Thursday, June 26, 2014

A Canadian CASL

On July 1st the Canadian Anti Spam Legislation act (CASL) will come into full effect and you are probably not aware it even exists.
How appropriate that the world's toughest legislation against unsolicited email would come into force on Canada Day.

If you are not aware of the CASL project, here is a little light reading for you.
 - The gov.ca website dedicated to CASL: http://fightspam.gc.ca/eic/site/030.nsf/eng/home
 - The specific regulations governing CASL: http://fightspam.gc.ca/eic/site/030.nsf/eng/00273.html
 - The actual full text of the law: http://laws-lois.justice.gc.ca/eng/acts/E-1.6/index.html
 - A great report from Deloitte on the impact of CASL: http://www.deloitte.com/...

There is a great deal more to tell, but first you may be asking why you might care.  Well, you know those annoying SPAM messages you keep getting in your email, even though you have clicked "unsubscribe" 20 times?  Now you can take strong legal action against any one of the people or companies that send those to you.  This is real and the Canadian government is very serious about protecting Canadian mail boxes.

Even better, this does not just affect people *IN* Canada, it applies to all Canadian citizens regardless of where their email inbox lives.  That means that if you live in Toronto and you use a Hotmail inbox in Seattle, you are still protected.  If you live in Vancouver and your mailbox is in Florida, this law still applies to you.

This is the scariest thing to happen to spammers in 40+ years of email history.  It may also be the most progressive thing to happen to netizen rights in the history of the Internet.  You may have noticed that in the last week or so, many of the mailing lists you subscribe to have been sending you a small reminder to confirm your request for their mail.  Any responsible sender who knows you are Canadian, has been reaching out to make sure you are ok with their newsletters and marketing messages.  No one wants to get caught on the wrong end of this big stick.

This is great news for Canadian citizens.  This is the first time in history that Canadian citizens have the power to directly and financially impact an offending SPAM sender in an impactful way.  If you skipped over that link above to the CASL website, you may want to go back and take a look as there are good resources for individuals to help identify spam as well as how to enforce the act.

The history behind CASL goes back several years and really owes some lineage to the CANSPAM project [ http://en.wikipedia.org/wiki/CAN-SPAM_Act_of_2003 ] enacted in the US in 2003. While the rules have good intention, and all responsible senders do their best to follow them, active spam senders are aware of how difficult it is to actually enforce them and penalize the offenders.  By the time CANSPAM was put into place, it had become a list of standards of good practice as opposed to an enforceable law. The good news is that the responsible senders who follow CANSPAM make it very easy to join and remove yourself from a mailing list.  CANSPAM was the first kick at controlling SPAM and has been effective with legitimate senders, but has been relatively "toothless" on actual illegal senders.  Relatively few (less than 20?)  known "spammers" have be affected by any real penalties or jail time.

CASL is an actual law that is enforceable, and that should have known spammers thinking twice about sending Canadians any unsolicited mail.  The people and companies named on the Registry Of Known Spam Operations list (ROKSO) should be especially worried.  CASL has real penalties that hurt where it counts.
"The maximum amount of [cash penalty], per violation, for an individual is $1 million, and for a business, it is $10 million."
- CASL FAQ 

This means that if a spammer refuses to take you off their list 5 times, they can be fined up to $50 Million CAD.  Don't be that guy.

Time will tell if CASL has more threatening teeth than CANSPAM.  It will be interesting to watch this play out.


Oh.. Happy Canada Day :)


Tuesday, April 29, 2014

My son is not a statistic.


There is a notice on my fridge.  It is pinned there with a magnet right under the words "PARTS ARE NOT CURRENTLY AVAILABLE".  It has been there for over a month and every day there is growing fear that my son's 2007 Pontiac G5 could become a death sentence.

The letter (posted in full below) starts by essentially saying 'The government says we have to tell you about this' and then follows by minimizing the potential risks down to "... a partial loss of electrical power and turning off the engine".   There is also the very real risk of this fault also disabling power brakes, power steering, airbags, and this has been public knowledge for over a year.  Even worse, the fault was known to General Motors as early as 2005.  This particular defect is found in 2.6 Million vehicles in North America and has been linked to 13 known traffic fatalities.

The really tragic part of this whole thing is that those lives may have been saved if GM line management had listened to their own engineers who identified a simple fix for under a dollar a piece. As far back as 2005,  company engineers proposed solutions for the switch problem, but GM had concluded that none of those fixes represented "an acceptable business case."  The parts to fix the problem could have amounted to as little as $0.57 not including labour.

