason I prefer to buy HP.

They're sending me out a new one, tomorrow morning, fed-ex, for free, with no hassle or argument.

That right there, is the reason I buy HP.

Even though I called at 9pm; I was on the phone with the support guy within minutes (actually, less than a minute after choosing printer support; but it took me maybe 2 minutes of IVR navigation to get there), and he was a native English speaker, talking to me from Portland.

The support engineer understood my problem immediately, and understood what steps I had already taken to attempt to resolve it. He agreed right off the bat, that the problem was almost certainly the firmware, and that he would probably have to replace the box; but just to get authorization he had me try one single maintenance procedure. When that one procedure didn't work, he immediately shipped me out a new printer, fed-ex.

It would be here Friday, but for the fact that I called after 6pm (I actually called them at 9pm); so instead it will be here Monday (though for an additional $30 I could have had it overnighted).

Note, I don't have to ship them the printer first, or drop it off at the depot; they're shipping me a new printer (ok, factory refurbished, but I don't care), and I'm sending the bad one back in the box they sent the new one out in.

Note also, that I didn't have to buy a special extended warranty to get this level of service; this is HP's standard "TotalCare" warranty for their printers (at least the ones that cost more than $100 anyway; I don't bother buying cheap printers, they aren't worth replacing the ink cartridges on).

Any other company, I would have been on hold for 30 minutes, only to be transferred to "Jeff", out in Bangalore...

... an aside to all those companies who offshore customer support like that: Telling the Indian guy to lie to us and say his name is "Jeff", when we KNOW he's an Indian guy in Bangalore who statistically is likely to actually be named Sunil, Rajesh, Kumar, or Muhammad (1/3 of all Indian males have one of those as part of their name. I work with a half dozen Sunils on a day to day basis); it doesn't make us feel better about talking to them, it just insults our intelligence...

Once I finally got to talk to "Jeff", he would completely ignore everything I had done, and my description of the problem, and eh would take me through his script. This isn't actually designed to SOLVE my problem, but to get rid of me in the most expeditious way possible. After being led through at least a half hour of useless BS, he would then fight me for 30 minutes, trying to get me to accept some solution other than replacing the box; or perhaps to accept that it wasn't their problem at all.

Instead, I spoke with a pleasant man in Portland, actually named Jeff; who sent me a new printer right away without arguing.

Personally, I'd say that's worth the extra few bucks.

Wednesday, June 18, 2008

The Hero With a Thousand Virgins

From the UK Telegraph:
Richard Danzig, who served as Navy Secretary under President Clinton and is tipped to become National Security Adviser in an Obama White House, told a major foreign policy conference in Washington ...

.. how American troops, spies and anti-terrorist officials could learn key lessons by understanding the desire of terrorists to emulate superheroes like Luke Skywalker, and the lust for violence of violent football fans.
Actually, though the presentation of the idea is ridiculous, he is in fact entirely correct.

The primary motivation these idiots have is to be known as an epic hero. Luke skywalker is a modern iconic representation of the Campbellian "hero with a thousand faces".

You have to remember that Islam, especially Arabic Islam, is a storyteller culture; where the iconic hero is the central figure. All of Arabic, and Islamic cultural history revolves around these central figures; be they conquerors or martyrs.

On the one side of things, their lives are utter garbage. Poverty, crime, corruption, no societal mobility, no opportunity for advancement or personal fulfillment, no opportunity to express themselves personally or sexually (never underestimate that power and frustration, especially in young men) and an overall excess of young males, and shortage of young females.

On the other side, is this opportunity to be revered as a hero. To end your pain and suffering, and be rewarded for it beyond compare in paradise, by the direct will of god.

It's no wonder that so many prefer blowing themselves up, to living their real lives.

Mulsim terrorists want to be known as Saladin, or Charlegmagne, or Henry V, or Achilles; rather than as Achmed, the man who died of dysentery in a "refugee camp".

The reason why westerners don't "get it", is because to us, legends and myths are just that. To a Muslim, the legend is as real as if he was standing there in the room with you.

To us, the Greeks and Romans are off in antiquity; to the Muslims, Mohammad and Saladin are yesterday, today, and tomorrow.

They really believe their own bull.

This is why liberals are always so sympathetic to the muslims, who so clearly state that they want to kill all the homosexuals, and adulterers and blasphemers. The liberals don't understand that THE MUSLIMS ACTUALLY MEAN WHAT THEY ARE SAYING, AND THEY ACTUALLY BELIEVE IT.

It honestly does not compute in the liberals brain that these statements could be serious. They dismiss them as nothing but posturing and rhetoric, because after all, no-one could actually MEAN those things, or REALLY believe in that enough to die for right?

Of course the same mis-understanding applies between liberals and conservatives; especially those of us who served.

We couldn't possibly actually believe that stuff about honor, duty, and country right? I mean why on earth would anyone risk their life for an idea? You must be doing it because you don't have any other choice, or because you're stupid, or you've been deluded by the propaganda machine or something... because no-body really does that, nobody believes that... right? It's just rhetoric, and you're all just hypocrites.

Except that most of us aren't.

That simply does not compute. Their belief system does not allow for the fact that someone could hold such strongly and deeply held beliefs contrary to their own, that once the offending parties were "convinced of the truth", they wouldn't come around; unless those people already knew that they were wrong, and were just pretending to disagree to gain advantage.

No, I'm serious, this is actually what they believe... and that folks, is just as dangerous in the long run as what the Muslims really believe.

My PGP Public Key

In keeping with the previous post on cryptography, here's my PGP public key.

Presuming you trust me to be the actual Chris Byrne, and a published entry on my blog to be a verified means of transmission, you should be able to sign this as a valid and trusted key.

-----BEGIN PGP PUBLIC KEY BLOCK-----
Version: GnuPG v1.4.7 (MingW32) - WinPT 1.2.0

mQGiBEhYcQ8RBACVF1gUAU90+OUu7UswLM1aCJ4/tCBKahiu+wX29U4vC47PstqW
Cw4MkbboqTTQgipXHx/JJYqiEMhna0HRqj/8ueRxMFx/lL5UAAavcLcX8jNexc+Q
AWuJR6GwfJ85mO8FE7F4YP7kwnby7JWqDyOOmbb9zFFz7niIxe3FrvBCVwCg3PDs
2Pz0Vln0j4QtJfg3DyimiYEEAJIqwzj05uULn2+NEAoCOQpC0+x0SVCiD0AKQZFD
VOkOIKBaA7tguU9gjzhbkfAM3xyYPTsZj6vmheP+/IQOtxUDsUGBDCWFHYznt1gh
/hDKSzozFfPePomLrwoC8bu4SblDpZbqvzMr20M78vOBiz8hYNUptjaqQ1poDmn2
YOQ+A/9U/RyTNpm2ftdfa4fQM686AdIBCb7YJ47P+Wln2I6mPl8f/aELPkmqDoQ/
/bwz5kkw0sQkUPLg88viEkKVzj9jMoz5djGPN/LReAzkG+QHhNlm/NPzXmy2+VS+
62dNfTw9pld9EvZFJMSUzUGs542B7u7eDfgAR4VbBVqE2+0x2bQuQ2hyaXN0b3Bo
ZXIgSi4gQnlybmUgSVYgPGNieXJuZWl2QGhvdG1haWwuY29tPohgBBMRAgAgBQJI
WHR4AhsjBgsJCAcDAgQVAggDBBYCAwECHgECF4AACgkQ6vkNwN2ltGdJqACeI+TF
T4u8UFu2kCwRvQ6sTZRptosAoNa/45xQcHDOB382vzEohUzEUFS/tC5DaHJpc3Rv
cGhlciBKLiBCeXJuZSBJViA8Y2hyaXNAY2hyaXNieXJuZS5jb20+iGAEExECACAF
AkhYcQ8CGyMGCwkIBwMCBBUCCAMEFgIDAQIeAQIXgAAKCRDq+Q3A3aW0Z0B7AJ9v
CswUv/aDR6vXGMOD5hbfYPtOLQCcC6rBlucu7SxvnySieGNmcRg6oKq0LENocmlz
dG9waGVyIEouIEJ5cm5lIElWIDxjYnlybmVpdkBnbWFpbC5jb20+iGAEExECACAF
AkhYdI0CGyMGCwkIBwMCBBUCCAMEFgIDAQIeAQIXgAAKCRDq+Q3A3aW0Z/iDAJwN
rCErtf/7dk/uoxUj4gUaneZFjgCgriTuXXSsZ/MTdtLGZ0m/P3cedLW5AQ0ESFhx
DxAEAMHBo+j3KrC7Xng1JMe7ksTJQcU7Y/9nhCB0K4RgQlALxVXHvwFmxJS9nLTl
rF6WdRw9Y7ZtDRCqAwhIkih+KQ8hnpleIjetXfQw7onU88oBtqmLRwzfNV4zEMDn
1bA59Nn1/eAJWqoKy0CMQ7S/gSQ5oJIJDsRYUIApJ0FV1X+zAAMFA/0XX+b74xIX
UbV+yaqdqoAerNU7lMoQ/1bPFHpPOlz+XQJQZ/OS32R0qGIiXOcgIxLFc6ykU3K+
nfpPRjsjYC6xliYutC9Mlw+UB4vzWNeBnwhvaV1U3A6NrecT68VCByLgN5rx089N
dxvFnOVvIMBTjCMDUy5xptgU9ujqwLQfZIhJBBgRAgAJBQJIWHEPAhsMAAoJEOr5
DcDdpbRnJ2sAmwYecSBN1BxcObDZ54PjtQAwBvUhAKCJqjqogyU1IaG69KFBQ7Gu
PSSlHA==
=a8FN
-----END PGP PUBLIC KEY BLOCK-----

