Pages

Showing posts with label rants. Show all posts
Showing posts with label rants. Show all posts

Sunday, 22 July 2012

Why I'll stop using Google's Chrome browser - problems with Chrome





For a while I've been trying Google's free Chrome browser, but I'm now about to give up up. As someone who uses tons of tabs, and has them reopen on each bootup, Chrome's just not manageable.

Here's why - a litany of problems and issues which, unfortunately, I just can't waste any more time trying to fix.

1. No "most recently-used" tab switching (or MRU) as standard. It's the only way to implement switching, in my view, especially for "power users" who have lots of tabs open. Yes, there's MRU Tabs and Recent Tabs, but, especially when I've got lots of tabs open, they're nowhere near as powerful as TabMixPlus, which is my single most essential add-on for Firefox (and I regularly donate). And I want to use Ctrl-Tab for switching, not Ctrl-q! This is the biggest, biggest bugbear for me.

2. Crashing or freezing my entire Windows 7 system when trying to open locations or, especially, when close Chrome, often because of the Flash plug-in "not responding". Yes, I've tried disabling Google's own Flash player plug-in, then disabling Adobe's plug-in, but neither worked. I ended up disabling both to stop Chrome making my PC unusable whenever I tried to shut down. And if I need Flash for a particular webpage, I just view it in Firefox, IE or Opera. (I haven't tried reinstalling Chrome, as I didn't want to waste any more time on this.) Even without Flash, Chrome often still takes ages to open a webpage.

Tip: if you disable all versions of Flash in Chrome, it may come back whenever you update Flash generally, which you ought to do for security reasons. So after updating Flash, go back into Chrome plugins and disable Flash again.

3. Sometimes blanking out my webpages after I've gone offline. If I've disabled my internet connection, and yes I do that if I'm leaving the computer for a while, or if I've put the computer in sleep mode then wake it up, often my Chrome pages are completely blank. Firefox and IE etc don't do that, they display the same pages as before perfectly well, why Chrome does I don't know. Yes I have the Reload All Tabs extension, but sometimes it doesn't work and I don't have time to reload every page individually (which does work). "Waiting for cache" is another fun way to blank out my webpages and test the patience.

4. Here's another way Chrome often goes Nyah and refuses to show me many or indeed sometimes any webpages:

"The server at tech.slashdot.org can't be found because the DNS look-up failed."

(That happens even when Firefox, IE and Thunderbird are working fine, so it's obviously not my internet connection or my ISP's DNS servers that were up the spout.)

5. Using up way too much memory on my Windows 7 64-bit computer with 8 GB RAM. I'm talking up to 196 MB per tab in some cases! Firefox 12 uses far less memory, with many more tabs.

So yes, I'm exporting my Chrome sessions and history so I can access my important recent webpages in Firefox, and giving up on Chrome now.

Thursday, 25 September 2008

Stupid Aid: misuse of "security", "data protection", "health & safety"





In a separate post I had a moan about security questions asked by banks and the like being too easy for bad guys to answer, and identification requirements not making much sense.

But, many of us have also experienced the opposite syndrome.

Unnecessary security questions

Most of us have had to deal with organisations whose security policies (or their implementation) result in unnecessary security measures, insisted upon by jobsworth staff in certain businesses, who seem to delight in forcing time-poor customers to recite their name rank & serial number (& even more) before they'll deign to answer any questions about the company's products, services or terms.

Yes, even when the question is clearly very general and could be answered (by someone who knows what they're doing, at least) without any access to a customer's account or personal details - e.g. what are their current interest rates?

Then the jobsworth acts like they're the injured party if you try to point out that it's unnecessary to go through all that before they can deign to answer your particular question. (They'll insist it's "data protection" or "standard procedures", usually.)