GM has obviously known about this problem for some time and they do have replacement parts that are available for only $30US, yet based on the recall notice tied to my son's car, "PARTS ARE CURRENTLY NOT AVAILABLE".  Yeah...

I would prefer that my son not become a statistic in a class action lawsuit.  It should never have come to this.  There are too many stories like this one and a common buyer for these vehicles are young adults.  General Motors knew about the problem and they ignored it, even after traffic deaths had been linked to the defect.  Parts are available, yet for some reason, they have not taken the time to ramp up production to fill these orders adequately, even though they have known about this problem for almost a decade.

Large companies like this have an even more important responsibility to their customer's safety and when they make a mistake, they should fix it.  When they knowingly ignore a potentially deadly defect, they should be punished appropriately.  The $1.3 Billion charge for recalls is a pin prick in their $37.4 Billion Q1 revenue.  As large as that number sounds, it is hardly punitive for a massive company like General Motors.  This is a $500 Billion Company so it is hard to imagine how any actual dollar amount could have any real impact.  More to the point, no dollar amount will ever make me trust them again or bring back the 13 lives that were lost to this incident.  This is one of those times when a corporation should not be able to shield it senior executives from the harm their decisions can result in.

Please help raise awareness and make GM get serious about actually resolving the problem they caused.




Friday, April 11, 2014

Heartbleed (yes, again)




I usually refrain from jumping on the common news bandwagon and just reposting already circulating
ideas, but I think the "heartbleed" security flaw is an important enough exception.  It is really (really, really) important that people know what this is and how to protect themselves, so I may be repeating information you already knew here.

Heartbleed [http://heartbleed.com/] is a compromise of the Secure Socket Layer (SSL) that drives secure communications on the internet.  Essentially, any web site where you may see HTTPS:// as opposed to HTTP:// could potentially be at risk.  Any secure communications using SSL based on OpenSSL will be affected.  It is a pretty big deal.  This xkcd comic does a great job explaining how the exploit works [http://xkcd.com/1354/]

Many companies use SSL to protect and secure their email, IM, and other private data when sending between servers and every one of those secure certificates will need to be discarded and rebuilt.  That causes down time and unique maintenance headaches for every server administrator.

Even if companies don't transport information using SSL, their web hosts (all of them) will need new security keys and that involves not only the generation of the cert, but stopping and restarting web services and everything that goes along with that.  It is a LOT of work.  Elastica Inc has a pretty decent Video here if you want a longer explanation.

BTW… you should change all your passwords.... NOW.  Even though you probably do not have any SSL protected data of your own, the servers you connect to *do*.  Lets say you use the same password  and username for several services - admit it - you do so do that.  If some "bad" person used this exploit to get your username and password from a server, they can then use that information in any number of other sites you also use that information on.

This is not just a password hack though.  This bug allows the adjacent data from memory (up to 64kb blocks) to be returned from the server unencrypted and untraceable. That means that any other data in the server may be returned to someone exploiting the bug.  Scary stuff.

This is being taken very seriously by everyone in the IT world and in some cases, it was easier just to shut down access to all servers while the software was being patched.

If you have any doubt about any service you use, there is a tool here you can use to check if a site has been patched. [http://filippo.io/Heartbleed/]

UPDATE:
I know there are many sites and blogs out there that are saying you don't need to change all your passwords, but I will disagree.  If you use a unique password everywhere then sure, you are fine, but if you are one of the millions of people who reuse passwords because it is too hard to remember them all ( admit it, that is you) then you need to change them all.  If you happened to reuse a password from your secure and unaffected bank login on a site that is affected, then there is potential for your credentials to have been compromised.


Sunday, March 16, 2014

Random thoughts and learning

Over the past year I have learned many important things I think are worth sharing.  Hopefully these tidbits will be worth something to others as well.

It takes exactly eight minutes to warm a bottle of homo (3.5%) milk.  Young parents have a whole new set of stresses to deal with but also a whole range of new assisting technology available too.  Automatic bottle warmers, network enabled video monitoring, and Internet help forums are only a few of the things I had wish I had twenty years ago. On the other hand, Internet bullies, social network predators, and infinite access to global information make guidance and parenting much more difficult.