Cryptonomicon - Part I

So, I mentioned in an earlier post, that I'd lost my PGP private key and keyring; and that this was kind of a major irritation for me. Now it's time to explain, in excruciating detail, what that is, and why it's important.

First things first, what the heck is PGP?

PGP stands for "Pretty Good Privacy", an encryption and key management scheme (and associated utilities) written by Phil Zimmerman (A.K.A. PRZ); based on the earlier work of Whitfield Diffie, Martin Hellman, and Ralph Merkle, on something called "public key cryptography".

PGP was published over government objections in 1991. It's a great story really. The feds spent 5 years trying to put PRZ in jail for exporting controlled weapons (which is what they classified encryption as), failed miserably, and he eventually moved to Ireland (I think he's back in the U.S. now).

It's safe to say that PGP, in one implementation or another, is the most used interactive encryption software in the world. I say "interactive", because just about every web browser has SSL encryption software built in (which is a similar, but different encryption scheme), but most people never interact with it specifically; they just know that when they type in HTTPS instead of HTTP, and the little key or lock shows up in the browser, that they are "secure".

In my particular case I use GPG, the free and open source GNU implementation of PGP; both because it's free and open source, and because there are versions of it for every operating system I use (and pretty much every OS I don't use as well).

There is also a commercial implementation of the PGP standard, called simply enough, PGP (though the fact that they named the software after the standard confuses people as to whether they "really have PGP" if they don't use the "Official" commercial version); as well as numerous other implementations, both free and commercial, and plugins for other applications etc...

Theoretically, all of these different implementations should work together, because they all implement the same standard; though sometimes (frequently?) incompatibilities can pop up; especially between the open source and commercial implementations.

As I mentioned in passing above, PGP is what is called a "public key cryptography" scheme; and it works pretty simply in concept (though the math behind it is complicated).

The basic idea behind it, is that when two people want to talk to each other securely, they shouldn't have to know or trust each other first.

... Now there's a logical leap that many people seem to have a problem making; and in order to talk about it, we need to talk about what exactly cryptography is, and a bit about how it works.

At it's most basic, cryptography is (literally, from the greek), "secret writing". It's any means of writing a message in a way that is meaningful to those with the knowledge to understand it, but meaningless to all others.

Now, there are a heck of a lot of ways of doing that, but they almost all break down into two basic categories, ciphers and codes.

A code is a way of making writing secret by using symbols. A red Octagon is a way of writing "stop" in code for example, as is the sequence ... - --- .--.

The symbols of a code can be anything, pictures, shapes, sounds, even numbers or letters. The most well known code (at least that we explicitly think of as a code) in the world is probably Morse code (as above) where dots and dashes represent number and letters. Another one that is commonly known, is the admiralty radio code, also called the "Q code", where entire paragraphs can be expressed as groups of three letters, (that are convenient to tap out in morse code).

The important part is that each symbol has meaning, but that meaning isn't understood by someone who doesn't know the code. So in Q code, the letters "QRN" aren't spelling any meaningful word; but if you know the code, you know they mean "I'm having trouble understanding you because of radio interference".

Of course most people don't think of these as codes in the cryptographic sense (and in fact there is an entire academic field of study about symbology and the representation of meaning, that has very little to do with cryptography, called semiotics); I'm just using them as an example to illustrate the point.

Generally, when people think of cryptographic codes, they are thinking more along the lines of codebooks; which are kept secret, and which usually have groups of letters and numbers which are used to represent other words, letter, numbers etc...

Again, the important part here is that each symbol has a distinct meaning that it represents, which is not apparent to someone who doesn't know the code. So the code 999 doesn't mean nine hundred and ninety nine; it actually means "Oh god, Oh god, we're all gonna die".

Ciphers are a completely different way of making writing secret. Instead of using symbols to make things secret, they use math.

Putting the difference more simply, if a bit obscurely, code is representational, ciphers are transformational... or perhaps more clearly, codes translate, ciphers transform.

Huh?

Codes translate symbols; like from one language to another. In a code, the meaning is there in the symbols, you just can't understand it without the code book; much as you can't understand Urdu without a phrasebook. If I say salgirah mubarak, you don't know that it means "Happy Birthday" in Urdu.

Critical to understanding the difference between codes and ciphers though, is understanding that just because you don't know the meaning, doesn't mean the symbols have no meaning.

Ciphers TRANSFORM, not translate; so each individual symbol of the enciphered text (actually called ciphertext) has no actual meaning, without the cipher, and the ciphers key.

The ASCII octal code sequence 062060060070 always means "2008", even if you don't know the code and can't read it; whereas the ciphertext 062060060070 is completely meaningless without the math.

I realize that the distinction there is lost on some, but trust me, it's important.

From a strictly practical standpoint there is a huge difference: A code has to have symbols representing everything you want to say, or a way of making up new symbols built into it; a cipher doesn't, because there is no meaning to any particular symbol, it's all just math in and math out.

Ok, so that's what cryptography is, and what ciphers are specifically. Now, how does it work?

Well, there's a couple elements here:

First, you need a cipher; which is any algorithm (an algorithm is any process of applying structured transformation to any set of information) designed to make information secret.

Second, in what most people think of as "conventional" cryptography, there has to be what is known as a pre-shared secret, or pre-shared key, often referred to by the acronym PSK.

So, let's say two parties want to communicate securely. Those two people decide to communicate using a cipher, they decide on the cipher, and they decide on the key for the cipher.

Remember, the cipher is the math itself; the bit that actually makes the writing secret. The key, is that part that lets two people use the same cipher that other people are using, without anyone else who knows the cipher being able to read what you wrote. I can tell the whole world I'm using AES encryption, and not worry that they'll be able to read my messages; because the key is secret, the cipher doesn't have to be.

There are of course ciphers without keys, but they are far less secure; and far less convenient.

To illustrate the difference, think of the simplest cipher everyone learns as a kid, the alphabet transposition cipher (also called a simple substitution cipher). You know, that's the one where A is 1, B is 2 and so on (in fact, this is so simple that it's almost a code, but in reality it is a mathematical transform, therefore a cipher).