UPDATE: of course, how could I forget, a friend just reminded me - once you've managed to get through one raft of security questions before they'll condescend to put you through to the right department, you guessed it: the next department then makes you go through all the same questions, all over again. And so on for the next department. Why on earth can't they just have one security check per call or contact? It's the same with credit card enquiries where you have to enter your long credit card number, date of birth etc on the telephone keypad first before they'll even add you to the queue of calls waiting to be answered. And when you finally get to speak to a real human being, they make you give exactly the same details all over again (including your credit card number and birthday that you'd already input before). Stupid, and exasperating.

Data protection

A related problem is when jobsworth call centre employees refuse to give out information about a customer to any third party, not even the parent of a child, or the close relative of a sick elderly person, "because of data protection". A friend has to deal with matters on behalf of a seriously ill family member who isn't physically capable of it, and the hoops that some people try to make my friend jump through are unbelievable.

A silly but true recent incident, which got some media publicity and was cited by the UK Information Commissioner's Office as an example of misunderstanding data protection, was when Marks & Spencer's staff refused to talk to a mother about a missing belt on her 7 year old son's Superman outfit "because of data protection" - forcing her to get him to come to the phone to give his mum permission to talk on his behalf!

As the ICO pointed out (my emphasis): "Whilst it right for organisation to be careful before releasing personal information, this case demonstrates an absence of common sense. In the circumstances it was obvious that the seven year old child would not have ordered the Superman suit himself. Marks & Spencer were not being asked to release any personal information: they were simply being told that a belt was missing from the order."

The ICO also pointed out some other examples of data protection rules misuse when urging organisations (my emphasis) "not to hide behind the Data Protection Act unnecessarily when dealing with individuals" - what the ICO calls "data protection duck outs" like "parents not being allowed to take photos of their child at a nativity play; teachers unable to promote the successes of pupils in the local media and priests prevented from praying for an ill person by name during mass", insurance companies refusing to send out a claim form if requested by someone other than the policy holder, and exam boards refusing to give a child's exams results to the parent (or indeed the child herself - only to the teacher, who'd entered the child for the exam!)

The ICO "data protection duck-out" note is worth a read as it points out some other data protection myths - it seems to be an update of an earlier ICO note on data protection myths and realities, also worth a look as it gives some other examples not in the later note (though unfortunately it's undated).

Now usually the stupid data protection duckout is probably not as bad as security questions which are too easy for bad guys to find out the answers to, as most of the time it's more annoying, irritating and time-wasting for consumers than outright dangerous.

However, there have been cases where it has had dire real life consequences. In 2003, 2 pensioners, George and Gertrude Bates, who had funds but were forgetful, died after British Gas cut off their gas for non-payment - and didn't tell social services about the disconnection because they thought the Data Protection Act didn't allow it. The ICO myths and realities note also noted complaints that "a gas or electricity company will not tell them whether their elderly relative or neighbour is in arrears and in danger of being cut off" using data protection as the excuse.

Another example (see e.g. Out-Law article) which is also well known - in 2004, Humberside police blamed the Data Protection Act for their failure to record information about 9 prior allegations against Ian Huntley, school caretaker and convicted murderer of schoolgirls Holly Wells and Jessica Chapman, who may not have been given that job if that information had been known.

The ICO have at least since produced a "Data Protection Good Practice Note: Providing Personal Account Information to A Third Party" which gives some examples of good and bad practice in this context, as part of a drive to produce more practical and user friendly guidance etc, but in my view a lot of it is just down to using common sense.

"Data protection" has also been used as an excuse by some public bodies hide information about their position or actions from the public. The European Ombudsman has expressed concern that European data protection rules were "being diverted from their proper purpose of helping to ensure respect for the individual right to privacy.. Instead, they are being used to undermine the principle of openness in public activities."

While that letter was written in 2002, it still holds true today: "data protection" should not be used to prevent the public from finding out information to which they are entitled. (In that context, the relationship between data protection and freedom of information is not an easy one, and in the UK the tension between them was considered in July 2008 by the House of Lords in Common Services Agency (Appellants) v Scottish Information Commissioner (Respondent) (Scotland) [2008] UKHL 47. I've not read it yet but it seems that it isn't necessarily much clearer how the balance between the two can be struck.)

