Tuesday, February 03, 2009

Hallelujah, he's finally gone!

Today is a great day my friend. Today is the day that BMW begins its return to grace and greatness; because today is the day that CHRIS BANGLE RESIGNS.

Thank you god.

For those of you who don't understand why I am thankful for this blessed event, let me give you some examples, of both pre and post Bangle BMWs.

Pre-Bangle:





Those are examples of the E34 M5 (1989-1995) and E39 M5 (1996-2004); what I believe to be the two best examples of the classic BMW sports sedan.

Admittedly I'm biased, in that I've owned two E34 5 series; and would still love an E39 540is or M5 (the E34s are still great; but they are getting a bit long in the tooth. Plus the E39 has almost twice the horsepower, more room, and better handling).

Some might call the styling boring, but I disagree. They are smooth, but hard edged. Muscular, but not overblown. Classic, clean, simple, and balanced.

Simply, they are a pure expression of form and function in harmony. Antoine de Saint-Exupery famously said "Perfection is achieved, not when there is nothing more to add, but when there is nothing left to take away.". With these cars, there is nothing left to take away.

Unfortunately, Chris Bangle decided that meant it was a perfect time to start adding stuff:


That, is called a "Bangle Butt"; because Chris Bangle insisted on adding it to all of his designs.

Who on earth could find that attractive?

Actually, just a more basic question, why on earth did BMW make this man head of design, when he admitted he didn't like how BMWs looked. He thinks the hoffmeister kink should be eliminated, and that the double kidney grill is old fashioned.

Bangle said repeatedly in interviews that he thought BMWs looked boring; and that he kinda liked ugly cars because they were interesting.

I guess these are VERY interesting then:


In case you were confused, no, those aren't Pontiacs; they are $40,000 to $90,000 BMWs... though you can certainly be forgive for the comparison. I for one think the recent 5 series looks an awful lot like a Pontiac Bonneville:


Here's a more explicit look at the similarities:

That would be a recent 3 series compared to a Pontiac G8 (what used to be the Grand Prix) of the same year. Striking resemblance wot?

Pontiac is of course famous for the "Excitement" look; achieved by taking standard GM three box products, and adding ridiculous plastic body cladding and pointless frippery.

Here's his latest, and "greatest" effort, the X6:


Which if you ask me, looks a lot like a slightly smoothed out Pontiac Aztek:


But maybe that's just me. I actually like good looking cars... I guess I'm not interesting.

Monday, February 02, 2009

Truer words...

From John Hansas, "What It Feels Like To Be A Libertarian" (spacing added for clarity):
"Libertarians spend their lives accurately predicting the future effects of government policy.

Their predictions are accurate because they are derived from Hayek’s insights into the limitations of human knowledge, from the recognition that the people who comprise the government respond to incentives just like anyone else and are not magically transformed to selfless agents of the good merely by accepting government employment, from the awareness that for government to provide a benefit to some, it must first take it from others, and from the knowledge that politicians cannot repeal the laws of economics.

For the same reason, their predictions are usually negative and utterly inconsistent with the utopian wishful-thinking that lies at the heart of virtually all contemporary political advocacy.

And because no one likes to hear that he cannot have his cake and eat it too or be told that his good intentions cannot be translated into reality either by waving a magic wand or by passing legislation, these predictions are greeted not merely with disbelief, but with derision."

Shuttin Detroit Down



You're definitely going to want to hit the HQ button to watch in high quality.

And now, just for fun, I scare the crap out of you

This is why I have an RFID blocking wallet, and passport wallet; and you should too.

Passport RFIDs cloned wholesale by $250 eBay auction spree
Video demo shows you how


By Dan Goodin in San Francisco
Posted in Security, 2nd February 2009 06:02 GMT

Using inexpensive off-the-shelf components, an information security expert has built a mobile platform that can clone large numbers of the unique electronic identifiers used in US passport cards and next generation drivers licenses.

The $250 proof-of-concept device - which researcher Chris Paget built in his spare time - operates out of his vehicle and contains everything needed to sniff and then clone RFID, or radio frequency identification, tags. During a recent 20-minute drive in downtown San Francisco, it successfully copied the RFID tags of two passport cards without the knowledge of their owners.

Paget's contraption builds off the work of researchers at RSA and the University of Washington, which last year found weaknesses in US passport cards and so-called EDLs, or enhanced drivers' licenses. So far, about 750,000 people have applied for the passport cards, which are credit card-sized alternatives to passports for travel between the US and Mexico, Canada, the Caribbean, and Bermuda. EDLs are currently offered by Washington and New York states.

"It's one thing to say that something can be done, it's another thing completely to actually do it," Paget said in explaining why he built the device. "It's mainly to defeat the argument that you can't do it in the real world, that there's no real-world attack here, that it's all theoretical."

More at this link...




By the way, this works on credit cards, keytags and keycards, and drivers licenses as well, if that wasn't clear from the video.

If you feel like scaring yourself some more, read the links here.

Small World

Funny thing. The fiancee of one my good friends, is the fulfillment manager for this product line:



The guy talking is one of her co-workers; and the group works down the street from me.

Roughly, Yes

Brilliant Strategery

A Little Perspective on Security


I used to teach a class on basic cryptography, and using cryptography in your organizations information security regime. I also taught classes on basic information security.

Mostly my students were mid level network and system admins, consultants, state and local law enforcement officers, and the occasional Fed. Mostly they were mature adults in mid career phase looking to either get some career boosting skills, some help in securing their organization, or some knowledge of how to investigate and deal with security, and security compromise.

Mostly.

Inevitably in any class there would be some genius (usually the 22 year old, most junior admin) who'd drunk the cypherpunk koolaid, and would always be talking about ridiculous key strength, or Van Eck shielding etc...

They always needed to be reminded of a couple things:
  1. There is no such thing as "secure" for anything useful; there is only "Secure Enough".

    There will always be a tradeoff between security, and usability. The only secure computer is one that's unplugged, sealed in concrete, with no data on it; and that isn't useful.

  2. If the NSA wants to read your email bad enough, they will. So would any other nation state. For that matter, so would Exxon Mobil, or Microsoft, or Google.

    You cannot begin to understand the resources available to those with billions or trillions of dollars and thousands or millions of people at their command. You cannot possibly protect yourself against such an array of resources if they are directed against you, and sufficiently motivated; unless you are a competing entity of the same scale.

    Forget 4096 bit encryption, they'll just phreak you, keylog you, or plant a camera over your shoulder; or if it comes down to it, kidnap and torture you.

  3. The NSA doesn't want to read your email. Neither does Google. Stop thinking so highly of yourself. You are an insignificant bug as far as the government or a major corporation are concerned.

    Seriously, nobody cares enough to bother; unless you are a terrorist, or are committing large scale theft or fraud; in which case see point 2 above.

    Your credit card and bank account info on the other hand... yeah, there are a lot of folks out there who would love to have that.

  4. Given points 1 and 2 however, the solution isn't crypto; it's not putting anything you need kept that secret onto a computer. If that isn't an option, then physical security is more important than the strength of your crypto.

    Only after physical security, and basic security practices are taken care of, should you be worried about how strong your crypto is (except when it comes to financial transactions). Crypto is a tool, not a solution.

  5. Given point 3, seriously, how much security do you really need? Security isn't about perfection; because perfection is impossible. Security is about managing risk.
So, how secure do you need to be to make the risk of a particular action acceptable to you?