Now with a simple cipher, anyone can read the message as soon as they know the cipher. With a keyed cipher though, you add in a unique element, so that someone who knows the cipher can't read your message, unless they know the key as well.

For example, knowing that I'm using a simple alphabet transposition, you know that "3,1,20" is "cat".

Let's use the same simple alphabetic substitution, but we'll add what's called an "offset vector", and that will be our key.

An offset vector is just a fancy way of saying "add or subtract this number to your result to get the real number"; so your key, is the number you add to each digit, to get the real message. In this case we'll add it to encrypt, which means we subtract it to decrypt. This is the simplest type of keyed cipher, and has been in use for thousands of years (the romans and greeks both used similar keyed ciphers).

So, for this example I'm going to use 3 as our key. Given the transposition cipher, and the key "3", you can decrypt the digits 7,18,10, as "dog"; by taking each number, and subtracting 3 from it, then transposing back from numbers to letters.

Importantly, you can't know what I've written, unless you know both the cipher, and the key; and in order for you to decrypt the ciphertext, I had to share the key "3" with you beforehand.

This is called "symmetric cryptography", because both parties are using the same cipher, and the same key to encrypt and decrypt it.

The problem with internet communications (or really any communications over a distance) is how do two parties agree to a pre-shared key, if they can't talk to each other in person? A phone could be tapped, someone could be reading the mail etc... (that's called a "man in the middle" attack, which I'll explain deeper later)

What about if one person wants to send secure communications to someone they don't know yet?

Well, the way around it, is not to actually send the keys over the wire; or for that matter, to ever communicate the decryption keys to each other at all.

Okay, but how can I decrypt what you send to me, if I don't have the key you used to encrypt it?

This is where what is called "asymmetric cryptography" is applied.

In asymmetric cryptography, we both agree on an encryption scheme, and a cipher, but we don't share decryption keys in advance.

Again this is where people start to say "huh?".

What we do is, we both come up with a pair of keys; which are mathematically related, but which can't be derived from each other (so if I know one of your keys I can't figure out the other one), . Then we use a cipher that lets you encrypt with one key, and let's me decrypt with the other key.

Remember, the keys are mathematically related, but you can't figure out one from the other. That's why this works... it's also why I said the math is complicated.

Ok, next part is, because of that split key thing, you can encrypt messages to me by having half of my key pair, and I can decrypt with the other half; and vice versa, I can encrypt to you using half of your keypair, and you can decrypt using the other half.

Different keys are used to encrypt and decrypt, thus "asymmetric cryptography".

So, it takes four keys instead of one; but now, I never have to send the key I'm using to decrypt your messages to me over the wire, and you never need to send the key you're using to decrypt messages sent to you.

Pretty neat eh?

Just one more step though. What if we don't know each other beforehand?

This is where what is called "Public Key Cryptography" comes into play.

So I explained that in asymmetric cryptography, each person generated two keys, and that messages were encrypted and sent to you using one key, and that you decrypted those messages using the other one.

Well, since you never have to send the decryption key to anyone, you can keep that secret; but you can give ANYONE your encryption key, because they can't decrypt your messages with it.

The "public" part comes in when you don't want to have to pre-share your encryption key. Again, because you don't need to keep your ENCRYPTION key secret (just your decryption key), and anyone can use it without contacting you first, presuming they can get it. If you want unknown parties to be able to send you encrypted messages without your prior knowledge, you can just publish your encryption key out to the world. That way any time anyone wanted to send you secured info, they can just look up your encryption key.

Of course the system works, because you have a public key that you publish to the world, and a private key that you keep secret. If you ever lost the private key, you wouldn't be able to decrypt messages people sent you with the public key; and if the private key is exposed, ANYONE can decrypt messages sent to you.

Now, that covers my public and private key, but what the heck is a keyring?

... and we're back to PGP again.

Put simply, a keyring is a list of, and copy of, all the keys you know and trust; formatted in a way that PGP can use them.

It's important to understand that PGP isn't the encryption keys, or the algorithms themselves; it's the scheme for how you use them all together.

What PGP does, is provide an agreed upon framework (a language and format if you will) for people to generate and manage keypairs; store, retrieve, and manage public keys in trusted way; as well as a standard way of negotiating encryption algorithms, and presenting data and keys to those algorithms, for encryption or decryption.

The whole thing forms what is called a Public Key Infrastructure, or PKI; which you may have heard somethign (possibly quite a lot) about; and which I will explain in a later post.

Part of that key management framework... in fact, just about the most important part; is a concept called "the web of trust".

The problem with a public key infrastructure, is that in order for it to be useful, everyones encryption keys have to be made public; and when you do that, someone can impersonate you by publishing an encryption key in your name. Unless you know who to trust, and what keys are valid; you can't send anything securely without first verifying the key with the person you want to send information to. The whole point of having the PKI, was so that you wouldn't have to do that.

That's where the "web of trust" comes in.

This is basically the idea that you may not know and trust that a key you got off the internet is valid for the real person you want to talk to; but you do know that your friends keys are valid, and they know that THEIR friends keys are valid and so on.

Ok, how does that solve the problem?

In the web of trust, each person designates any keys he knows are good, by cryptographically "signing" them with their own key (sign as in signature, not as in "detour"). Then, when you download a key off the net, you know it's good because you've signed the key, of a guy who signed the key you downloaded; and you trust the guy who signed the key.

Basically I trust Bob and Bob trusts Steve, so I trust Steve. Trust becomes a transitive property of the keyweb.

Yes, it's like VD. You're not just trusting your friends, you're also trusting everyone they trust, and everyone they trust and so on and so forth; so be careful who you trust.

Remember, one poison key that you sign as trusted, can poison hundreds or thousands(or in the case of important signers that LOTS of people trust, like public certificate authorities, millions) of other trust relationships, and make an entire portion of the web untrustworthy.

It all sounds much more complicated than it really is; and for the most part the system works; but those key relationships can get complicated.

This is why the keyring files are important. It's essentially a record of who I trust, and who trusts me; in the form of a copy of all the keys I've signed, a copy of the keys of everyone who has signed mine, and a copy of all the keys of people I've communicated with; as well as a list of keys I know to be bad or invalid.

All pretty important stuff.

Of course, if you lose your keys, you can always generate new ones; but that means you won't be able to decrypt communications sent using the old ones. More importantly from a web of trust standpoint, you won't know whose keys to trust unless you got the key directly from them, and no-one will be able to trust your key, unless they got it directly from you; because you wont have signed any keys as being valid, and no-one will have signed your key as being valid.

Cascading further, keys signed using your OLD key can no longer use that signature as part of their trust metric; but because you can't revoke a key without first having that key, no other member of the web can be notified that your old signature is invalid, except by manually updating them all individually.

This by the way is why personal keys should always include an expiration date; and then should be renewed and refreshed periodically. My old keys have all expired now; which means they are still usable to encrypt and decrypt, but the web of trust knows that they are not to be trusted.

For a serious user of encryption, this loss of a keyring is devastating. Losing the private key is a major inconvenience; but if it's got an expiration, it doesn't corrupt the trust web too badly; and it's usually acceptable to be unable to decrypt a message, because you can usually tell the person who sent it that you have new keys. What is NOT acceptable, is not knowing what keys to trust.

You can't simply assume that keys are valid and trustworthy; so when you lose your keyring, you have to rebuild your portion of the web. This means you have to go back and manually fetch, and verify all the keys of everyone you communicate with, then sign them again; and get everyone to sign your key again etc... etc...


Ok, so that was a bit obscure, and probably mreo than most of you ever wanted to know about encryption... and yet it was barely a thumbnail sketch. For purposes of length and clairty, I've GROSSLY oversimplified this, left out... oooh about 90% of even the absolute basics; and deliberately used technically incorrect but logically correct illustrations.