National security

Another type of unnecessary restriction "for national security" relates to "security" guards and the like preventing people from taking photos in perfectly public places, notably transport hubs - train stations, bus stations etc. Recently I witnessed London Transport staff stopping a tourist in Liverpool Street Station from taking a photo of their companion outside the Tube barriers! (And see this Guardian comment on the difficulties faced by a white female photographer openly trying to take publicity photos of a (non-white) man in central London.)

That's really stupid. The smart way for a real terrorist to take pictures of intended targets would be to use a small concealed camera, hidden "spy cameras" are easy and not expensive to buy, ,and so tiny these days that no one would notice. And I've no doubt a lot of terrorists are smart. If someone is openly snapping pics, why on earth assume they must have some evil purpose in mind? And how would fuzzy pics of a Tube barrier help a bad guy, honestly?

(Digressing further, I also think it's stupid that because of the UK Criminal Justice & Immigration Act 2008 section 63 you can now be a criminal for just possessing "extreme pornographic images" of things which, if you did them, would be perfectly legal to do, even if others might think they were grossly offensive, obscene or disgusting. How can merely having a photo of something be worse than actually doing it? Though I'm not advocating evening it up by criminalising "obscene" acts! On the contrary, I think what adults do in private with informed consent is their business. Possibly, even if it's potentially life-threatening - look at dangerous "manly sports", they're perfectly legal aren't they? Double standards still rule.)

Does technology or modern life make you stupid?

Now on to stupidity and technology / the complexities of modern life and living.

The ICO had thought it appropriate to mention the DP duckout at the start of "Stupid Aid Week" (1-5 September in 2008), whose slogan is "Make Stupidity History".

Stupid Aid Week was started in 2007 by public relations consultant Andy Green after he "asked [in a restaurant] for a slice of lemon in my water and was told I couldn't have one because it would involve using a knife and that would mean carrying out a risk assessment... Stupidity is not about low intelligence, it's about inflexible thinking without asking questions... Whether it's being told 'the computer says 'No', facing an unhelpful call centre hiding behind 'data protection', or just inflexible 'jobsworths'. I'm trying to get people to stand up for themselves more and not be fobbed off."

Other examples he's given: a car running into another car because "the sat nav didn't show the T-junction"; and not being able to make a doctor's appointment more than 2 weeks in advance because the computer only allowed scheduling for up to a fortnight. And top 6 excuses for stupid decisions or stupid thinking (including "it's health and safety"!)

As he puts it, is technology (to which I'd add complex "data protection" laws and the like) getting in the way of common sense?

While his "Flexible Thinking Forum" is billed as a "not for profit social enterprise enabling businesses and organizations improve their people’s creative thinking skills", it doesn't seem to involve more than 1 person; there's not been much mass takeup of his Stupid Aid campaign (e.g. as I write no one has suggested even one example of stupid thinking on his submission page yet) but it's certainly an excellent way for him to promote his consultancy practice and his new book Overcoming Stupidity in the World Around You: The Stupid Aid Survival Guide, which is described as aiming to provide "practical tools, tips, ideas and inspiration of what to do when you are faced with examples of bureaucracy gone mad, daft decisions, or inflexible ‘jobsworths’". (No, I haven't got a copy.)

It's very clever indeed of Andy Green to get free publicity not just from the ICO but also from the AA and from the Institution of Occupational Safety and Health for his Stupid Aid Tour 2008 and book launch, but then he's a PR expert! (Though what's less clever is that he hasn't directly linked from the book's page to where to buy the book, and the press release for the book launch is only available in full in DOC format.)

By the way, I like the AA stupidity examples like councils wasting employee time and money painting double yellow lines in spaces so small that only toy cars could park there. And the IOSH is sponsoring, for a second time, the World Conker Championships on 12 October 2008 at Ashton, near Oundle, Northants to make the point about "health & safety" stupidity.