School is overrated. When I entered my first round of post-secondary education nearly thirty years ago (*cringe*) the accepted and proven way to get ahead was to 1) get a degree, 2) get a good job with it and then 3) earn your way to the top through promotions in the classic way.  Boomers institutionalized that process, gen x accepted it, gen y rebelled against it and Millennials just bulldoze past it.  Today, the Internet and all its connected facilities make it possible for bright young entrepreneurs to bypass that old process.  They get an idea, then learn it, master it, and build a business out of it… often while they are still in high school.  The number of C-level executives in their twenties is impressive.  Note to Boomers and Gen X… the rules have changed.

It’s always a good day for a tutu. Seriously, life is too short to fill it with unfulfilling activities and stress.  Play.  Enjoy. Revel in life. Work does not have to be boring and oppressive. The most productive and successful people I know do not see their work as ‘work' at all.  When making a living is consuming your entire life, it is time for a change.

Power is shifting.  There is a global revolution going on through several fronts. The planet’s youth are all connected in spite of the establishment efforts to control communications.  The Internet cannot be contained – that ship has sailed, genie is out of the bottle.  Citizens in Beijing and London and Toronto and Kiev and Cape Town can share ideas, form alliances, and rebel in amazingly coordinated ways.  When companies do bad things they are no longer buried by corrupt media and governments.  The information is in the blogosphere within seconds and replicated instantly.  World governments, you no longer control the masses.   Individuals now have all the information, and information is power.

I’m only dancing.  Entire concepts of relationships have been shattered and re-imagined. You could put all kinds of labels on it but the fact is that labels are irrelevant to most of the twenty-something people I know.  They are much more focused on the concept of loving who you love and ignoring what the rest of the world wants to call it.  That level of free and open respect may take a while to catch on, but it is here and it is real.

The world is tiny and your friends are only a click away.  I thought I was progressive when I knew I had several on-line friends in other countries.  That is now old news.  Your teen aged children and a whole generation of ‘Millennials’ have friends all over the globe and don’t even know where they actually live.  Country borders are irrelevant and there is no real difference between on-line and off-line friends. 

Those are the highlights as I ramble out a stream of consciousness.  They may seem like random and disjointed thoughts but that is the other thing I have discovered… information happens in blobs, not streams.

Friday, January 24, 2014

Situational Awareness

The furnace guy was here yesterday.  Nice guy.  
Fixed up a few things and did a tune up.  No worries.  
Handed me a bill for $100 or so and all is good.

Then he says "Your ohms are a little high.  I read 4.3 and we normally like to see that under 4"

"... Um... ok... what does that mean to me?" I asked.  "Is that a bad thing?"

He looked at me like I was asking him to explain quantum mechanics.  Clearly we were already having a communication issue.  He seemed to be gathering up some patience to explain to me in simple words what that really meant and then said  "The resistance in the thermocouple in the furnace, it is a bit high so you should consider replacing it."

"Okay, thanks" I said " I still have no idea what that means.  Should I get you guys to replace it at the next service then?"

He smiled a bit, obviously happy he had gotten that through my thick skull.  "Yes, that would be good"

"Ah, okay then."  It seemed we were communicating in english again.

He finished up the credit card paperwork and as he was heading for the door he said "Oh, and the AFUE was at around .9 and I was able to get it up to .95 so that should help out a bit"

His proud smile did not change the fact that I had no clue what that meant.

"Great, I think.  What exactly does that mean?"  I was trying not to sound completely ignorant, but it was clear now that I was completely incompetent in the realm of the furnace repair gods.

"You should save about $20 a month in gas" he said, having finally stooped to my level, needing to reply in tiny words I could relate to.

"Oh, thanks, I appreciate it"



The lesson here is that people who work in a technical field tend to assume everyone knows their terminology and what it all means.  I have been working in the computer/software/electronics industry for a very long time and have seen this over and over and over everywhere I go.  One of the hardest things for a technically oriented person to do is translate complex concepts into terms that are consumable by people who are not so deeply involved in technical details.  This is what makes a good Sales Engineer very valuable to a sales organization. 

Translating complex technical concepts into business needs and strategic goals is a difficult skill to hone, but Project Managers, Implementation Engineers and Sales Engineers need to be very good at that in order to make sure the client has a clear understanding of what the technology will do for them as opposed to how it works under the hood.