In fact I based this post off a greatly condensed and simplified version of the introductory chapter of some training materials I wrote a few years ago, when I was teaching a basics of encryption class.

Just to let you know what a "basic" course is, the class covered a full five days, 6 hours a day, with a maximum of 12 students per instructor; and over 200 slides of material, with several hundred pages of supporting materials.

Yes, that's the basic introductory course. The advanced course was another 5 days, required the intro course as a pre-requisite; involved passing a certification test on the introductory course, as well as pre-reading a rather long and obscure text book before taking it.

I do this for a living; and let me tell you, the reality of encryption tends to be a lot more complicated and messy than what I've described above. If you thought this last bit was hard to understand, you should see how confused and messy things get out in the world.

Update: Because there seems to be interest (and a lot of confusion) about this topic, I think I'll make it into a series, and expand and clarify in later posts. Go ahead and leave comments about specific questiosn or issues you'd like to see me address.

Trust, but Verify

I've said this before, and I'll say it again: The most intelligent thing Ronald Reagan ever said was
"Trust, but verify".

Expanding on that, it is silly to just say "never assume anything" because we're human beings, we have to make assumptions to get by. If I could give you just one piece of advice in this life though, it would be this:

Never trust your in your assumptions; always verify them.

What follows is a classic example of Making an Ass of U and ME... or at Least ME Anyway.

I've lost my keyring.

No, not my car and house keys (securely 'binered to my belt loops thankyouverymuch); my PGP keyring, along with my private key files.

I have a lot of encrypted communications and other files archived, and generaly, I conduct a fair amount of encrypted communications; though I haven't been doing much of it recently (which is part of the problem).

Flat out, I don't send anything containing PII, PCI, PHI, PLI, or PFI over public networks without encrypting it; and I won't do business or communicate with anyone who doesn't follow the same policy (those stand for Private "X" Information - "X" being Identity/Identifiable, Confidential, Health, Legal, and Financial respectively, in the acronyms above. You may also see them as CII, CPI, CHI, CLI, and CFI; meaning Confidential "X" Information, depending on what auditing and security standards are in use in an organization)

Also, as a matter of security, and in some cases personal preference and/or eccentricity; I customarily exchange correspondence with certain people in an encrypted manner.

This is a pretty big deal, because it means that I can't decrypt my old archived files or communications that use those keys; and because people might try and send me new stuff that I can't decrypt either.

So, how did that happen? You'd think after all that I'd take care to make sure something that important was never lost right?

Well, I've had to completely replace all of my computers over the past few months; starting first with my primary desktop, then my secondary desktop, and most recently my laptop. In the process, I hadn't bothered installing PGP yet on any of the new boxes; until today that is. I was copying a bunch of my archived files over to my laptop, and though "Hey, I should install PGP again".

Thus begins my story of assumptions creating failures.

So, before I stop using a computer (presuming the hard drives are functional of course) I copy all of my files off the drives, onto a backup drive. Usually I also make a backup image of the drive just to be safe, but because I ASSUMED I HAD GOOD COPIES OF ALL MY FILES, I didn't bother this time.

I assumed this, because I did a bulk copy, didn't see any failures, and verified a couple of my files. I ASSUMED THIS WAS SUFFICIENT.

So I wiped my old computers, one by one; each time ASSUMING I HAD A VALID COPY of my keys, on my backup drive, and on my NAS box.

Then, because they were my old computers, no longer in use, I also wiped my backups of them; and destroyed the backup media; because I ASSUMED I HAD GOOD COPIES OF ALL THE FILES, on my backup drive and on my NAS.

Well...

I installed GPG on my new laptop, and went to import my keyring... and it wasn't there on the backup drive. Oh the directory was there, but my secring, pubring, seckey, and pubkey files were not.

Ummm... ok don't panic, I've got backups. I ASSUME THE NAS COPY IS GOOD.

NAS box, same problem.

Ok, don't panic, I alway keep an encrypted archive file of my keyrings and keyfiles; and I ASSUME THE FILE IS GOOD, AND UNCORRUPTED.

Uhhh oh.... The archive file on the backup drive is damaged and unrecoverable.

Uhh oh two, the NAS copy is the same file.

Not to worry, I also keep a copy of the archive file on my thumb drive; and I know those keys are good because I used them a few months ago...

Only I replaced my thumb drive a little while after I had last used the crypto stuff on it; and didn't bother copying the file over at the time, because I had copies of it on my laptop, my desktop, my backup drive, and my NAS drive; and I ASSUMED THEY WOULD ALL BE GOOD, AND I'D BE ABLE TO COPY THINGS OVER LATER.

Now remember, I had every reason to believe everything was good. My PGP was functioning on my laptop and the other computers, right up to the day I wiped them. My problem was that I assumed that keeping a straight backup copy from one of those computers was sufficient, and I never verified the validity of my assumption.

See you have to remember, that a copy is a copy; and it may be imperfect. Just because the source is good doesn't mean the copy is.

I THEN MADE A CASCADING SERIES OF DEPENDENT ASSUMPTIONS, WITHOUT EVER ONCE VERIFYING THE FIRST ASSUMPTION WAS VALID.

What I presume happened is that my backup copy didn't copy those files, because they were in use and locked at the time; and I probably just suppressed the error (some bulk copy command lines don't output error messages).

I verified several of the files from the copy, but I didn't do a file for file verify, because I was just copying, not using backup software.

Then I wiped my completely functioning PGP keyrings off those boxes when I decommissioned them.; without ever verifying that I had a valid copy.

Then I compounded my error, and overwrote the copy on my NAS box with the bad copy from the backup drive; without ever verifying.

Then I wiped my old thumb drive, because I assumed all the other copies were good, without ever verifying.

Now some might ask, "why did you wipe all those files. Even the backups"

That's simple, every copy you have increases the chance of compromise; so keeping as few copies as possible is just good security practice. Four is a standard; one online (the active copy), one in online backup (the backup drive), one in near line (the NAS copy) and one in physical archive...

Wait a sec, what about physical archive?

Unfortunately, no; all my physical archives for my working set files (the non machine specific files that I share across all the machines I work on) are done off the NAS or nearline backup, and rotated out periodically; or are of full system images, which I destroyed after I wiped those machines.

I checked them anyway, and finally found an OOOOLD key archive that has the private key... only one problem...

I've changed the passphrase a couple times in the last few years; and I forgot the old passphrase that I originally used when I generated that key. I've cycled through my usual metric for creating passphrases, and it isn't any of them; so I can import my keyring, but I can't use my own private key, and since I never set a revoker, I can't revoke it either (you can't revoke an invalid key without the passphrase).

So my friends, remember, an unverified backup, is WORSE than no backup at all; because when you have no backups, you are careful about making sure copies of critical data exist before you delete things; whereas with a bad backup, you might be just a bit careless, as I was, and end up losing your data.

Tuesday, June 17, 2008

17 and 22


The Boston Celtics just pasted the L.A. Lakers 92-131 in game six of the NBA finals; going 4-2 in 6 for their 17th championship, and their first championship in 22 years.

Paul Pierce, Celtic team captain, has been named finals MVP.

Kevin Garnett, Celtics scoring leader, defensive leader, and 2008 all star, was named defensive player of the year.

The NBA has had 66 years of championships. Of those, the Celtics have won 17, the Lakers 14... that's just under half of all championships won by just two teams (and for those of you statistically minded, just under 26% of all championships to the Celtics); so yes, the rivalry is that big.

This just puts one more rung on the ladder for LA to climb before they can even try and credibly say they are the best team of all time... though it wont stop the Lakers sycophants.

First a world series victory for the Red Sox (and looking to do it again); then the Patriots go undefeated in the regular season and playoffs (just to blow the superbowl, don't remind me); then the Bruins make the playoffs (again, just to blow it but hey, that's kind of expected these days); now the Celtics take their first championship in 22 years...