Sure, eventually, given enough time and data capture, a cracker is going to be able to recover some of your email; but if it's two years from now, and you never discussed anything that would harm you two years down the road over email (and you shouldn't), "can't be broken in two years by someone other than a government or a large corporation" is enough security.

If on the other hand you're the president of the United States, you really shouldn't be using a blackberry; even for "personal" email. It's just an unreasonable risk, because EVERYONE is going to be trying to crack it, and eventually they WILL succeed.

For most people, the only major risk they will take with their computers is online banking; and current cryptography (presuming proper practices are followed) is sufficiently secure that it isn't worth the effort for anyone other than a nation state seeking to track terrorist funding, to crack it.

Remember folks, given sufficient time and motivation, "they" WILL get in. It's not whether you're paranoid, it's whether you're paranoid enough; or in this case, "secure enough".

For most people, in most situations, "secure enough" is pretty simple:
  1. Never do anything that requires any degree of security without strong encryption, and take reasonable precautions surrounding your internal data security; and that will keep your end of the data pipeline secure from everyone but large corporations and governments.

  2. Remember though, the other end is susceptible to compromise. You don't control that end, and that end may not be encrypted. Most data compromise occurs through careless handling at the endpoints, not in transmission.

  3. Also remember that your laptop or desktop may be lost, or stolen, or keylogged, or compromised and remotely controlled. Take reasonable precautions against such things; balancing the risk of compromise, against the value of using your computer to do those things that could be compromised

  4. An infinite amount more data has been compromised by poor physical security, or by simple human error; than by any deliberate attack against information systems.
So you have to evaluate the effort you spend trying to secure your network; against the effort to secure your office, and your users, and your service providers etc...

Actually, above all of that, people need to understand what exactly security is. For most folks, it's just some vague notion of being "safe"; but in the context of information security (and that's ALL information, not just electronic data) security has a very specific meaning:

Security is C.I.A.

No, not the Central Intelligence Agency, though that is a convenient and amusing coincidence to those of us in the field (security professionals have an odd sense of humor, believe me); but it is an acronym.

C.I.A stands for:
Confidentiality: Your confidential information must be kept private. No one should be able to access your confidential information without your knowledge and approval.

Integrity: Your information must be protected from tampering. No one should be able to modify your information without your knowledge and approval.

Availability: Your information must be available to authorized users when they need it. No one should be able to prevent authorized users from accessing your information without your knowledge and approval.
Most people only every think about the confidentiality aspect of security; but integrity and availability are equally as important, and often harder to achieve. Worse, a compromise of integrity or availability can be far more damaging than a compromise in confidentiality.

After all, what good is keeping your bank account data secure, if you can't get your balance when you need to; or if someone has altered the account number on a funds transfer to redirect it to Burkina Faso, instead of your bank account?

Again though (and this is going to get irritating because I'm going to repeat it several times), for most people, most of the time; an appropriate degree of security isn't that complicated. You just need to follow good security practices, take simple precautions, and balance your risk against your convenience.

Ok, How? What are the risks? What are "reasonable measures"?

Well, I can't tell you how to run your life, or what your specific risks are; or even how to weight those risks against convenience and usability; those are all individual determinations. I can however use myself as an example.

The first question is about risks. These are the things which make people paranoid; because as human beings we are generally poor at evaluating risk, and especially evaluating relative risks against rewards or utility.

For example, people worry to a ricidulous degree about their credit card being stolen online; but worry comparitively little about using their credit card in stores and restaurants; or the fact that credit card companies mail their cards to them via first class mail. In fact, over 99% (yes, really, over 99%) of all credit card compromises are either at retail point of sale, or through the mail.

I have a simple philosophy about risk, and that is "You don't stop mosquitos with machine guns"; by which I mean you don't want to try and identify and address every specific possible risk, because you can't possibly know what every risk is.

Instead, you want to build a good solid foundation of security and information management technologies and practices, appropriate to your overall level of risk; which by it's nature will address ALL risks as a whole. You also want to have the tools and techniques available to you for responding appropriately when there IS a compromise.

So to extend the analogy, don't try and shoot down the mosquito; put on some bug repellent, and a mosquito net, and live in a house with as few open windows as possible; and keep some antibiotics, qunine, and doctors information around for when you do get bit.

As to reasonable measures, again you have to figure out what is appropriate (or available) to your environmnet; but I can use myself as an example.

I take simple, but effective, precautions to mitigate and manage my risk; and balance it against the convenience and usability I expect from my systems.
  1. Whenever possible, I use strong passwords that are not related to me or my personal data in any way; and which cannot be related to any word in any dictionary, or any variant or misspelling, or character substitution thereof.

    I suggest taking a song lyric; stanza from a poem; or a phrase, sentence, or paragraph from a book or story you know very well; then using either the first letter of each word, or the first letter of each sentence, and mixing in capitalization, punctuation marks, and numbers to reach at least eight characters.

    Passwords thus derived are very easy to remember, but essentially impossible to guess, or use some kind of pattern matching algorithm on (called a dictionary attack). Oh and you'll never run out of them so long as you can remember a song.

    I wont say "don't use the same password for everything"; because you've all heard that a thousand times already; but if you're like me you WILL use the same password for many things.

    That's OK. It's better to use a single good strong password for most things, than to try and remeber a dozen weaker passwords.

    Choose a good, strong password; and use that password for all those accounts that don't require a lot of security (like online forum accounts or somesuch) and you should be fine.

    Please though, do use a different (and hopefully even stronger and better) password (and a different username too, if you can choose it) for each of your online banking accounts, credit card accounts, and home utility acounts. Also, never use the same password for your secure accounts as you do for your email accounts. That way one account being compromised won't result in all your other accounts being compromised.

    Oh and PLEASE PLEASE PLEASE, change your passwords every once in a while. It doesn't have to be every few weeks; but a couple times a year would be a good idea. The longer you use the same password, the more likely that password is to be compromised.

    Unfortunately, some companies or web sites insist on using stupidly insecure things as passwords (like social security numbers), or have password policies that prevent you from using good passwords; but I try to minimize what I do with those companies over a network.

    In fact, I sometimes decide simply not to do business with those companies based on their poor security practices.

  2. I never write anything down, or store anything on a computer, or transmit anything via a computer or network (oh and that includes phones by the by) that I am not prepared for the New York Times to publish; without encrypting it first.

    Even then, I don't transmit any truly critical secret data over any public data network, excepting credit card purchases and online banking; because I have decided that the (small) risk of compromise is worth the (very large) convenience of those things.

  3. I use a strong open source encryption scheme, and associated software; and I keep them updated.

  4. I keep my computers patched and updated, to try and keep ahead of vulnerabilities.

  5. I do all my computing behind a hardware firewall. I even have a mini hardware firewall that I travel with, and that protects me at client sites, wireless hotspots, hotels etc...

  6. I try and only use software that is not inherently, stupidly, buggy and insecure. I unfortunately have to use Microsoft operating systems for much of what I do; but I don't use internet explorer unless forced into it for example.

  7. I do not engage in stupidly risky behavior with my systems, or my data.

    I don't disclose private information to anyone without good reason, authentication, and security (is that REALLY your credit card company on the phone?); and I don't give websites that data either.

    I don't visit shady web sites, or use my credit card in shady retailers.