In a former life, I made it a periodic exercise to have my engineering team watch out for this kind of thing in their daily personal interactions and it is amazing how much it happens.  The roofing guy assumes you know everything about the benefits of asphalt shingles over clay.  The car mechanic assumes you know the difference between "Dot-3" and "Dot-5".  The mortgage person assumes you know why GDS and TDS are different and how to calculate both.

When talking to your own customers it is no different.  The fact that a customer has been successful in business does not immediately imply that they have any clue *why*.  I have personally spoken with customers who have surprised me by not knowing some important technical details of how their business runs, but that is okay if they understand the business value it can bring them.  Trying to inject technical jargon into a conversation about business goals can be dangerous and inappropriate so it is important to always gauge the situation and the audience.

I have no idea how my furnace works, but "the furnace guy" did *something* to save me $20 a month and I am warm so I am also happy.

Sunday, January 5, 2014

HAPPY NEW YEAR

HAPPY NEW YEAR !!!

Ok, enough of that.  Lets get down to business.

I am going to agree wholeheartedly with a number of my friends in asserting the sentiment "don't just wish for a happy new year, make it happen".  Be the change you want to see, proactively engage, change the universe from your small corner of it.  Forward!

I'll start with this blog and focus more on the type of content I put in it as well as the audience it serves.  For the past several years, I have used this as a random outlet, but clearly readers are interested in helpful tidbits like Fixing my Keurig B60 coffee maker (22,800 hits) and  Nerf Gun Meeting Control (50,100 hits) so I will be posting much more of that type of content here.  If I can help people be more effective and self sufficient, I'll call that a win.

Next on this list is just to "live".  Going through the motions, earning a living, paying the mortgage is not enough.  Not for me, not for anyone.  I envy so many of the young people in my life who were raised in a time that was not entirely focused on "grow up, get a job, work hard, then die".  We all must play more.  Focus this year is on improving my golf game.

Another big focus this year will be to continue work supporting social change and the efforts of people in developing countries.  North Americans spend far too much time whining about first world problems when there are entire populations who need clean drinking water.  Forget the 1%... What can the 99% do to help each other?

I am planting a stake in the ground and marking this as a year of revolutionary change.  I see that on business, personal and social levels.  I will be a catalyst for change and societal norms will not get in my way.

As we say in Calgary, its time to Cowboy Up.  Hope you all come along for the ride.


Wednesday, December 18, 2013

A Christmas Story


Yusef ben Ya'akov was a carpenter in Natz'rat near the sea of Galilee.  He was a good man and a fine carpenter.  He was working when he first heard the decree from Rome that all citizens were to return to their family home to be counted.  For Yusef, that meant traveling to Bet Leḥem, the ancestral city of David.  It meant leaving his home in Natz'rat with his betrothed wife Miriam and walking to the city he had left a few years earlier far to the south.  Miriam, at the time was quite heavy with child and due to deliver in only a few weeks.

Miriam, daughter of Joachim left her home in Natz'rat with her betrothed husband shortly after the degree. Emperor Augustus required all citizens to return to their traditional family homes and since Miriam and Yusef were both of the house of David, they both needed to return to Bet Leḥem in Judea.  Traveling at this time would prove difficult as she was only weeks away from giving birth.

Yusef and Miriam could not make the long journey on foot so Yusef enlisted the donkey he had used for work to carry Miriam.  It was near the end of harvest now and in a few more weeks the weather would grow colder, so now was the best time to move. There was hostile land on the direct path, so they chose to take a safer route to the east, but that also took longer, even with one of them on the back of the donkey. It took a good 10 days of travel to reach Bet Leḥem, and they were glad to be done with the travel.

On their arrival, Yusef was able to locate a very small room to stay in.  It was tiny, and adjacent to the stable, where some shepherds had been staying at night. He was also able to find work to keep them fed while they waited for the census counters to mark them counted.  In the time that followed, Miriam gave birth to a son and they named him Yeshua as they had both been instructed in dreams.

One clear night several days after the Miriam gave birth, Yusef picked up the child from his bed of straw.  The days were getting colder and the stars we shining with a crisper edge.  He looked deep into Yeshua's eyes and whispered "You will be a strong boy and I will teach you to be a fine carpenter. You will build and mend, and you will be kind to all you meet."

How could he know, looking down at this tiny child, that hundreds of generations from now, in a land he had never heard of, people would call this child not Yeshua ben Yusef but  King of Kings, Prince of Peace, Jesus Christ.


Merry Christmas.