2007-2008... What a season for Boston sports.

The Mythbusters of Rock and Roll



Oooh, this one should be fun... I mean the sheer volume and... audacity shall we call it?... of Rock and Roll myths is material seriously ripe for exploration.

I wonder how you could get away with doing a mythbusting segment on the mudshark incident.



Monday, June 16, 2008

Space Case

So, a few months back, Mel and I started on a daunting task: reorganizing the house

Now, when I say "a few" I mean "right before Christmas"; and when I say daunting, what I mean is about 4000 sq feet worth of stuff, two adults, two kids, two dogs, and two cats; packed into about 1800 square feet of house.

Our house is laid out a bit oddly. We have essentially an "L" shaped ranch (probably the most common house style in the Phoenix metro area), on an inside corner/cul-de-sac lot (the street is a cul-de-sac, but the yards form square corners, so we've got kind of a rhomboid shaped yard). The house is about 60 feet in both legs of the "L", with one leg being 26' wide, and the other being about 14' wide.

My semi-detached office is at one end of the L; the three bedrooms and two bathrooms (including a master with en suite) are at the other, and in the angle where they meet are our entryway, the kitchen, the dining room, and the living room, on a kind of open plan (actually half open half not. Big open archways without doors, but full height walls).

I call the office semi-detached, because it is its own completely separate construction onto the house (from the late 70s or early 80s). It's 16'x14', with its own entrance, and its own sliding glass back door into the back yard. It's on two separate electrical circuits from the main house etc... The only thing it shares is ventilation really; and its vent trunk is completely separate from the main trunk of the house as well.

Unfortunately, it doesn't have a door to close it off from the rest of the house, just an open archway into the kitchen; so we got two sets of heavy privacy curtains, and hung them on both sides of the arch; and it actually blocks out sound better than most interior doors would.

We had originally intended this space to be a sort of rec room, and we semi-ironically titled it the "rumpus" room; serving as a general craft, arts, recreation, etc... area; but instead, it quickly got turned into ... bulk storage would probably be the best way to describe it.

Now, I have to explain something here. Mel is a wonderful wife and mother, she takes care of the kids and me better than anyone could ask for, but there are two things she is absolutely hopeless at:
  1. Cleaning
  2. Organization
So understand that when I say "bulk storage" I mean the room was essentially filled, to the point of being inaccessible, with "stuff"; that she just couldn't find a home for elsewhere.

Meanwhile, I managed to pack my home office, all my gun stuff, all my tools, all the camping gear, and a whole bunch of other crap besides, into the 12'x12' "third bedroom" (maybe for a small child, but to me it's an overgrown closet).

I was bursting at the seams in there; and trying to maintain organization, and have enough space to work... it just wasn't happening. Plus, Mel was having a hell of a time keeping her crafitn gorganize,d having to break everythign pout and clear off space, then set everything back when she was done.

So, a few months back, we decided to make the rumpus room my office, gunroom, hobby room etc... and take what I had been using for the purpose, and make it Mels craft/sewing/reading room.

We also decided to reorganize the back half of the living room, which is currently an unusable jumble of exercise area, bookshelves, and the kids computer desk and art area.

So we started out by cleaning up, and moving, all the stuff that was "in the way" (which in fact temporarily made everything worse) and we trashed a whole bunch of stuff that was just taking up space.

Then we went down to our friendly neighborhood Ikea, and bought the book cases, drawers, shelving units, desks, tables, and chairs necessary to complete our tasks.

This of course made everything even worse again.


We've tossed most everything that needs to be tossed (we'll need to make a final cull out I'm sure, but we've got the majority); and we've done the math: once we have all the shelves and drawers and everything else setup and filled up, our house will actually be clean and organized...

... or at least as clean and organized as an 1800sq ft, house with 2 cats, 2 dogs, and 2 kids under seven CAN be.

Oh and we moved the 700lb 4 foot wide 5 foot high 2 foot deep gun safe into my new office as well; and the part of our old sectional that didn't break horribly, so I can have additional seating and lounging area (Mel likes to join me while I'm working sometimes, just reading next to me etc... It's very nice).

Then life happened.

First, the court troubles of earlier this year hit us, and made it impossible to concentrate on anything else through March.

Then we get a bunch of crap from the city about my tools being outside, and needing to build a shed (still unfinished by the by. I've got everything ready to go, and built the foundation and deck; but then it rained literally every day I had off for six weeks, and it's been 100+ degrees out every day I've had off since).

Then Mels mom got sick.

Meanwhile, we're packed into even less space than before, because of all the stuff waiting to be assembled and/or moved. We've got so much stuff out of sorts that our covered back porch is full of "stored" stuff; and I've been using our not very large (and again overfull of stuff) bedroom as an office.

Seriously folks, it may sound nice, working from your bedroom all day; but I'm in this one room 16 hours a day, and believe me that isn't fun.

Well, no more; or at least in the process of being no more.

When Mels mom passed, she left behind a HUGE amount of craft supplies, books etc... and Mel wants her craft room to keep them all in; so today, she finally started back in digging out those two rooms.

By the time I got off work, she was ready for me to do the literal heavy lifting, and move my two gun benches.

I tell you, she got an amazing amount of work done in a few hours.

I've now got the makings of my working area set up, with an 8 foot long counter high welded steel bench with a 4" butcherblock top along one wall (under a 6' picture window actually; it's quite nice), end capped with my 28" rollaway tool box on one side, and butted into my 4'x2' flat workbench (also counter height) in the corner; giving me 12 linear feet of 2 foot deep work space. (the rollaway top has my top chest on it).

Butted up against that flat bench on the one blank wall in the room, is my 5' loading bench, with my work hutch, powder measure, press etc... on it; making the total linear bench space 17 feet (though the last 5 is obstructed).

The tool hutch is also a vented work hood for doing brazing, soldering, and other work where sparks might fly, or flammables need to be controlled; and it's got a work light and power strip on a filtered UPS, rated high enough for using a Foredom or a 200 watt soldering iron.

Unfortunately, the next 4 feet of wall are taken up by a closet door (at the other end of the "L' beyond the roll-away is my entry door), so I can't really extend out any further; and my options for a "U" leg on the current "L" are somewhat limited.

What I'm thinking though, is that I'm going to take the press off the corner of my current loading bench, and build a 6'x2' deep flat bench to match the existing setup; butting it into the face of the current loading bench where the press is mounted, and mounting the press on the 2x6s inside facing corner instead. This way I'll get 8' of linear bench space that I can walk around three sides, as well as all the undertop storage space (which believe me I need). There's plenty of floor space in that "U" area for this. Oh and I'm going to build some book shelves along the entire back face of the bench, and the side of the other bench, to take advantage of that space (about 4 feet) between the "island" and the opposite wall.

Finally, I'm going to take an existing 48' x 28" desk I have, and butt it up to the side of my rollaway, and use that as a pass table for things that belong in the office, but that everyone uses; like my office printer/copier/scanner; and the camera and video camera charging stations.

This will end up as kind of a "c" shape really, except the bottom leg of the C is flat, with a 4 foot entryway into the interior of the work space; and will give me a total of 27 linear feet of 2 foot or so deep work space, with under-top storage; and wall hutch/wall shelf storage for 9 of those feet.
On the long steel bench, I'm setting up a computer work station near one end, with an under counter arm mounted keyboard drawer; and my two tower PCs, and NAS array underneath (there's plenty of room).

Oh and I've got my GigE/wireless N router and GigE switch set up underneath, as well as my multiline cordless phone set up on the corner of the bench with the computer station. I've also got triplex high gain extension antennae mounted up near the ceiling in the two corners, and center of the wall. All of that is on its own small filtered UPS, separate from the computers and the tools; so that if my power goes, I'll still have my cordless phone,and hopefully my DSL.