    I don't let strange people drive my car or walk around in my house. I also don't download or run untrusted files with executable content, or ANY files of any kind without virus and spyware scanning) that would be likely to result in compromise.

  8. I use multiple layers of malware detection and prevention, including virus scanning, spy and adware scanning, intrustion detection, and configuration management systems (yes, configuration management is a security tool); and I keep them up to date.

  9. I attend to the physical security of my systems, my data, and my environment.

    I keep my laptop and smart phone secured to my person at all times while traveling. I keep strong passwords on my systems and encrypt sensitive data, and don't travel with my most sensitive data; in case I DO lose a system, or it is stolen.

    Oh and it should go without saying, I don't keep physical copies of passwords around for people to read. Post it notes have broken more security than weak crypto by two or three orders of magnitude.

    I also attend to the physical security of my computing and data access environments. I only perform operations that require security in environments that I trust; and I protect those environments against physical compromise (or in the case of wireless networks, using strong encryption).

    Anything physical (printed, stored, saved, written) with confidential data on it gets securely stored (in safes or security cabinets) when it's not being accessed. After that physical media is done being used, it is either securely erased, or securely destroyed.

    I shred any physical media with any kind of personal data on it. Crosscut shredders that can handle cd roms and DVDs are your friend. Secure file deletion programs (the software equivalent of a shredder) are also your friend.

    Yes, the NSA can probably recover something from your hard drive after using a secure delete program. Unless you're the president, the president of a bank, or connected to Osama Bin Laden; no-one wants your email bad enough that you should worry about it.

    If you're really paranoid, or just bored, do what I do: Degauss the things with an industrial degausser, then take them out into the desert and shoot them full of holes, blow them up, or slag'em with thermite.

    Or more boring, hire a data destruction service to put them through a chipper-shredder (yes, they make a chipper shredder for hard drives. They're great fun to watch actually).

    Remember, post it notes, ethernet ports, wireless networks, cd-roms, and flash drives (or USB ports), are all far easier to compromise than strong encryption.

  10. I keep multiple, known good, encrypted copies of all my critical data, on read only media, in at least two separate and reasonably secure environments.

    I also keep at least two backups of all my systems; one online or nearline, and one in a fire safe (I try to keep them current, but admittedly I fall behind some times).

    It doesn't matter how secure your data is, if you can't get to it; or if it gets lost or stolen or destroyed.
By taking just those basic, common sense precautions, I've protected myself against at least 99.99% of the possible threats out there (or at least the ones I can personally address. Again remember, most compromises are at the endpoints. You can't take personal precautions against your banks janitorial service throwing out a printout with your data on it.); without significantly reducing my convenience or usability; and without taking undue effort or energy.

I'd say that's about the best you can hope for given the world we live in today.

Sunday, February 01, 2009

Won and Lost by a Toe Pick


And in other news, a massive upsurge in suicides, car accidents, broken windows, broken hands and broken legs to be expected in Las Vegas and the entire state of New Jersey.

Seriously, this is going to be about the biggest loss the bookies have ever taken.

Main Course for the Big Game

Just thought I'd tease y'all with some pictures of my Andouille Guiness Chili; currently simmering away waiting for half time.


The full setup:


That'sa lotta meat (about 7-1/2 lbs):


Yes, really, it is a lotta meat:


Two hours to chili goodness:

Friday, January 30, 2009

Let me just talk about numbers again for one second

So let me ask you, what do you think would stimulate the economy more:

1. $819 billion of taxpayer money and bad debt on our national credit cards; distributed via political favoritism, cronyism, and cherry picking of favored causes

2. $2,676 in the pocket of every single man, woman, and child in America

3. $7,122 for each and every household in America

4. $11,870 for every household in America that actually pays taxes

5. $17,804 for every household in America that pays taxes above the margin line (they pay more taxes than the government costs per household)

Obviously, all but number one are politically unlikely because they would take control away from the politicians and actually give the people some of their money back...

...And of course 4 and 5 are right out, because that would be "taking money from the poor to give to the rich" (of course it wouldn't be, in fact all but 4 and 5 would be yet more redistribution of wealth from the middle class to the poor, or the politically favored).

Think about it though... which do you think would actually stimulate the economy the most? Which would result in the most job creation? Which would result in the most wealth creation? In fact, which would result in the most people with their lives materially improved in the long term?

Yes, that's right, it's options 4 and 5; because options 1, 2, and 3, are nothing more than broken windows.

The Unselfaware Irony of Fascism

Eric Arthur Blair famously said "The word FASCISM has now no meaning except in so far as it signifies
"something not desirable.
".

In this he was referring (among other things) to the tendency of those on the left to call anything which restricted their tendencies or desires in any way fascists; which in such usage has been the preferred cavil of liberals and leftists since the 1940s.

Sadly, most of those making such imprecations don't understand the true definition of fascism: a belief in the supremacy of the state and it's leaders, over that of individuals; elevated to a level of blind enforced obedience and popular obeisance.

Fascism, for all intents and purposes, is the worship of the state, and of the "Dear leader". Critically, when instituted it is always instituted by a majority, or a very strong minority, of willing subjects (I cannot call them citizens); who are looking for the government to "heal all their ills".

Pledge of Allegiance Becomes Pledge to Obama

By Alan Gray, NewsBlaze


A parent in the Clark County School District of Las Vegas, Henderson area reported January 27th that his son, who is in 1st grade, came home yesterday saying that he didn't want to go back to school anymore.

When asked why, the boy said that during the Pledge of Allegiance the teacher put up a large image of Obama next to the flag.

Thinking that the boy might be exaggerating, the man asked his son if he was sure, and suggested that by "large" he might mean an 8x10 photo of the president. The boy apparently said "No, it is a large picture of Obama and when we are done, the teacher turns off the image."

The same thing was not done for President Bush last year.

After investigating this morning, the other parent reported that what the boy said was true.

At least three of the five classrooms have an overhead projector and as the children stand to recite the Pledge of Allegiance, the teacher turns on the classroom overhead and a full body image of Obama, with six U.S. flags behind him, comes up about 4 feet away from the flag that hangs on the wall. The screen is apparently around five feet by six feet.

In the image, President Obama appears to be staring straight out with no facial expression, just a serious look. All of the kids in each class faced the President, instead of the flag that hangs in the corner.


15 years ago, I swore an oath to defend this country, and our constitution. Not our president, or our government; but our constitution. The president is our commander in chief; but our loyalty, our duty, our honor; is owed to the constitution, not to the president.

10 days ago, President Obama swore a similar oath; not to defend our government, or our leaders; but our nation, and our constitution.

America is an idea, not a man, or a government. That idea is expressed, however imperfectly, in our constitution; and those of us who chose to serve, be it in government, or the military; swear to defend that idea.

Isn't it ironic, how the only serious proponents of fascism today are militant islamicists, and western leftists; the very people who, in form at least, rail against fascism... which they are most often accusing US of?

Thursday, January 29, 2009

Let's just say, I'm familiar with the lesson

Though this programmer doesn't work in my organization (we're between three and four times larger than that), I am very familiar with his pain:

Here's a brief overview of what Bruce had to go through to get four (one each for development, testing, staging, and production) Windows-based Web servers:

Week 1 -
At the same time Bruce's group started the project he went to procure the servers. He was told that all he needed to do was put in a Service Request with the Windows Server Team and they would get what we needed. However, that request is cancelled because when the Windows Server Team saw that the servers were for a new application they said, "Whoa, you have violated rule #38,991 of the Mega Bureaucracy! New applications must go through the Process for Application Implementation and Navigation."