But is it really technology that's making people "stupid"? I don't think technology as such can be blamed. While it does seem that lots of computer use (as opposed to reading) can affect brain, personality and identity, in this context personally I wonder if the seemingly increasing abrogation of responsibility and refusal to think beyond rigid literal rules are partly due to information overload - there's too much you need to know about these days, it's too difficult to understand most of it, so the path of least resistance is just to stick your head in the sand, stick to reciting the rulebook, and not have to think about anything.

If modern society is to achieve a sensible balance between security and freedom / convenience, a lot more people will need to start putting on their thinking hats and taking their common sense pills!

Security, data protection, proof of identity: daft questions, measures, implementation





You have to answer a raft of security questions when trying to manage your account at your bank, credit card company or other financial institution.

But, are they the right questions? And are they asked appropriately?

What about other "security measures" used or insisted upon by institutions - are they commensurate with the risks they're supposed to address, do they even make sense in some cases?

Insecure security policies

Security questions - too easy!

Tom Morris has written an excellent blog post on "How to fail at security". He looks at the security information his bank asks him to provide to verify his identity, i.e. prove that he is who he says he is - which is very much the same sort of security information that banks and financial institutions generally, and indeed other kinds of organisations or businesses, require: date of birth, first school etc

And he noted how easy it is for other people to find the information needed to answer most of the standard security questions (e.g. parent's first name) correctly so they can masquerade as you.

This point was brought home with a vengeance a few days ago when hackers got into the Yahoo! email account of Sarah Palin, Republican Vice President nominee and running mate of the US Republican Party's 2008 Presidential candidate John McCain. The incident was widely covered in the media.

The BBC reported that it seems the hackers managed to access her account by resetting her Yahoo! password (i.e. they used the "Forgot your ID or password" link), answering the security questions correctly because they had found out her date of birth, zip code and other personal information through Wikipedia and other online databases.

A recent BBC 3 documentary aimed at young people called "Mischief: Your Identity for Sale", which was made before the Palin email incident, also showed how much personal data people innocently and unthinkingly make available to the world (including bad guys) on Facebook and other social networking sites, which can then be obtained and used against them for nefarious purposes.

Even before all this, I've gotten into the habit of giving a different birthday date and zipcode / postcode to different sites that require the information when you try to sign up, and yes different mother's maiden name etc too. I figure it's none of their business, most of the time they don't need to know anything more than my login details and the fact that I'm over 13 (for US sites) or over 18 in most other places. And of course, this practice makes things more secure for me - though I have to ensure I remember or keep a secure note of what site has which info!

Even so, one of the banking sites I use just requires real name, postcode, birthday and mother's maiden name to login. (And a password, not even a PIN, which may not survive a dictionary attack for long.)

Now Tom had suggested that banks should use digital signatures and other, better, security measures.

I'm not sure how that would work when speaking on the telephone; plus, non-geeks seem to have a big knowledge gap where digital signatures are concerned, though they've been around for years.

I'd be the first to say I don't know enough about digital signatures yet. I'm only starting to use GPG, myself, and I think it's still too difficult and inconvenient for the vast majority of non-geeks to use. Possibly digital signatures are still to hard to use as they've not been implemented widely enough and their implementation is still not effective or user-friendly enough for the average consumer.

Indeed, more often than not just digitally signing a clear unencrypted email simply doesn't work, because of how email systems (like Outlook) handle the email; it claims the email's not been properly signed even when it has been. Which won't help persuade the average non-techie to trust its reliability, will it? Normally the whole email needs to be encrypted before a valid signature will definitely be considered valid.

Other security policies

Here are other examples of other security policies which are not exactly helpful or secure.

Password security. It's received wisdom that to create strong passwords that are less vulnerable to being guessed or discovered by bad guys, a combination of upper and lower case letters, numbers and symbols should ideally be used.

But what does a customer trying to sign up for "My T-Mobile" find?

That's right, they actually stop you from using special characters (e.g. a hyphen - ), i.e. they actually stop efforts to make your password more secure.