I've also mounted a full length 16 outlet industrial power strip, and a copper grounding bar to the back of the 8 foot bench (love that steel construction); and I've got the whole thing on a Xantrex 1800watt filtered UPS and reserve power supply (4 hours reserve time at 1800 watts draw). The Xantrex is rated for 20 amp tool use on each of the six main outlets on the unit (the thing is the size of a full tower PC and weighs about 100lbs), so I'm not worried about it handling anything I throw at it, and keeping mr. power spike and mrs. brown-out away.

In fact, the only thing in the room not on a filtered UPS is the lights (and actually, I've got two low voltage fluorescents on the UPSes just for emergency lighting). I've learned my lesson on dirty power.

The wall opposite the picture window (the perpendicular angle to the closet), is 16 feet long, but 6 of those feet are taken up by a sliding glass door; and 2.5 of them by the door swing of the closet. The rest, has the aforementioned 4' wide safe (actually it's 3.5'), a 2.5' wide 6' high 5 tier shelf unit, and the 6' remains of my old sectional, technically blocking the sliding glass door.

The final wall has 10 linear feet blank, before the 4' wide archway into the kitchen, so we've got 6' high 5 tier shelving along 8 of those feet, and a 2' wide, 5' high ammo cabinet taking up the rest of it. Unfortunately the bottom two tiers of the shelving unit in the corner are partially blocked by the sofa, but they can still be accessed, and used for bulky items I don't need very often.

So, as of right now, the basic framework is set up; but nothing is actually squared away; which is going to be a huge job in and of itself. I expect it will take me a full week or more to get things set right.

I just hope I have enough space for everything... but I don't think I do. Honestly, I don't see how I can possibly squeeze any more useful workspace, or storage space, into a 16'x14' room. I need to figure out what can go into storage, and what needs to stay...

Oh, and I need to finish the damn shed.

Thursday, June 12, 2008

A Few Notes Following Mom's Death

That's what the back of my poor truck looks like right now. I picked the kids up on Monday because Dad was sick. Dad had asked me to take care of all of Mom's crafting stuff, and so I decided to take full advantage of the trip and load up the truck. That's about a quarter of what I will eventually end up dealing with. Mom left behind literally thousands of dollars worth of craft supplies, but almost none of it has real value second-hand. The scrapbooking supplies are particularly worthless after the package has been opened, but I'll find a home for them (Lani, that most likely means you.)

Dad wanted all of the unfinished craft items and unused supplies off of his back porch and out of his sight. I think all of it reminded him too much of how much was left undone, and how Mom wasn't expecting to die so soon. Also in the truck are a few boxes of family heirlooms which he loaded himself before anything else, I suspect because they, too, were a reminder, and he knows I'll hold on to them in case he ever wants them back.

* * *

I've never experienced a death in my family before. Sure, my maternal grandparents have passed on, but I never met them. My mom's sister died of a brain tumor in 1996; I barely knew her. My paternal grandparents are still kicking around at 88 and 91. This has been quite a shock for me, and I'm amazed I've been able to deal as well as I have. Granted, I received 6 weeks of prior warning, but I held out hope until she was admitted to the ICU due to respiratory arrest. After her kidneys shut down and the doctors gave her a 20% chance of surviving the week last Tuesday, I had to accept what was going to happen.

That Tuesday within 15 minutes of Dad's call I had arranged for JohnOC to watch the kids and Chris had canceled his full day of video conferences so he could take me to Tucson to say good bye.

When she died on the Thursday I'd had enough time to come to terms with the end being near.

***

On Thursday I drove down to Tucson with the kids in tow so I could meet up with my brother Mark and his family. They'd flown in the day before and been lucky enough to be there for Mom's last bit of consciousness.

The doctors disconnected the life support at midnight Wednesday night, and I arrived at the hospital with the kids at 9:15. Dad took the kids from me and took them to the play area in pediatrics so he could "be Grandpa for a while." I took his post at Mom's bedside. She was passed out due to the comfort drugs. At 9:55 the nurse and I decided to call Dad back; her vitals were dropping fast. He made it in just as the nurse verified the lack of pulse; we were both there at the end.

* * *

Dad and I recovered pretty quickly; we'd both been there for the past six weeks so we'd had time to adjust. Within an hour we were picking up his things from the place he'd been staying in Tucson. Within 2 hours we were on the way to the small town where he lived. Amazing how fast life changes.

* * *

The "celebration" (Dad's term) was held on Sunday. Chris and I drove in Saturday afternoon and stayed at the only hotel in the small town. The beds sucked but at least it was clean. He really hit it off with my uncle and his wife. My uncle (Mom's brother) is a retired Army Sergeant-Major so they have a lot of common ground. All 4 of us are Catholics, and as much as we wanted to have a proper wake we could not find a single place to buy hard alcohol in that god-forsaken town. We made do with beer and alcopops.

* * *

It's odd going to a potluck honoring someone's life. I saw people I hadn't seen in decades, including the girl/woman who was my best friend for the first 14 years of my life. We'd drifted apart, mostly because she was an annoying know-it-all teenager. Nice to see that almost everyone grows up sometime.

* * *

The service was simple. Favorite hymns, Dad's eulogy, and whoever wanted to say something was given the chance to do so. Dad spent most of the service holding my seven-week-old nephew, and trying not to bawl. Evidently Philip was even more of a comfort to Dad than he was to me, and that's saying something.

As Chris said to Dad, nothing better to remind you why we put up with all of this pain than a brand-new baby.

* * *

I scanned a couple of old pics out of the family photo album and had them enlarged for the service. This is the resulting 11x14 that Dad ended up hanging up in the living room. He says that's the way she looked when they met almost 42 years ago.


I miss you Mom.

Mel



I think this one is a lot more than 800lbs




I realize a lot of my readers have no idea of the context of this cartoon; not being sports fans, or particularly not being basketball fans.

Lemme 'splain... no, is too long; lemme sum up:

Last year, an NBA referee name Tim Donaghy was ratted out to the FBI, by his own mod connected bookie, for gambling on games he himself was officiating.

Now, this in and of itself is a felony, as well as a major no-no in all professional sports (at least in the U.S.). While some sports allow players to bet, officials must always remain impartial and dis-interested in the outcome of a game.

Now, this in itself would have been a huge scandal... but then Tim Donaghy did something. He opened his mouth REAL WIDE, and started talking about not only himself, but other refs, and the league itself.

Specifically, he alleges that perhaps HALF of all NBA refs place illegal bets on a regular basis (disallowed by their contracts, as well as just being illegal); and that he personally knew of at least 27 that were betting on NBA games, including games they had officiated.

Now, in case you thought that was bad enough, there's more.

Donaghy also alleges, with a great deal of supporting detail, that the league itself has refs deliberately manipulate games, in order to produce results that will attract more fans and viewers; such as favoring, or disfavoring particular players with foul calls.

Ok, that's bad, but everyone knew that was happening. We all know that certain players get extra scrutiny, or extra leeway, on the court, based on referees perceptions; we just didn't know the league itself was doing it explicitly.

But wait, there's more...

Donaghy also claims, again with specific detail, that the league makes a practice of briefing refs to use those calls to shade games, to produce closer results; because blowouts (excepting EXTREME blowouts) are bad for ratings.

Well... I think most people have noticed games seem to be a lot closer than they used to; but mostly we just assumed it was the effect of free agency.

But wait, there's more...

Worst of all, Donaghy claims that the league has been deliberately fixing games in certain teams favor; to extend highly rated playoff series that looked like they would end in less than 7 games for example, or to put teams that draw greater TV viewers higher in the standings, and deeper into the playoffs.

According to Donaghy, the NBA western conference finals in 2002 and 2005 were both deliberately extended by officials, to make the full 7 games; specifically to enhance TV ratings and revenues.

Of course the league is denying everything; rightly saying that Donaghy is a convicted felon, desperate to both reduce his sentence, and to spread the blame around, and discredit the league.