Bruce starts into the fill the first two PAIN forms (one being 20 pages long with 150 questions), sends them off to the server team, and immediately receives a response that, no, do not directly send PAIN forms to the group they go to. Instead, open a project with the Mega Bureaucracy's project tracking system, attach the forms and THEN assign the project to the group.

A few days later, he receives word that the project has been accepted, slotted, and a project manager assigned. Bruce figures, "Cool, now we are moving! I'll have my servers in no time!" He and his boss have a conference call with the PM and express to him the time critical nature of these servers. The PM agrees to push them forward saying that the request isn't complex and shouldn't take much effort.

...Snip...

Week 18 - The head of IT for our division finds out that we are still waiting. Heads start rolling...even poor Bruce's. "WHY DIDN'T YOU CALL ME SIX %($$!*& WEEKS AGO???" the IT head blasts.

Week 19 - The servers are built (it only took 2 days to build them!) and are signed off for production support.

Week 20 - Bruce distributes the application URL pointing to the brand new servers.

Through all of this Bruce learned a couple things. First, don't even think of going around the Mega Bureaucracy, even if somebody says you can. The Mega Bureaucracy remembers and brands you a heretic. Second, if you think you will need help from the Mega Bureaucracy, start early, fill out all of the forms, stand in the right lines, sacrifice to the appropriate gods, and don't even hint that you would think of going around them. Finally, he who yells loudest gets move the front of the queue soonest - as holy and almighty as The Mega Bureaucracy is, they're happiest to get rid of their crabbiest customers first.

The silver lining in all of this? Apparently, the Guardians of the Mega Bureaucracy seem to now be willing to consider that there is a different tier of requests that don't require so many stopping points, designed to make sure that users really, REALLY know what they want to request. Bruce remains positive saying that, maybe in a few years, after meetings to plan meetings, forms to request forms, they will have a process that only has an initial questionnaire of 10 pages and 75 questions.

Remember how I said I love my job, when I'm able to thwart the bureaucracy enough to actually do it? That's pretty much what I'm talking about; though because I'm at a higher level, I've actually got more layers, more forms, and more questions to deal with.

Oh and 20 weeks start to finish for four servers? That's fast. I've had similar requests take 18 months before.

We do have an "accelerated" process that's supposed to take 10 days... and it does... 10 days from the forecast install date until the server it turned over to testing. Then two weeks in testing before it's handed over to you.

Of course you have to be on the forecast 30 days in advance of your planned install date. And to get on that forecast you have to project the funding and capacity request six weeks to three months in advance of the forecasting date; and get enterprise planning approval from your organizations enterprise planner.

It's all very complicated.

Say you have a need for computing resources to run your application. What you do is you go to your enterprise planner and let them know you need computing resources (if you have a very good idea of what you need already, including approximate costs); or before you go to your planner, you come to me and say "I think I might need some servers".

Either way, the next step is to consult with me and my team. We work with you to figure out your business and technical requirements. Then we architect a high level solution to fit within enterprise standards, practices, and direction; or if necessary get exceptions to those standards, practices, and direction. We also decide if your solution can be met from our standard catalog of preconfigured (not really) offerings, or if it has to be a custom configuration.

If you can use a standard offering, then you MAY be eligible to go through the "10 day" process. Otherwise, it's the "custom" non-expedited process for you.

At the end of that initial consultation we give you a high level architecture, and a guidance number, that will be your budget request to within +/- 20%, and the core of your business case.

Then you go back and write up a business case; and take it to your planner, and your management, with that guidance number; and ask for the budget allocation and to be put in the project pipeline.

If your planner and management give you approval, then your project is opened by your planner and the project manager for your organization, and the timeline officially begins.

This could be any time from the day after you ask your planner, to 12 months later by the way.

Your first step in the project pipeline is back to my team; where we re-evaluate the project and account for any changes that may have occurred since we first consulted with you. Then we take the high level architecture we originally created, and refine it into a detailed architecture and design. We also get guidance quotes from any outside vendors, and internal quotes from all the supporting groups; and produce a costing document accounting for all hardware, software, support, infrastructure, facilities, and labor costs, extended out for four years.

This will be your final budget number to within 10% unless there are changes to the project made during the implementation process.

Finally, we all meet together to ensure that the proposed solution meets the business needs of your group, that it is within budget, that it fits on the schedule, and that it meets enterprise standards, practices, and direction; or that exceptions for such have been approved.

You sign off on it as the project requester, the planner signs off on it, and as chief architect, I sign off on it; certifying it as ready to go.

But wait, there's more.

Up 'til now, the clock isn't running. Once we sign off on it and get ready to kick it into implementation, this is where things get REALLY complicated.

The first step is funding approval (finance departments for the enterprise, and for your organization; as well as your management and your enterprise planner), hardware approval (hardware finance), software licensing approval (software finance).

We can't move to implementation phase without those; and they aren't covered by all the previous approvals.

For this process the clock IS running; and it's a 7 day clock, that can be extended out to 30 days. If that clock runs out the project is canceled and you have to start over.

Once you get the funding approvals, THEN the actual implementation phase begins, and we hand the project over to the Systems Integration department, who manage the implementation and integration process.

So then you get that 10 day server build thing right?

Well, no.

First, the project has to go through hardware engineering (the guys who write the build sheets and parts lists), and the output of the HE team goes back to ME for my approval (to ensure it matches what we specified in the design and architecture phase). From there, it goes back to the vendor for a final quote using the parts specified in the HE build sheet. That quote is sent to contracts to for contract approval, and then on to purchasing.

Then there's the network infrastructure approval (network engineering), security approval (security team), firewall approval (firewall team), hostname and IP address allocation and approval (DNS management), datacenter approval (datacenter engineering),power approval (power committee); before systems integration hands it off to the build team for your 10 day build.

And remember, that's the expedited "10 day" process. The groups involved in all the above have agreed that once the clock starts running at funding approval, that their inputs and approvals for projects that have been approved by my group to go through the expedited process, will be completed within the 30-45 day forecasting window (depdning on what exact date you submitted the request).

So when it comes down to it, the "10 day" process, is actually 6-13 weeks plus 10 days to actually build the box (it usually only takes a few hours actually, but they build it within a 10 day window), plus 14 days for testing.

The non-expedited process can take any amount of time at all; in my experience up to two years; so long as it doesn't take more than 90 days in any one stage (including each individual approval), which will trigger automatic cancellation and you have to start all over again.

Of course, it is entirely possible if someone with enough clout, shouts loud enough, or bad enough things are happening; to have 24 new $300,000 boxes and 20 terabytes of enterprise SAN storage, on the floor, built, tested, and ready to go in 7 days.

It's all about who's yelling, how loud, at whom.

Oh and all that stuff? My team does about five hundred of them a year; and that's actually only about 1/4 of my job responsibilities. The other stuff is even more convoluted and takes even more time.

Aint big business just grand?

Wednesday, January 28, 2009

What getting it wrong means


Today was the 23rd anniversary of the Challenger disaster; January 28th 1986.

I was one of the schoolchildren that NASA had arranged to watch the challenger launch via closed circuit TV. I remember sitting there in science class, gray haired and floral printed Mrs. Burke and the kids I'd been with since kindergarten all around me.