Who has access to your password? A financial organisation recently sent me some information in a document which they'd password-protected with the password they originally sent me for logging in to their site. Now that particular document would have had to be manually passworded, so that means someone there had to be able to look up my login password for their system in order to be able password protect that document!

While I'm pleased they thought about password protecting the document before emailing it to me, and I can only login to view my personal financial information (but not to carry out any transactions), I'm not sure that allowing staff such easy access to customers' login passwords (and information about their financial positions!) is really a good idea. (There's no way to let me change my password online either.)

Proofs of identity

As for the supposed "anti-money laundering" proofs of identification that some banks or credit companies force applicants to provide, why can't there be more consistency across the different financial institutions in terms of the range of acceptable documents, how recent they have to be, and whether they have to be originals?

F'rinstance, one credit card company insists on getting your original photocard driving licence or passport (old style licence has to be less than 12 months old, but hello, if it's old style it's not likely to be recent! And why must documents without a photo be more recent than ones with?). Are you really going to trust the post, or indeed the bank, not to lose such an important piece of ID?

Another organisation will accept a certified copy of your passport etc - but only if signed it's and stamped by a bank, solicitor, accountant, doctor or police officer. "Actually I'm not ill, doctor, just thought I'd drop in, now sign here please". "Hello ossifer, can you just stamp and sign here, thag u bery much". I think not!

And stamps can be easily forged, so why on earth insist on one? What's to prevent bad guys from looking up a doctor or finding a local solicitor etc, checking the name of the general practice or law firm they work for, then forging their signature and applying a rubber stamp that has the name of the practice or firm on it? How on earth would the financial institution known the signature is genuine, or that the stamp really is the official stamp of the practice or firm? Do they have a copy of all signatures and pictures of what official stamps look like for every GP, solicitor, accountant etc? Again, I think not.

Council rent books or tenancy agreements or benefits documents are fine for some, but the middle income person is shafted again if they don't rent from a council and aren't on benefits.

Some firms accept e.g. a letter from your insurance or pensions company, but some won't. It's nice (or something...) to know a certified copy of a shotgun licence or firearms certificate is good enough for others, though!

Council tax statements are usually only issued annually so you can only provide one that's dated within the last 3 months for 3 months of the year. If you're applying for a credit card or bank account during the other 9 months, you can't use your council tax bill.

As for bank or credit card statements, are you kidding? My bank transactions and purchases are none of their business. And I'm not going to put my original bank or building society passbook in the post to them either! I'm only prepared to send them a gas or electricity utility bill, so thank goodness for quarterly bills. ("Letter from county court" is funny though - what about a court letter demanding payment of your hugely overdue debts, would that do?!)

With security questions and the like, there's sometimes the opposite syndrome too of "too much (unnecessary) security", when employees of banks, call centers etc insist on full "security details" even when they're completely irrelevant to the question you're trying to ask them because you're not wanting personal information or account information, you just want general info about the company or its service. My rant about that is in a separate post!

Saturday, 29 March 2008

"Strictly youth dancing - ministers join 'Strictly' stars and Royal Ballet to boost youth dance", pah





When I saw the above Dept of Culture press release headline (it was issued a while back, I'm slow!), first my mind boggled, then I got angry.

The initial image which that line conjured up in my mind's eye was of British ministers desperately trying to be hip, awkwardly trying their hand, or rather shuffling feet, at joining the "yoofs" in dance - and it wasn't a pretty picture. Even if mildly amusing.

Then, I got annoyed. Talk about making Dumb Britain worse. Why aren't they putting as much money into "supporting" young people into the sciences? Oh no, kids in the UK need to be helped into dance. I'm as much of an arts fan as the next person, e.g. I love music and the vocal arts, but more money ought to be going into what's much, much harder to do: firing children's imagination about science, stimulating their intellectual curiosity about the world. I'm not even going to start about the educational system in the UK generally. Oh wait, I have.

The 19th century was the century of the British Empire, the 20th of the American. The economic powerhouses of the 21st century will be from the Asia-Pacific / India - and no one should be at all surprised. Decline and fall, indeed.