Yep, they're right... The problem is, a LOT of people think he's telling the truth... including a lot of coaches and players; though they'll never say so, because the league would fine the hell out of them (they've fined owners, coaches, and players, hundreds of thousands of dollars before for suggesting that games might have been fixed by officials).

Worse, independent analysis of the callmaking in those series supports Donaghys claim. It appears that a consistent pattern of improper foul calling (both calling fouls that were borderline, and not calling fouls - including some very blatant ones) from more officials than just Donaghy, may have changed the outcome of several different playoff series over the past 10 years.

Wow.

No, seriously, wow.

The NBA is a multi-billion dollar industry, with tens of thousands of people employed directly in the business; and hundreds of thousands directly impacted by the business. The entire thing is built on a foundation of assumed honesty in officiating. You just can't have a league that fixes games; unless you want to fall to the status of professional wrestling.

This is potentially the biggest scandal in American professional sports since the 1918 world series. In terms of the real effects, this is FAR more severe than any steroid scandal.

... and the NBAs response is... "Ummm.... he's a liar"

I'll be honest with you, I used to love basketball. I was born and raised in Boston, home of the greatest basketball team of all time, the Boston Celtics (yes, objectively if you looks at the numbers, the Celtics are the best, the Lakers are second). Basketball was a strange combination of courtesy, sportsmanship, and if not gentlmen, than gentlemanly behavior on and off the court; with rough and tumble, elbow throwing, charging, in your face agression.

Then something changed... The gentlemen all retired. The coaches and the managers stopped caring about their players behavior, as long as the numbers were there. The players themselves stopped caring about their teams performance, so long as their own numbers were there.

Basketball stopped being about the game, and started being about the stars.

Oh sure, Bird, and Magic, and Kareem and Dr. J. and Wilt were all stars before the era of Jordan; but it was always understood that they were a part of the whole. The story was about the Celtics or the Lakers, it wasn't about Bird or Magic.

In the late 80s though, as revenues increased, and players salaries increased even faster... It all fell down.

I call it the "thugification" of the NBA.

It started first in the colleges actually; when teams, despreate for a share of the HUGE NCAA revenues, started recruiting, and allowing to stay in school and play; playuers who couldn't have even finished high school, never mind attended (or graduated) college. They accepted a standard of behavior that would otherwise have ended these "student athletes" in jail many times over.

Now this isn't to say that athletes weren't always given special treatment, or that they were Rhodes scholars and choir boys'; far from it. But when Bill Russell went to San Francisco state, you can be sure he wasn't assaulting other students, raping anyone, or in fact spending his time doing anything other than making sure his game improved, and making sure he stayed in school (at least until he was eligible for the draft). Now remember, Russell was well known as one of the roughest men in basketball; very sensitive to any perceived (and real; he WAS a black man form Louisiana playing in a "white" sport in the 1950s) offense.

The biggest "thug" in the NBA up 'til the late 80's was Bill Laimbeer, who wouldnt hesitate to knock you on your ass, or throw an elbow in your teeth; but he never choked anyone, or got caught beating up his girlfriend in the parking lot.

Soon of course, this thugification spread into the NBA. It was slow at first, because the old schoolers, both players, and coaches (and owners), were still around; and there's no way that Walton, or Lambier, or Bird, or Riley, or Russell, or Auerbach; were going to let you get away with that sort of streetball, no class, no respect bull. Certainly, your behavior off court would have an impact on your status on court; and if you wanted to play, you kept clean and out of trouble (at least in public).

Then the old school team players, and teamwork coaches, all started to retire. And the money got bigger. And people got greedier.

Then Bird, and Magic, and Mchale, and Laimbeer, and Walton, and Kareem, and... well everyone who grew up in the old era of basketball; they all retired.

What broke the camels back for me, was Latrell Sprewell.

In 1997 Latrell Sprewell choked his coach on court, at a practice. Here's what wikipedia has to say on the incident:
"Sprewell's career has been permanently overshadowed by an incident on December 1, 1997, in which he attacked head coach P. J. Carlesimo during a Warriors practice.

When Carlesimo yelled at Sprewell to make crisper passes (specifically asking him to "put a little mustard" on a pass[1]), Sprewell responded that he was not in the mood for criticism and told the coach to keep his distance. When Carlesimo approached, Sprewell threatened to kill him and dragged him to the ground by his throat, choking him for 10-15 seconds before his teammates pulled Sprewell off his coach. Sprewell returned about 20 minutes later and landed a glancing blow at Carlesimo before being dragged away again."


Rightly, the Golden State Warriors voided Sprewells contract, and the league suspended him for the rest of the season; but the players union force his contract to be reinstated, and the suspension to be reduced to 68 games.

The Warriors did the right thing; and though the union forced them to carry Sprewells contract, they did not allow him to play. He was eventually traded to the Knicks, during their desperate 1999 season; after the player lockout, and several failing seasons under first Don Nelson, and then Jeff Van Gundy.

As far as I'm concerned, the NBA ceased to be a worthwhile entity on the day Latrell Sprewell stepped back onto the court.

... and then there was Ron Artest... I wont go into detail here, just look at his wikipedia page, and the page on the Pacers-Pistons brawl.

The thing is though, I mention Artest specifically because he was involved in a very public incident; but he is by no means exceptional in todays NBA. Right now, there are players on the court who have either admitted to, or been proven to have beaten their wives, girlfriends, or complete strangers. There are those who have raped, and those who have had sex with underage girls. There are those who have shot people other than in self defense. Tattoos proclaiming "thug life forever", and gang symbols are common.

Now, if you want to call me racist for this, go ahead I don't care. I know what I am and what I am not. It's not about race, it's about CLASS, or the lack thereof; RESPECT, or the lack thereof; DECENCY, or the lack thereof.

In 2004, the league realized that they had a HUGE image problem and massive behavior problems with players; and they started really cracking down on bad behavior on and off the court. Of course it took a stadium clearing brawl, a number of very public and messy trials; and most important to the NBA, a MASSIVE drop in ratings and attendance; to have any impact... but at least it was something.

This cleanup effort seems to have had a very positive impact the last few seasons; and combined with revised free agency and contract policies, and a realignment of competitive teams and markets; the NBA has been climbing out of the hole it dug itself in the late 80s.

I actually found myself interested in the NBA season this year; even before the playoffs... of course that might be because my beloved Celtics are clearly the best TEAM in the NBA today (There are individual players better, but no other TEAM is better as a whole. Take away Kobe, or maybe Kobe and Gasol; and the Lakers are out of the playoffs. Crittenden, Brown, Fisher, and Odom don't - and didn't, thus the trade - get you to the playoffs. Take away KG, or even KG and Pierce; and you've still got Allen, Rondo, Posey, and Davis putting the Celtics in the playoffs); but honestly in the last couple of seasons, I've been impressed with the quality of team play, and the emphasis on full court play, passing, and game management; instead of just the flashy, ratings grabbing, "look at me, I'm a superstar" style of play favored throughout the '90s.

The NBA has really been turning around, at least in my eyes.

Until today that is.

I'll be honest with you here. If Donaghy is proven true, or if even a whiff of credible evidence, or a credible witness, can be found to support what he's saying...

That's it, game over.

Wednesday, June 11, 2008

Growth as a Man?

This one is going to be a little strange, and very personal; but I think it strongly illustrates a point I want to explore....

I just woke up from a nap, wherein I had an odd dream:

I was someone else (extremely unusual in my dreams); a very rich, single man, throwing a party in a luxury hotel suite, for a number of friends and acquaintances from his old neighborhood; while on a trip back there for business.

In the course of this party, several people went off to rooms to have sex. I was tired, and went to MY room, telling everyone to continue enjoying the party; and some time later, an acquaintance who I knew to be a "player", came into my room with a beautiful pair of women, obviously sisters.