It seemed like it took forever for the countdown, and then the engines, and the steam and smoke and it took FOOOOREVER for it to lift off; but there it went.

73 seconds...

When you're a kid, 73 seconds seems like an awful long time.

Most of the kids were already starting to turn away, bored; but I was still watching, and so was Mrs. Burke.

73 seconds...

I don't remember seeing the explosion honestly. I know I was watching, I know I saw it, I remember the emotions.. confusion, anger, fear, sorrow, more confusion... but I don't remember seeing the explosion.

What I remember most is Mrs. Burke gasping, and crying. I'd never seen a grownup outside of my own family cry in public before. and in the halls you could hear the sound of more crying. More grownups crying.

We were all sent home that day. Everyones faces looked wrong. Everyone knew that those people had died; but bigger than that, something great had been wounded badly that day.

That's what happens when engineers get it wrong.

Occasionally in my work I have been asked why I make such an effort to make sure I get everything right.

Everyone who knows me, knows that I am absolutely driven to get things right. There are a lot of reasons for that, involving my family, my ego, and just my general character; but there's also something that was absolutely ingrained in me during my education.

This question always shocks me; in that I can't imagine why anyone wouldn't try to do things right whenever possible; after all, it's your job, and any job worth doing is worth taking pride in; but I have a very specific example, and a very specific reason to explain it.

My degrees are in aerospace engineering and computer science. My aerospace engineering degree taught me to get it right no matter what it takes; because aerospace engineers can't afford to be wrong.

My degree advisor (a famous safety expert actually, who was involved in the Challenger investigation) said something to all of us that has stuck with me ever since. "When a programmer screws up, maybe a few hundred people lose some data. when an aerospace engineer screws up, a few hundred people die".

Remember Challenger? That's what happens when Aerospace Engineers get it wrong.

Challenger blew up, because some O-Rings were not quite as resilient as they should have been, because it was a little colder than planned on launch day.

It's an awfully small mistake, to cause such an awfully big problem; but that is the nature of the beast.

The engineers in charge of the o-rings were convinced by their bosses that it could be OK to go ahead with the launch, because they had designed enough safety factor in, that things wouldn't go wrong. They were told to "take off their engineer hats, and put on their manager hats"; and in their manager hats, decided that the risks were low enough, and having the launch on schedule was important enough, that they should continue.

They were obviously, tragically, wrong.

Richard Feynman (a personal hero of mine) was a part of the committee investigating the accident, and he famously said:

"For a successful technology, reality must take precedence over public relations, for nature cannot be fooled."

No, it cannot. The laws of physics do not forgive error.

There's another example that struck me from when I first read of it as a child; and has had a profound impact on me ever since; informing on everything that I do.

Do you remember what the first jetliner was?

Most people remember it as the Boeing 707, and indeed it was the first commercially successful jet airliner; but the first jetliner to enter service was in fact the Dehaviland Comet, in 1952.

The reason people don't remember the Comet as the first jetliner, is because it was withdrawn from service in 1954, after suffering five crashes in two years, killing 109 people; and wasn't returned to service until late 1958, after the Boeing 707 had already started to become the dominant airliner.

It turns out, that there were two very small errors in the design; that had very large consequences.

The first problem, was that leading edge of the engine inlets was curved a little bit too sharply, causing the engines to lose power at certain angles. This caused the first two crashes, both within a few months of entering service.

The second mistake was even smaller, but was far more serious.

The comet was not only the first jetliner; but also the first aircraft in airline service that flew as high, or in as great temperature extremes. This of course has an impact on the aircraft, which is after all made of aluminum only as thick as heavy paper.

When an aircraft is pressurized, it turns into an aluminum baloon; stretching very slightly. It contracts slightly when depressurized. While pressurized (well... at all times really, but the impact is greater while pressurized), turning, climbing, and descending; stretch, compress, and stress the aircraft in many ways.

This is reasonably well understood, and was even then; but this was a whole new category of aircraft. The only similar aircraft in existence at the time were military bombers (in fact the Comet was itself a variant of a military bomber design, the "Nimrod" which served in the RAF for over 20 years); and military bombers don't have amenities like cabin windows.

A cabin window is of course a hole in the aluminum skin of the aircraft; which as I said is being stretched tight like a baloon.

You might have noticed when flying in a modern jetliner that the windows are kind of a flattened oval shape at the top and bottom; with very gently rounded corners.

The Dehaviland Comet is the reason why... or rather physics is the reason why, but the Comet is what taught us the lesson.

The windows of the Comet had roughly square corners. In physics, square corners are often called something else: Stress Risers; because stress tends to concentrate at those points.

Over the course of a few hundred flights, pressurizing and depressurizing, small cracks would form at the square corners of the windows. Eventually these small cracks would travel along the skin, becoming large cracks; and causing the entire fuselage to fail in mid flight.

It's a very small error, caused because the designer liked the look of square windows (which previous unpressurized airliners had); and didn't take stress risers into account.

It was a very small error, that cost 109 people their lives.

That's what happens when you don't do everything humanly possible to get it right.

In my current job of course, peoples lives don't depend on me getting things right. I'm not a doctor, or an aerospace engineer, or a fighter pilot; but it's still important that I get things right, and not just for my own satisfaction.

In my position, if I get something important wrong, my company could lose millions, or even hundreds of millions of dollars. Peoples jobs are lost over such things; their lives changed greatly for the worse.

And the thing is, you never know what's going to be important. Get the corners of windows wrong, or the flexibility of a little piece of rubber at 32 degrees; and people die. The law of unintended consequences is always in play.

Remember, you can never do just one thing. No matter what you do, or try, or say; no matter what precautions you take; you cannot know all the consequences, effects and impact of your actions.

So you better get it right.

Bronchitis busts my ass

So, the sinus thing from last week has drained into my chest and gone bronchial.

No biggy, happens to me about once a year; but it's still a pain in the ass... or rather chest.

I'm still working though. 12,000 word storage architecture doc published today.

Mental energy gone. Physical energy gone. G'night.

More Lethal to Artistic Types

The age of 27, Seconal, or their own egos...

Just a random thought...

Just in case, I'd avoid taking barbiturates when you're 27.

Tuesday, January 27, 2009

A Kind of Coming Out and a Confession

Well, for those of you who haven't figured it out already, I'm a submissive.

A what?

A submissive. Someone who's foremost desire is to submit and please, who is happiest and healthiest with someone else else in control.

I had a big long post semi-written up where I explained all of this, and then realized what I was doing.

I was trying to justify myself, but there's no justification needed.

I am a submissive. I am not weak, or stupid, I'd just much rather my dom (Chris) be in control.

It's honestly that simple. I don't know why I've been so ashamed of the way I am for so long. So ashamed that I've been writing about it at another site instead of just coming out and saying it.

That is who I am. I am no longer ashamed of being who I am.

More anon.

Mel

Oh Believe Me, We've Got the Postage

Dilbert.com

The most dangerous phrase strikes again

Seriously, congresscritters are morons. There can be no other explanation.

Sadly, this is not the most idiotic, ridiculous, laughable, or embarrassingly stupid law ever proposed; but it's close:

" New Law Will Require Camera Phones to 'Click'
Author: Michael Horton

A new bill is being introduced called, Camera Phone Predator Alert Act, which would require any mobile phone containing a digital camera to sound a tone whenever a photograph is taken with the camera's phone. It would also prohibit such a phone from being equipped with a means of disabling or silencing the tone.

While its a good gesture, I do not believe having such a law would deter criminals from hacking their camera phones to take pictures in inappropriate ways. Also, the real criminals would not even use a camera phone but would probably use other devices such as a hidden camera. Regardless, at least with the bill signed into law it would allow prosecution and jail time for individuals that get caught with a camera phone that does not make the noise.

One question does remain, what if you have a camera phone that doesn't make the noise at all or is suppressible? Would older phones still be covered under this new law?"
So, if my finger happens to be blocking the speaker, what then?

What if my phone breaks and the tone doesn't work?

What about digital cameras; they're quite small and easy to conceal?

What about deliberately hidden cameras, or novelty cameras that look like other things, will those be illegal as well?

Yet another example of one idiot... or given the subject matter probably thousands of idiots... saying to another idiot (one with power over us, god help us) "There ought to be a law"; the most dangerous phrase in the English language.

Monday, January 26, 2009

The Unintentional Straight Pull Bolt Action Rifle

So it seems like Ambulance Driver is having a little trouble with his AR. It'll run for 30-100 rounds, then it becomes a straight pull bolt action.

Well, we've all been there at one time or another. Hell, I had it happen to me at a rifle event once (bad ammo).

Thank god it never happened when I actually NEEDED the rifle for serious social purposes (which is why I always have known good ammo and magazines, and clean and lubricate properly).

Since the rifle in question is a decent quality piece (a Bushmaster), the problem gets progressively worse the more he shoots, and he doesn't mention having problems with his magazines (the usual culprit when ANY semi-auto isn't cycling properly); I'm guessing it's one of two problems:
  1. Cheap nasty steel cased ammo

  2. Overlubrication
Seriously folks, I don't care how cheap you are, or how expensive ammo is, AR's are not designed to function with anything other than brass cased ammo.

Brass and steel cases expand to seal the chamber (called obturation) differently, and retract from that seal differently. This alters the timing of the weapon and causes unreliable extraction. This is especially true of M4's with their shorter, higher pressure gas system; which is much more sensitive to proper timing.

Also, steel rims, combined with that different timing, work the extractor of an AR MUCH harder than designed; and can detension an extractor spring in as little as 500 rounds instead of the 5000 or so (or 20,000 if you have the machine gun spring buffer, and an o or d ring in) you'll get with brass.

Also, the powders they tend to use in steel cased ammo are nastydirty; and will gum up the gas system and bolt, and blowback more residue into the receiver, coating everything with FAR more carbon than in higher quality ammmo.

Additionally, that difference in obturation causes firing residue to blow back into the chamber, progressively coating it with more hot sticky stuff; until extraction and even feeding become difficult. If the extraction get's sticky enough, it can actually chip the extractor, or tear the head off a cartridge leaving you with a not every effective club.

Again, these issues are exacerbated in shorter length carbines.

It doesn't matter whether it's polymer or Lacquer coated; steel is just generally not great for ARs. It will have problems with extraction over time, I guarantee it to you.

Seriously, that's just more to clean, and less reliability; don't use it.

I suspect the biggest problem he's having though, is that he's overlubing the weapon.

Almost everyone does.

Even better, most folks don't recognize overlubricating for what it is, think they're UNDER lubricating the weapon, and make the problem worse by squirting even more goop in there.

Then when that fails, they make it yet worse by switching to another product incompatible with the first that has suspended nano super slip lube in it or somesuch crap; and they might as well squirt superglue into their action.

Overlubing will gum up your rifle in a magazine or three pretty easily; even if you're using clean ammo, and you're not in a dusty environment. Add in dirty ammo or dust, and again, you might as well be using superglue for lube.

So, what is the proper lubrication for an AR (this applies to an M16 as well; you just need an additional drop or two for the auto sear mechanism)

Alright first things first, you need to undo the damage.... actually you should do this when you first get your AR, and every 1500 to 5000 rounds (depending on conditions and ammunition) or every six months anyway.

For this you will need your normal cleaning supplies, CLP (or something similar), original Militec (or something similar), and a non-chlorinated degreaser/cleaner that doesn't attack ABS plastic (I use M-Pro 7, Slip, or Hoppes elite; all essentially the same thing); and you may need a carbon solvent (I use Hoppes elite).
  1. Detail strip and clean the rifle, paying special attention to your bolt and carrier, trigger mechanism, and your chamber and chamber extension. Clean them to bare metal, with a degreaser, and if necessary a carbon solvent (especially the internal passages of the bolt and carrier). Use a chamber brush and barrel extension brush to make sure they are really properly clean.

  2. Spray your trigger mechanism, the internal surfaces of your receiver, your barrel extension, and your receiver pin bosses, LIGHTLY with CLP. Then cycle the trigger a few times to distribute, and let sit to dry.

  3. After a few minutes, wipe every surface you can reach clean and dry. If you happen to have some compressed air, you can let it sit a few minutes then blow it off; but lightly means lightly, so that shouldn't be necessary.

  4. If you reassembled them after cleaning, disassemble your bolt and carrier mechanism; then coat your bolt and carrier mechanism and all components thereof (including the internal passages, using a q-tip if necessary) liberally with CLP.

  5. Let sit for a few minutes, and wipe all the parts down til completely dry. Remember to pass a Q tip through the firing pin passage in the bolt and carrier to wipe them dry.

  6. Then let it sit for a few more minutes, and wipe them all down again.

  7. Put a single drop of militec or something similar on each trigger pin.

  8. Put single drop of militec into the trigger and sear, and smear a bit into the hammer hooks and disconnector, then cycle the trigger a few times to distribute. If this is an M16/M4, also put a single drop on the auto hooks, and a single drop on the auto sear pin.

  9. Put a single drop of militec on the safety or selector, and smear it around with a q-tip; then cycle the safety a few times to distribute.

  10. Wipe everything you can reach with your fingers or a qtip, to distribute the lube. Nothing should look "wet" or greasy.
That may seem like it's a bit fussy, or a lot of work; but remember this isn't your general clean and lube procedure. You only need to do this every few thousand rounds.

Also, it sounds a lot more fussy than it really is. It took me longer to write it up than it does to actually do it.

What you're doing there is cleaning off all the pre-existing or built up residue and lubricant; then establishing a coat of protectant and baseline lubrication level on all surfaces.

Now, when you reassemble from your detail strip, and again every time you clean the rifle:
  1. Put a single drop of militec on both of the bolt rails, then spread up and down the rails.

  2. Put a single drop smeared evenly around the body of the bolt and a little into the cam slot and onto the cam. DO NOT put any lubricant into the gas rings, the firing pin passage, or under the extractor; enough will be there from the CLP earlier, or will migrate there during use.

  3. Fit the bolt and cam back into the bolt carrier, then work them back and forth a bit to distribute the lube, and disassemble again.

  4. Put single drop on a q tip wiped around the entirety of the bolt ears; then wipe it off with your finger tip to spread it out a bit, and a dry q-tip to make sure no lube builds up in the corners. DO NOT LUBRICATE THE BOLT FACE, EJECTOR, OR EXTRACTOR; they will get enough lubrication from the initial CLP coat, and through surface migration.

  5. Wipe all the bolt and carrier parts down with your fingers to spread the lube evenly; and so none of the parts or surfaces are actually "wet".