He suggested a foursome; and I pleaded tiredness, but the three climbed into bed with me anyway. I could tell on of the sisters was "up for anything", so to speak; but the other just seemed... resigned I suppose? While of course my Lothario friend was quite eager.

I took the reluctant one in my arms (I was on my back with her over me), and said "do you really want to do this?", she replied "they always want this.. I'm used to it, it's OK".

I continued to hold her, but I was struck by how sad, and empty that was. Presently, "the player" finished with her sister, and positioned himself behind the girl in my arms, and moved her hips to where he could penetrate her. I told her "Well, I don't want this. I want you to look me in the eyes, and kiss me".

She did, and while she was being taken roughly from behind, we looked in each other eyes, held, each other, and kissed. She soon achieved orgasm; which was clearly irrelevant to my "friend", excepting that it hastened his.

While he... finished his business, she just looked at me and said "thank you, that was wonderful. You're awfully good at this". Meanwhile "the player" ... well, it was clear to him that the woman didn't really exist, except as a receptacle for his penis. He was triumphantly strutting about, looking to fist bump and high five, hooting like a fratboy, while the women quietly dressed themselves, and slunk away.

I was never so disgusted to be a man in my life, as watching this little boy, with a grown up body, and a shrunken soul... nor was I more ashamed for women, watching these two accept... or even actively encourage... their own reduction to that objectified status.

I love sex. I think it is a beautiful, wonderful, amazing thing. I don't believe that sex must always be linked with love, or for that matter anything more than just good hard rocking sex... but it shouldn't be cheap. It shouldn't be hollow and empty.

Let me tell you something else... I watch an 18 year old girl, half naked (as what passes for street clothes these days), and obviously completely empty headed; strutting through a mall, and I feel... sad? Maybe that's not right.

A few years ago I might have said "I'm not interested, because she's WAAAAY too young (in mind, if not in body); but at least I can appreciate the equipment"... Today though I don't even have that level of interest.

Of course I am faithful to my wife; but we all know the old principle of "I'm married, not blind or dead". One would think I could enjoy the view so to speak. Honestly though, I don't think I could even get it up, without the mental and spiritual engagement. She'd open her mouth and vapid, stupid, immature idiocy would pour forth; and she could be as much a goddess as Bridgit Bardot in "and God created woman" and I'd be saying "why don't you go home little girl".

.. except that Bardot WASN'T a vapid empty headed little girl; or she wouldn't have been the goddess that she was...

I suppose people have been saying the same thing as they get older, since people first managed to break the age of 30; and the breed or die imperative first slowed enough to allow the appreciation of the finer points of each other. Certainly, I can remember hearing similar things said through the years by all sorts of folks... or the lamentations of women who noted its lack...

Honestly though, how can a man, a REAL MAN not an overgrown boy; look at one of the desperate, sad little girls; so convinced they have it all because they can wiggle their hips and make adolescent boys cry... how can he look at them, and feel anything other than disappointment, or pity, or shame for them?

How could he respect himself, if had sex with one of them; just because of her lovely body?

How is it that we cheapen ourselves so?

Tuesday, June 10, 2008

Boy... He came to the right place

They're Dragging Me in Deeper

The Apple Cult that is...




And this time they've got my wife too.

With the announcement of the new iPhone 3G, iPhone 2.0 software, and mobile.me; the announcement of 3G networking and GPS; and the price cut down to $199 for 8gb and $299 for 16gb models; Mel and I will both be getting iPhones, and signing up for mobile.me.

Right now, we both carry around a smartphone, and a separate MP3 player (yes, our smartphones CAN be mp3 players, but they don't work well in that role); and there's a complex dance of multiple synchronizations required to get our media, contacts, calendars, and files all synced... and even then there's lots of issues with duplicated or out of date items; and there's no push, pull, or over the air sync for anything except hotmail and pop-email. It's even more difficult for us when we try and coordinate schedules and the like between us.

With the iPhone and mobile.me, everything just works. You can automatically sync over the air, with outlook, get push mail and two way sync from exchange, sync your outlook into mobile.me and have two way push to and from the iPhone, as well as to other computers (both Mac and PC).

The damn thing even has native Cisco VPN client, for connecting to my work network; and my company is one of the participants in the iPhone enterprise beta program, so we'll be supporting all the exchange integration features etc...

They've even fixed full iWork, and MS Office file access, natively. Theres already a native suite of connectivity tools, including remote desktop, ssh, FTP and SFTP, and other basic UNIX tools, announced for later this year.

Combine that, with some of the other apps already announced with the full SDK, and the iPhone really has no equal as a smartphone; unless you absolutely need to have a hard keyboard. Now that it's got 3G and GPS, there's really nothing keeping me on the windows mobile platform, and LOTS of reasons to leave.

If it comes down to it, I won't need my laptop with me for most essential computing tasks.
I can only think of two apps or services that I won't have with the iPhone (neither of them necessary for work), that I might miss from Windows Mobile: Napster to Go, and Mobipocket.

I would guess that Mobi is already working on MobiPocket reader for the iPhone; and it's been bandied about that The Steve has considered offering a subscription based music service (though I doubt it's going to happen).

A few months ago I said that if Apple got the SDK right, added 3G and GPS to the hardware, opened up the development program, and rolled out wide to many countries and providers they would become the standard mobile platform for the world.

Guess what?

They did it.

I bet Ballmer is throwing chairs all over the place right now.

Three Words

Well, three words, and three thoughts associated with them...

I've not spoken much about politics this year, specifically because when I WAS talking about it I found that it was absolutely impossible to have any kind of civil discourse with the Paulistinans, and Obamaddeans; and that the Mitt and Huck types were all heavily into self delusion.

Let's not even talk about Bob Barr (libertarian he certainly is not... publicity stunt, he certainly is), or Dennis Kucinich (really... my life would be so much better if I never heard his name again).

What was the point? The aggravation wasn't worth it.

Now that the parties have settled on their respective choices (finally), I'm going to say what will hopefully be my last GENERAL words on the subject (obviously I may end up commenting more as particular issues come up).

I'm going to be voting for John McCain (or more particularly not for McCain, but against the Democratic Party) and here's why (three words, three thoughts):
  • Barack
  • Hussein
  • Obama
  • Supreme Court Justices
  • Executive appointments
  • Cooperative congress

So, let me just close with the sentiments of my good friend Kim DuToit:

Monday, June 09, 2008

A long week

Much of last week was spent making arrangements, and just coping. We're all exhausted... just wrung out really.

Mels dad decided that he wanted to keep some life around him, so our girls have been staying with him since the night Kathi passed; and they'll be there 'til Friday. Mels brother Mark, and his 4 kids (including a 7 week old) are with him too, so he's absolutely surrounded by reminders of why we put up with all the troubles that come.

Kathi is going to be cremated, and that won't be for another week or so; so there won't be a funeral. Instead, we had a memorial celebration at her church yesterday; a potlatch lunch, followed by testimonials, hymns, and a lovely sermon by their pastor, who was a great friend to Kathi (and of course still is to Roger).

I ended up playing videographer and photographer; which seems kind of odd to me, recording a memorial service; but that's what they wanted, so hey, who am I to say no.

Mel is doing OK. She's never had to deal with this before, so she doesn't really know what to expect; and you can't just tell someone what it's like, and have them know inside... but she's getting by, and we're supporting each other. Thank god for those cose personal relationships; I can't imagine having to lose a parent, and being alone with it.

And now... well, as soon as we get some sleep... the great cleanup begins. Cleanup the house here, and Rogers house. Cleanup all of Kathis stuff. Trips to goodwill and craigslist and ebay...

In some ways, it's amazing how much physical evidence our lives leave behind; but when you think about it, it's far more amazing how little.

The back of a truck seems like such a small space for the remnants of 61 years of living... but of course the real remainder is what lives on in the people whose lives we've touched; not what we pack away in boxes.