  6. You generally don't want to re-lube the trigger mechanism with every cleaning; because you don't detail clean the trigger every cleaning, and it can cause lubricant and residue to build up. If however you're feeling any drag or grit in the trigger or selector mechanism and don't have time for a detail cleaning, re-lube the trigger and selector as above.

  7. Reassemble taking care to ensure the gas ring gaps are not aligned; then cycle the weapon and dry fire a few times to distribute the lubricant.

  8. Finally, wipe down every visible surface you can get to with a clean dry cloth.
When you're done, no surface on the rifle should look "wet", and if you wipe any part with a clean white cloth you should come back with a slight oily residue, but no heavy smear of oil and no carbon.

Again, this sounds a lot more fussy than it really is. It takes less than five minutes, and no tools; and even the q-tips are optional (you can spread lube into small spaces with the firing pin and your fingers; it's just not as easy or convenient as a q-tip).

That's it. Everything else is overlubing and will attract residue, dirt, and grit like a magnet.

UPDATE: Reposting with some edits on a Monday, because there's a lot of AR owners who really need to read this; and nobody ever reads anything posted on a Saturday.

Also, I have heard several supposedly knowledgeable "authorities" stat that it is "impossible to overlubricate an AR". Those people are on crack.

Actually, I'd guess they are overgeneralizing from their own personal experience; which is limited to environments where overlubrication isn't a problem. They are most likely people who never shoot anywhere but on a clean range with clean commercial ammo; or they are garrison or fleet marines who never served in a desert environment.

Seriously, I think sailors and fleet marines believe lubricant is best applied with a firehose. Also someone should teach them yes, it is actually possible to clean your weapon too much. When you're wearing off the hard anodizing, that's a sign you've gone too far.

Most airmen on the other hand (outside of those who have served in combat support of course), if they even remember what an M16 looks like, think lubricant is something purchased with their other Class VI "critical supplies".

Sunday, January 25, 2009

Is it my imagination...

... or do Snickers not taste as good as they used to?

Maybe it's my imagination, or maybe it's my palette changing; but to me, snickers definitely taste less rich, and less savory than they used to.

And I'm not talking better than 20 years ago, I'm talking better than 2 or 3 years ago.

I've heard that some major candymakers have stopped putting cocoa butter in their chocolate and are now using hydrogenated palm oil and soy lecithin... at which point you shouldn't even call it chocolate; but I don't think that would account for it all by itself.

To me, the chocolate has a milder, less intense flavor, and a poorer "lower quality" mouth feel. The caramel seems chewier but less sticky, and less salty... in fact it has no savoriness at all, and very little buttery flavor; and the peanuts definitely seem less salty to me.

Snickers used to be my favorite candy bar (though my favorite mass market chocolate candy has always been, and still is, Reeses peanut butter cups); now I really don't care for them.

I think I've noticed the same lack of savoriness and poorer mouthfeel in M&Ms as well; and I'm SURE that neither the chocolate nor the peanut butter in peanut butter cups are as good as they used to be (though I still like them).

Random Pop Culture Thought Excercise

So, imagine they are producing a modern 3 stooges Biopic, and you have to cast Larry, Curly, and Mo (not Shemp, Curly Joe, or Joe Besser).

Who would you cast?

Seriously this is tricky. They're going to need to able to play natural physical comedy, as well as drama and depression. Also, they need to be short (Curly was the tallest, at 5'5), but have physical presence. Oh and they're going to need to play a broad age range.

Larry is easy, David Paymer. He not only looks the part, he can sound it too. My only concern is that he might be a little old at this point.

Curly, there are a lot of options; but I'd love Michael Chiklis in the role (update: apparently he played Curly in a 2000 tv movie that I didn't know about. So I guess I'm not the only one).

The hard one is Mo, and I'm really having a hard time with it.

I think Jason Alexander could pull it off, but he's just too... small isn't the word, maybe pinched? I mean he's short (5'5 just like the boys) and broad, but he doesn't have a broad presence. Like he's wound up too tight.

Actually... thinking of it, Alexander could probably play any one of the three; but he's not "just right" for any of them.

Wallace Shawn could probably pull it off; and he's just one of my favorite actors on the planet; but he's just a little TOO short.

Paul Giamatti maybe? He's another one of my favorite actors, and he's relatively short at 5'8; and again he could probably play any one of the three... maybe not Curley, but definitely either larry or moe... still not sure he's "just right" though.

I dunno I'd have to think about it some more, and I'm not going to bother right now.

Who'd y'all pick?

Oh and if I were to cast for Shemp, my ideal choice as a performer would be Richard Kind; but for the fact that he's too tall.

Friday, January 23, 2009

No Joy

There's an old pilots expression "No Joy" which means "No contact" or "action unsuccessful" depending on the context.

I have a problem in my life... one I suspect I share with a lot of folks out there.

Other than my wife and kids, I have no joy in my life.

Or perhaps it's better put that while there is joy in my life, I can't see it; or I can't reach it.. or the action is unsuccessful... thus the phrase is both literal, and appropriate in its military context here.

Oh, I have fun sometimes, and I have satisfactions. I get satisfaction from my job; when the bureaucracy can be thwarted enough so I can actually do it. I have hobbies, and interests, but I'm rarely able to pursue them between money and time consideration. I love my friends, and have some fun in spending time with them. I love my kids, my wife, my dogs... but the joy in them is tempered with care and responsibility and worry.

I'm not depressed by any means. In fact I don't think I ever really have been depressed in the way most people mean. Misery, melancholy, and despair are just not in my nature. Also, I'm not "unhappy" in a general sense. Sure there are specific things that I'm unhappy about; but I love my wife and kids, I like my job, and in general my life is just fine (if a bit boring... by my standards anyway. Other people tell me my life is soap operaish, but you don't really see it that way from the inside. My standard of "not boring" is almost dying on a regular basis).

I just have no joy.

I've lived this way before, for years at a time sometimes (and worse, no joy, and being alone); but some years ago I decided I wasn't going to do that any more. Life isn't life without joy.

I'm not sure what I'm going to do about it; but I am going to do something.

There are many things I COULD be taking joy in, were it not for the pressing cares and burdens of my life. I used to take great joy in shooting, driving, flying, boating, hiking, reading, music, and movies... now at best they are a relief, not a joy.

It's a bit hard to explain, but it's kind of like chronic pain. If you live your entire life with pain at level 4 or 5, going down to pain level 1 or 0 is a tremendous relief; but it's the absence or lessning of, or relief from, pain and stress; it's not truly joy.

Even typing this, it feels something= like "Poor poor pitiful me"; but it's surprisingly wearing supporting four on a single income (even if that income is substantial); helping my mother out, dealing with Mels family, dealing with the legal issues, dealing with the stress of work, trying to improve our life together, and find the money to pay for it all...

I'm not one of those to go hermit, but I need some simple joys.

There's always my kids of course, but tempered with that joy is always the responsibility, and the care, and the worry (and yes the aggravation and the irritation). It's a duty and responsibilityI gladly bear, but you can't just throw it all away, and that's the kind of joy I need.

Maybe it's an odd quirk of my own psychology, but the second something becomes a duty, it is no longer a pleasure.... maybe I'm saying that wrong. When there is an expectation attached to a pursuit, other than my own internal expectation, then it is no longer strictly a joy for me; even though I may enjoy it.

I HATE having my vacations and weekends scheduled. I can't rest I can't relax. It's no vacation if I HAVE to do it.

I need to have something I have the freedom to enjoy or abandon as whim strikes me. I need to have something that excites and energizes me. I need to have something that is stress relieving; but is not only stress relief.

I need to ride motorcycles again, or fly, or fly RC airplanes, or build things, or do something that is nothing but fun (I have a very different definition of fun than most); and I need to be able to enjoy that fun without worry or care, at least for a time.

And no, before you ask, shooting doesn't do that for me. I love shooting, I have fun shooting, I get tremendous satisfaction and stress relief from shooting; but it isn't joyful (except in certain limited circumstances, like my first 1000 yard group, or achieving a goal I haven't reached before, or blowing things up with guns and explosives).

I guess the first step is to try to reduce some of the burden.

We're working on it. The legal bills have destroyed us financially for over three years now, and will be doing so for a while yet. I suppose that is our biggest burden.

Taking care of the kids, I've never seen as a burden, nor providing for the family. A sacred duty, and the only thing I really take joy in now, even if it is tempered; but not a burden.

My mother... oy... I'm not even going to talk about that anymore.

Mels family... well they aren't as bad as mine at least.

Other than getting the legal bills out of the way, I think lessening the burdens isn't going to be too productive in the next few years. Over time they may work themselves out, but there's nothing I can really do about them right now... not and live with myself afterwards anyway.

So I guess I'm just going to need to find some way to wrest joy out of the jaws of the grinder of life.

Wish me luck.

Just a little check on the numbers

So, as of today, the FedGov has committed, or is planning to commit to approximate $4 trillion (with a T) worth of "bailout" and "stimulus".

Just so we understand that number let's see what that means relative to personal and household income in the united states.

If we assume the current US population (2008 estimate) is relatively accurate at 306 million spread across approximately 115 million households; that's approximately $13,000 for every individual in the United States, or about $35,000 for every household.

The median personal income in the United States for those over 25, and with earnings (meaning it discounts all the unemployed, retired, and children and teens); is approximately $32,000. The mean household income for all households (including the unemployed, retired, children and teens) is approximately $46,000 with an individual earnings mean of about $23,000.

$13,000 for every individual, where the mean individual income for the employed is $32,000. $35,000 for every household, where the mean household income is $46,000.

It get's even worse if you account for the fact that approximately 40% of individuals and households pay effectively no income taxes; and only about 40% are above the margin line (meaning they pay more in taxes than the government pays out in expenses per person).

For the 40% of households and individuals above the margin line, that means a load of $32,500 per individual, or $87,500 per household.

Oh and of course that doesn't include the load posed by our $3 trillion dollar funded federal budget, and our $1 trillion budget deficit.... which conveniently matches the so called "stimulus" and "bailout" numbers.

...wait a sec...

So congress and the president have committed to, or are proposing that we spend a sum equal to our total budget; which is already in deficit by 1 trillion dollars (with a T)... thus increasing our deficit to 5 trillion dollars.

Oh and then there's our $11 trillion dollar national debt... which means they would effectively increase our national debt by almost 50% (to $16 trillion) in just one year.

In case you were interested, our gross domestic product per year is about $14 trillion; or $47,000 per capita... which happens to also be about the same as our median household income.

So let me get this straight...

In order to "bail out" and "stimulate" our economy, the politicians have committed to, or are proposing, that we spend an amount equal to our entire current budget; in the process increasing our national debut to more than our annual gross domestic product; and imposing a debt load on every household larger than their median yearly income.

Someone tell me again how this is anything other than a bad idea?

That's a little like saying "in order to get out of mortgage debt, we should put our mortgage on our credit cards".

Yeah... some folks tried that recently... didn't work out too well for them.

UPDATE: A reader comments that this makes perfect sense if you understand what the "stimulus" is really about.

I disagree. He presumes that I believe the so called stimulus plans are even intended to work.

They are not, and I am well aware of that.

Were they actually intended to work, they would be given as tax credits, deductions, and rate reductions or exemptions. This would directly increase the amount of money EVERYONE had to spend, and reduce all costs across the board. It would also eliminate the overhead of administering the program etc...

That would greatly and rapidly stimulate economic activity. In fact, in general, it would result in revenues HIGHER than they were before the tax cuts; though there is certainly a point of diminishing returns.

However, that would also reduce government funding, government power, and government control; and it would dramatically reduce politicians vote buying opportunities.

Their real purpose is to:
  • Increase governmental authority and control over the private sector
  • Increase the patronage money and opportunities for politicians to buy votes…
… but I’m pretty sure most of my readers understood that already.

The thing is, this mechanism won't achieve the true intended results either; or it will, but in an inefficient and suboptimal way.

The problem is, the people pulling this scam don't have even the most basic clue about economics.

David Poyer Fans

Hey guys, please tell me that they get better as they go; because I finished "The Med" yesterday; and it was a disjointed, poorly plotted, poorly paced, not very well written book.

The sections focused directly on Lenson were well done; but the rest... Junk.

UPDATE: Got a cople comments i the "sorry you didn't like it" vein, but I think I was a bit unclear.

I see great potential in the story, but the first novel in the series was poorly executed, excepting those portions of it directly relating to Lenson, and in Lensons POV (the book is in first person passive present, and switches back and forth between four POV characters).

My question is, does the writing technique, style, and execution improve, to allow that potential to become something good.

Thursday, January 22, 2009

Just a Thought...

You might end up with a lot more converts to your cause if you didn't insinuate that everyone who looks into a government job is an unprincipled apparatchik.

Just a thought.

Bullseye

Updates, Both Legal and Personal

Some of you may have been wondering how it is that Chris and I could get married, yet no legal update had been posted.

It's quite simple; only half of our legal issues (or really, 1/4) are resolved at this moment. The judge decided something very odd, and so we've been grappling with what to do ever since.

We expected the judge to rule on jurisdiction in one of two ways, either by ruling that AZ had jurisdiction, or ruling that BC had jurisdiction.

He did neither. He ruled that although he could take jurisdiction over the divorce (which he did, yay!) he did not think AZ could have jurisdiction over the children. He did not decline jurisdiction, nor hand it to BC, he just essentially said, "I don't think AZ can take jurisdiction."

We essentially ended up with a non-ruling ruling. Since then, after recovering from the "huh?" reaction Chris, my lawyer, and I had, we've been pursuing legal avenues to get the case looked at again. We've filed a Motion for New Trial and Additional Findings of Fact which, when translated to plain English means, "hey judge, we think you overlooked something and if you didn't, we'd like to know what you're referring to in your ruling."

My lawyer filed the final paperwork on Tuesday, and now it goes before the judge. Within the next 60 days we'll have one of three things; an "oops, I was wrong and here's the new ruling," a new trial, or an actual basis for an appeal.

Obviously life for us continues to be expensive while we wait for the judge. No matter what, our legal expenses keep coming. We have a plan for catching up (other than me finding a job that doesn't require the additional cost of day care) that will be revealed shortly. And no, this will not be another appeal for help, we've come up with an actual way to raise money that we think will be well received.

Unfortunately this means we will not be doing the big wedding in May. Legal costs are still in the "oh my god" range and we can't afford to do the wedding at this point in time. We've decided to wait the 2 1/2 years until my Catholic annulment comes through and have the big wedding when we have our religious wedding. However we will still be at the 2nd Amendment Blog Bash, since there's nothing like attending a nation-wide blogger meetup 20 minutes from your own house.

Despite the wedding plans falling through, we hope to see you all at the annual meeting in May.

Mel